HomeSecurityUser files of 26 companies sold on hacking forum

User files of 26 companies are being sold on hacking forum

According to Bleeping Computer, a on a hacking forum user, said to belong to 26 companies.

hacking forum stolen user files

Many times, when cybercriminals and hacking groups breach a company and steal user databases, they work with data breach brokers, people who take the data and sell it on behalf of the hackers. The brokers advertise the stolen data on hacking forums and dark web marketplaces to find buyers.

A few days ago, a data broker put up for sale 368.8 million stolen files said to belong to 26 companies.

Some are new breaches that have not been disclosed. These 8 companies, which had not disclosed a breach, are Teespring.com, MyON.com, Chqbook.com, Anyvan.com, Eventials.com, Wahoofitness.com, Sitepoint.com and ClickIndia.com.

In a conversation with the broker, BleepingComputer learned that Teespring are selling for $3,800-$4,000, MyON for $2,800, and Chqbook for $1,800. There are currently no prices for the remaining databases.

In the table below, you can see the companies whose data is said to be sold on hacking forums. The table also includes the number of files exposed and whether the breach is known or not:

CompanyUser RecordsKnown?
Teespring.com 8.2 millionNo
MyON.com13 millionNo
Chqbook.com1 millionNo
Anyvan.com4.1 millionNo
Eventials.com1.4 millionNo
Wahoofitness.com1.7 millionNo
Sitepoint.com1 millionNo
Clickindia.com 8 millionNo
Juspay.in 100 millionYes
Knockcrm.com 6 millionYes
Mindful.org1.7 millionYes
Bigbasket.com 20 millionYes
Reddoorz.com 5.8 millionYes
Hybris.com (SAP.com)4 millionSAP client data
Wedmegood.com1.3 millionYes
Wongnai.com 4.3 millionYes
Geekie.com.br 8.1 millionYes
Accuradio.com2.2 millionYes
Everything5pounds.com2.9 millionYes
Cermati.com2.9 millionYes
Netlog.com (Twoo.com)53 millionYes
Reverbnation.com 7.8 millionYes
Fotolog.com33 millionYes
Pizap.com60 millionYes
ModaOperandi.com1.2 millionYes
Singlesnet.com 16 million

Responses from companies

BleepingComputer contacted the companies listed on the hacking forum, but they have not publicly reported any incidents of breach.

MyON confirmed that its systems were breached , but stated that students' personal data has not been exposed

In July 2020, we learned that a criminal was attempting to sell our data on the dark web. We immediately began investigating ways to stop potential threats to our data or our customers’ data. We were subsequently able to confirm that, in accordance with federal and state privacy laws, no sensitive student or customer information was compromised.“.

We are committed to protecting the privacy of users’ and customers’ data and have implemented additional protections in addition to standard information security measures. Additional information about these efforts is described in our information security overview and Privacy Hub at https://www.renaissance.com/privacy/,” MyON told BleepingComputer.

From the samples found on the hacking forum, the exposed MyON information consisted of login names, BCrypt hashed passwords, and names.

On the other hand, Chqbook.com claims that it has not been a victim of a breach.

There has been no breach and no information belonging to our customers has been compromised. Data security is a top priority for us and we conduct regular security checks to ensure the safety of our customers’ information,” Chqbook told BleepingComputer.

However, BleepingComputer has emailed some of the users mentioned in Chqbook's sample to confirm whether the data belongs to them.

Finally, TeeSpring said it launched an investigation after learning that a broker was selling its data on a hacking forum.

User files of 26 companies are being sold on hacking forum

What should users of these sites do?

At present, not all companies have confirmed a breach.

However, users who have an account on any of the sites listed above must change their password and use a new, strong and unique password, exclusively for that site.

If the same password has been used on other sites, a change must be made there as well.

Source: Bleeping Computer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS