How hackers start selling data center logins for some of world’s largest corporations

The previously unreported data caches involve emails and passwords for customer-support websites for two of the largest data center operators in Asia: Shanghai-based GDS Holdings Ltd. and Singapore-based ST Telemeter Global Data Centers, according to Re-security Inc., which provides cybersecurity services and investigates hackers. About 2,000 customers of GDS and STT GDC were affected. Hackers have logged into the accounts of at least five of them, including China’s main foreign exchange and debt trading platform and four others from India, according to Re-security, which said it infiltrated the hacking group.

 

 

 

It’s not clear what - if anything - the hackers did with the other logins. The information included credentials in varying numbers for some of the world’s biggest companies, including  Alibaba Group Holding Ltd., Amazon.com Inc., Apple Inc., BMW AG,  Goldman Sachs Group Inc., Huawei Technologies Co., Microsoft Corp., and Walmart Inc., according to the security firm and hundreds of pages of documents that Bloomberg reviewed.

 

 

 

Responding to questions about Resecurity’s findings, GDS said in a statement that a customer support website was breached in 2021. It’s not clear how the hackers obtained the STT GDC data. That company said it found no evidence that its customer service portal was compromised that year. Both companies said the rogue credentials didn’t pose a risk to clients’ IT systems or data.

 

 

 

However, Re-security and executives at four major US-based companies that were affected said the stolen credentials represented an unusual and serious danger, primarily because the customer-support websites control who is allowed to physically access the IT equipment housed in the data centers. Those executives, who learned about the incidents from Bloomberg News and corroborated the information with their security teams, who asked not to be identified because they weren’t authorized to speak publicly about the matter.

 

 

 

The magnitude of the data loss reported by Resecurity highlights the growing risk companies face because of their dependency on third parties to house data and IT equipment and help their networks reach global markets. Security experts say the issue is particularly acute in China, which requires corporations to partner with local data service providers.

 

 

 

“This is a nightmare waiting to happen,” said Michael Henry, former chief information officer for Digital Realty Trust Inc., one of the biggest US data center operators, when told about the incidents by Bloomberg. (Digital Realty Trust wasn’t affected by the incidents). The worst-case scenario for any data center operator is that attackers somehow get physical access to clients’ servers and install malicious code or additional equipment, Henry said.  “If they can achieve that, they can potentially disrupt communications and commerce on a massive scale.”

 

 

 

The hackers had access to the login credentials for more than a year before posting it for sale on the dark web last month, for $175,000, saying they were overwhelmed by the volume of it, according to Re-security and a screenshot of the posting reviewed by Bloomberg.

 

 

 

“I used some targets,” the hackers said in the post. “But unable to handle as total number of companies is over 2,000.”

 

 

 

The email addresses and passwords could have allowed hackers to masquerade as authorized users on the customer service websites, according to Re-security. The security firm discovered the data caches in September 2021 and said it also found evidence the hackers were using it to access accounts of GDS and STT GDC customers as recently as January, when both data center operators forced customer password resets, according to Re-security.

Enjoyed this article? Stay informed by joining our newsletter!

Comments

You must be logged in to post a comment.

About Author