Collection #1 data breach

Soldato
Joined
25 Nov 2007
Posts
5,581
Location
London
Oh no — pwned!
This password has been seen 12,460 times before
Oh no — pwned!

This password has been seen 1,085 times before
Oh no — pwned!

This password has been seen 47 times before

 
Caporegime
Joined
26 Dec 2003
Posts
25,666
Just change your passwords regularly using unique passwords and it will keep any damage to a minimum. The main people at risk are those who have used the same password on multiple sites for years on end..
 
Commissario
Joined
16 Oct 2002
Posts
342,149
Location
In the radio shack
This is using a password of the same format I currently use for everything (same number of characters, numbers and symbols).

aLllxrh.png

Still working my way through all my logins in 1Password, weeding out ones that no longer exist and changing everything else. I'm confident everything is perfectly secure but some of those passwords have been used for nearly ten years so it can't hurt to change them. I have 2FA enabled for any site that supports it.
 

Pho

Pho

Soldato
Joined
18 Oct 2002
Posts
9,325
Location
Derbyshire
This is using a password of the same format I currently use for everything (same number of characters, numbers and symbols).

aLllxrh.png

Still working my way through all my logins in 1Password, weeding out ones that no longer exist and changing everything else. I'm confident everything is perfectly secure but some of those passwords have been used for nearly ten years so it can't hurt to change them. I have 2FA enabled for any site that supports it.

Most of these password breaches are likely caused by poor security of the site in question than brute forcing: e.g., they store your password in the database in plain text or use weak encryption. Mind you even then they could have a super secure database but a hacker gets in and modifies the login script to dump the password you enter to a text file. So whilst having a super complex password is clearly a good idea it might not save you either :p.

Which is why using random + complex passwords + 2FA everywhere is your best bet.

When I moved over to lastpass I spent hours updating all my logins everywhere!
 
Soldato
Joined
21 Apr 2007
Posts
6,593
Basically I've had those emails saying OH LOOK WE GUESSED YOUR PASSWORD! here it is! (Insert my throwaway forum password). Pay us a ransom.

My assumption is they've finally cracked the databases that got leaked many years ago like xfire, nexusmods etc.

I use proper complex passwords for important accounts. All different. Email, facebook, paypal, ebay and my 2nd email. All different passwords.
 
Soldato
Joined
9 Jul 2003
Posts
9,605
Went through all my old email inbox's a few weeks ago after receiving scam emails with old passwords. Was surprised at how many sites I had signed up to years ago that I'd completely forgotten about but were still active.

Most don't let you delete your account either so just removed as much personal info as I could and changed the password to a long unique one using a password manager. Took bloomin ages though.
 
Soldato
Joined
21 Apr 2007
Posts
6,593
Hi!

As you may have noticed, I sent you an email from your account.
This means that I have full access to your account: At the time of hacking your account(my email) had this password: "a throw away forum password"

You can say: this is my, but old password!
Or: I can change my password at any time!

Of course! You will be right,
but the fact is that when you change the password, my malicious code every time saved a new one!

I've been watching you for a few months now.
But the fact is that you were infected with malware through an adult site that you visited.

If you are not familiar with this, I will explain.
Trojan Virus gives me full access and control over a computer or other device.
This means that I can see everything on your screen, turn on the camera and microphone, but you do not know about it.

I also have access to all your contacts and all your correspondence from e-mail and messangers.

Why your antivirus did not detect my malware?
Answer: My malware uses the driver, I update its signatures every 4 hours so that your antivirus is silent.

I made a video showing how you satisfy yourself in the left half of the screen, and in the right half you see the video that you watched.
With one click of the mouse, I can send this video to all your emails and contacts on social networks. I can also post access to all your e-mail correspondence and messengers that you use.

If you want to prevent this, transfer the amount of $746 to my bitcoin address (if you do not know how to do this, write to Google: "Buy Bitcoin").

My bitcoin address (BTC Wallet) is: xxxx

After receiving the payment, I will delete the video and you will never hear me again.
I give you 48 hours to pay.
I have a notice reading this letter, and the timer will work when you see this letter.

Filing a complaint somewhere does not make sense because this email cannot be tracked like my bitcoin address.
I do not make any mistakes.

If I find that you have shared this message with someone else, the video will be immediately distributed.
Bye!



So had another one of these today.... it's insane how many of them are going around now. I've probably got like 10-20 in my inbox.....
 
Soldato
Joined
27 Nov 2005
Posts
24,838
Location
Guernsey
Don't know too much about this so I will post as I understand it...

So there has been a big email/password dump on a hacker forum (plain text format) millions of users maybe affected check https://haveibeenpwned.com/ to see if your on the list I will post news sources below:
My e-mail says this

Oh no — pwned!

Pwned on 6 breached sites and found no pastes (subscribe to search sensitive breaches)

1 Anti Public Combo List (unverified): In December 2016,
2 Collection #1 (unverified): In January 2019,
3 iPmart: During 2015,
4 Kickstarter: In February 2014,
5 Nexus Mods: In December 2015,
6 Onliner Spambot (spam list): In August 2017,
 
Soldato
Joined
10 Jan 2012
Posts
3,712
Location
UK
My main email has 15 breaches and 2 pastes.
Mostly on sites that I couldn't give a toss about as they have no real personal data.
I change my main stuff, email, banking etc once in a while so not bothered.
Forums have throw away passwords for the most part, which again I don't care. Only certain ones have real data (this one included) and they have more secure passwords.
 
Soldato
Joined
9 Mar 2003
Posts
14,956
I have been the last pass thing for awhile now. All the important sites use unique passwords, the less important sites I am still getting through. Its taking a long time....
 
Man of Honour
Joined
13 Oct 2006
Posts
91,934
they store your password in the database in plain text or use weak encryption.

There are still a lot of sites that just generate a relatively short hash from your entered password and it doesn't really matter how long or complex your password is past a certain point (on those sites) - obviously easy to guess weak to dictionary attack passwords are bad but often having something hugely complex and hard to brute force is just making more work for yourself while on many sites not making you any more secure.

My e-mail says this

I'd highly recommend anyone using the same login credentials as on Kickstarter upto that 2014 breach change their passwords if still using the same credentials - I'm pretty sure atleast some and possibly all the passwords have been exposed as well somehow whether poor or non-existent encryption or some other reverse engineering.

A few months back I had an unauthorised successful login on an account that I'd forgotten used the same details as my Kickstarter account - fortunately 2FA did its job and I'm fairly certain the password wasn't wasn't easily brute forced or guessed, etc. and it has been a common factor in other cases I know of where people have had accounts hacked.
 
Last edited:
Back
Top Bottom