← Outbrain

2013 Outbrain — Syrian Electronic Army phishing; content-recommendation admin compromise

2013 Unknown records affected Share on X

Data compromised

Public reporting centered on widget integrity and publisher traffic redirection; no enduring customer PII inventory cited

Technical writeup

The Syrian Electronic Army compromised Outbrain after a spear-phishing campaign impersonating Outbrain leadership harvested employee credentials, enabling access to administrative consoles that powered recommendation widgets embedded on major publisher sites. For a short interval attackers redirected widget traffic; Outbrain took services offline to recover. Incident narratives emphasized editorial/widget impact more than large static PII database exfiltration.

Root cause

Workforce phishing enabling administrative account takeover

References