Apple says it was attacked by hackers, will issue malware removal tool today

140

In a statement provided to The Verge, Apple says that hackers infected a "small number" of its computers in an attack that exploited a Java vulnerability. As Reuters originally reported, the company says "there was no evidence that any data left Apple," and no user information is said to have been compromised. Apple says the rare security breach utilized the same malware that was recently used to target Facebook and other companies. Despite being a high-profile target, the situation is highly unusual for Apple, and the company says it is working with law enforcement to track down those responsible.

"Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plug-in for browsers," the company said in its statement. "The malware was employed in an attack against Apple and other companies, and was spread through a website for software developers. We identified a small number of systems within Apple that were infected and isolated them from our network."

"There was no evidence that any data left Apple."

Apple plans to release a software tool today to protect customers against malware used in the attack against it and Facebook.

The attack on Apple is just the latest in a string of cyber attacks that have targeted companies, publications, and government agencies in the US. Last week, Facebook admitted that its systems were targeted by a "sophisticated attack" last month after a handful of employees visited a compromised mobile developer website. Facebook said it had discovered no evidence that user data had been compromised. Similar attacks have recently targeted The Wall Street Journal, The New York Times, and Twitter.

Apple declined to comment further on the situation. The company's full statement can be read below:

Apple has identified malware which infected a limited number of Mac systems through a vulnerability in the Java plug-in for browsers. The malware was employed in an attack against Apple and other companies, and was spread through a website for software developers. We identified a small number of systems within Apple that were infected and isolated them from our network. There is no evidence that any data left Apple. We are working closely with law enforcement to find the source of the malware.

Since OS X Lion, Macs have shipped without Java installed, and as an added security measure OS X automatically disables Java if it has been unused for 35 days. To protect Mac users that have installed Java, today we are releasing an updated Java malware removal tool that will check Mac systems and remove this malware if found.

More from The Verge

Back to top ^
X
Log In Sign Up

forgot?
Log In Sign Up

Please choose a new Verge username and password

As part of the new Verge launch, prior users will need to choose a permanent username, along with a new password.

Your username will be used to login to Verge going forward.

I already have a Vox Media account!

Verify Vox Media account

Please login to your Vox Media account. This account will be linked to your previously existing Eater account.

Please choose a new Verge username and password

As part of the new Verge launch, prior MT authors will need to choose a new username and password.

Your username will be used to login to Verge going forward.

Forgot password?

We'll email you a reset link.

If you signed up using a 3rd party account like Facebook or Twitter, please login with it instead.

Forgot password?

Try another email?

Almost done,

By becoming a registered user, you are also agreeing to our Terms and confirming that you have read our Privacy Policy.
Spinner.vc97ec6e

Authenticating

Great!

Choose an available username to complete sign up.

In order to provide our users with a better overall experience, we ask for more information from Facebook when using it to login so that we can learn more about our audience and provide you with the best possible experience. We do not store specific user data and the sharing of it is not required to login with Facebook.

tracking_pixel_5345_tracker