Hacker Gives Away 272 Million Stolen Accounts for $1
Stolen usernames and passwords from Yahoo, Google and Microsoft's webmail services are reportedly being traded by Russian criminals. They are said to be among a batch of 272.3 million accounts, though most are from a popular Russian service.
The trade has been revealed by Hold Security in a discussion with Reuters. Hold's founder says his staff uncovered the batch when trawling an online forum used by hackers.
The person who provided the information claimed he had a total of 1.17 billion records, but agreed to hand over a portion of them. It seems that while many criminals buy and sell such records for relatively large amounts, this hacker was more interested in the prestige and was offering the files for less than a dollar.
Even at that price, Hold's staff refused to pay, citing a company principle of not paying for stolen information. Instead they persuaded the hacker to pass on the details in return for favorable posts about him in online forums.
Russian Firm Hit Hard
With duplicates removed, the files covered 272 million different users. Around 57 million were from Mail.ru, a Russian webmail provider. That's an astonishing number given the company reports having 64 million active users.
The haul also reportedly included details of 40 million Yahoo Mail accounts, 33 million Hotmail accounts and 24 million Gmail accounts, alongside those for services in China and Germany. (Source: reuters.com)
Hold Security passed on the files to the relevant companies 10 days ago and gave them time to deal with them before going public. Mail.ru says it is examining whether the data is up to date before contacting affected customers, but says many of the username/email combinations may be outdated or bogus.
Phishing Boom May Follow
Security experts say there's likely no need for immediate panic, but have warned that there's a risk that the hacker may pass on the data to less reputable recipients. For that reason, users should watch out for an increase in phishing emails if cybercriminals get hold of the email addresses. (Source: bbc.co.uk)
The incident should also serve as a reminder of the importance of not using the same passwords for multiple services, particularly ones which can allow access to confidential data such as emails and online banking.
What's Your Opinion?
Are you concerned that a hacker may be giving passwords away so cheaply, meaning they could be seen by many criminals? Do you think the low asking price means the data probably isn't accurate? Should webmail companies do more to keep users safe and secure?
Most popular articles
- Which Processor is Better: Intel or AMD? - Explained
- How to Prevent Ransomware in 2018 - 10 Steps
- 5 Best Anti Ransomware Software Free
- How to Fix: Computer / Network Infected with Ransomware (10 Steps)
- How to Fix: Your Computer is Infected, Call This Number (Scam)
- Scammed by Informatico Experts? Here's What to Do
- Scammed by Smart PC Experts? Here's What to Do
- Scammed by Right PC Experts? Here's What to Do
- Scammed by PC / Web Network Experts? Here's What to Do
- How to Fix: Windows Update Won't Update
- Explained: Do I need a VPN? Are VPNs Safe for Online Banking?
- Explained: VPN vs Proxy; What's the Difference?
- Explained: Difference Between VPN Server and VPN (Service)
- Forgot Password? How to: Reset Any Password: Windows Vista, 7, 8, 10
- How to: Use a Firewall to Block Full Screen Ads on Android
- Explained: Absolute Best way to Limit Data on Android
- Explained: Difference Between Dark Web, Deep Net, Darknet and More
- Explained: If I Reset Windows 10 will it Remove Malware?
My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in cyber crimes (sextortion / blackmail / tech support scams) with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 21 years of excellence! Click to view our rating on the BBB.
Comments
"I'll buy that for a dollar!"
Selling all that information for $1.00 seems incomprehensibly cheap; surely that much information (if it were valid) is worth thousands more. I'm willing to bet that the data is either incredibly old, outdated, or entirely bogus.
Favorable comments in posts?
"lol" pfft" Gag" I no tht hkr" "wht a nice gy" Etc etc etc.
I don't know, really think he could have been persuaded to surrender them gratis instead of for a dollar, for 'favorable' posts about him, if they were all just "old, outdated, or entirely bogus" ? Don't think he'd get too many.
Anyways, if that were so, as long as everyone thought they were valid, their accounts would have been safe. Now maybe all these hackers are going to try to update their info. Rotten days are here for everyone, for a while, anyways... I'm going to be abswering my relatives calls a lot more, it seems.. "Stop! Dont! click that llink! .. no.. it *doesn't mean your credit card ios frozen" "no paypal is NOT hosted on ezeSx dotcom"" "No your accounts *aren't* frozen unless you click that email link" DON'T do ANYTHING until I get there"
Yikes!