2013 Outbrain — Syrian Electronic Army phishing; content-recommendation admin compromise
Data compromised
Public reporting centered on widget integrity and publisher traffic redirection; no enduring customer PII inventory cited
Technical writeup
The Syrian Electronic Army compromised Outbrain after a spear-phishing campaign impersonating Outbrain leadership harvested employee credentials, enabling access to administrative consoles that powered recommendation widgets embedded on major publisher sites. For a short interval attackers redirected widget traffic; Outbrain took services offline to recover. Incident narratives emphasized editorial/widget impact more than large static PII database exfiltration.
Root cause
Workforce phishing enabling administrative account takeover