Web hosting service Dreamhost was hacked, according to an official post in the company’s status blog. According to Dreamhost, “Last night we detected some unauthorized activity within one of our databases. While we don’t have evidence that customer passwords were taken at this time, we’re forcing a change out of caution”.
If you are Dreamhost customer, you will need to change your password at the next login.
Dreamhost didn’t give any information about the nature of the hackers attack, or if any information was compromised. Customers reported being unable to access their account via cPanel and problems while trying to change their passwords, as required.
Customers and users complained, in various comments and tweets, about the various security problems Dreamhost has had during the years and about servers downtime. One customer said: “I had a number of my sites compromised about two months ago. The root cause was some malicious scripts that got inserted into the .htaccess files of my Drupal, WordPress and just everything else I have out there.
At the time, DreamHost had nothing to say about this other than it was probably something I did other than any security holes on their shared servers”.
Another Dreamhost customer pointed out: “This is the third incident of this kind in less than a year. The time has come for DreamHost to realize the hacker community has painted a big, bright bulls eye on their backs, and they need to do much more to protect their customers. This is unacceptable”.
Using a shared hosting service is always risky, because you are sharing space with many other websites, either one of which might compromise the server’s security. Make sure you choose a hosting service that puts an emphasis on server security. If you are using a CMS to run your site, be sure to update it to the latest version. Also, use strong passwords and change them on a regular basis.