HomeSecurityThe leak of 16 billion credentials is not due to a new breach

The leak of 16 billion credentials is not due to a new breach

News recently broke of the “mother of all breaches,” generating widespread media coverage, full of warnings and scaremongering. However, it appears to be a collection of already leaked credentials, which had been stolen via malicious infostealers in previous data breaches and credential stuffing attacks.

See also: UBS: Data leak affects thousands of employees

credential breach

To be clear, this is not a new data breach — or even a breach — and the websites involved have not recently been hacked to steal these credentials.

Instead, these stolen credentials had likely been circulating for a long time, perhaps even years. They were then collected by a cybersecurity company, researchers, or malicious actors, and repackaged into a database that was exposed online.

It is unclear who owns the leaked data. While it could be security researchers gathering data to audit and monitor leaks, it is almost certain that some of the leaked datasets belonged to cybercriminals.

Cybernews, which spotted the brief report of this data collection, reported that it was stored in a format typically associated with infostealer, although they did not share samples. The only positive here is that all of the datasets were only exposed briefly: long enough for researchers to uncover them, but not long enough to figure out who was controlling vast amounts of data. Most of the datasets were temporarily accessible via insecure Elasticsearch or object storage snapshots.

An infostealer is malware that aims to steal credentials, cryptocurrency wallets, and other data from an infected device. Over the years, this type of software has become a huge problem, leading to data breaches worldwide.

Infostealers affect both Windows and Mac systems, and when they run, they collect all the credentials they can find stored on the device, storing them in what is called a "log".

See also: United Kingdom: 23andMe fined for 2023 data breach

The leak of 16 billion credentials is not due to a new breach
The leak of 16 billion credentials is not due to a new breach

An infostealer log is usually an archive that includes numerous text files and other stolen data. The text files contain lists of credentials stolen from browsers, files, and other applications.

If someone is infected with infostealer malware and has a thousand credentials stored in their browser, the infostealer will intercept them all and store them in a so-called “log.” These logs are then uploaded to servers , where the credentials are either used for further attacks or sold on cybercrime marketplaces.

The problem with infostealers has become so large and widespread that compromised credentials have become one of the most common ways cybercriminals gain access to networks.

Below, you can see a sample of the leaked data, which includes URLs to Facebook, Google, Github, Zoom, Twitch, and other login pages:

The leak of 16 billion credentials is not due to a new breach

The most important step in protecting yourself from such incidents is to adopt and maintain basic cybersecurity practices — ones you should already be practicing. If you're concerned that an infostealer might be on your computer, first scan it with a reputable antivirus program before changing any passwords. Otherwise, any new credentials you enter could be intercepted as well.

Selecting the team

🔑 Secure your passwords with Proton Pass

Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.

  • ✔ Encrypted storage of passwords & passkeys
  • ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
  • ✔ Free version — on all devices
Get your free Proton Pass →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Once you've made sure your system is clean, focus on improving your password management and security.

See also: Zoomcar: Data breach affects 8.4 million customers

Many users today have dozens or even hundreds of passwords stored in their browsers for convenience. But if their system is infected with an infostealer — which can happen simply by opening an email or installing a “broken” app — then the attacker immediately gains access to all of those accounts: email, social media, banking, work platforms, and more.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS