16 Million Fortune 500 Passwords Added to Dark Web in 12 Months
Wednesday, October 30, 2019
Web security company, ImmuniWeb says there are now over 21 million (21,040,296) stolen user credentials belonging to Fortune 500 companies available on the Dark Web – over 16 million (16,055,871) of which were compromised during the last 12 months.
Stolen User Credentials: The Most Popular Passwords
Ilia Kolochenko, CEO and Founder of ImmuniWeb, said: “These numbers are both frustrating and alarming. Cybercriminals are smart and pragmatic, they focus on the shortest, cheapest and safest way to get your crown jewels.
“The great wealth of stolen credentials accessible on the Dark Web is a modern-day Klondike for mushrooming threat actors who don’t even need to invest in expensive 0day or time-consuming APTs. With some persistence, they easily break-in being unnoticed by security systems and grab what they want.
He added: “Worse, many such intrusions are technically uninvestigable due to lack of logs or control over the breached [third-party] systems.”
There were only 4.9 million (4,957,093) fully unique passwords amid the 21 million records the company identified, suggesting that many users are using identical or similar passwords. It recommends using an Attack Surface Management (ASM) solution to map the risk, implementing an organization-wide password policy enforceable on the integrity of in-house and third-party systems, and always using two-factor authentication (2FA) on business-critical systems. Read Full Article
Forbes: These Are The 32 Passwords You Really Shouldn’t Use Unless You Want To Get Hacked
Silicon UK: City Of Johannesburg Threatened With Ransomware Data Release