Showing posts with label Data Breach. Show all posts
Syrian Electronic Army Leaks Account Details of over 1 Million Forbes Readers
After the Forbes website and twitter hack, Syrian Electronic Army leaked account details of over 1 Million Forbes readers. The leaked detail contains login info of users such as email id and password. The password exposed are encrypted but can be cracked by simply using hash cracking tools or also some online sites.
All the leak was uploaded to a secure server with two versions of the dump, a text file and other was compressed version of the text file. They posted URL of the dump in a tweet.
Referring to their other tweet it looks they managed to do a successful phishing/social engineering attack on staff writer Alex Knapp and grabbed some important login credentials, which furthermore lead to the massive Forbes user database leak.
The leaked user details look like this (data has been deliberately altered):
To recover the passwords from this exposed database you'll need a lot of computing power and also time.
Still as there are millions of email id's included in the leak can be targeted for spamming, SEO and even phishing/Social engineering attacks.
Forbes later responded to this breach in their facebook post:-
Security message: Forbes.com was targeted in a digital attack and our publishing platform was compromised. Users' email addresses may have been exposed. The passwords were encrypted, but as a precaution, we strongly encourage Forbes readers and contributors to change their passwords on our system, and encourage them to change them on other websites if they use the same password elsewhere. We have notified law enforcement. We take this matter very seriously and apologize to the members of our community for this breach.
This breach makes a plus one to the list of victims suffered from 'SEA' hack. The Syrian Electronic Army previously has targeted big organizations such as Microsoft, CNN, Paypal, Ebay, Facebook.
All the leak was uploaded to a secure server with two versions of the dump, a text file and other was compressed version of the text file. They posted URL of the dump in a tweet.
Referring to their other tweet it looks they managed to do a successful phishing/social engineering attack on staff writer Alex Knapp and grabbed some important login credentials, which furthermore lead to the massive Forbes user database leak.
The leaked user details look like this (data has been deliberately altered):
To recover the passwords from this exposed database you'll need a lot of computing power and also time.
Still as there are millions of email id's included in the leak can be targeted for spamming, SEO and even phishing/Social engineering attacks.
Forbes later responded to this breach in their facebook post:-
Security message: Forbes.com was targeted in a digital attack and our publishing platform was compromised. Users' email addresses may have been exposed. The passwords were encrypted, but as a precaution, we strongly encourage Forbes readers and contributors to change their passwords on our system, and encourage them to change them on other websites if they use the same password elsewhere. We have notified law enforcement. We take this matter very seriously and apologize to the members of our community for this breach.
This breach makes a plus one to the list of victims suffered from 'SEA' hack. The Syrian Electronic Army previously has targeted big organizations such as Microsoft, CNN, Paypal, Ebay, Facebook.
Saturday, 15 February 2014
Posted by Pavan
Tesco supermarket suffered from data breach
Popular Supermarket Tesco suffered from a data breach. In this hack more than 2,000 of its customers’ accounts with their personal details were published on Pastebin.
The leaked data included the email addresses, plain text passwords and Tesco Clubcard point balances of 2,239 of the company’s customers.
The hackers are said to have stolen Clubcard points from customers in a small numbers, which Tesco has agreed to provide refunds for those victims.
In the response of this breach, a Tesco spokesperson said, "We take the security of our customers' data extremely seriously and are urgently investigating these claims.”
“We have contacted all customers who may have been affected and are committed to ensuring that none of them miss out as a result of this. We will issue replacement vouchers to the very small numbers who are affected."
On the paper, the leak number looks small but it have raised the security issue for the Tesco. Tesco was suffered from breach a year ago. In that breach vouchers worth of over a hundred pounds was suddenly disappeared from the customers account.
According to some security researchers, the hackers compiled the stolen details from other websites and then found that Tesco customers used the same username and password combination as those on previous hacks.
The customers are advised to use a different password for every single online account they own. Also try to avoid the dictionary words which are easy to crack even by just guessing. Use a strong password which include lower case, upper case, numbers, special symbols which are harder to crack.
Posted by Pavan
800,000 Customers’ detail stolen in Data Breach at French Telecom ‘Orange’
Orange Telecommunications, One of the world’s largest mobile operator service suffered massive data breach.
The French multinational telecommunication company announced recently, it was targeted by unknown hackers on 16th January 2014, who allegedly gained access to the accounts of up to 800,000 customers of Orange website.
According to some sources report, the company warned their customers in an email that their Client Area website orange.fr was hacked and user details of 3% customers have been stolen, but the passwords are not affected.
The user detail contains information such as names, mailing address, email, landline and mobile phone numbers.
The company warned, with the user details lost in this attack, hackers can perform phishing attacks, allowing them to steal personal data, including bank account details and passwords by sending emails that look as if they have come from official sources.
Orange has confirmed the data breach, and after the discovery of the attack, they closed "My Account" page from the official Orange website quickly for a few hours as a precaution. Orange also reported that it had found the source of the attack and has filed an official complaint with authorities.
CEO Stéphane Richard must be feeling awkward because as per his speech, protecting client data was “fundamental” for the company. As precaution Orange customers should change the login credentials of the affected accounts.
The French multinational telecommunication company announced recently, it was targeted by unknown hackers on 16th January 2014, who allegedly gained access to the accounts of up to 800,000 customers of Orange website.
According to some sources report, the company warned their customers in an email that their Client Area website orange.fr was hacked and user details of 3% customers have been stolen, but the passwords are not affected.
The user detail contains information such as names, mailing address, email, landline and mobile phone numbers.
The company warned, with the user details lost in this attack, hackers can perform phishing attacks, allowing them to steal personal data, including bank account details and passwords by sending emails that look as if they have come from official sources.
Orange has confirmed the data breach, and after the discovery of the attack, they closed "My Account" page from the official Orange website quickly for a few hours as a precaution. Orange also reported that it had found the source of the attack and has filed an official complaint with authorities.
CEO Stéphane Richard must be feeling awkward because as per his speech, protecting client data was “fundamental” for the company. As precaution Orange customers should change the login credentials of the affected accounts.
Monday, 3 February 2014
Posted by Pavan




