What Australian business owners need to know about the current exploitation campaign targeting their websites

On a long enough timespan, even the most well-built structures will start to degrade and eventually collapse.

Last week the Australian government released a technical report that there has been a large-scale global exploitation campaign targeting website content management systems, which many Australian small businesses use.

If you have a business website in Australia, there’s a high likelihood that it has been targeted by a sophisticated scheme by international parties to harvest your data, and the data you hold of your customers’ data.

In some cases, they will have succeeded.

What does this mean for Australian website owners?

According to the ACSC Cyber Security and Australian Small Businesses 2023 report (link):

Australian businesses face increasingly sophisticated and capable cybercriminals targeting what matters most to them; their money, data and reputation.

If you’re affected, it means you and your customers may have had their personal data taken by foreign scammers, spammers, and otherwise unscrupulous fellows. They may get targeted by these people using various scams, which are becoming increasingly sophisticated.

Your website’s records can be immediately copied to anywhere in the world and dissected, sold, or worse.

But how could this happen?

If you’re not familiar, running a content management system (CMS) is essentially like building a portal that opens up access to the nuts and bolts of a website.

Not only can one do the normal things we might expect to do to a website, such as editing a page or article’s contents, or change its template to show or hide specific components, it can also include various integrations to other aspects of your business.

These integrations can get very personal very quickly. The initial direct communications a website has with its business’ eventual customers, which is usually facilitated by a contact form being submitted, which then sends an email or two, is often storing this data – sometimes for months, sometimes for years, sometimes forever.

But not only that – if you run an ecommerce store only, your customer purchases are usually stored there indefinitely. It’s often used to track store inventories.

What does this mean for web developers and website hosting businesses?

If any of your sites have been infected, it’s your first and foremost responsibility to fix the issue – without trying to upsell services during a disaster – and then to accurately and comprehensively report the incident to all involved parties.

The discussion around payments can come later, if at all, because first you need to rebuild all of the trust you’ve just lost.

First steps if you detect that your website has been infected

You need to get your friendly web developer to confirm whether any of your websites or servers have been affected. But generally, follow these rules:

  1. Inspect the CMS for evidence of foul play, such as:
    • Any unknown users in the content management system with administrator access
      • Many of them intentionally use innocuous names like “admin” or “backup”
    • New plugins created in the directory that shouldn’t be there
      • Many of them, however, will intentionally hide or delete themselves after execution, so you may only be able to tell based on the folder’s last modified date
    • Executable scripts in the uploaded content directory
      • Many exploitations start by allowing for certain types of files that can then be used to execute code remotely
  2. Once a website content management system has been identified as compromised, immediately start writing an incident report and log when, how, and by whom the malicious entity was discovered, as well as the steps taken to mitigate the issue
    • Your firm should ideally have an incident report template or process, so that should be followed
  3. Treat servers with identified tampering as compromised, then isolate it and audit the network log
    • In this process, if possible for recording-keeping, you want to ideally grab the offending IP address and exact time the connections and attempts were made
  4. Restore the site to the most recent “known-good” backup

Once the website has been restored to a good state, all contained software + plugins must be updated before bringing the site back online. It then needs to be monitored to ensure that the exploit does not continue – as they often include multiple insidious ways of reinstalling themselves even after the website has been “cleansed”.

What should Australian business website owners do?

In my opinion, we should all be honest about what happened.

This issue happened because these exploits targeted known software vulnerabilities, and in most cases there were patches publicly available.

Honestly, this was caused by an extended lapse in judgment.

So who is to blame for the business website vulnerabilities?

It’s not always productive to play the blame game, but it does need to be investigated and understood by all parties. It should be noted that it is not intended to punish anyone, but to be used as an area for learning.

If you pay for website hosting with maintenance and support, and your business website was still compromised – it seems fairly clear-cut whose fault it was.

But what if the business is paying for quarterly maintenance – where the website gets updated once every 3 months, and the exploit happened within that period of time?

Regardless, if you pay for website hosting and your business website was compromised, you should be having a frank discussion with your web hosting IT services folk about precisely what data could have been stolen, and what steps have been taken to document and mitigate the issue, and what steps are being taken to prevent it from happening again in the future.

If your web host offered maintenance plans as an optional service and your business decided to self-manage website security, then you are both to blame.

Firstly, the business owners who decided to forego paying for website security to cut on costs are to blame – but secondly, the web hosts who knowingly let their customers host websites on their own infrastructure without continuously applying updates, allowing them to be exploited, are just as much to blame.

How to fix the issue when our customers’ personal data has been stolen

Once your business website was infected, the dastardly deed was done – the exploiter is immediately able to make a full copy of the entire site and download to recreate offline, so you’ll never know which parts have or have not been accessed.

So all we can do now is to do what we can to help our customers.

By reaching out to our customers and telling them the truth about what happened – telling them what you currently know, and what you’re doing about it – they may eventually begin to trust us again.

Tell them that, despite the circumstances, you do take their privacy seriously and are actively working to regain their trust.

Apologise, and actually mean it.

Own it, learn from it, and make sure it doesn’t happen again.

What to do if no customer data has been stolen

Even if your website has not been compromised, you can craft a message to your customers letting them know that your company or employees will never ask for bank details or your credit card number online.

Every few months, it’s worth sending a message or two like this as a security heartbeat, of sorts. And the more often it’s done, the more normal and less surprising it feels.

What to do about potential website vulnerabilities, going forward

There’s no single definitive answer about what is best for business website vulnerability mitigation, but there are some general trends one should follow:

  • Live website software should be set to automatically update
    • If that’s not possible, it should at least follow a weekly, rather than monthly or quarterly, plugin update cycle
  • Monitor or block the ability to create files in the execution environment
    • Making live-accessible directories read-only
    • If there needs to be a process for getting plugins installed on a website, consider adopting a formal process for this
  • Restrict the amount of users with full access
    • Lower levels of access for non-essential users
  • Regularly reset passwords, and use a dedicated password manager
  • Consider adopting more cloud services where it makes sense – for instance, the form processor doesn’t need to happen within the website, but can be handled using an external service

If you are currently, or know anyone currency experiencing a mass-scale website vulnerability, please contact us for a free website audit and we’ll see how we can help.