Showing posts with label Tumblr. Show all posts
Showing posts with label Tumblr. Show all posts

Saturday, October 1, 2016

Open Forum: What online security measures do you use?





By Rob Thubron on September 30, 2016, 6:00 PM


Yahoo’s admission this week that a 2014 hack led to over 500 million accounts being compromised was just the latest in a long line of hacks perpetrated against companies.

LinkedIn, Dropbox, MySpace, Tumblr, VK.com, are just some of the firms that have had user data leaked online at some point. And it’s not just the number of sites being breached that is increasing, other online risks such as phishing emails, malware, ransomware, fraud, tracking, and id theft are on the rise.

Today, more people than ever before use the internet, and many aren’t tech-savvy enough to follow reasonable security practices. But even the most advanced users can slip up; Facebook CEO Mark Zuckerberg had his Twitter and Pinterest accounts compromised after hackers reportedly re-used his leaked LinkedIn credentials (password: dadada).

For this Weekend Open Forum we want to know what online security measures do you take? Do you pay for an antivirus program such as Norton or do you go with a free option? Do you always use virtual private networks to protect yourself? Are password managers the best way to avoid using the same login credentials on multiple sites? And, like Zuckerberg, would you go as far as sticking some tape over your webcam? Whatever methods you use, do let us know.

Friday, September 30, 2016

Security analyst says Yahoo!, Dropbox, LinkedIn, Tumblr all popped by same gang Says five-strong 'Group E' may have lifted a billion Yahoo!records, sells to states



30 Sep 2016 at 06:17, Darren Pauli


Five hackers are said to be behind breaches totalling up to a staggering three billion credentials from some of the world's biggest tech companies including the Yahoo! breach that led to the loss of 500 million credentials.

The claims, made to The Reg by recognised threat intelligence boffin Andrew Komarov, pin the world's largest hacks on "Group E", a small Eastern European hacking outfit that makes cash breaching companies and selling to buyers including nation states.

Komarov told The Register the group is behind a laundry list of hacks against massive household tech companies including the breach of Yahoo!, Dropbox, LinkedIn, Tumblr, and VK.com among other public breaches.

The analyst says the same hacking group has breached other major tech firms but would not be drawn on revealing the names of the affected companies nor the number of compromised credentials. Komarov has reported those breaches which are not on the public record to police.

He goes further and says much of the reporting concerning the Yahoo! breach was inaccurate, and suggests the number of affected credentials could be as high as one billion, double what was reported.

Group E had, according to Komarov, breached Yahoo! and sold the massive data haul through a recognised hacker identity who served as a broker.

It was then sold to a unnamed nation-state actor group.

Komarov's employer InfoArmor says it performed "extensive analysis of collected intelligence" from the Yahoo! hack from different sources to "clarify the motivation and attribution of the key threat actors" concluding "many recent press reports and published articles have significant inaccuracies".

Yahoo! last week pinned the breach on a unnamed state actor but did not say if, as Komarov claims, that the group bought the credentials from Group E which conducted the intrusion.

The company did not respond to a request for comment by the time of publication.


Hacking gangs Group E, For Hell, and broker Tessa88. Mind map by Andrew Komarov.

Komarov tells The Register Group E, so called after the first letter of its leader's moniker, broke into sites using a variety of attack vectors.

"Web apps vulnerabilities and exploitation, plus network intrusion through infection … [and] direct access to databases and source code," Komarov says.

Sites breached by the five-person Group E hacker outfit. Statistics via Andrew Komarov
Breach companyNumber of recordsYahoo! 500 million (up to 1bn)
Myspace 360 million
LinkedIn 167 million
Vk.com 137 million
Qip.ru 133 million
Badoo 126 million
Dropbox 103 million
Rambler.ru 101 million
Tumblr 50 million
LastFM 43 million
Fling.com 40 million
Mobango.com 6 million
Other combined dumps: 600 million


A second group known as "For Hell" used the same broker to sell stolen databases and masterminded other high profile breaches. Komarov says one member known as ROR[RG}) hacked Ashley Madison, Adult Friend Finder, and the Turkish National Police, while a second team mate known as "arnie" or "darkoverlord" conducted breaches of unnamed health care organisations.

Komarov, an established threat intelligence man formerly of Intelcrawler before its acquisition by Arizona-based security firm InfoArmor, is one of a handful of cybercrime intelligence analysts who closely monitor closed crime forums and dark web sites.

He fingers a Russian-speaking criminal hacking identity known as Tessa88 as the broker used by the two hacking groups.

That broker is claimed by hackers including some speaking to Vulture South to be a part-time scammer for selling bogus credentials, although the claims cannot be verified. Komarov says Tessa88 was at pains to mask the identity of the hacking groups when selling the Yahoo! credentials to the nation-state actors.

Thursday, September 29, 2016

Security group claims Yahoo hack was not "state-sponsored"





By Rob Thubron on September 29, 2016, 1:30 PM



When Yahoo last week confirmed that 500 million of its accounts had been leaked following a hack that took place in 2014, the company said that state-sponsored actors were behind the attack. But according to an independent security firm, a gang of cybercriminals-for-hire was responsible.

Arizona-based InfoArmor, which provides companies with protection against employee identify theft, released an investigative report claiming there is no evidence that a nation-state stole the data.

Last year, Yahoo became one of several companies, including Google, Facebook, and Twitter, to say it would alert users who they suspect have accounts that have come under attack by state-sponsored hackers. It has never revealed how it determines this, or what evidence it has to prove the 2014 hack was orchestrated by a government.

Andrew Komarov, InfoArmor’s chief intelligence officer, concluded that the Yahoo hackers were cybercriminals after reviewing a sample of the leaked data. The firm acquired this from “operative sources” as part of an investigation into a five-person criminal gang located in Eastern Europe known as Group E.

“They have never been hired by anyone to hack Yahoo," said Komarov "They were simply looking for well-known sites that had many users […] According to our information, most of the group's clientele are spammers."

Komarov added that Group E has sold the Yahoo data to at least three different clients. One was a state-sponsored party who had an interest in exclusive database acquisition, and the other two were notable criminal gangs who planned to use it for spam campaigns. "We don't see any reason to say that it's state-sponsored. Their clients are state sponsored, but not the actual hackers," Komarov told the Wall Street Journal.

InfoArmor also believes that Group E was behind the high-profile hacks of LinkedIn, Tumblr, and Dropbox.
Related Posts Plugin for WordPress, Blogger...