Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Skype Hacked By ‘Syrian Electronic Army’ – Expert Comments
Articles

Skype Hacked By ‘Syrian Electronic Army’ – Expert Comments

ISBuzz TeamBy ISBuzz TeamJanuary 2, 2014Updated:July 5, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
skype
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Following news that Skype social media platforms were hacked by the ‘Syrian Electronic Army‘, here are some thoughts and opinions from Lancope, LockPath, High-Tech Bridge, Cenzic, New Net Technologies & AccessData on how & why this happened.

Bala Venkat, CMO at Cenzic said:

“Cyber criminals are taking to media networks and platforms to put fear into enterprises and the government. The attack on Skype was no exception. This illustrates how social media and communication platforms are becoming pricey soft targets.

One vulnerability is all it takes for the hackers to get in and do some costly damage! While this attack originated at the social media networks, it could easily propagate across the digital chain and pose serious consequences at the national and global level. Enterprises must put tight security programs and controls in place across all stages of the development and deployment process. Better to be proactive than sorry!”

Mark Kedgley, CTO at New Net Technologies said:

The objective of the attack on Skype´s social media platforms by the ‘Syrian Electronic Army’ seems to be pure ‘hacktivism’, with the aim of highlighting the NSA/Microsoft collaboration which they have absolutely achieved.

This sort of attack demonstrates that even seemingly ‘valueless’ IT assets such as your social media channels can be targeted. And if hacked, this can cause huge damage and embarrassment by association. The conclusion of your customers will be that ‘your company has been hacked and has questionable security’.

Organisations should treat social media accounts like any other – regularly change passwords and use complex pass phrases where permitted.

Tim ‘TK’ Keanini, CTO at Lancope said:

Keeping your social media accounts for your company safe and secure is not as easy as it sounds with larger organizations.  Often times, it is an outsourced company that staff’s these Twitter, Facebook, Pinterest accounts and their security practices may not be up to industry standards.  They often will not turn on the two-factor authentication because it assumes that a single user will be associated with the account and often times with these large online brands, there are multiple people who staff a single account and two-factor makes it almost impossible to manage.

Larry Slobodzian, Senior Solutions Engineer for LockPath said:

Breaches like these can be prevented with a proactive, holistic approach to security and compliance that includes an enterprise-wide approach to managing governance, risk and compliance (GRC). For instance, software that is not correctly configured may allow hackers to access sensitive data. While security tools can scan and manage vulnerabilities, the tools often require a combination of functional teams and create data silos, making it hard to enforce and track efforts to manage the vulnerabilities. A GRC program can set the policy and expectations for identifying software vulnerabilities across the enterprise and provide a single view of the current risk, trends, and process performance.

Ilia Kolochenko, CEO at High-Tech Bridge, said:

“I will focus my attention on the technical side of the attack, which is quite interesting. According to the BBC, Skype’s web blog and twitter account were compromised. These two resources are not usually interconnected and a compromise of one should not lead to the compromise of the other, therefore I see the three most probable attack scenarios as being:

1) Password reuse technique. In this case the web blog could be compromised via XSS or SQL injection attack and when the hackers managed to get the passwords of admins they probably tried them on other resources such as social networks. Conversely, hackers could bruteforce Skype’s twitter account password [in 2013 simple or predictable twitter passwords led to a number of important hacks of celebrity accounts] and try it to login into the blog.

2) An APT (Advanced Persistent Threat) scenario. Here, hackers may have profiled Skype employees (via LinkedIn or other public “self-exposure” places) to find the person who may manage its web and social media resources. The person was then compromised and the hackers gained access to multiple corporate resources that were accessible from his or her machine. Many people have huge email archives on their work stations, including dozens or even hundreds of “password recovery” or “registration confirmation” emails. This is a very dangerous practice as attackers can easily get access to such email archived information and, for them, it’s a golden mine.

3) The web blog had a direct link with the twitter account, which allowed posting of tweets directly from the web application. If this was the case, the Skype team should investigate how their website was actually compromised.

As a conclusion, this sad example is a good reminder that hackers don’t care about public holidays and while you are relaxing in the mountains they are still busy hacking your network.”

Lucas Zaichkowsky, Enterprise Defense Architect at AccessData said:

“The Microsoft Skype breach appears to be limited to social media accounts used by whoever is in charge of posting on behalf of Skype. The good news is that means the Skype service itself wasn’t affected and users shouldn’t be concerned. This is a modern day equivalent of web site defacement, a form of hacktivism that goes back over a decade (e.g. Mafia Boy). It’s a black eye for Skype and hopefully a wakeup call for all organizations to be careful to secure the systems and accounts used for social media. Making use of two factor authentication is an excellent example.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}