British Hosting Firm Admits Pakistani Hack

A Leeds-based web hosting firm has informed the Information Commissioner’s Office (ICO) its systems have been compromised by hackers.

On Saturday morning, John Strong, the managing director of eUKhost Ltd, posted an announcement on its website, warning that the billing system of eUKhost had been compromised.

Pakistani hackers

“Although the method of the compromise remains unclear, we can confirm that an administrator level login was compromised and an IP address added to an allow list to allow a successful login,” Strong warned. “We are still investigating how this compromise occurred and we can’t currently see any evidence of a database dump. However, with our billing system compromised on any level, passwords stored within and not changed since signup can potentially be compromised.”

TechWeekEurope spoke to eUKhost’s Strong, who confirmed the hack had actually taken place back in February, but the company only became aware of the intrusion on Friday after the hacking group responsible for the hit revealed the intrusion on YouTube.

Strong also confirmed to TechWeekEurope that the Pakistani hacking group known as UrduHack was responsible for the intrusion.

But how did they gain access? “We believe they used an old piece of testing software that was not properly shut down, and this allowed the hackers to elevate certain privileges and allowed them to gain access,” Strong said.

Not Malicious

But Strong admitted the hack could have been a lot worse, if the hackers had had malicious intent.

“The hacking group responsible is not the type to cause trouble with individuals,” said Stong. “They are the kind of hackers that just want to prove they can do something. Their motive was not financial, and they were not interested in compromising our systems, they just wanted to prove they could do it,” he said.

Stong confirmed that eUKHost has now moved its billing system to a new server and changed the encryption algorithm. He also confirmed that payment details do not appear to have been compromised.

Strong also admitted that eUKHost had been lucky this time and was guilty of not following the advice it usually gives its own customers.

“It has not been pleasant,” admitted Strong. “But it could have been a lot worse if it had been a different type of hacker. They could have done a lot of damage so we have been lucky. We are also a bit guilty of not following our own advice that we give to our customers, so we are a little embarrassed that we have not practised what we preached.”

As a company, eUKHost is based in the UK, but it has 21,000 customers worldwide and hosts millions of websites. It leases space in data centres in Maidenhead and Milton Keynes.

Think you know security? Try our quiz!

Tom Jowitt

Tom Jowitt is a leading British tech freelancer and long standing contributor to Silicon UK. He is also a bit of a Lord of the Rings nut...

Recent Posts

Ofcom Urges Tech Firms To Tame Toxic Algorithms

New child safety laws sees Ofcom calling on tech firms to “tame toxic algorithms” to…

2 hours ago

Jack Dorsey Resigns From Bluesky Board, Calls X ‘Freedom Technology’

Another u-turn? Former Twitter boss Jack Dorsey suddenly quits Bluesky's board of directors, and calls…

3 hours ago

FTX To Repay Creditors In Full, $11 Billion

Good news for creditors. CEO John Ray III says bankrupt crypto exchange FTX will be…

19 hours ago

US Revokes Some Intel, Qualcomm China Export Licences – Report

Chip giants Intel and Qualcomm complain of sales impact after United States revokes some of…

20 hours ago

EU Requests Content Moderation Data From X

Using the Digital Services Act, European Commission asks X (formerly Twitter) for details over reduction…

21 hours ago

Chinese Hack Exposes Ministry Of Defence Payroll Data

Payroll records of nearly all members of the UK's armed forces have been exposed, reportedly…

22 hours ago