eCommerceNews New Zealand - Technology news for digital commerce decision-makers
Story image
Massive 2.2bil-username data dump leaked on dark web
Fri, 1st Feb 2019
FYI, this story is more than a year old

A second major data dump has hit the dark web in two weeks, compromising of 2.2 billion unique usernames and passwords.

The data dump has been dubbed Collection #2-5 and contains 845GB of data and over 25 billion unique records.

This makes the second leak three times bigger than the Collection #1 dump leaked last month, identified by Australian Cybersecurity expert Troy Hunt.

Wired reported that Collection #2-5 was discovered and has been analysed by security researchers at Germany's Hasso Plattner Institute and cybersecurity firm Phosphorus.io.

Users can go to the Hasso Plattner Info Leak Checker to see if their email details and credentials have been compromised in the latest data dump.

OneSpan security competence centre and security strategy senior manager market Frederik Mennes says, “2.2 billion unique records is a staggering number.

“We are becoming accustomed to breach notification news, but sad to say, the use of multi-factor authentication is still not utilised whenever and wherever possible.

“Companies should remember that easy targets will continue to be exploited first, because cybercrime follows the path of least resistance,” Mennes says.

“Technology is evolving, and next-generation authentication, intelligent adaptive authentication, is gaining momentum.

“This technology utilises AI and machine learning to score vast amounts of data, and based on patterns, analyses the risk of a situation and adapts the security and required authentication accordingly.

OneSpan innovation centre chief security architect Steven Murdoch says, “This password leak shows that large quantities of stolen passwords are readily available to anyone, regardless of how low their budget.

“However, data from recent breaches will be considerably more expensive to obtain.

“Companies should recognise the limitations of password authentication and are in the best position to mitigate the weaknesses. They should implement additional measures, such as the detection of suspicious behaviour.

“Two-factor authentication, or even better, FIDO/U2F, should be offered to customers. Customers can also help by not re-using passwords across multiple sites and using a password manager if needed.

“The website TwoFactorAuth.org gives instructions on how to enable two-factor authentication on many popular sites, as enabling 2FA, and preferably FIDO/U2F, will significantly help to improve their security.