IBurst hacked

08.11.2005
In the middle of last week, a hoax e-mail was sent to WBS's iBurst subscribers saying that the company had reviewed its packages and billing.

A reader contacted Computing South Africa, having first picked up the story on the MyADSL forum. The e-mail, which appeared to have come from WBS's mail server, said: "As of 1 December, future and existing iBurst subscribers will have their usage cap doubled at no extra cost whatsoever."

iBurst head of marketing, Jacki Mpondo-Hendriks, says that the e-mail was a hoax, and that this was communicated to the iBurst subscribers. However, the hoax goes much deeper, it seems.

A subsequent posting on MyADSL revealed that the hoax e-mail was sent by [a group of] hackers, who gained access to iBurst's back-end systems via a known vulnerability.

The posting on MyADSL read: "...apologies to everyone who thought our last e-mail was for real. We just wanted to get some public awareness and pressure going, and we felt this would be the best way. We hope that iBurst will take our recommendations into consideration, and secure their damn servers properly."

The posting goes on to say that channel partners had been sent another mail from WBS's mail server indicating that iBurst's systems had been compromised and that their details were exposed.