iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
In late November 2014, attackers reportedly altered Forbes.com’s “Thought of the Day” widget and used it to direct selected visitors toward malware. Security researchers said the campaign targeted people associated with defense, financial-services, and other organizations; it was not evidence that every Forbes visitor or the entire Forbes network was compromised. In February 2015, iSIGHT and Invincea linked the activity to Codoso Team, also known as Sunshop Group.
What happened on Forbes.com?
The compromised component was Forbes.com’s “Thought of the Day” widget. Reports described a watering-hole campaign: attackers tampered with a website that people in selected organizations might trust or be permitted to visit, then reportedly redirected selected visitors to a malicious site. That site could attempt to exploit vulnerabilities in Adobe Flash Player and Microsoft Internet Explorer that were unpatched at the time. The reporting does not establish that all visitors were redirected or infected.
Steve Ward, then a senior director at iSIGHT Partners, explained the appeal of the site to The Washington Post: “It’s a trusted place that all of the employees in a targeted organization are going to be allowed to go to,” he said. The Washington Post’s February 10, 2015 report described the widget as compromised for three days.
When did the compromise occur, and how did Forbes respond?
The incident was reported in February 2015, but the file modification occurred in November 2014. Forbes said it discovered the issue on December 1 and that the file had been modified on November 28. The Washington Post also reported that the widget had been compromised for three days; that duration comes from the contemporaneous reporting, not a published count of affected visitors.
#1 Best Overall
In a statement reported by The Washington Post, Forbes said: “On December 1, 2014, Forbes discovered that on November 28, 2014, a file had been modified on a system related to the Forbes web site.” Forbes said it immediately reverted the file and began an investigation. The company said its investigation found “no indication of additional or ongoing compromise nor any evidence of data exfiltration.” Those findings describe what Forbes reported about its systems and investigation; they do not establish whether a visitor was infected or whether the attackers accomplished their aims. The Washington Post report covered Forbes’s statement and the researchers’ account.
Who did researchers say was targeted?
Security firms described defense and financial-services organizations among the targets. SecurityWeek reported that Invincea observed attempts against some defense-industry customers, while iSIGHT saw activity aimed at financial-services organizations and other sectors. The companies were not named, so the reporting does not support identifying particular victims. SecurityWeek’s February 11, 2015 account summarized the firms’ findings.
The targeting described by researchers was selective, not evidence of a mass infection of Forbes readers. The available reports do not give a verified total of infected visitors or affected organizations.
Recommended Free Tools
Why was the activity attributed to Codoso Team?
iSIGHT and Invincea attributed the activity to Codoso Team, also known as Sunshop Group. That is a researcher attribution reported in contemporary coverage, not a judicial finding or conclusive proof of state responsibility. The reports identify the group name but do not establish who directed the operation.
Rank #3
A 2016 SecurityWeek retrospective discussed later activity that Palo Alto Networks Unit 42 attributed to Codoso and described similarities to the Forbes campaign. That later reporting provides group context; it does not independently prove who conducted the 2014 Forbes incident. SecurityWeek’s 2016 retrospective covered that later activity.
What remains unknown?
The public reporting did not establish how many visitors were successfully infected, whether any organization suffered a resulting compromise, or what precise objective the attackers sought to achieve. SecurityWeek quoted Invincea COO Norm Laudermilch: “Neither iSight or Invincea had the visibility in the attack to be able to tell whether the attack group had achieved its objective against its victims, or even what the exact objective was.” The uncertainty applies to the outcome of the reported campaign, not to Forbes’s statement that it reverted the file.
Rank #4
The sources also do not establish the full duration of the broader campaign. The reported three-day period refers to the compromised widget as described by The Washington Post.
The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →How to read the claims in the 2015 coverage
- Forbes’s account: Forbes said it found and reverted a modified file, and that its investigation found no indication of ongoing compromise or evidence of data exfiltration.
- Researchers’ account: iSIGHT and Invincea described selective targeting through the widget and attributed the activity to Codoso/Sunshop.
- Unresolved outcome: The coverage did not determine successful infections, victim count, or whether the attackers met their objective.
AFP’s 2015 coverage cited researchers’ historical estimates that Forbes ranked 61st in the United States and 168th globally. Those are rankings reported in 2015, not current traffic figures. AFP’s February 2015 report included the figures.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

