Satoshi Nakamoto Blog
Image default
Collections hack Cyber cybersecurity data breach Dropbox Hacking Hacks LinkedIn NEWS Security The-Latest Yahoo

2.2B hacked user details found in new ‘Collections’ freely shared databases



Two weeks after a massive database of nearly 773 million unique email addresses and 21 million plain text passwords was found online, the group behind the release has shared even more data, bringing the total pieces of data available to nearly 3 billion.

The new databases, Collections #2 through to #5, are being shared on hacker forums and file-sharing sites and are said to contain a total of 845 gigabytes of stolen data.

Like Collections #1, the data is believed to primarily be a collection of separate data breaches from the past. But the numbers are remarkable, with 25 billion total records and 2.2 billion unique usernames and passwords in the new databases. The databases are believed to include user data stolen in the successful hacks of Yahoo Inc., LinkedIn Inc. and Dropbox Inc., among others.

Notably, though, the new databases, like Collections #1 before it, include some stolen user credentials that have not been seen before in similar data breaches. This suggests that some of the data was obtained in more recent hacks that haven’t been indexed or made publicly available before.

“This is the biggest collection of breaches we’ve ever seen,” Chris Rouland, a cybersecurity researcher and founder of Phosphorus.io, told Wired Wednesday. “It’s an unprecedented amount of information and credentials that will eventually get out into the public domain.”

Distribution of the databases is also growing rapidly. Rouland said the files were being “seeded” by more than 130 people and that they had been downloaded more than 1,000 times as of yesterday.

Jacob Serpa, product marketing manager at Bitglass Inc., previously told SiliconANGLE that the whole affair reveals the failure of organizations to secure their data.

“Leaked credentials leave individuals vulnerable to account hijacking across all services where they recycle their usernames and passwords,” Serpa said. “Unfortunately, this includes the corporate accounts they use for work purposes, meaning that their employers are also put at risk by their careless behavior. Organizations must simultaneously defend their data against leakage and authenticate their users to ensure that they are who they say they are.”

For those concerned that their accounts may have been compromised, data in Collections #1 can be checked on Have I Been Pwned. The Hasso Plattner Institute also has a tool that can be used to check Collections #2 to #6.

Image: Pixabay

Since you’re here …

… We’d like to tell you about our mission and how you can help us fulfill it. SiliconANGLE Media Inc.’s business model is based on the intrinsic value of the content, not advertising. Unlike many online publications, we don’t have a paywall or run banner advertising, because we want to keep our journalism open, without influence or the need to chase traffic.

The journalism, reporting and commentary on SiliconANGLE — along with live, unscripted video from our Silicon Valley studio and globe-trotting video teams at theCUBE — take a lot of hard work, time and money. Keeping the quality high requires the support of sponsors who are aligned with our vision of ad-free journalism content.

If you like the reporting, video interviews and other ad-free content here, please take a moment to check out a sample of the video content supported by our sponsors, tweet your support, and keep coming back to SiliconANGLE.





Source link

Related posts

Reserve Bank of India Denies Involvement in Draft Bill to Ban Cryptocurrencies

satoshi

Dual 2-in-1 Wireless Charging Pad for the iPhone Gets $10 Off

satoshi

Get Closer to the Formula 1 Grand Prix Action With The Dream VR – VRFocus

satoshi

Bitcoin Is Entirely Legal in More Than 111 Countries Worldwide

satoshi

A simple bug makes it easy to spoof Google search results into spreading misinformation

satoshi

DeepMind ‘closes chapter’ in AI research with new self-learning AlphaZero system

satoshi