LowEndBox - Cheap VPS, Hosting and Dedicated Server Deals

Blesta Hacked - Ransom Gang Threatens to Leak Customer Details Tomorrow

BlestaYesterday Blesta customers received an email from support@blesta.com informing them that Blesta’s servers had been hacked.  The criminals state that they’re holding customer data hostage, awaiting ransom payment from Blesta.

Now at first you might think, well, this is just a ransom scam, the sort of “fake breach” emails that circulate regularly.

However…the emails appear fully authenticated, with SPF, DKIM, and DMARC, and were sent through Blesta’s own infrastructure.  Eeek.

We should caution that just because someone compromises an email system does not mean they’ve compromised everything.  But if what the email claims is true, this is potentially catastrophic.  Blesta is a popular billing system, and holds customer data, API keys, automation info, and more.  If Blesta is compromised, this breach could cascade very widely.

No word from Blesta yet.

Check out this article on Webhosting Today with full details.  Thanks to RackNerd for alerting us to the news!

No Comments

    Leave a Reply

    Some notes on commenting on LowEndBox:

    • Do not use LowEndBox for support issues. Go to your hosting provider and issue a ticket there. Coming here saying "my VPS is down, what do I do?!" will only have your comments removed.
    • Akismet is used for spam detection. Some comments may be held temporarily for manual approval.
    • Use <pre>...</pre> to quote the output from your terminal/console, or consider using a pastebin service.

    Your email address will not be published. Required fields are marked *