Apple, Gooogle, Facebook, Paypal… 184 millions d’identifiants en fuite, un festin pour les pirates
Recently, a significant data breach exposed 184,162,718 unique identifiers, accessible without any password protection or encryption measures. This breach included numerous sensitive documents, such as email addresses, usernames, passwords, and URLs for…
Recently, a significant data breach exposed 184,162,718 unique identifiers, accessible without any password protection or encryption measures. This breach included numerous sensitive documents, such as email addresses, usernames, passwords, and URLs for account access or authentication. Details of these findings can be found in the expert report .
The compromised services encompass a wide range of platforms, including Apple ID, Amazon, Discord, Instagram, Snapchat, Twitter, WordPress, and Yahoo. More critically, the breach involved login credentials for government portals, banks, financial institutions, and healthcare platforms across multiple nations. This exposure poses significant risks to affected individuals, as highlighted by security researcher Jeremiah Fowler.
To verify the authenticity of the exposed data, the researcher contacted individuals whose credentials were included in the database. Confirmation of the validity and activity of these passwords was received. Following this, the web host restricted server access, although the database owner's identity remains confidential at this time.
Recently, a significant data breach exposed 184,162,718 unique identifiers, accessible without any password protection or encryption measures.
The likely source of this data aggregation is identified as "infostealers." These malicious software programs are designed to extract personal information from infected devices, targeting browser-stored credentials, email clients, and instant messaging apps. Some variants can also capture autofill data, cookies, cryptocurrency wallet details, and even screenshots or keystrokes. Cybercriminals typically distribute these tools through phishing emails or pirated software containing harmful payloads.
A significant concern is the compromise of email accounts, such as Gmail, which can serve as "data goldmines for criminals." Users often inadvertently treat email accounts as free cloud storage, retaining sensitive documents like tax forms, medical records, contracts, and passwords without considering their vulnerability.
Researcher Jeremiah Fowler, adhering to ethical guidelines, did not download the database but utilized screenshots for verification purposes. He advises users to be aware of the sensitive information stored in their email accounts and recommends regularly deleting old sensitive emails containing personal identification information, financial documents, or other important files.
D’après Journal du Geek.
