HomeSecurityThe Megabreach of 773 Million Passwords Started Years Ago

The 773 Million Passwords Megabreach Started Years Ago

passwordsNews recently broke that nearly 773 million email addresses and 21 million passwords were posted on a hacking forum. The Guardian called it “the largest collection of hacked data ever.” But in an interview with the person selling the stolen data, KrebsOnSecurity learned that it’s nowhere near the largest collection of stolen data, and that the files are at least two to three years old.

The folder, labeled “Collection #1,” which is 87GB in size, was first analyzed by Troy Hunt, who runs the HaveIBeenPwned breach notification service. Mr. Hunt said the data theft is likely “made up of many different breaches of individual data from literally thousands of different sources.”

KrebsOnSecurity reached out to Alex Holden, CTO of Hold Security, a company that specializes in hacking issues. Holden said the data appears to have been first posted on underground forums in October 2018 and that this is just a subset of a much larger amount of passwords circulating online.

Below is a screenshot of a subset of the offers, which total 1 Terabyte of stolen and hacked passwords:

The 773 Million Passwords Megabreach Started Years AgoAs seen above, the “Collection #1” offered by this seller is 87GB in size. He also lists a Telegram username by which he can be reached – “Sanixer.” So KrebsOnSecurity reached out to Sanixer to learn more about the origins of “Collection #1,” which is being sold at a bargain price – just $45.

Sanixer said that “Collection #1” consists of data pulled from a huge number of hacked sites and is not its “freshest” offering. Unlike most of its other products – “Collection #1” was at least 2-3 years old. Other password packages, which are not shown in the screenshot above and are over 4 terabytes in size, are newer data (less than a year).

Holden said that the practice of collecting large numbers of credentials and posting them online is nothing new, and that the data is much more useful for things like phishing, extortion and other indirect attacks – as opposed to stealing inbox messages. Holden added that his company had already acquired 99% of the data in “Collection #1” from other sources.

“It has been popular for several years by Russian hackers on various Dark Web forums,” he said. “Because the data is collected from a series of breaches, it is usually older data and does not pose an immediate risk to the general user community. The sheer volume of it is impressive, but the data is not very useful.”.

A key reason so many accounts are at risk is that too many people have the bad habit of choosing easy passwords, using those passwords and email addresses across multiple sites, and not taking advantage of multi-factor authentication options when they are available.

If “Collection #1” has you spooked, changing your password will definitely help – unless of course you have a habit of using it everywhere. Don’t do that. As we can see from the above offer, your password is worth a lot more to you than it is to cybercriminals (in the case of “Collection #1,” just .000002 cents per password).

For most of us, the most important passwords are the ones that protect incoming emails. That's because in almost all cases, the person who has control of the email address can reset the password for all services or accounts associated with that address – simply by requesting a password reset link via email.

And instead of thinking about passwords, consider using unique, long passphrases – several words in a row that you can remember. In general, a long, unique passphrase takes a lot more effort to crack than a short, complex one. Unfortunately, many sites don’t allow users to choose passwords or passphrases that exceed a small number of characters, or they may allow long phrases but ignore anything entered after the character limit.

If you are the type of person who likes to reuse passwords, you should definitely use a password manager, which helps you choose and remember strong and unique passwords/passphrases and essentially allows you to use the same strong password across all websites.

Finally, if you haven't already, visit twofactorauth.org and see if you're taking full advantage of multi-factor authentication on sites you trust with your data. The upside of multi-factor is that even if thieves manage to guess or steal your password because they simply hacked a website, your password will be useless to them unless they can also compromise the second factor – whether that's your mobile device or your security key.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS