- User names and passwords could open the door to online bank accounts, corporate networks, health records
- Experts say amount of stolen information is ‘overwhelming’
- Working to identify where data was stolen from – and who is at risk
- Criminals are selling 1.25 billion email addresses, which would be of interest to spammers
By
Mark Prigg
12:42 EST, 26 February 2014
|
15:56 EST, 26 February 2014
A cybersecurity firm has uncovered stolen credentials from 360 million accounts that are available for sale on cyber black markets.
The team describe the find as ‘mind boggling’ and say they are unsure how the information was aquired by hackers – or exactly what details are for sale.
However, they warn the discovery could represent more of a risk to consumers and companies than stolen credit card data because of the chance the sets of user names and passwords could open the door to online bank accounts, corporate networks, health records and virtually any other type of computer system.
Experts fear the user names and passwords could open the door to online bank accounts, corporate networks, health records and virtually any other type of computer system.
BIGGEST BREACH IN HISTORY?
360 million records were obtained in separate attacks, including one that yielded some 105 million records, which would make it the largest single credential breaches known to date.
Experts believe the credentials were stolen in breaches that have yet to be publicly reported.
Alex Holden, chief information security officer of Hold Security LLC, said in an interview that his firm obtained the data over the past three weeks, meaning an unprecedented amount of stolen credentials is available for sale underground.
‘The sheer volume is overwhelming,’ said Holden, whose firm last year helped uncover a major data breach at Adobe Systems Inc in which tens of millions of records were stolen.
Holden said he believes the 360 million records were obtained in separate attacks, including one that yielded some 105 million records, which would make it the largest single credential breaches known to date.
He said he believes the credentials were stolen in breaches that have yet to be publicly reported.
The companies attacked may remain unaware until they are notified by third parties who find evidence of the hacking, he said.
‘We have staff working around the clock to identify the victims,’ he said.
He has not provided any information about the attacks to other cybersecurity firms or authorities but intends to alert the companies involved if his staff can identify them.
The massive trove of credentials includes user names, which are typically email addresses, and passwords that in most cases are in unencrypted text.
Holden said that in contrast, the Adobe breach, which he uncovered in October 2013, yielded tens of millions of records that had encrypted passwords, which made it more difficult for hackers to use them.
360 million records were obtained in separate attacks, including one that yielded some 105 million records, which would make it the largest single credential breaches known to date.
The email addresses are from major providers such as AOL Inc, Google Inc, Microsoft Corp and Yahoo Inc and almost all Fortune 500 companies and nonprofit organizations.
Holden said he alerted one major email provider that is a client, but he declined to identify the company, citing a nondisclosure agreement.
Heather Bearfield, who runs the cybersecurity practice for accounting firm Marcum LLP, said she had no information about the information that Hold Security uncovered but that it was plausible for hackers to obtain such a large amount of data because these breaches are on the rise.
She said hackers can do far more harm with stolen credentials than with stolen payment cards, particularly when people use the same login and password for multiple accounts.
‘They can get access to your actual bank account. That is huge,’ Bearfield said.
‘That is not necessarily recoverable funds.’
After recent payment-card data breaches, including one at U.S. retailer Target, credit card companies stressed that consumers bear little risk because they are refunded rapidly for fraud losses.
Wade Baker, a data breach investigator with Verizon Communications Inc, said that the number of attacks targeting payment cards through point-of-sales systems peaked in 2011.
That was partly because banks and retailers have gotten better at identifying that type of breach and quickly moving to prevent crooks from making fraudulent transactions, he said.
In addition to the 360 million credentials, the criminals are selling some 1.25 billion email addresses, which would be of interest to spammers, Hold Security said in a statement on its website
Share or comment on this article
-
Horror moment man is floored by single, fatal punch -
Bieber tries to walk the line after DUI arrest -
Tunnels used by drug kingpin to avoid capture -
NFL star Ray Rice drags unconscious fiancee from elevator… -
Run! Woman chased by ‘stampeding herd’ of rabbits in Japan -
Police footage of Justin Bieber in custody after DUI arrest -
Bieber does push-ups in cell after DUI arrest -
Idol’s Savion Wright remembers dead brother -
Cheeky monkey steals man’s GoPro for the ultimate selfie -
Controversial final seconds of High school basketball final -
Slapped in the face by a whale’s tail: Girl gets a little… -
‘I want to stay with my mummy!’ Newborn refuses to let go
-
EXCLUSIVE – An ‘affair’ with white sheriff’s daughter, drugs… -
‘I couldn’t believe my luck!’: 17-year-old’s boast as… -
‘She wasn’t scared a bit’: How girl ELEVEN grabbed gun and… -
‘If it seems too good to be true, it probably is’: Ex-NFL… -
Five kids in nine months! Couple who adopted triplets became… -
Actor Seth Rogen calls out U.S. Senators for walking out of… -
Could newly discovered gold coins be the haul stolen by… -
American woman, 31, was found ‘painted in blood from head to… -
Woman, 35, ‘had sex with schoolboy, 12, in the back of her… -
It’s almost a shame you have to land! Pilots reveal the 26… -
An unexpected punchline! The JOKE that got a man banned for… -
Three-year-old girl mauled to death by her family’s pet pit…
Comments (58)
Share what you think
-
Newest -
Oldest -
Best rated -
Worst rated
The comments below have been moderated in advance.
Peter,
Eastleigh,
14 hours ago
Call centres abroad the next big scandal.
Billy The Kid,
The Alamo,
15 hours ago
We’re advised that the internet is like the street, so why are we so ready to conduct our financial affairs in a ‘street’?
Angela Briers,
Nottinghamshire, United Kingdom,
15 hours ago
In the past, only you knew what came through the letter box. This must be part of the big Society everyone speaks about.
Dada,
Out of the Way, United Kingdom,
15 hours ago
All my passwords are different for each website, and are offline. In a book. Hack that.
PrefertheSundaySport,
bedford, United Kingdom,
16 hours ago
I don’t have on line banking….I use a phone as, I have to admit, Halifax call centers are blooming good
Laidbk,
Swindon,
16 hours ago
360 million must be a Chinese bank
Electric Dragon,
Southampton,
16 hours ago
This is why I have a QQ Mail account – it’s actually one of the safest Email systems ever, as it adheres to strict Chinese government regulations when it comes to online activity, and if you try to send mail with prohibited content, it warns you saying your email cannot be sent.
hfgjfjfghjfg,
London, United Kingdom,
17 hours ago
WAKE UP
Every ID is for sale when in the wrong hands.
Sandroski,
London,
17 hours ago
I received a letter last October from Adobe in The US stating that my account had been hacked. I believe they should protect our data more sensibly.
Tony,
Hampton, United States,
17 hours ago
If GCHQ is as good as they say it is, they should be able to trace those who have done the hacking. If they can’t, perhaps they can explain what they do with their time and our money.
The views expressed in the contents above are those of our users and do not necessarily reflect the views of MailOnline.
Who is this week’s top commenter?
Find out now
