Data breach notification service Have I Been Pwned has added over 284 million accounts that have been stolen by info-stealer malware.

Have I Been Pwned founder Troy Huntreported finding 284,132,969 compromised accounts while analyzing 1.5 TB of stealer logs, likely collected from multiple sources and shared on a Telegram channel (ALIEN TXTBASE).
According to Hunt, 23 billion strings with 493 million unique pairs of websites and email addresses (affecting 284 million unique email addresses) have been exposed
“We also added 244 million never-before-seen passwords to Pwned Passwords“.
See also: New distribution campaigns of info-stealer malware Lumma and ACR Stealer
Due to the large number of accounts, the data may also include both old and new credentials stolen through credential stuffing attacks and data breaches.
Using new APIs, which allow up to 1000 email address searches per minute, and stealer log searchers, domain owners and website administrators (who pay a monthly subscription) can now identify customers whose credentials were stolen by searching the added stealer logs based on the email domain or website domain.
“The introduction of these new APIs will finally help many organizations identify the source of malicious activity and, more importantly, prevent and block it before it does any damage,” he added.
Ordinary users can also see if their information has been stolen by info-stelaer malware if they are subscribed to Have I Been Pwned alerts.
“But it will only show which sites their credentials were stolen on if they use the notification service to verify their address. I didn’t want to show that information publicly as it could expose the use of sensitive services,” Hunt said.
See also: Phishing attacks distribute FatalRAT malware

Protection from info-stealer malware
Static detection methods for security are not enough to avoid software antivirus malware . A more robust approach should incorporate , equipped with advanced analysis capabilities.
It's also important to keep your operating system and applications up to date. These updates often include security that can protect your computer from the latest threats.
Information security training is also crucial. This means knowing how to recognize and avoid phishing attacks , which attackers often use to install info-stealers.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Salt Typhoon uses custom malware JumbledPath in attacks
Also, don't forget to use firewalls and monitor network traffic to help you immediately detect suspicious activity. Users to avoid executable files downloaded from strange websites.
Finally, using strong passwords and enabling two-factor authentication can provide an extra layer of protection. This can make it harder for attackers to gain access to your account, even if they manage to steal your password.
Source: www.bleepingcomputer.com
