An attack on sites in the Gawker blog network has led to an alert about passwords on other sites and an investigation by the FBI. A group called Gnosis stole account information for 1.3 million of Gawker’s 1.5 million registered users, including passwords and e-mail addresses.
Yahoo, Twitter, LinkedIn and the online World of Warcraft, among others, have requested that users change their passwords as a result of the attack. Gnosis said it hacked Gawker because of its “arrogance.”
Gawker sites had criticized the hacker group 4Chan, which has reportedly been involved in recent online attacks against MasterCard’s site. The MasterCard attacks were in response to the credit-card company’s closing WikiLeaks’ account following the controversy surrounding WikiLeaks’ release of classified government documents.
‘A Monster Release’
The sites in the Gawker network that were compromised were Lifehacker, Gizmodo, Jezebel, io9, Jalopnik, Kotaku, Deadspin and Fleshbot. Registration is required on those sites if a user wants to comment.
The purloined e-mail addresses and passwords were posted on peer-to-peer networks in a large file. Along with the download, Gnosis posted a note. “So, here we are again,” the note read, “with a monster release of ownage and data droppage. Previous attacks against the target were mocked, so we came along and raised the bar a little.”
Earlier this week, the New York Post reported that the FBI was meeting with Gawker Media CEO Nick Denton to look into the matter.
A column about the attack was recently posted on Lifehacker. “We understand how important trust is on the Internet,” the column noted, adding that Gawker was “deeply sorry for and embarrassed about this breach of security — and trust.” The column, written by “the management of Gawker,” said the sites were “working around the clock” to ensure security, and recommended changing user passwords on other accounts, especially if the same…