Skip to main content

Security experts Kaspersky report advanced hacking attack against its own network

A row of padlocks on a computer screen. The middle one is colored red and is open, indicating it is insecure.
Image used with permission by copyright holder
Kaspersky, a high-profile company in the computer security business, has rather ironically, been hacked. In a blog post titled, “Kaspersky Lab investigates hacker attack on its own network,” the Russia-based outfit said it’d recently discovered an “advanced attack” on its own internal networks.

CEO Eugene Kaspersky described the breach as “complex [and] stealthy,” adding that it was “quite confident” a nation state was behind it. He declined to name any names. Kaspersky said the recently discovered malware exhibited similar characteristics to a Trojan named Duqu, which received widespread coverage in 2011 after being used in attacks against Iran, India, France, and Ukraine.

Recommended Videos

Keen to reassure those who use its products and services, the security firm said that neither had been affected by the attack, “so our customers face no risks whatsoever due to the breach.” It added that no customer data had been taken by the hackers. Kaspersky said that although the company is still investigating the incident, he believes that “the prevalence of this attack is much wider and has included more top-ranking targets from various countries.”

So why exactly was Kaspersky Labs among those targeted by hackers? The company is adamant the cybercriminals were intent on finding out more about its latest technologies, among other things.

“The bad guys also wanted to find out about our ongoing investigations and learn about our detection methods and analysis capabilities,” Kaspersky said in his post. Of course, if a company in the business of computer security can’t make sense of a hack on its own systems, then what hope is there for the rest of us? Thankfully, Kaspersky Labs now appears to be on top of the situation, and is promising to use the incident to further improve its defensive technologies.

Addressing the fact that some may question why a company in the business of computer security would report an attack on its own systems, Kaspersky said it was simply the right thing to do, and that it could happen to anyone. As he wrote in his post: “There are just two types of companies – those that have been attacked and those that don’t know they’ve been attacked.”

Trevor Mogg
Contributing Editor
Not so many moons ago, Trevor moved from one tea-loving island nation that drives on the left (Britain) to another (Japan)…
Experts found a record number of zero-day hacks in 2021
A digital depiction of a laptop being hacked by a hacker.

Google has published the 2021 review of Project Zero, revealing a record amount of zero-days exploits (labeled as “one of the most advanced attack methods”) exhibited by some of the world’s largest technology companies.

Project Zero is an initiative started by Google in 2014 aimed at detailing security defects known as zero-day exploits. These vulnerabilities are dangerous as they essentially remain undetected unless a mitigation system has been implemented, thus leaving systems, databases, and the like completely exposed to hackers.

Read more
Tesla factories’ security cameras caught up in wider hack
Tesla Gigafactory

A Silicon Valley startup offering cloud-based security camera services has had its systems breached in an attack that gave hackers access to numerous live feeds, some of them coming from Tesla factories.

Verkada, which launched in 2016, had around 150,000 of its cameras hacked, with many of the devices installed in hospitals, schools, police departments, prisons, and companies that besides Tesla also included software provider Cloudflare, according to a Bloomberg report on Tuesday, March 9.

Read more
Ring’s defense of recent hacks is as shoddy as its security, lawyer claims
ring door bell illustration

After a series of Ring camera hacks, the Amazon-owned security company has claimed that any intrusions into its customers' cameras or accounts were perpetrated by hackers who obtained login credentials from hacking forums or the dark web, not from the company's database.

Lawyers representing some of the hacking victims in a class-action lawsuit against Ring told Digital Trends that their clients used unique passwords that could not have been hacked anywhere else.

Read more