Hacker who stole over 600 mn account details strikes again

Image
IANS San Francisco
Last Updated : Feb 15 2019 | 7:06 PM IST

A hacker who stole close to 620 million user records from 16 websites has struck again, this time breaking into 127 million more records from eight more websites.

According to a TechCrunch report late on Thursday, the hacker now has 18 million user records from travel booking site Ixigo and 40 million from live-video streaming site YouNow.

"Houzz, which recently disclosed a data breach, is listed with 57 million records stolen and Ge.tt had 1.8 million accounts stolen," said the report.

According to the hacker's listings, Ixigo used an outdated "MD5" hashing algorithm to scramble passwords, which these days is easy to unscramble.

"YouNow doesn't store passwords," a spokesperson was quoted as saying.

In a statement to IANS, Ixigo said it is currently investigating this alleged security breach.

"We are a travel marketplace and we take our users data and privacy seriously. We do not store payment, cards or financial information for any of our users," said a company spokesperson.

"We encrypt and hash our passwords with a one-way hashing algorithm. While we have already taken pre-emptive security measures such as two-factor authentication, we will also, as a precaution, reset passwords and security tokens of our users," the spokesperson added.

Earlier, the same hacker claimed he had user records from several major sites like more than 151 million records from MyFitnessPal and 25 million records from Animoto.

It has been claimed that databases, which are aimed at making "life easier" for hackers, can be purchased from the Dream Market cyber-souk, located in the Tor network, for less than $20,000 in bitcoin.

The stolen information mainly includes account holders' names, email addresses and passwords, according to the report that appeared this week.

The price appears to be relatively cheap because the information is targeted at spammers and credential stuffers who could use the information to also get access to other sites for which the users use the same usernames and passwords.

While some of these websites - particularly MyHeritage, MyFitnessPal and Animoto - warned their customers last year that they had been compromised, several others have started notifying users about the hacks.

--IANS

na/bg

(Only the headline and picture of this report may have been reworked by the Business Standard staff; the rest of the content is auto-generated from a syndicated feed.)

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Feb 15 2019 | 6:30 PM IST

Next Story