Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 18 submissions in the queue.
posted by Fnord666 on Thursday July 09 2020, @07:42AM   Printer-friendly
from the get-your-hot-fresh-credentials-here! dept.

15 Billion Credentials Currently Up for Grabs on Hacker Forums:

Fifteen billion usernames and passwords for a range of internet services are currently for sale on underground forums – shedding light on the sheer scope of compromised credentials that are fueling account takeovers on the internet.

A report released Wednesday — "From Exposure to Takeover" by the Digital Shadows Photon Research Team — found that 100,000 separate data breaches over a two-year period have yielded a 300 percent increase in stolen credentials, leaving a veritable bonanza of account details on dark-web hacker forums up for grabs.

Most of the credentials are from consumers, and while many are sold on forums—for an average price of $15.43—many also are given away for free by hackers, researchers found.

[...] The credentials being flogged online vary in access and price, according to the report. They include usernames and passwords for everything from bank or financial accounts–which comprised 25 percent of the credentials analyzed–to video- and music-streaming services, to antivirus programs.

Unsurprisingly, credentials for bank and other financial accounts are also the most expensive to purchase, selling for an average of $70.91 a piece, researchers found. Indeed, data that puts potential financial gain on the table tends to be the most valuable to threat actors.

Data for accessing antivirus programs earned the second-highest price on hacker forums, at an average of $21.67. Threat actors apparently find access to media streaming, social media, file sharing, virtual private networks (VPNs) and adult-content sites far less valuable, with these credentials traded "for significantly under $1" on forums, according to the report.

While consumer credentials comprised the bulk of those researchers tracked, organizations are not immune to the risk of credential theft and potential reuse for nefarious purposes, particularly if financial gain is involved. The report uncovered 2 million accounting email addresses exposed online, with those referencing "invoice" or "invoices" the most commonly advertised on hacker forums, researchers said.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by bzipitidoo on Friday July 10 2020, @02:15AM

    by bzipitidoo (4388) on Friday July 10 2020, @02:15AM (#1018928) Journal

    > particularly if financial gain is involved.

    There it is. Web site and data erasure vandalism might be fun and all, but in most cases it doesn't make the perps any money.

    A protection I rely on is not all this security theater, it's that most of my online accounts and activities aren't worth anything, that is, there's no way to get any money. Suppose someone hacked into my account here on SoylentNews, what could they do, really? Might be able to charge something to my credit card, but I trust SoylentNews doesn't keep that info. Right?

    I haven't reused passwords for a decade now, and never for anything valuable, so figuring out this one won't help break into any of my other accounts on other sites. Been about that long since I went through the accounts where I had reused passwords and changed them all. So if a site screws up and leaks my password, no big deal for me.

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2