Australian drone technology company CubePilot has suffered a major cyberattack after threat actors hijacked its website's DNS records on July 24.
The attack allowed cybercriminals to redirect visitors to fake versions of CubePilot's websites while showing valid HTTPS security certificates. This means usernames, passwords, and other information entered on the company's portal or forum that day may have been stolen.
CubePilot has regained control of its website, revoked the fake security certificates, and reported the incident to the Australian Cyber Security Centre and law enforcement. The company is also investigating the attack and will contact affected users if needed.
Customers are advised to change any passwords that were reused on other accounts. CubePilot also warned users not to install firmware downloaded between July 24 and July 25 until it confirms the files are safe. Firmware downloaded before July 24 is believed to be secure.
Several online services, including the community forum, documentation portal, and ERP system, remain offline while the investigation continues. The company also warned customers to verify any payment requests by phone before making payments.
CubePilot develops flight controllers and navigation systems for drones used in agriculture, surveying, search and rescue, and defense. The company has also supported Ukraine by supplying drone equipment, including through Australian government aid.