3 ms·
A great example of folks either re-using passwords, or simply not being aware that their credentials have been included in a previous leak/breach. For an idea
by graystevens 9y ago
A great example of folks either re-using passwords, or simply not being aware that their credentials have been included in a previous leak/breach.
For an idea of a timeline, and a useful reminder to check your own personal accounts (and those dreaded shared accounts internally):
- Feb 15 2014 - Kickstarter breach occurred
- Oct 08 2017 - HaveIBeenPwned import the dump, suggesting it is publicly available, or at least being shared around.
- Oct 24 2017 - Coinhive suffer their DNS breach.
Services such as Troy's HaveIBeenPwned are an excellent resource, and I can whole heartedly recommend signing up for the 'Notify Me' function: https://haveibeenpwned.com https://haveibeenpwned.com
I recently released something similar for corporate environments, allowing businesses to produce pseudo-users to insert into their user base. These 'canaries' are unique to them & come with real email addresses and phone numbers, so should they ever be contacted you can be pretty sure you've suffered a breach of some kind. We of course also check the usual suspects (Pastebin, Tor) for any similar evidence of a breach. Can see some more details here: https://breachinsider.com https://breachinsider.com