<html><head><meta http-equiv="Content-Type" content="text/html charset=windows-1252"></head><body style="word-wrap: break-word; -webkit-nbsp-mode: space; -webkit-line-break: after-white-space;" class=""><div><blockquote type="cite" class=""><br class=""><div style="font-family: Calibri, sans-serif; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; font-size: 16px;" class=""><br class=""></div><div style="font-family: Calibri, sans-serif; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px; font-size: 16px;" class=""><div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Arial;" class=""><b class=""><span style="font-size: 19pt;" class="">ICANN Targeted in Spear Phishing Attack<span class="Apple-converted-space"> </span><o:p class=""></o:p></span></b></div><div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Arial;" class=""><b class=""><span style="font-size: 17pt;" class="">Enhanced security measures implemented<o:p class=""></o:p></span></b></div><p class="MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Arial;"><span style="font-size: 14pt;" class=""> </span></p><p class="MsoNormal" style="margin: 0in 0in 12pt; font-size: 11pt; font-family: Arial;"><span style="font-size: 14pt; font-family: Calibri;" class="">ICANN is investigating a recent intrusion into our systems. We believe a “spear phishing” attack was initiated in late November 2014. It involved email messages that were crafted to appear to come from our own domain being sent to members of our staff. The attack resulted in the compromise of the email credentials of several ICANN staff members.<o:p class=""></o:p></span></p><p class="MsoNormal" style="margin: 0in 0in 12pt; font-size: 11pt; font-family: Arial;"><span style="font-size: 14pt; font-family: Calibri;" class="">In early December 2014 we discovered that the compromised credentials were used to access other ICANN systems besides email:<o:p class=""></o:p></span></p><p class="MsoListParagraphCxSpFirst" style="margin: 0in 0in 12pt 0.5in; font-size: 11pt; font-family: Arial; text-indent: -0.25in;"><span style="font-size: 14pt;" class="">·<span style="font-size: 7pt; font-family: 'Times New Roman';" class="">     <span class="Apple-converted-space"> </span></span></span><span style="font-size: 14pt; font-family: Calibri;" class="">The Centralized Zone Data System (<a href="http://czds.icann.org/" class="">czds.icann.org</a>)<br class="">The attacker obtained administrative access to all files in the CZDS. This included copies of the zone files in the system, as well as information entered by users such as name, postal address, email address, fax and telephone numbers, username, and password. Although the passwords were stored as salted cryptographic hashes, we have deactivated all CZDS passwords as a precaution. Users may request a new password at<span class="Apple-converted-space"> </span><a href="http://czds.icann.org/" class="">czds.icann.org</a>. We suggest that CZDS users take appropriate steps to protect any other online accounts for which they might have used the same username and/or password. ICANN is providing notices to the CZDS users whose personal information may have been compromised.</span></p><p class="MsoListParagraphCxSpFirst" style="margin: 0in 0in 12pt 0.5in; font-size: 11pt; font-family: Arial; text-indent: -0.25in;"><span style="text-indent: -0.25in; font-size: 14pt;" class="">·<span style="font-size: 7pt; font-family: 'Times New Roman';" class="">     <span class="Apple-converted-space"> </span></span></span><span style="text-indent: -0.25in; font-size: 14pt; font-family: Calibri;" class="">The ICANN GAC Wiki (<a href="http://gacweb.icann.org/" class="">gacweb.icann.org</a>) </span></p><p class="MsoListParagraphCxSpLast" style="margin: 0in 0in 12pt 0.5in; font-size: 11pt; font-family: Arial; text-indent: -0.25in;"><span style="font-size: 14pt; font-family: Calibri;" class="">Public information, the members-only index page and one individual user’s profile page was viewed. No other non-public content was viewed.<span class="Apple-converted-space"> </span><o:p class=""></o:p></span></p><p class="MsoNormal" style="margin: 0in 0in 12pt; font-size: 11pt; font-family: Arial;"><span style="font-size: 14pt; font-family: Calibri;" class="">Unauthorized access was also obtained to user accounts on two other systems, the ICANN Blog (<a href="http://blog.icann.org/" class="">blog.icann.org</a>) and the ICANN WHOIS (<a href="http://whois.icann.org/" class="">whois.icann.org</a>)</span><span style="font-size: 14pt; font-family: Cambria;" class=""> </span><span style="font-size: 14pt; font-family: Calibri;" class="">information portal. No impact was found to either of these systems.<span class="Apple-converted-space"> </span><o:p class=""></o:p></span></p><p class="MsoNormal" style="margin: 0in 0in 12pt; font-size: 11pt; font-family: Arial;"><span style="font-size: 14pt; font-family: Calibri;" class="">Based on our investigation to date, we are not aware of any other systems that have been compromised, and we have confirmed that this attack does<span class="Apple-converted-space"> </span></span><span style="font-size: 14pt; font-family: Calibri;" class="">not impact any IANA-related systems.<o:p class=""></o:p></span></p><div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Calibri;" class=""><span style="font-size: 14pt;" class="">Earlier this year, ICANN began a program of security enhancements in order to strengthen information security for all ICANN systems. We believe these enhancements helped limit the unauthorized access obtained in the attack. Since discovering the attack, we have implemented additional security measures.<o:p class=""></o:p></span></div><p class="MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Arial;"><span style="font-size: 14pt; font-family: Calibri;" class=""> </span></p><div style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Arial;" class=""><span style="font-size: 14pt; font-family: Calibri;" class="">We are providing information about this incident publicly, not just because of our commitment to openness and transparency, but also because sharing of cybersecurity information helps all involved assess threats to their systems.<span class="Apple-converted-space"> </span><o:p class=""></o:p></span></div><p class="MsoNormal" style="margin: 0in 0in 0.0001pt; font-size: 11pt; font-family: Arial;"><span style="font-size: 14pt; font-family: Calibri;" class=""> </span></p><p class="MsoNormal" style="margin: 0in 0in 12pt; font-size: 11pt; font-family: Arial;"><span style="font-size: 14pt; font-family: Calibri;" class="">For additional information about the attack, please monitor the ICANN website.<o:p class=""></o:p></span></p></div><div style="font-family: Calibri, sans-serif; font-size: 14px; font-style: normal; font-variant: normal; font-weight: normal; letter-spacing: normal; line-height: normal; orphans: auto; text-align: start; text-indent: 0px; text-transform: none; white-space: normal; widows: auto; word-spacing: 0px; -webkit-text-stroke-width: 0px;" class=""><div class=""><br class=""></div><div class=""><div class=""><font face="Arial" style="font-size: 10px;" class="">David A. Olive</font></div><div class=""><div class=""><font face="Arial" style="font-size: 10px;" class="">Vice President, Policy Development Support<br class=""><font class="">General Manager, ICANN Regional Headquarters –Istanbul</font></font></div><div class=""><span style="font-size: 10px;" class="">Hakki Yeten Cad. Selenium Plaza No:10/C K:10 34349 Fulya, Besiktas, Istanbul</span></div><div class=""><font face="Arial" style="font-size: 10px;" class="">Internet Corporation for Assigned Names and Numbers (ICANN)</font></div><div class=""><font face="Arial" style="font-size: 10px;" class=""><br class=""></font></div><div class=""><font face="Arial" style="font-size: 10px;" class=""><font class="">Direct Line:</font><font class=""> +90.212.999.6212 </font></font></div><div class=""><font face="Arial" style="font-size: 10px;" class="">Mobile:       + 1. 202.341.3611</font></div></div><div class=""><font face="Arial" style="font-size: 10px;" class="">Mobile:       +90.533.341.6550 </font></div><div class=""><font face="Arial" style="font-size: 10px;" class="">Email:  <a href="mailto:david.olive@icann.org" class="">david.olive@icann.org</a></font></div><div class=""><font face="Arial" style="font-size: 10px;" class=""><a href="http://www.icann.org/" class="">www.icann.org</a></font></div></div></div></blockquote></div><br class=""><div apple-content-edited="true" class="">
***********************************************<br class="">William J. Drake<br class="">International Fellow & Lecturer<br class="">  Media Change & Innovation Division, IPMZ<br class="">  University of Zurich, Switzerland<br class="">Chair, Noncommercial Users Constituency, <br class="">  ICANN, <a href="http://www.ncuc.org" class="">www.ncuc.org</a><br class=""><a href="mailto:william.drake@uzh.ch" class="">william.drake@uzh.ch</a> (direct), <a href="mailto:wjdrake@gmail.com" class="">wjdrake@gmail.com</a> (lists),<br class="">  <a href="http://www.williamdrake.org" class="">www.williamdrake.org</a><br class="">***********************************************

</div>
<br class=""></body></html>