This is a short overview of what happened on Friday August 28 2009 to the services. A more detailed post will come at a later time after we complete the audit of all machines involved. On August 27th, starting at about 18:00 UTC an account used for automated backups for the ApacheCon website hosted on a 3rd party hosting provider was used to upload files to The account was accessed using SSH key authentication from this host.

To the best of our knowledge at this time, no end users were affected by this incident, and the attackers were not able to escalate their privileges on any machines. While we have no evidence that downloads were affected, users are always advised to check digital signatures where provided. runs FreeBSD 7-STABLE and is more widely known as Minotaur serves as the seed host for most websites, in addition to providing shell accounts for all Apache committers.

The link for this article located at Apache Foundation is no longer available.