D-Link confirmed a phishing attack exposed old registration records
- Organization
- D-Link
- Exploit
- Phishing
- Industry
- Networking Hardware
D-Link, the Taiwanese networking equipment maker, confirmed on October 18, 2023 that it had been breached after an employee fell for a phishing email. The company published its findings after an internal and external investigation into what an attacker had actually taken.
The disclosure followed a listing posted to the BreachForums criminal marketplace on October 1, where a seller offered D-Link data for 500 dollars. The seller claimed to hold roughly three million customer records along with the source code for D-Link's D-View network management software, and said the trove included details on Taiwanese government officials as well as D-Link executives and employees.
D-Link disputed most of it. According to the company, the affected system was a product registration server running in a test lab environment on D-View 6, a platform that reached end of life in 2015, and not its cloud infrastructure. D-Link said roughly 700 records were involved, describing them as outdated and fragmented, inactive for at least seven years, and containing low sensitivity, semi-public information. It said no user IDs or financial data were compromised.
The company also said the seller appeared to have manipulated login timestamps to make the data look more recent than it was, and characterised the wider claims as containing numerous inaccuracies and exaggerations. The seller's figures were never independently verified, and D-Link said it had shut down the obsolete server and reviewed access to its remaining systems.