CNVD Law says website not defaced, confirms ‘failed brute-force’ attack
- Cybersecurity, Hacking
-
Photo courtesy of Deep Web Konek
Co Nazario Velasco-Catera and Divinagracia (CNVD) Law Offices denied reports that its website was successfully defaced, saying an attempted cyberattack failed to alter its existing website or compromise client information.
In a statement, the law firm said it received a report that its website had allegedly been defaced and immediately investigated the incident.
βWe confirm that there was an attempt to hack our website through a brute-force attack, which is a program that keeps guessing passwords until one works. However, the attempt was not successful,β CNVD Law said.
The firm issued the clarification after cybersecurity advocacy and watchdog page Deep Web Konek reported that the CNVD Law website appeared to have been defaced by individuals identifying themselves as Filipino hacktivists.
Images circulated online showed a black webpage carrying the name and emblem of βGrimSec Philippines – G.S.P.β along with a politically charged message calling for accountability.
The apparent defacement drew attention because one of CNVD Law’s partners is serving as a private prosecutor assisting the House prosecution panel in the impeachment proceedings involving the a government official.
New page, not homepage
CNVD Law disputed the characterization that its website itself had been altered.
According to the firm, none of its existing pages were changed, replaced, or taken down. Instead, the intruders allegedly created a new page using βcnvdlaw.com/index.html,β an address the firm said it had never used.
βMost websites use index.html as their default landing page, so adding one there made it appear that our homepage had been hit. It had not,β the firm said.
CNVD Law said it has since moved its website to a more secure server as a precaution.
No client data stored
The firm also stressed that its public-facing website does not contain client information, case records, personal or financial data, nor does it process transactions.
Client files and communications are kept in separate secured systems that were not involved in the incident, it added.
βThere was, quite simply, nothing there to take,β CNVD Law said.
The firm did not identify the attackers, but acknowledged that public interest in CNVD Law had increased after one of its partners appeared as a prosecutor in the impeachment proceedings.
βWe leave the question of motive to the proper authorities. Our work continues as it always has,β the firm said.
Deep Web Konek later clarified that the hacker group allegedly behind the incident was GrimSec Philippines and stressed that Deep Web Konek itself was not involved in the attack.
