Chinese firm issues US recall after massive cyberattack

Image
AP Beijing
Last Updated : Oct 25 2016 | 4:48 PM IST
A Chinese electronics maker has recalled millions of products sold in the US following a massive cyberattack that briefly blocked access to websites including Twitter and Netflix.
Hangzhou Xiongmai Technology said in a statement that millions of web-connected cameras and digital recorders became compromised because customers failed to change their default passwords.
The hack has heightened long-standing fears among security experts that the rising number of interconnected home gadgets, appliances and even automobiles represents a cybersecurity nightmare. The added convenience of being able to control home electronics via the web also leaves them more vulnerable to malicious intruders, experts say.
Unidentified hackers seized control of gadgets including Xiongmai's on Friday and directed them to launch an attack that temporarily disrupted access to a host of sites, which also included Amazon and Spotify, according to US web security researchers.
The "distributed denial-of-service" attack targeted servers run by Dyn Inc, an internet company located in Manchester, New Hampshire. These types of attacks work by overwhelming targeted computers with junk data so that legitimate traffic can't get through.
"The issue with the consumer-connected device is that there is nearly no firewall between devices and the public internet," said Tracy Tsai, an analyst at Gartner, adding that many consumers leave the default setting on devices for ease of use without knowing the dangers.
Researchers at the New York-based cybersecurity firm Flashpoint said most of the junk traffic heaped on Dyn came from internet-connected cameras and video-recording devices that had components made by Xiongmai. Those components had little security protection, so devices they went into became easy to exploit.
In an acknowledgement of its products' role in the hack, Xiongmai said Monday that it would recall products sold in the US before April 2015 to demonstrate "social responsibility." It said products sold after that date had been patched and no longer constitute a danger.
Liu Yuexin, Xiongmai's marketing director, said in an interview on Tuesday that Xiongmai and other companies across the home surveillance equipment industry were made aware of the vulnerability in April 2015. Liu said Xiongmai moved quickly to plug the gaps and should not be singled out for criticism.
"We don't know why there is a spear squarely pointed at our chest," Liu said.
The company, which also makes dashboard cameras and computer chips, said it would recall more than 4 million web-connected cameras and has offered customers a software security fix.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Oct 25 2016 | 4:48 PM IST

Next Story