Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Thursday July 09 2020, @07:42AM   Printer-friendly
from the get-your-hot-fresh-credentials-here! dept.

15 Billion Credentials Currently Up for Grabs on Hacker Forums:

Fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums – shedding light on the sheer scope of compromised credentials that are fueling account takeovers on the internet.

A report released Wednesday — "From Exposure to Takeover" by the Digital Shadows Photon Research Team — found that 100,000 separate data breaches over a two-year period have yielded a 300 percent increase in stolen credentials, leaving a veritable bonanza of account details on dark-web hacker forums up for grabs.

Most of the credentials are from consumers, and while many are sold on forums—for an average price of $15.43—many also are given away for free by hackers, researchers found.

[...] The credentials being flogged online vary in access and price, according to the report. They include usernames and passwords for everything from bank or financial accounts–which comprised 25 percent of the credentials analyzed–to video- and music-streaming services, to antivirus programs.

Unsurprisingly, credentials for bank and other financial accounts are also the most expensive to purchase, selling for an average of $70.91 a piece, researchers found. Indeed, data that puts potential financial gain on the table tends to be the most valuable to threat actors.

Data for accessing antivirus programs earned the second-highest price on hacker forums, at an average of $21.67. Threat actors apparently find access to media streaming, social media, file sharing, virtual private networks (VPNs) and adult-content sites far less valuable, with these credentials traded "for significantly under $1" on forums, according to the report.

While consumer credentials comprised the bulk of those researchers tracked, organizations are not immune to the risk of credential theft and potential reuse for nefarious purposes, particularly if financial gain is involved. The report uncovered 2 million accounting email addresses exposed online, with those referencing "invoice" or "invoices" the most commonly advertised on hacker forums, researchers said.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 0) by Anonymous Coward on Thursday July 09 2020, @11:42AM (2 children)

    by Anonymous Coward on Thursday July 09 2020, @11:42AM (#1018610)

    ..antivirus creds?!

  • (Score: 3, Insightful) by looorg on Thursday July 09 2020, @12:33PM

    by looorg (578) on Thursday July 09 2020, @12:33PM (#1018622)

    I found this one a bit odd to. But I don't think they care or want them for their anti-virus properties. I would see it more as intel on person or company, so you know what they are running so you can tailor future attacks of them better or to prevent or circumvent said protection. For most people just running MS defender (or whatever it's called again) is probably good enough, and it's free.

  • (Score: 2) by The Vocal Minority on Friday July 10 2020, @05:22AM

    by The Vocal Minority (2765) on Friday July 10 2020, @05:22AM (#1018970) Journal

    Password reuse