Online advertising giant Adform was hacked, proving once again why ad blockers are necessary
Sign in<br>Subscribe
Online ads provider Adform was hacked. On July 27, the company began serving ads containing malicious code. The company says in its latest annual report that its serves 1.5 billion ads to people's devices daily.<br>According to security researcher Kevin Beaumont, who first revealed the incident, some of the code that Adform used to load its ads on its customers' websites was maliciously altered. The code was designed to trigger when it loaded in a victim's web browser.<br>The malicious code replaced a victim's crypto wallet address in their computer's clipboard with crypto wallet addresses controlled by the hacker. The code replaces the crypto addresses in the clipboard every three seconds, all but guaranteeing that the victim will inadvertently paste in the attacker's crypto wallet address and send their crypto to the hacker instead of its intended destination.<br>Per Beaumont's blog:<br>"This allows end user devices of downstream websites to be compromised with crypto stealing malware. Meaning if you visit example.com and they use Adform, example.com will compromise your device."<br>If you've ever needed another reason to use an ad-blocker, this is it. By blocking ads, you can prevent pervasive tracking, surveillance, and yes, even malware, from landing on your computer.
PLEASE SUPPORT THIS NEWSLETTER!
~this week in security~ is my weekly cybersecurity newsletter and blog supported by readers like you. Please consider signing up for a paid subscription starting at $10/month for access to exclusive articles, analysis, and more.<br>Or, you can submit a one-time tip or gift a paid subscription to show your support!<br>Recent blogs include: When AI chatbots and LLMs get legal, check your privilege | Most fitness wearables lack end-to-end encryption and don't disclose government data demands | U.S. judge denied feds a month-long warrant to snoop on the phones of thousands of Ohio residents | Why ad blockers are a top security and privacy defense for everyone | A beginner's guide to analyzing the network traffic of apps and websites
Subscribe to support this newsletter
Adform has now disclosed the breach, but the company didn't say how it was initially compromised or how many people may have been affected. When I reached out to the company with questions about the incident, a spokesperson referred me instead to its public statement.<br>Per its statement, Adform said it was still investigating if the hackers also took information about which websites a person visited; Adform said the code suggests this was possible.<br>I went to check out Adform's statement but couldn't at first, in large part because my ad blocker (uBlock Origin on desktop; Filtr/Wipr on iPhone) prevented Adform's entire domain from loading. Even had I visited a website that contained the malicious Adform code, this shows my ad blocker would have prevented the code from loading.<br>Practice safe browsing, use an ad-blocker.
~ ~
Thank you so much for reading ~this week in security~! I hope you enjoyed and found this article helpful. If you like it, please share a link on your social media! Please email me with any feedback, questions, or comments about this article: this@weekinsecurity.com.
Reading this online? Get ~this week in security~ by email
a weekly cybersecurity newsletter by Zack Whittaker, plus analysis and blogs. All the news you need to know. No slop.
Subscribe
Email sent! Check your inbox to complete your signup.
No spam. Unsubscribe anytime. This newsletter does not use email open or link trackers.
You might also like...
31
Jul
'26
When AI chatbots and LLMs get legal, check your privilege
Using AI tools and LLMs for sensitive matters, such as for legal and medical uses, raises important questions about where that data goes and who can access it.
4 min read
22
Jul
'26
Most fitness wearables lack end-to-end encryption and don't disclose government data demands, says EFF
Most fitness wearables don't use end-to-end encryption to protect users' health information, leaving open the door for government demands for data.
3 min read
15
Jul
'26
U.S. judge denied feds a month-long warrant to snoop on the phones of thousands of Ohio residents
The magistrate judge's decision offers a rare view into how the government seeks to use cell-site simulators during law enforcement investigations.
5 min read
08
Jul
'26
Reframing smart glasses as 'pervert glasses'
Smart glasses equipped with cameras, microphones, and AI are a creeping privacy and security nightmare, prompting backlash.
5 min read
28
Jun
'26
Reflections on eight years of writing ~this week in security~
Your favorite weekly cybersecurity newsletter marks eight years on the web.
6 min read
Powered by Ghost