Story image

Chinese threat actor linked to leak of more than 200 million Japanese PII datasets

21 May 2018

More than 200 million pieces of personal information harvested from Japanese website databases have been spotted for sale on underground forums.

Leaked personal information includes names, credentials, email addresses, dates of birth, phone numbers, and home addresses.

Security firm FireEye uncovered the databases for sale in December 2017 and says the information is most likely authentic.

The Japanese databases were harvested from May-July 2013 and May-June 2016 and appear to be from between 11-50 websites. The websites include those in the retail, entertainment, financial, food and beverage, and transportation sectors.

FireEye believes the data is genuine for a number of reasons, particularly because the data was varied and not available through public data sources. However, many of the datasets were duplicates.

“Out of a random sample of 200,000 leaked email addresses, the majority were previously leaked in major data leaks. This indicates that the email addresses sold in these datasets were unlikely to be fabricated specifically for this data leak,” FireEye adds.

According to a sample of more than 190,000 credentials, 36% contained duplicate values. There were also fake email addresses, suggesting that the number of genuine credentials and sets of PII is ‘significantly lower than advertised’, FireEye says.

“Due to the low-profile nature of most of these websites and possible negative effects on the actor's reputation, the actor selling the data has little incentive to falsify the data sources,” the firm adds.

The threat actor, who was asking ¥1,000 CNY ($150.96 USD), has been selling databases on Chinese underground forums since 2013. While several buyers were interested in buying the dataset, many complained that they did not get the product that was advertised.

The identity of the seller behind this latest dataset is connected to a personal living in China’s Zheijiang province, FireEye speculates.

“The actor sells data exfiltrated from websites in China, Taiwan, Hong Kong, European countries, Australia, New Zealand, and North American countries. We also found two other personas likely connected to this actor through a common QQ address. This QQ address is also connected to an individual living in China’s Zhejiang province,” FireEye explains.

“As the actor has a significant portion of negative reviews on underground forums, it is still possible that the information is fabricated or contains data previously sold by the actor. Notably, negative reviews linked to this vendor claim that the actor does not deliver data or does not provide the product that the buyer expected.”

The company warns that while the dataset will most likely not precede large-scale attacks against entities or individuals caught in the leak, the information could be used to target other entities if individuals reused credentials between the compromised websites and other personal or business-related accounts.

“The lists of leaked email addresses and PII can also facilitate identity theft, spam and malware propagation, and fraud,” FireEye concludes.

Salesforce continues to stumble after critical outage
“To all of our Salesforce customers, please be aware that we are experiencing a major issue with our service and apologise for the impact it is having on you."
D-Link hooks up with Alexa and Assistant with new smart camera
The new camera is designed for outdoor use within a wireless smart home network.
Slack users urged to update to prevent security vulnerability
Businesses that use popular messaging platform Slack are being urged to update their Slack for Windows to version 3.4.0 immediately.
Secureworks Magic Quadrant Leader for Security Services
This is the 11th time Secureworks has been positioned as a Leader in the Gartner Magic Quadrant for Managed Security Services, Worldwide.
Google puts Huawei on the Android naughty list
Google has apparently suspended Huawei’s licence to use the full Android platform, according to media reports.
Using data science to improve threat prevention
With a large amount of good quality data and strong algorithms, companies can develop highly effective protective measures.
General staff don’t get tech jargon - expert says time to ditch it
There's a serious gap between IT pros and general staff, and this expert says it's on the people in IT to bridge it.
ZombieLoad: Another batch of flaws affect Intel chips
“This flaw can be weaponised in highly targeted attacks that would normally require system-wide privileges or a complete subversion of the operating system."