WD My Book Users Wake Up To Find Their Data Deleted (arstechnica.com) 3
PuceBaboon writes: Ars Technica is reporting that some owners of Western Digital's My Book network-connected disk drives are experiencing data loss on their devices. The as yet unverified problem appears to be an externally initiated factory-reset, resulting in a loss of all existing data. At this early stage, Western Digital is warning users that they should disconnect their devices from the internet to protect their data. A thread on Western Digital's support forum alerted Ars Technica of the problem. Western Digital representatives write in an email: The incident is under active investigation from Western Digital. We do not have any indications of a breach or compromise of Western Digital cloud services or systems. We have determined that some My Book Live devices have been compromised by a threat actor. In some cases, this compromise has led to a factory reset that appears to erase all data on the device. The My Book Live device received its final firmware update in 2015. At this time, we are recommending that customers disconnect their My Book Live devices from the Internet to protect their data on the device. We have issued the following statement to our customers and will provide updates to this thread when they are available: https://community.wd.com/t/action-required-on-my-book-live-and-my-book-live-duo/268147
UPDATE (6/26): Western Digital wrote Friday that "Some customers have reported that data recovery tools may be able to recover data from affected devices, and we are currently investigating the effectiveness of these tools." After reviewing logs from their affected customers, the company now believes the affected devices were directly accessible from the Internet, allowing attackers to remotely install a malicious Trojan file.
"Our investigation of this incident has not uncovered any evidence that Western Digital cloud services, firmware update servers, or customer credentials were compromised. As the My Book Live devices can be directly exposed to the internet through port forwarding, the attackers may be able to discover vulnerable devices through port scanning."
UPDATE (6/26): Western Digital wrote Friday that "Some customers have reported that data recovery tools may be able to recover data from affected devices, and we are currently investigating the effectiveness of these tools." After reviewing logs from their affected customers, the company now believes the affected devices were directly accessible from the Internet, allowing attackers to remotely install a malicious Trojan file.
"Our investigation of this incident has not uncovered any evidence that Western Digital cloud services, firmware update servers, or customer credentials were compromised. As the My Book Live devices can be directly exposed to the internet through port forwarding, the attackers may be able to discover vulnerable devices through port scanning."