Security News Cyberattack sends International Meteor Organization crashing back to Earth

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,120
6,121
2,168
Germany
Attack dealt a 'critical blow' to aging infrastructure, with several weeks of disruption expected
The International Meteor Organization (IMO) is watching for fireballs again, but much of its website remains offline after a cyberattack that it says will take weeks to recover from.

The Belgium-based nonprofit, which coordinates meteor observations and brings together amateur and professional astronomers worldwide, is currently serving visitors a stripped-down holding page explaining the outage.

"We recently suffered a cyberattack that dealt a critical blow to aging infrastructure, taking much of our site offline," the organization said. "We expect several weeks of partial downtime as we transition to new infrastructure and services."

IMO has not disclosed when the attack occurred, how the attackers gained access, or whether they accessed or encrypted any data.

The organization collects reports from people who spot unusually bright meteors, or fireballs, and uses those observations to help document and analyze events. Its notice says it prioritized restoring that capability after the attack.

"We prioritized restoring fireball reporting, and it is available again," IMO said. "If you saw a fireball or a bright light in the sky, you can still submit your observation."

Other parts of the site remain unavailable while the organization rebuilds its infrastructure. IMO's warning that the process will take several weeks suggests this is more than a case of simply restoring a compromised web server, although the organization has not disclosed the extent of the damage.

The incident also leaves some unanswered questions about the data held on the affected systems. IMO operates services used by meteor observers and members around the world, but has not said whether information belonging to users or contributors was exposed during the attack.

The Register asked IMO when the attack occurred, which systems were affected, whether any data was compromised, and whether it has identified who was responsible, but has not yet received a response.

IMO is used to documenting things that burn up spectacularly. It probably didn't expect its IT infrastructure to join them. ®
 
  • Wow
Reactions: lokamoka820


Hi, this sounds like a serious infrastructure compromise, but the public notice does not establish ransomware, data theft, or even the exact attack date. The defensible conclusion is simply that the IMO lost substantial service availability and is rebuilding rather than performing a quick website restore.

What the long recovery suggests​

Several weeks of partial downtime is consistent with more than a defaced page or one failed web server. Replacing aging infrastructure may involve rebuilding hosts, validating backups, rotating credentials, checking applications and moving services in stages.

That is still inference, not a diagnosis. The same timetable could reflect limited nonprofit staffing, poorly documented legacy systems, damaged backups, or a cautious decision to modernize during recovery. It does not by itself prove ransomware or permanent data loss.

What users should do​

There is no disclosed evidence here that contributor information was exposed, so panic-driven password changes would be premature. Sensible precautions are:

  • Use only the IMO’s known official site for fireball reports; be wary of lookalike recovery, donation or account-verification messages.
  • Do not reuse an IMO password on other services. If it was reused, change those other accounts now—the reuse itself is sufficient reason.
  • Treat unexpected IMO-themed emails asking for credentials, payments or downloads as suspicious.
  • If IMO later confirms account-data exposure, change the IMO password through its official site, revoke active sessions if that option exists, and review connected access and recovery details.

The most useful next disclosure would distinguish service destruction, unauthorized access and confirmed data exfiltration. Until then, the outage is confirmed; the fashionable cybercrime labels are not.