Mail.ru Denies Mass Password Breach; Researcher Stands by Findings

Advertisement
By Reuters | Updated: 7 May 2016 11:07 IST
Russia's top Internet company, Mail.ru said on Friday a sliver of its users' email accounts was vulnerable while denying that tens of millions of other users were at risk after researchers found its data circulating among cyber criminals.

The company said in a statement credentials tied to its email accounts appeared to have been stolen from other, unrelated sites such as social networks or e-commerce sites that ask users to sign up using email addresses like Mail.ru and pick passwords, which most often will not be the same as those for the email accounts.

"The database is most likely a compilation of a few old data dumps collected by hacking web services where people used their email address to register," the Moscow-based company said.

However, the security expert who uncovered what he said were hundreds of millions of hacked usernames and passwords into some of the world's biggest websites, said Mail.ru's own analysis suggested that tens of thousands of users were at risk.

Advertisement

Alex Holden, founder of Hold Security, a US firm that specialises in recovering stolen credentials from hackers, told Reuters on Wednesday his researchers had coaxed a young Russian hacker into disclosing the stolen data.

Advertisement

Reuters reported on Wednesday Hold Security's discovery of 272.3 million stolen credentials globally, including 57 million at Mail.ru and smaller fractions of the email user bases of Google, Yahoo and Microsoft . Mail.ru recently reported 64 million monthly active email users.

In a statement, the Moscow-based company said its own study of sample data provided by Holden had found that 99.982 percent of Mail.ru account credentials on the hit list were invalid. Most had incorrect passwords or used fake email addresses.

Advertisement

But the company acknowledged that 0.018 percent of the usernames and passwords might have worked and said: "We have already notified the affected users to change their passwords."

A Yahoo spokesperson said the company had obtained a sample of Hold Security's data and does not believe "there is any significant risk to our users based on the claims shared with the press."

Advertisement

Thefts of personal information or financial losses can result from hackers breaking into other accounts relying on the same credentials.

Mail.ru said it found that 12.42 percent of the sampling had been marked by its computers as suspicious and blocked.

Holden said he had supplied a randomised sample of data that represents less than one-tenth of the exposed Mail.ru records. He said he was ready to provide Mail.ru the full dataset.

Hackers know users cling to favourite passwords. It is why attackers reuse old passwords found on one account to try to break into other accounts of the same user.

Mail.ru said its experts constantly monitor the web for data dumps to see if Mail.ru account credentials are compromised. It said the "sole purpose" of revealing the possible credential theft was to create media hype and to promote Holden's business.

Holden, whose firm earns commissions from providing threat intelligence to big companies, said he had spent the past week informing any company whose credentials appeared to have been stolen and was doing it for free.

"We have no claim to this information because we just retrieved it from the hacker and are sharing it with the community," he said. Hold Security refuses to publish the database of stolen accounts but said it provides specific data to authorised technical staff at the affected firms.

© Thomson Reuters 2016

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Fusion India Launch Teased; Might Launch With This Chip
  2. OTT Releases of the Week (Feb 16 - Feb 22): Know What to Watch This Weekend
  3. Here's When Xiaomi Will Launch the Xiaomi 17 and Xiaomi 17 Ultra Globally
  4. Poco X8 Pro, X8 Pro Max Colour Options, Design Leaked Online
  5. Xiaomi Teases a New Computing Device, New Tablet Expected to Launch Soon
  6. Vivo V70 Elite Review: Vivo's V-Series Goes 'Elite'
  7. Hello Bachhon Set for OTT Release on Netflix: See Details
  8. Realme P4 Lite With 6,300mAh Battery Launched at This Price in India
  1. Redmi A7 Could Launch Soon as Handset Bags Thailand’s NBTC Certification
  2. Poco X8 Pro, Poco X8 Pro Max Design and Colour Options Seen in Leaked Renders
  3. Hello Bachhon OTT Release Date: When and Where to Watch Vineet Kumar Singh Starrer Online?
  4. Xiaomi Teases India Launch of New Computing Device; New Tablet With Keyboard or Laptop Expected
  5. Realme C83 5G India Price, RAM and Storage Configurations Leaked Online
  6. Xiaomi 17 Series Global Launch Date Announced; Xiaomi 17, Xiaomi 17 Ultra Expected to Debut
  7. Google Blocked 266 Million Risky App Installs, Prevented 1.75 Million Policy-Violating Apps in 2025
  8. Motorola Edge 70 Fusion India Launch Teased on Flipkart; Leaked Marketing Image Hints at Snapdragon 7s Gen 4 SoC
  9. Google Releases Gemini 3.1 Pro With Ability to Execute Complex Tasks; Pomelli Gets New Photoshoot Feature
  10. Theatre: The Myth of Reality OTT Release: Where to Watch Kerala Film Critics Award-Winning Movie Online?
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.