Western Digital says some My Book Live devices are being compromised by malware leading to a factory reset erasing all data, believes its servers weren't hacked
Western Digital My Book NAS owners worldwide found that their devices have been mysteriously factory reset and all of their files deleted.
Context & Ripple Effects
My Book Live owners are facing data loss from remote compromises, while Western Digital initially separated the incident from a breach of its own servers. Follow-up code analysis pointed to removed authentication code, shifting attention from the vendor's central systems to the security of the devices themselves.
First-order effects
- My Book Live owners whose devices are reset lose locally stored files, making recovery and support the immediate issue for Western Digital.
- The apparent authentication gap gives attackers a route to trigger destructive actions on exposed devices, rather than requiring access to Western Digital's servers.
Second-order effects
- Western Digital's response must address both erased-device remediation and the product-code weakness identified in the subsequent analysis of the wipes.
- NAS buyers and administrators have a concrete reason to reassess whether internet-accessible storage devices remain safely authenticated and supported.
Third-order effects
- The episode points to a broader security burden for connected storage vendors: device-level authentication and long-term maintenance can determine customer data safety even when central servers are not breached.
The trend: Connected storage is becoming a security-lifecycle product, with device software protections carrying as much weight as the vendor's central infrastructure.