Netimperative
Netimperative
  • Home
  • Ads
  • Content
  • Mobile
  • E-commerce
  • Social
  • Regulation
  • Video
  • Viral
Menu
  • Apple
  • Amazon
  • Facebook
  • Google
  • twitter
  • WhatsApp
  • YouTube

Biggest hack yet? 1.2bn passwords stolen in global data theft

August 6, 2014

Russian hackers have stolen 1.2 billion user name and password combinations in what could be the biggest ever data theft, hitting big name websites “in virtually all industries across the world” according to a US security firm.


hacked.jpg
Hold Security, based in Milwaukee, says a ‘Cybervor’ gang stole the information from 420,000 web and FTP sites.
The information is said to relate to half a billion email addresses and is a stark reminder that marketers can’t skimp on tech areas like security and testing in the rush to launch online services- potentially putting valuable customer data at risk.
The New York Times reports that so far it appears little of the information has been sold to other online criminals.
Instead, it says it is being used to send marketing pitches and junk messages on social networks such as Twitter.
‘Users will not know their computer is being hacked’
Hold Security claims the gang used a botnet, a network of infected computers controlled by a hacker, to identify weaknesses in websites that people visited.
Users typically do not know their machine is being manipulated by a botnet.
“The botnet conducted possibly the largest security audit ever,” says Hold Security on its website, which says it spent seven months researching the alleged breach.
“Over 400,000 sites were identified to be potentially vulnerable to SQL injection flaws alone. The CyberVors used these vulnerabilities to steal data from these sites’ databases. To the best of our knowledge, they mostly focused on stealing credentials, eventually ending up with the largest cache of stolen personal information, totaling over 1.2 billion unique sets of emails and passwords.”
Hold Security says the Russian gang targeted every site visited by an infected botnet machine and did not differentiate between well-known sites and smaller ones.
The company has not named the sites that were affected but says the list “includes many leaders in virtually all industries across the world, as well as a multitude of small or even personal websites”.
Hold Security has a history of uncovering major hacking attacks and previously uncovered a large data theft from software company Adobe.
What this means for marketers- keeping customer trust with a data security strategy
Tips from the Digital Training Academy:
• Create secure passwords that use mixed case letters and numbers Best practice is to change them regularly so if there is a security breach you are not aware of, then over time the organisation is naturally protected.
• Only give access to the services people need, and if tools like a website CMS have different levels of access (such as those for people who write vs the editor vs the administrators) then fully apply the functionality.
• If developers use simple passwords such as “admin” or back doors to services before launch then these passwords and loopholes should be removed at launch.
• Someone in your organisation should own cyber security.
• Organisations should look at super-password solution tools that manage access for teams rather than relying on each manager having to remember a complex list.
• Well-funded organisations should have standards and guidelines in place to align their agencies behind best practice.
• Cyber security teams should have a process in place for testing their networks, an approach that often uses “ethical hackers” to identify weaknesses
Read the Hold Security announcement here
http://www.holdsecurity.com/news/cybervor-breach/

Uncategorized agencies, email, global, marketing, security

Archives

Tags

advertising agencies Amazon analytics Android Apple apps Australia BBC brands Brazil broadband China Christmas comScore content digital marketing ecommerce email Entertainment Europe Facebook France games Germany global Google government images infographic local marketing media Microsoft music Privacy retail Search security smartphones technology Twitter UK video YouTube

Recent Posts

  • Top six Valentine’s Day ads for 2022
  • 2021 Halloween: digital marketing campaigns we loved this year
  • Empowering employees; the critical link between EX and CX
  • Investing in in-app social features is a must in a world that is crying out to be connected
  • QR codes, Gen Z and the future of OOH

Copyright © 2025 Netimperative.

Magazine WordPress Theme by themehall.com

We use cookies to improve the website and your experience. We’ll assume you’re okay with this, but you’re welcome to opt-out
Cookie settingsACCEPT
Privacy & Cookies Policy

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. This category only includes cookies that ensures basic functionalities and security features of the website. These cookies do not store any personal information.
Non-necessary
Any cookies that may not be particularly necessary for the website to function and is used specifically to collect user personal data via analytics, ads, other embedded contents are termed as non-necessary cookies. It is mandatory to procure user consent prior to running these cookies on your website.
SAVE & ACCEPT