HomeSecurityAnonymous hack includes elements from previous leaks!

Anonymous hack includes elements from previous leaks!

As protests over the death of George Floyd in Minneapolis have spread across America, cyberattacks have targeted Minnesota police. On Sunday, Anonymous claimed responsibility for an attack that took down the Minneapolis Police Department website and published a set of stolen email addresses and passwords. A closer look at the leaked 798 email addresses and passwords suggests that no data was stolen, meaning that they were actually repackaged data from previous leaks and cyberattacks unrelated to the killing of George Floyd. Troy Hunt, a security and founder of the “Have I Been Pwned” database, examined the list of credentials that were released and found that 95 percent had already been leaked from previous breaches. Using old, stolen credentials is nothing new, as cybercriminals often repackage data to sell as new leaks. In April, a document came to light that included 25,000 email and passwords belonging to members of the World Health Organization and the Centers for Disease Control, data also compiled from earlier hacks.

Anonymous hack includes elements from previous leaks!

With the latest leak, Anonymous appears to be taking advantage of the anger that has erupted against police brutality to spread false and misleading news, thus amplifying misinformation online. Specifically, Hunt said in an interview that there is this social anger in Minneapolis and people need to believe that this hack group will do something, since for many, Anonymous symbolizes social justice. There were several signs that led Hunt to conclude that the leaked credentials did not come from a new breach. In addition to the fact that 95% of them were already publicly available, he had found 87 email addresses that were duplicated. If this was a new hack, the database would not have the same email addresses with different passwords. The number of weak passwords in the dataset also raised suspicions, Hunt added. It found passwords that were only two letters or PIN, which are highly unlikely to be allowed to log into internal networks in a large city. It is more likely that the so-called leak came as a collection of “@minneapolis.mn.us” email addresses with passwords from previous breaches, including data from sites like LinkedIn.

Some of the passwords and emails work for other accounts. Hunt said one of the credentials worked to log in to Twitter . That's likely due to the fact that most people use the same passwords for multiple accounts, rather than a new breach.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS