A report by Bleeping Computer says that users of a popular gun-swapping website may have had their email addresses, usernames, and passwords stolen
An August 10 post on a cybercrime forum says stolen databases, containing a total of 240,000 records from the Utah Gun Exchange, are being given away for free . The same hacker is offering two other smaller stolen databases, one from a hunting site and another from a kratom herbal site, for free
What connects all of the above, according to information provided to the
publication by information threat experts, is that all of the
advertised databases came from Utah-based businesses
hosted on the same Amazon cloud server.
Lawrence Abrams, said the actual data from each site is different, but “consists of email addresses, login names, and passwords.” Abrams also confirmed that while it was not possible to validate all of the exposed data in these databases, many of the email addresses belonged to registered site users.
It is believed, since July 16th is the latest
date stamp on any of the database records, that
a breach could have occurred then. If that is indeed the case, then misconfiguration
of the cloud server “buckets” could be the root
cause.
Chris Hauk of Pixel Privacy agrees that “at first glance,
it appears to be another case of databases stored
on Amazon’s AWS service that were not properly
secured.”
“Cloud storage solutions are convenient and cost-effective,
but we must not forget that properly configuring any cloud service
means configuring the components, such as S3 buckets, securely,”
said Tim Mackey, principal security strategist at
Synopsys’ Cybersecurity Research Center (CyRC). “Certainly in this context it involves reviewing
the security requirements for stored data,” Mackey added
, and “it also ensures that regulations such as the
Privacy Act 2020 are adhered to.”
Reduce the risk of targeted spear-phishing attacks
In the meantime, it seems reasonable to me to assume that if you are a user of Utah
Gun Exchange or one of the other sites mentioned in the original
report, your account credentials may have been compromised.
“Affected users should change their passwords
to a secure and unique password, while ensuring they
do not use the same password on other websites,”
Hauk said, “they should also be aware of phishing attempts
targeting them.”
This last point, about the potential for “spear-phishing,”
is worth paying attention to. Any cybercriminal will
tailor an initial attack to have credibility. In this
case, that could mean emails asking you
to click on a link to reset
your password on the relevant website , or something that has as its subject something that
interests you – in this case, issues related to arms exchanges.

