The Los Angeles Times Cryptomining Attack (Incident)
ID: f597c559-5b5b-5ba4-b4af-623769b13863
STIX ID: report--f597c559-5b5b-5ba4-b4af-623769b13863
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2018-02-22
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
The Los Angeles Times website was compromised when attackers modified files in an unprotected Amazon S3 bucket to inject CoinHive Monero-mining JavaScript into an interactive homicide map, causing visitors' devices to unknowingly mine cryptocurrency. Others discovered the exposed bucket and left a "BugDisclosure.txt" warning urging the site to secure the storage; while only the cryptominer was found, the open permissions could have allowed deployment of more harmful code.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
