'360 million newly stolen credentials on black market'

Advertisement
By Reuters | Updated: 26 February 2014 10:58 IST
A cybersecurity firm said on Tuesday that it uncovered stolen credentials from some 360 million accounts that are available for sale on cyber black markets, though it is unsure where they came from or what they can be used to access.

The discovery could represent more of a risk to consumers and companies than stolen credit card data because of the chance the sets of user names and passwords could open the door to online bank accounts, corporate networks, health records and virtually any other type of computer system.

Alex Holden, chief information security officer of Hold Security LLC, said in an interview that his firm obtained the data over the past three weeks, meaning an unprecedented amount of stolen credentials is available for sale underground.

Advertisement

"The sheer volume is overwhelming," said Holden, whose firm last year helped uncover a major data breach at Adobe Systems Inc in which tens of millions of records were stolen.

Holden said he believes the 360 million records were obtained in separate attacks, including one that yielded some 105 million records, which would make it the largest single credential breaches known to date.

Advertisement

He said he believes the credentials were stolen in breaches that have yet to be publicly reported. The companies attacked may remain unaware until they are notified by third parties who find evidence of the hacking, he said.

"We have staff working around the clock to identify the victims," he said.

Advertisement

He has not provided any information about the attacks to other cybersecurity firms or authorities but intends to alert the companies involved if his staff can identify them.

The massive trove of credentials includes user names, which are typically email addresses, and passwords that in most cases are in unencrypted text. Holden said that in contrast, the Adobe breach, which he uncovered in October 2013, yielded tens of millions of records that had encrypted passwords, which made it more difficult for hackers to use them.

Advertisement

The email addresses are from major providers such as AOL Inc , Google Inc , Microsoft Corp and Yahoo Inc and almost all Fortune 500 companies and nonprofit organizations. Holden said he alerted one major email provider that is a client, but he declined to identify the company, citing a nondisclosure agreement.

Heather Bearfield, who runs the cybersecurity practice for accounting firm Marcum LLP, said she had no information about the information that Hold Security uncovered but that it was plausible for hackers to obtain such a large amount of data because these breaches are on the rise.

She said hackers can do far more harm with stolen credentials than with stolen payment cards, particularly when people use the same login and password for multiple accounts.

"They can get access to your actual bank account. That is huge," Bearfield said. "That is not necessarily recoverable funds."

After recent payment-card data breaches, including one at U.S. retailer Target, credit card companies stressed that consumers bear little risk because they are refunded rapidly for fraud losses.

Wade Baker, a data breach investigator with Verizon Communications Inc , said that the number of attacks targeting payment cards through point-of-sales systems peaked in 2011. That was partly because banks and retailers have gotten better at identifying that type of breach and quickly moving to prevent crooks from making fraudulent transactions, he said.

In addition to the 360 million credentials, the criminals are selling some 1.25 billion email addresses, which would be of interest to spammers, Hold Security said in a statement on its website.

© Thomson Reuters 2014
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 2026 With 6.3-Inch Display Goes Official
  2. Anthropic Brings Its Cybersecurity AI Model Claude Mythos to India
  3. Apple's Design Awards Winners Include CD Projekt Red's Cyberpunk 2077
  4. Honor X7e With a 7,500mAh Battery Debuts Globally at This Price
  5. God of War Laufey Revealed at State of Play: Everything You Need to Know
  6. Nothing Ear 3a, CMF Buds Neo Visit Regulatory Databases, Might Launch Soon
  7. Sony Bravia 7II 4K TVs With Cognitive Processor XR Debut in India
  8. Computex 2026: Top 10 Product Launches and Announcements on Day 1
  9. Hisense Launches U7SE 144Hz ULED Mini-LED TV Series in India
  1. WhatsApp Said to Be Developing On-Device Scam Detection Feature for Android
  2. Motorola Edge 2026 Launched With 6.3-Inch Display, MediaTek Dimensity 7450 SoC: Price, Specifications
  3. Honor X7e Launched With 7,500mAh Battery, 50-Megapixel Rear Camera: Price, Specifications
  4. God of War Laufey Revealed With Extended Gameplay Trailer Showcasing New Protagonist, Setting and Combat System
  5. Redmi Turbo 5 India Launch Date Spotted in Leaked Promotional Image: Expected Specifications, Features
  6. Samsung Galaxy Z Fold 8 Ultra Spotted on Bluetooth SIG Database; New Leak Hints at Battery, Charging Upgrades
  7. Apple Design Awards 2026 Winners Announced: Guitar Wiz, NBA, Cyberpunk 2077: Ultimate Edition Bag Top Spots
  8. Anthropic Expands Project Glasswing to 15 Countries, Brings Claude Mythos to India
  9. Nothing Ear 3a, CMF Buds Neo Spotted on Regulatory Databases Ahead of Anticipated Debut
  10. Samsung Galaxy Z Fold 8, Galaxy Z Fold 8 Ultra Could Feature Vastly Different Designs, Leaked Dummy Units Suggest
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.