Collection 1 Data Breach Exposes More Than 772 Million Email Addresses (zdnet.com)
A collection of almost 773 million unique email addresses and just under 22 million unique passwords were exposed on cloud service MEGA. Security researcher Troy Hunt said the collection of data, dubbed Collection #1, totaled over 12,000 separate files and more than 87GB of data. ZDNet reports: "What I can say is that my own personal data is in there and it's accurate; right email address and a password I used many years ago," Hunt wrote. "In short, if you're in this breach, one or more passwords you've previously used are floating around for others to see." Some passwords, including his own, have been "dehashed", that is converted back to plain text. Hunt said he gained the information after multiple people reached out to him with concerns over the data on MEGA, with the Collection #1 dump also being discussed on a hacking forum. "The post on the forum referenced 'a collection of 2000+ dehashed databases and Combos stored by topic' and provided a directory listing of 2,890 of the files," Hunt wrote.
The collection has since been removed. You can visit Hunt's Have I Been Pwned service to see if you are affected by this breach.
Starting a couple of months ago, I've received a huge number of extortion emails. At this point it's extortion spam.
All the emails follow the same pattern, and all including somewhere (usually in the To: line, for some reason) an old "burner" password I used on web sites where I don't care if the password leaks.
Here's a rough paraphrase:
I have received dozens of copies of this email, with the text slightly different. Some of them end with "Don't hate me, everyone needs to do their own job." Some of them call the mysterious malware "RAT software". A couple of times the email was translated into Japanese. (I can read just a little bit of Japanese and was able to recognize it, and I showed it to a fluent friend who confirmed that it fit the above pattern.)
<sarcasm>I must say, my computer is running pretty well considering how many elite international hackers have been messing with it and installing RAT software and such.</sarcasm>
As it happens, I got one copy of the email at least a week before the deluge started. I realized it would have been very scary for someone who uses the same password everywhere and doesn't know how easy it is to forge the "From:" header. Doubly scary if that person actually visits porn sites.
lf(1): it's like ls(1) but sorts filenames by extension, tersely
Just stop sharing your damn creds. If you can't do that, then stop sharing THE damn creds.
"Jail the execs!"
"Hold them accountable!"
"Fine them!"
"We need new laws!"
None of that shit is going to happen. If you keep making accounts for every little thing, pretty soon I'm gonna need to create a throwaway account to pump fkg gas. Just stop.
Checkout as guest. No thanks. I do NOT agree.
Do you really NEED an account for everydumbthing.com?
Creds have value, otherwise, you would not be asked to give them away every other keystroke. Treat them as such.
Sometimes, the only way to win is not to play.
You are being ripped off every second of every day, so that advertisers can help rip you off even more tomorrow.