We were hacked and this is what we did about it.
Dear Exposed Vocals Users,
Let me start by saying that no one is 100% safe from having their website hacked (even the FBI’s website gets hacked). Hacking is common, yet one of the most common devastating experience for the website owners.
As you may have heard or read, Exposed Vocals learned in mid-September that criminals forced their way into our systems and successfully injected adware into a bunch of files stored on our server. All of our users personal information is safe as it is stored on third party servers and in a separate database within our website that was not effected. Our billing information is handled through Stripe and PayPal. This data was not effected by this attack.
As part of our ongoing investigation, we discovered that this attack originated through our Music Video Hub. The hackers injected malware into a bunch of posts and header files in effort to redirect traffic to spam and potentially unsafe websites. Some of the traffic patterns seen during the redirection process match the patterns of a well-known traffic distribution system used by several malware distribution campaigns. In order to completely insure our server is free of this injection, we had to remove over 358,000 user profiles and music videos. Since our music video hub database is separate from our music review, interviews and featured publications database, all of those pages and profiles are safe. Fortunately, this is an isolated incident. Unfortunately, we were forced to remove 60% of the data on our platform. All from our Music Video section. This is well worth the price to pay to ensure our users have a safe and enjoyable experience on our platform.
Exposed Vocals was developed in 2009 and we managed to grow with all of you and the music industry. Over the past 10 years, we’ve managed to keep our platforms safe and secure. As hackers become more brazen, we’ve had to beef up our security. We’ve invested heavily in more powerful servers to combat DDoS attacks and now we’re investing in more powerful firewalls and security scanning measures to keep our systems safe. We’re also running daily backups to prevent this from happening again.
Thousands of sites have been hacked and compromised with malicious code in September according to security researchers at Sucuri and Malwarebytes. We feel that our platform fell victim to this same campaign and have been working diligently with our server admins and security experts to close any back-doors and remove any infected files.
I am truly sorry this incident occurred and sincerely regret any inconvenience it may cause you. Because we value you as a user and your trust is important to us, we are allowing all accounts to upload an unlimited amount of music videos on our NEW, SAFER and SECURE music video hub. This is newly developed and light on content and profiles. You’re welcome to create a new account for free and start by uploading as many of your music videos as you’d like, We’re looking forward to building and growing with you for the next 10 years.
Randy Morano – CEO and Founder of Exposed Vocals, LLC
Twitter @RandyMorano