IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Western Digital to provide recovery services for hacked NAS drives

Users affected by the cyber attack will be able to upgrade to a new My Cloud device

Western Digital has announced a new trade-in programme to help customers mitigate the effects of a mass malware attack that saw terabytes of data wiped from users’ NAS drives overnight.

Those who lost data as a result of the hack will be able to benefit from Western Digital’s data recovery services, as well as a trade-in programme for My Book Live network-attached storage devices that were targeted in the attack. Customers partaking in the programme will be able to upgrade to a new supported My Cloud device.

Both programmes will become available starting July, the company stated.

The announcement comes after it was found that cyber criminals used not one but two vulnerabilities in order to remotely wipe terabytes of data from Western Digital My Book Live devices.

This is according to an investigation conducted by Ars Technica and Censys CTO Derek Abdine, which found that hackers exploited an undocumented vulnerability in a file named system_factory_restore.

The Discovery of the flaw comes after Western Digital identified a zero-day flaw that was attributed as the source of the attacks. Labelled as CVE-2021-35941, the unauthenticated factory reset vulnerability had been introduced to the My Book Live over a decade earlier, in April 2011.

Meanwhile, the Ars Technica and Censys investigation found that a Western Digital developer had edited out an authentication check which originally asked users to type in their password prior to remote access being enabled. 

Related Resource

Owning your own access security

The key to building strong cloud security and avoiding the risk of vendor lock-in

Whitepaper front coverDownload now

Security expert HD Moore told Ars Technica that it seems as if someone at Western Digital “intentionally enabled the bypass”.

In a statement, Western Digital said that an internal “investigation of this incident has not uncovered any evidence that Western Digital cloud services, firmware update servers, or customer credentials were compromised”. 

“As the My Book Live devices can be directly exposed to the internet through port forwarding, the attackers may be able to discover vulnerable devices through port scanning. The vulnerabilities being exploited in this attack are limited to the My Book Live series, which was introduced to the market in 2010 and received a final firmware update in 2015,” it stated, adding that the vulnerabilities “do not affect” the company’s “current My Cloud product family”, which will be offered as an upgrade to the impacted customers.

Featured Resources

2022 State of the multi-cloud report

What are the biggest multi-cloud motivations for decision-makers, and what are the leading challenges

Free Download

The Total Economic Impact™ of IBM robotic process automation

Cost savings and business benefits enabled by robotic process automation

Free Download

Multi-cloud data integration for data leaders

A holistic data-fabric approach to multi-cloud integration

Free Download

MLOps and trustworthy AI for data leaders

A data fabric approach to MLOps and trustworthy AI

Free Download

Recommended

2022 IBM's Security X-Force cloud threat landscape report
Whitepaper

2022 IBM's Security X-Force cloud threat landscape report

22 Nov 2022
2022 Magic quadrant for Security Information and Event Management (SIEM)
Whitepaper

2022 Magic quadrant for Security Information and Event Management (SIEM)

22 Nov 2022
Seven realities facing SMBs as they enter a future of increased cyber threats
Whitepaper

Seven realities facing SMBs as they enter a future of increased cyber threats

21 Nov 2022
The top 12 password-cracking techniques used by hackers
Security

The top 12 password-cracking techniques used by hackers

14 Nov 2022

Most Popular

The top 12 password-cracking techniques used by hackers
Security

The top 12 password-cracking techniques used by hackers

14 Nov 2022
How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

15 Nov 2022
Interpol arrests nearly 1,000 cyber criminals in months-long anti-fraud operation
cyber crime

Interpol arrests nearly 1,000 cyber criminals in months-long anti-fraud operation

25 Nov 2022