Murky Details Surround Bed, Bath and Beyond Breach
Wednesday, October 30, 2019
According to a report on stolen credentials and Fortune 500 companies from ImmuniWeb released this week (Bed, Bath and Beyond is No. 258 on the Fortune list), millions of stolen corporate credentials available in the Dark Web are exploited by cybercriminals for spearphishing and password re-use attacks.
ImmuniWeb’s analysis of the quality and quantity of stolen credentials accessible on the Dark Web found there to be over 21 million (21,040,296) credentials belonging to Fortune 500 companies, amid which over 16 million (16,055,871) were compromised during the last 12 months. As many as 95 percent of the credentials contained unencrypted, or bruteforced and cracked by the attackers, plaintext passwords.
The most common sources of the exposures and breaches were third parties (e.g. websites or other resources of unrelated organizations); trusted third parties (partners, suppliers or vendors); and the the companies themselves (e.g. their own websites or in-house other resources). Read Full Article
Bleeping Computer: 21 Million Logins for Top 500 Firms Offered on the Dark Web
SecurityWeek: 21 Million Stolen Fortune 500 Credentials For Sale on Dark Web