SFOConnect.com and SFOConstruction.com suffered a security incident in which bad actors injected a malicious code to steal users login credentials. The first compromised website addresses the airports construction project and provides a centralized way for third parties and contractors to bid on new or upcoming construction plans. The two platforms were taken offline as an immediate countermeasure after removing the malicious code, and Airport ITT reset all SFO related email and network passwords The two websites are still accessible outside the airport network. Users who have accessed the two platforms using IE browsers are recommended to act quickly and change the password used to access those devices.”]

