We have just discovered that our primary web hosting server
(daphne.bluephyre.ca) has been compromised by hacker(s).
Our preliminary investigation seems to indicate that they gained access
to the server via a particular user account, probably because the
account had a weak or too simple password. That user account has been
temporarily disabled pending further investigation.
The server in question does not contain any personal information, or
credit card information. We DO NOT under any circumstances keep credit
card information on ANY of our servers.
The main purpose of the hackers attack on the server seems to have been
solely to use it to launch attacks against other servers. As a result,
they kept a low profile and do not seem to have done any other damage.
We will over the coming days and weeks begin moving accounts to another,
non-compromised server which was already being configured to replace
daphne.bluephyre.ca. As a result of this attack will we be accelerating
this replacement.
*** IMPORTANT ***
In the meantime, we recommend changing your FTP/SSH/Master password via
the ‘Change Password’ option at: https://secure.bluephyre.ca/.
We appreciate your patience in this matter. We will keep you informed.
Thank you for your continued business!
– Server Management Team