Rechercher
Contactez-nous Suivez-nous sur Twitter En francais English Language
 

Freely subscribe to our NEWSLETTER

Newsletter FR

Newsletter EN

Vulnérabilités

Unsubscribe

Data of 200 million Yahoo users for sale on the Dark Web - Expert comment

August 2016 by Brendan Rizzo, Technical Director - EMEA at HPE Security - Data Security

Reports are circulating about a huge data leak of 200 million Yahoo users. This data
is being offered for sale on TheRealDeal dark web market by “peace_of_mind” (aka
Peace). The batch of data is, apparently, being sold for 3 Bitcoins and contains
usernames, passwords and dates of birth. For users based in the United States, the
dump also includes backup email addresses and users’ ZIP codes.
The comments from
Brendan Rizzo, technical director EMEA at HPE Security - Data Security.

“Enterprises need to follow best practices of encrypting all sensitive personal
data as it enters a system. Encryption stays with the data whether at rest, in
motion or in use, so if an attacker accesses the data, they get nothing of value.
The ability to neutralise a breach by rendering data useless if lost or stolen,
through data-centric encryption, is an essential benefit to ensure data remains
secure. Credentials that never need to be recovered in clear form should be strongly
protected with state-of-the art methods, for example, strong standards based keyed
hashing.

Hackers will steal anything of value and this story is no exception. Data has high
value to attackers, and even though the information for sale on the black market is
several years old, it can still be used for social engineering attacks for spear
phishing to attempt to gain access to deeper systems with even more lucrative data
that can be monetised directly if stolen.

We have a saying in security, it’s not a matter of if a breach will happen, but
when. Beyond the threat to sensitive data, companies need to be concerned with the
impact a data breach can have on their reputation and, ultimately, on their bottom
line. A data-centric approach to security is the industry-accepted cornerstone
needed to allow companies to mitigate the risk and impact of cyber attacks and other
attempts to get this sensitive information.”


See previous articles

    

See next articles


Your podcast Here

New, you can have your Podcast here. Contact us for more information ask:
Marc Brami
Phone: +33 1 40 92 05 55
Mail: ipsimp@free.fr

All new podcasts