Jump to content

Hackers Uploaded 42M Record that Contains Email Address and Credit Card Data to Free Anonymous Hosting Service


steven36

Recommended Posts

Hackers uploaded a collection of 42 million Email Address , plain text passwords, Spotify details, and partial credit card data to free anonymous hosting service Kayo.moe.

 

https://s7d8.turboimg.net/sp/584df5f761d0bdb537de5247c5412e5f/EMAILS.jpg

 

The operators of the service Kayo reached out to the security expert Troy Hunt to report the data and for further investigation. Kayo shared 755 files totaling 1.8GB.

 
 

According to Hunt, the data is typically taken from multiple data breaches and then combined into a single list to perform Credential stuffing attacks. The data is not related to Kayo.moe and the platform is not affected by any incidents.

 

https://s7d1.turboimg.net/sp/7ab4bd9f2d2dff39968463873e16551c/Kayo.me-data.png

 

 

The data also contains a number of files, some with partial credit card data, logs and some with Spotify details. While checking for Email, Hunt found 42M unique values Email Address 93% of them already exists in HIBP.

 

 

 

Quote

 

There was no single pattern for the breaches they appeared in and the only noteworthy thing that stood out was a high hit rate against numeric email address aliases from Facebook added Hunt.

 

These Credential stuffing attacks can be avoided by using a unique password for each service and change the passwords to all accounts at least once a month.

 

You can also strengthen your security by taking additional precautions such as moving to two-factor authentication. Don’t use the same password for multiple accounts, especially Internet banking and other accounts where money or sensitive information are involved.

 

Source

Link to comment
Share on other sites


  • Replies 1
  • Views 1.1k
  • Created
  • Last Reply

You can tell people to use pass phrases instead of passwords and to use a minimum of 16 mixed items but until websites start making that a requirement then lazy people will keep making simple passwords and using the same password multiple places.  Fortunately credit card theft isn't the threat it once was since a good credit card company will offer one time use numbers.  So every purchase I make on the internet uses a one time use number that can never be used again.  Eventually I know that numbers will actually be reused but as a one time use it doesn't make any difference since if I gave out a credit card number I just used it would not work again anywhere.

Link to comment
Share on other sites


Archived

This topic is now archived and is closed to further replies.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...