Get App
Download App Scanner
Scan to Download
Advertisement
This Article is From Jan 06, 2022

Hackers Tried Recycled Passwords on More Than a Million Accounts

More than 1 million online accounts across 17 well-known companies were the victim of hacking attempts that reused previously stolen passwords swirling around the internet, New York's top law enforcement officer said Wednesday.

The ruse, known as a “credential stuffing attack,” involves a cyber criminal trying to repeatedly access someone's account by deploying user names and passwords that were previously made public. User names and passwords are sometimes posted or sold on the dark web or hacking forums after being stolen in cyberattacks.

Attorney General Letitia James said hackers take advantage of the fact that people tend to re-use passwords across multiple sites. In a credential-stuffing attack, the hacker may submit hundreds of thousands, or even millions of login in attempts using specialized software.

James said more than 15 billion stolen credentials are currently in circulation, putting those users' personal information “in jeopardy.” She said her office worked with the 17 firms, which weren't named, to help shore up their cybersecurity, protect their customers and further understand how the attacks occurred.

The attorney general's office spent months monitoring online communities dedicated to credential stuffing and found thousands of posts that contained customer login credentials that hackers had tested for attacks. From those posts, state officials compiled credentials to compromised accounts at 17 well-known online retailers, restaurant chains and food delivery services. 

©2022 Bloomberg L.P.

Essential Business Intelligence, Continuous LIVE TV, Sharp Market Insights, Practical Personal Finance Advice and Latest Stories — On NDTV Profit.

Newsletters

Update Email
to get newsletters straight to your inbox
⚠️ Add your Email ID to receive Newsletters
Note: You will be signed up automatically after adding email

News for You

Set as Trusted Source
on Google Search