HomeSecurityWhy is Comcast making its users change their passwords?

Why is Comcast making its users change their passwords?

Hackers combined usernames and passwords of Comcast accounts with usernames and passwords that they had obtained from earlier hacks.

 

comcast_logo_detail

 

Another example of why it is necessary for users to use multiple passwords in any transaction they make on the Internet.

Comcast , the largest cable TV and Internet service provider in the US with more than 28 million subscribers, revealed on November 9 that it is necessary for about 200,000 of its users to change their passwords after the company discovered that their information was sold and resold online on the black market .

This specific incident was not the result of hacking into Comcast's databases, but the hackers combined the usernames (in Comcast's case, usernames are email addresses) and passwords of the company's accounts with usernames and passwords from previous hacks at other companies.

This not only shows how often people use the same username and password across different accounts but also is a striking example of how common the theft of such data has become.

Essentially, all the usernames/emails and passwords that were found at risk were obtained by online thieves who use readily available software to match them with those from other accounts (from social networks, retail stores, etc.) that have already been stolen.

Traders of stolen personal information typically operate on networks that are part of the so-called “ Dark Web . ” The Dark Web is the colloquial term for the anonymous network enabled by Tor, proxies, and other privacy-focused technologies. It is not available on the public Internet and is accessed through specialized software.

The sites and services on the Dark Web can range from collaborative platforms for dysfunctional stores to shops that sell illegal goods and hubs for darker criminal activities.

In the case of Comcast, the names were sold on the Dark Web last weekend as a list of 590,000 combinations of usernames and their passwords, which the anonymous seller claimed belong to Comcast users.

As the CSO notes, the seller demanded $1000 for the entire list. When the company was notified and checked the accounts, it was determined that only one third of the 590,000 combinations were breached.

Thus, to protect its 200,000 customers, the company locked their accounts over the weekend and forced them to verify their identity and change passwords.

If these codes have not been used on other accounts that have been hacked, the chances of Comcast accounts being sold on the black market have decreased significantly.

 

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS