IT News, Blog & Top Tips from SpecTronics

What you should know about the Russian hacker password heist

11-Aug-2014 17:17:19 / by Ben Spector

A gang of criminals has stolen 1.2 billion unique password and username combinations. The massive theft has damaged companies around the world. Here are the details of the crime and some ways of strengthening the security of your information.

What happened

A group of Russian hackers has stolen the largest amount of Internet credentials in history, Milwaukee-based Hold Security announced this week. The stolen information includes 1.2 billion usernames and password combinations, as well as 500 million email addresses.

Hold Security, who discovered the theft, has declined to name the victims in light of its nondisclosure agreements and the fact that several of the targeted companies still remain vulnerable. However, The New York Times confirmed Hold Security’s findings by hiring an expert unaffiliated with the security company who then determined that the database of stolen identities was genuine.

The Details of the Information Theft

The gang of cyber criminals built up their pool of stolen credentials over a span of several years. They started work on their illicit enterprise in 2011, when they began buying personal information on the black market. However, in April 2013, they advanced their capabilities. Alex Holden, the founder and chief information security officer at Hold Security, said that he believes that the group teamed up with another criminal entity, which he has not yet identified, in order to learn more about various hacking techniques.

Since then, the group has begun using botnets — networks of computers that have been infected by a virus — for stealing information on a gargantuan scale. By July, they were able to steal 4.5 billion records, each with a username and password. Although many of these records overlapped, Holden estimated that around 1.2 billion of them were unique.

According to the security firm, the hackers captured information from over 420,000 websites. The victims were from countries around the world, and ranged in size from small businesses to large corporations.

Another Instance in a Growing Trend of Cyber Crime

This is not the first large-scale information theft to occur in recent history, with several information security breaches just coming last year. In December, Eastern European hackers stole 40 million credit card numbers and 70 million other pieces of personal information, including addresses and phone numbers.

Similarly, US authorities uncovered in October a Vietnam-based identity theft scheme that had managed to steal around 200 million personal records. That stockpile of stolen data included credit card information, bank account records, and Social Security numbers.

How to Protect Your Information

While it remains unclear what companies were struck by the latest theft, there can be no doubt that both corporations and consumers should be on their guard. First and foremost, those concerned about the safety of their records should change their passwords, making sure not to duplicate passwords for multiple sites.

Another crucial measure involves using a password manager tool. These applications create unique passwords for each site that a person visits, and then stores them in a database secured by a master password. This decreases the likelihood of a person using the same password twice or choosing one that is too easy to hack.

Managing passwords is only one part of the solution. While it is a good first step, it is often not enough on its own. Other security features such as secondary or two-factor authentication should also be used when the opportunity presents itself. Websites that use this method will send users a message with a one-time code that they must enter before accessing the system.

While consumers should take care to protect themselves, information security companies are still the best method for stopping hackers. Contact us to learn more about the most optimal security options for your organization.

Topics: News

Ben Spector

Written by Ben Spector

Subscribe to Email Updates

Lists by Topic

see all

Posts by Topic

see all

Recent Posts