Story image

Massive 2.2bil-username data dump leaked on dark web

01 Feb 2019

A second major data dump has hit the dark web in two weeks, compromising of 2.2 billion unique usernames and passwords.

The data dump has been dubbed Collection #2-5 and contains 845GB of data and over 25 billion unique records.

This makes the second leak three times bigger than the Collection #1 dump leaked last month, identified by Australian Cybersecurity expert Troy Hunt.

Wired reported that Collection #2-5 was discovered and has been analysed by security researchers at Germany’s Hasso Plattner Institute and cybersecurity firm Phosphorus.io.

Users can go to the Hasso Plattner Info Leak Checker to see if their email details and credentials have been compromised in the latest data dump.

OneSpan security competence centre and security strategy senior manager market Frederik Mennes says, “2.2 billion unique records is a staggering number.”

“We are becoming accustomed to breach notification news, but sad to say, the use of multi-factor authentication is still not utilised whenever and wherever possible.

“Companies should remember that easy targets will continue to be exploited first, because cybercrime follows the path of least resistance,” Mennes says.

“Technology is evolving, and next-generation authentication, intelligent adaptive authentication, is gaining momentum.

“This technology utilises AI and machine learning to score vast amounts of data, and based on patterns, analyses the risk of a situation and adapts the security and required authentication accordingly.”

OneSpan innovation centre chief security architect Steven Murdoch says, “This password leak shows that large quantities of stolen passwords are readily available to anyone, regardless of how low their budget.

“However, data from recent breaches will be considerably more expensive to obtain. 

“Companies should recognise the limitations of password authentication and are in the best position to mitigate the weaknesses. They should implement additional measures, such as the detection of suspicious behaviour.

“Two-factor authentication, or even better, FIDO/U2F, should be offered to customers. Customers can also help by not re-using passwords across multiple sites and using a password manager if needed.

“The website TwoFactorAuth.org gives instructions on how to enable two-factor authentication on many popular sites, as enabling 2FA, and preferably FIDO/U2F, will significantly help to improve their security.

Thycotic debunks top Privileged Access Management myths
Privileged Access encompasses access to computers, networks and network devices, software applications, digital documents and other digital assets.
Veeam reports double-digit Q1 growth
We are now focussed on an aggressive strategy to help businesses transition to cloud with Backup and Cloud Data Management solutions.
Paving the road to self-sovereign identity using blockchain
Internet users are often required to input personal information and highly-valuable data from contact numbers to email addresses to make use of the various platforms and services available online.
Tech Data to distribute Nutanix backup solution in A/NZ
Tech Data will distribute HYCU Data Protection for Nutanix backup and recovery software to their network of partners across Australia and New Zealand.
Veeam releases v3 of its MS Office backup solution
One of Veeam’s most popular solutions, Backup for Office 365, has been upgraded again with greater speed, security and analytics.
Too many 'critical' vulnerabilities to patch? Tenable opts for a different approach
Tenable is hedging all of its security bets on the power of predictive, as the company announced general available of its Predictive Prioritisation solution within Tenable.io.
Safety solutions startup wins ‘radical generosity’ funding
Guardian Angel Security was one of five New Zealand businesses selected by 500 women (SheEO Activators) who contributed $1100 each.
Industrial control component vulnerabilities up 30%
Positive Technologies says exploitation of these vulnerabilities could disturb operations by disrupting command transfer between components.