Showing posts with label breach. Show all posts
Showing posts with label breach. Show all posts

Tuesday, July 24, 2012

Over 8 million Gamigo user logins leaked months after breach


password, hacking, breach, login, gami
Millions of user logins swiped from a German gaming company earlier this year have appeared online this month. In February, hackers bypassed the security of free-to-play MMORPG outfit Gamigo, taking over 11 million email addresses and encrypted passwords (though only 8.24 million of the addresses were unique), making it the largest breach of its kind this year, topping June's leak of 6.46 million LinkedIn credentials.
After appearing online this month, security researchers have analyzed the dump, which reportedly includes 3 million US (.com) email addresses, 2.4 million German (.de) addresses, 1.3 million French (.fr) addresses, and 100,000 t-online.de addresses. Users affected by the breach don't really have to worry about their Gamigo account being compromised as the company quickly forced passwords to be reset back in March.
However, folks who used their Gamgio credentials across multiple sites remain at risk and should be extra vigilant about resetting the passwords to those accounts -- especially the email account used on Gamigo. The leak contains addresses for various services including Windows Live Hotmail, Gmail and Yahoo, as well as accounts at companies such as Allianz, Deutsche Bank, ExxonMobil, IBM and Siemens.
ZDNet notes that over 5,000 email addresses were created specifically to register at Gamigo, suggesting those users should be safe, but that's only a tiny fraction of the accounts involved. It's also worth emphasizing that Gamigo protected user passwords with a one-way cryptographic hash algorithm, so complicated passwords may remain secure. PwnedList will tell you if your email address is involved.

Friday, July 20, 2012

password theft soars 300% to 12 million in the first quarter


hacking, research, breach, identity theft, experian, opinion matters, password the
Cybercriminals illegally trading stolen personal information online such as passwords has soared exponentially to 300% during the first four months of 2012, according to the latest research from Experian CreditExpert and market research agency Opinion Matters.
Experian concluded that 12 million pieces of personal information were illegally sold during the four-month period, 90% of which consisted of login details and passwords. The figures dwarf the credit agency's data for last year, which totaled 9.5 million.
"The reason password and login combinations make up nine out of ten illegally traded pieces of data is because they give access to a huge amount of other valuable information, such as address books and related accounts," said Peter Turner, managing director at Experian Consumer Services in the UK and Ireland.
The research suggested consumers were still not being as careful online as they could be, and revealed that Britons on average used just five different passwords for their 26 online accounts. It also revealed that a quarter of British internet users used a single password for most of their online profiles and accounts.
Experian urges consumers to create different strong passwords for each site, but Websense Security Labs senior manager Carl Leonard disagrees that strong passwords are enough to protect important data.
"They're as strong as a simple lock against professional thieves. Passwords can be guessed, cracked or stolen through social engineering," Leonard said. "Worse still businesses can be attacked and stories of breached password databases make for uneasy reading. Businesses need to think carefully how they secure password information for which they are responsible -- encrypting password records and securing the database makes good sense."
So far this year, an increasing number of sites have succumbed to hackers, with breaches resulting in millions of passwords being published online. With identity theft increasing, it's important to make online accounts as secure as possible.
Leading security authorities recommend passwords at least eight characters long with a mixture of lower and upper case letters, numbers and special characters -- but most importantly, that they are different for each online account you have. Services like LastPass can also help by creating randomly generated passwords for each of your online accounts with one master password to remember.

Friday, June 22, 2012

Hacker claims to have broken into nearly 80 banks, provides evidence


visa, hacking, breach, credit card, mastercard, white hat, grey hat, black hat, reckz
A self-proclaimed grey hat hacker known as Reckz0r claims to have accessed nearly 80 large banks, collecting a massive amount of customer data in the process. To verify these claims, the hacker made a plain text file available on AnonFiles.com that contains roughly 1,700 user accounts, complete with names, addresses, e-mail addresses and phone numbers.

The file offered up as proof contains data from alleged customers in the US and other parts of the world. Credit card numbers were withheld from the data dump and the full collection of information hasn’t been released simply because there is too much of it. Reckz0r noted that the full data dump containing Mastercard and VISA accounts is around 50GB or larger.

In a Pastebin post last week, Reckz0r is self-described as a former member of Anonymous and UGNazi as well as the creator of SpexSecurity. The author notes that they were doing these things for nothing and will move forward using their intelligence for good as a white hat hacker.

Members of the hacking community generally fall into one of three categories. White hat, or ethical hackers, use their skills for non-malicious purposes such as testing the security of a network for a business. A black hat hacker is traditionally described as the stereotypical hacker that is out for personal gain or to cause malice. Those falling somewhere in the middle are known as grey hat hackers.