Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

limbicnuminousity

(1,407 posts)
Mon Jan 22, 2024, 06:15 PM Jan 2024

Massive 26 Billion Record Leak: Dropbox, LinkedIn, Twitter All Named

Last edited Mon Jan 22, 2024, 08:10 PM - Edit history (1)

Source: Forbes

Security researchers have warned that a database containing no less than 26 billion leaked data records has been discovered. The supermassive data leak, or mother of all breaches as the researchers refer to it, is likely the biggest found to date.

The research team thinks that the 26 billion record database, found on an open storage instance, will likely have been compiled by a malicious actor or data broker. “Threat actors could leverage the aggregated data for a wide range of attacks, including identity theft, sophisticated phishing schemes, targeted cyberattacks, and unauthorized access to personal and sensitive accounts,” they say.

If there is good news to be found in such a discovery, it is that little of this appears to be new data. Instead, the researchers say, it’s more a case of compiled records from thousands of previous breaches and data leaks. What’s more, there are undoubtedly a large number of duplicate data records within this compilation. The inclusion of usernames and password combinations does, however, still mean this is a cause for concern. I’d expect a surge, if current levels aren’t high enough, in credential stuffing attacks over the coming weeks as a result.

Although the data from this latest breach and leak compilation discovery has yet to be entered, you can use this free leak checker tool at CyberNews. This will reveal earlier instances where your email address has been leaked, including some of the services from the MOAB database. You can also use the free Have I Been Pwned service as well.


Original post citing Tom's Guide
Even if you’re super careful online, your personal and financial information can be exposed in a data breach. Sometimes though, hackers compile credentials and information from past breaches and put it all together to make it easier to use in their attacks.

As reported by Cybernews, this is exactly what happened with a new, supermassive Mother of all Breaches (MOAB) which contains 26 billion records or 13 terabytes of data taken from previous leaks, breaches and hacked databases. In a recent investigation alongside cybersecurity researcher Bob Dyachenko, the news outlet discovered all of these exposed records on an open instance.

-snip

If you want to see if your personal or financial information was exposed online as a result of this leak, you’re in luck as Cybernews has created its own data leak checker to make things easier. Likewise, the popular data leak site HaveIBeenPwned will likely also have these records available to search soon.

Read more: https://www.forbes.com/sites/daveywinder/2024/01/22/massive-26-billion-record-leak-dropbox-linkedin-twitterx-all-named/?sh=3de52915472a



The data leak website to check is https://cybernews.com/personal-data-leak-check/

26 billion records is substantial.
19 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Massive 26 Billion Record Leak: Dropbox, LinkedIn, Twitter All Named (Original Post) limbicnuminousity Jan 2024 OP
When I use the data leak website, I get a BLOCKED page bucolic_frolic Jan 2024 #1
you want my personal information , pay me $100.00 hour. no questions asked,. AllaN01Bear Jan 2024 #2
Companies hoard data. Turbineguy Jan 2024 #3
I just gave them my email address and they tell me ... FakeNoose Jan 2024 #4
l checked and it told me all the sites where my data had been compromised... Trueblue Texan Jan 2024 #13
According to the leak checker all three of my emails have been leaked. Coventina Jan 2024 #5
If I give my info on that link, they'll have it. Who knows what they'll do with it? brush Jan 2024 #6
Not much there im worried about... getagrip_already Jan 2024 #7
Chinese company sab390 Jan 2024 #15
K&R! nt Carlitos Brigante Jan 2024 #8
I got a letter last week Marthe48 Jan 2024 #9
I got 2 letters in December saying my data had been hacked. louis-t Jan 2024 #10
I just received a letter from a credit card company for more info questionseverything Jan 2024 #11
A bunch of "leaks." Igel Jan 2024 #12
Boooo mahina Jan 2024 #14
I am so sick of these data breaches thinkingagain Jan 2024 #16
Seems like by going there you provide MORE data for the compilation. I don't trust these kind of sites. live love laugh Jan 2024 #17
Must be old data as only hits are for my now defunct email address. sinkingfeeling Jan 2024 #18
Yep - my data has been leaked progressoid Jan 2024 #19

FakeNoose

(32,854 posts)
4. I just gave them my email address and they tell me ...
Mon Jan 22, 2024, 06:26 PM
Jan 2024

... "You are safe for now."

So it answered instantly, without checking any kind of a database or list.
This makes me wonder. Maybe this is all a scam to collect people's email addresses.
Hmmmm....

Trueblue Texan

(2,451 posts)
13. l checked and it told me all the sites where my data had been compromised...
Mon Jan 22, 2024, 08:02 PM
Jan 2024

...nothing important was compromised--I try not to give out my phone number but I sure have been getting tons of spam calls in the last 3 months.

getagrip_already

(14,934 posts)
7. Not much there im worried about...
Mon Jan 22, 2024, 06:30 PM
Jan 2024

The only site on the list I used was LinkedIn, and that only had public data on me.

Twitter helpfully deleted my account I hadn't used in over 10 years. But that had zero personal info anyway.

What the hell is tencent anyway?

sab390

(185 posts)
15. Chinese company
Mon Jan 22, 2024, 08:43 PM
Jan 2024

I don't know all of what it owns but it's things like tic TOC and I think that new one that sells a bunch of Chinese crap.

Marthe48

(17,087 posts)
9. I got a letter last week
Mon Jan 22, 2024, 06:35 PM
Jan 2024

traditional USPS. The letter said that some of my data might have been compromised sometime last year, but there is no indication that my data was compromised, but if I'm concerned, I can sign up for the protection the company that sent the letters offers. I threw it away as soon as I saw it was a pitch based on fear.

louis-t

(23,309 posts)
10. I got 2 letters in December saying my data had been hacked.
Mon Jan 22, 2024, 06:38 PM
Jan 2024

One from a health insurance company I haven't used in 10 years and one from a mortgage servicer that sold my mortgage 10 years ago. They should not be able to keep your info including ss# in their computers just waiting to be hacked. If I ever do biz with them again, they can get my info then.

Oh, and I accepted the offer of 1 year and 2 years of ID protection at no cost. It should be 5 years.

questionseverything

(9,665 posts)
11. I just received a letter from a credit card company for more info
Mon Jan 22, 2024, 06:50 PM
Jan 2024

Before they could approve my “requested” card

I had never heard of the company

Hubby is dealing with it and going to “freeze “ both our names


It’s a hassle because if I actually want to finance something new we have to “unfreeze “ first but better than getting ripped off


🧐

Igel

(35,383 posts)
12. A bunch of "leaks."
Mon Jan 22, 2024, 07:27 PM
Jan 2024

But I have no memory of some of the sites.

One I signed up with and never used. But that was before 2004. Not like I still use a lot of passwords from that far back.

As for actual personal data (SSN, birthdate, etc.)--that I can't change. Then again, I'm really duplicitous. I'm from 40 to 75 years old, always male but sometimes I was born in Rochester NY, sometimes Atlanta GA, sometimes Baltimore MD, sometimes Chicago IL. (Yes, I have a lookup table for sites I currently care about.)

I like my current bank account passwords. I flipped my keyboard to face the wrong direction, closed my eyes, and typed. Then went back and randomly inserted special characters and capitalization. Maxed out the # of characters allowed in a password for my accounts. The shortest is over 20 characters.

thinkingagain

(906 posts)
16. I am so sick of these data breaches
Mon Jan 22, 2024, 09:03 PM
Jan 2024

Regardless of if your affected by them or not they are annoying and stressful.

Medical breaches recently so far my husband has gotten at least three letters from different companies that he was part of that breach.

But I think laws need to be made for more protection for the consumer, such as no company needs your keep your data for more than like 30 days after your encounter with them, (such as like retail )
Other ones like a year after you close an account or haven’t activity with you
for a year.
Your account could be closed and info deleted.
They also need to make it so you can access your annual report anytime unlimited not just once a year for free. .
And that you have access for free to all three credit agencies where you can just log into your account and freeze it at any time and unfreeze it any time you don’t have to go through hoops to do this.
You can do that at two of the three the third one charges you to have an account to do that. I think you may have to use an app on at least 1 for free to do this.

Maybe have two different network in pro structures one that does just emails and the other one is the one that the information stored.
So if the information is being compromised by when you open the link etc. and an email, then it wouldn’t get the private information.

I am rambling because I’m frustrated because it seems like just about every day. You hear about these great big data breaches, and they keep getting bigger and bigger.

sinkingfeeling

(51,490 posts)
18. Must be old data as only hits are for my now defunct email address.
Tue Jan 23, 2024, 01:59 AM
Jan 2024

The sources are from a forum I joined in 2002 and a 2004 order.
I was surprised to get a letter at my current address this week from an oncology clinic in Arkansas. Their data was hacked and someone might have my cancer history from 2009. I was surprised they had tracked me down. Guess there's no place to hide anymore.

Latest Discussions»Latest Breaking News»Massive 26 Billion Record...