Jump to content

FBI seeks hacker after 1.2 billion logins are stolen

CtW

Source: http://www.bbc.com/news/technology-34920557

 

_86866380_thinkstockphotos-495897672.jpg

 

The FBI has linked a hacker to the theft of 1.2 billion internet credentials - the largest heist of its kind.

 
A hacker known as "mr.grey" is named in court documents filed by the bureau last year, according to the Reuters news agency.
 
The hacker was linked to the stolen logins via a Russian email address.
 
Previously, "mr.grey" had advertised the credentials to Facebook and Twitter accounts for sale online.
 
It was the American cyber security firm Hold Security that initially reported the theft of the credentials and an additional 500 million email addresses last year.
 
The Russian crime ring responsible for stealing the data - dubbed CyberVor - had breached more than 420,000 websites, according to Hold Security.
 
In August, the firm said, "To the best of our knowledge, they mostly focused on stealing credentials, eventually ending up with the largest cache of stolen personal information, totalling over 1.2 billion unique sets of e-mails and passwords."
 
Hold Security then began marketing a "breach notification service" to users concerned that their details had been affected, for $120 (£71) per month.
 
Whatever the identity of the perpetrator behind the CyberVor breach, the method used was something of a departure from how botnets - large networks of computers linked together maliciously - are usually used, according to Dave Palmer, director of technology at security firm Darktrace.
 
"What's interesting about this is botnets are usually used to harness their massive scale to attack an individual target - like taking computer games consoles down last Christmas for example," he told the BBC.
 
"It's instead been used as a massive scanner scanning websites all around the world for weaknesses."
 
Mr Palmer added that the vulnerabilities which allowed computers to be drafted into such botnets as well as the flaws in websites which meant login details could be hacked were preventable.
 
"We're still getting caught out by these attacks," he said.

Holy crap that is a ton of user info. I really hope I'm not affected by this although that seems unlikely. It would be helpful to know which sites were hit, but given the sheer amount of credentials and affected sites, its likely many of the sites i and other people use are affected. I hope nothing too bad comes of this and that the FBI catches who did this.

Link to comment
Share on other sites

Link to post
Share on other sites

Thanks like the whole of India. :o

CPU: AMD Ryzen 5 5600X | CPU Cooler: Stock AMD Cooler | Motherboard: Asus ROG STRIX B550-F GAMING (WI-FI) | RAM: Corsair Vengeance LPX 16 GB (2 x 8 GB) DDR4-3000 CL16 | GPU: Nvidia GTX 1060 6GB Zotac Mini | Case: K280 Case | PSU: Cooler Master B600 Power supply | SSD: 1TB  | HDDs: 1x 250GB & 1x 1TB WD Blue | Monitors: 24" Acer S240HLBID + 24" Samsung  | OS: Win 10 Pro

 

Audio: Behringer Q802USB Xenyx 8 Input Mixer |  U-PHORIA UMC204HD | Behringer XM8500 Dynamic Cardioid Vocal Microphone | Sound Blaster Audigy Fx PCI-E card.

 

Home Lab:  Lenovo ThinkCenter M82 ESXi 6.7 | Lenovo M93 Tiny Exchange 2019 | TP-LINK TL-SG1024D 24-Port Gigabit | Cisco ASA 5506 firewall  | Cisco Catalyst 3750 Gigabit Switch | Cisco 2960C-LL | HP MicroServer G8 NAS | Custom built SCCM Server.

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

I find it crazy that the FBI or CIA don't hire people like him/her. Put those skills towards a moral cause and get paid a good amount of moola, too

They would love to, but the unfortunate truth is that the people like this aren't interested in working for a government at all and, from what I have read, a lot of them truly get enjoyment out of knowing they are doing something malicious.

END OF LINE

-- Project Deep Freeze Build Log --

Quote me so that I always know when you reply, feel free to snip if the quote is long. May your FPS be high and your temperatures low.

Link to comment
Share on other sites

Link to post
Share on other sites

Thanks like the whole of India. :o

Or Russia, US, France, UK, Japan, Germany, Canada, South Korea

 

IIRC that makes 1.2 billion, or with in 100 million. :P

My build : http://uk.pcpartpicker.com/p/Ck8VkL

[spoiler spoiler=Crimson Skyline]  My build: http://uk.pcpartpicker.com/p/Ck8VkL | I5-6600K | Hyper 212 Evo | Asus Z170 Pro Gaming + ROG Front Base | Axevir Core Series Red 2X8 2400 | Sandisk SSD Plus 240 GB | Western Digital 1TB Blue | MSI R9 390 | Corsair 760T | Corsair 850 RMI | Dell U2515H IPS | Hyper X II Cloud Red | Corsair K95 RGB | Logitech G602 |

[spoiler spoiler=Laptop] I7 3232QM | Nvidia GT635M | 17.6" TN | 1TB HD | 6GB RAM

Link to comment
Share on other sites

Link to post
Share on other sites

LOL that guy... But its 1.2Billion over how many years... The guy just scanned and scanned for weaknesses... This is exactly why passwords should always be encrypted in a strong way when stored on a server

"Great minds discuss ideas; average minds discuss events; small minds discuss people."

Main rig:

i7-4790 - 24GB RAM - GTX 970 - Samsung 840 240GB Evo - 2x 2TB Seagate. - 4 monitors - G710+ - G600 - Zalman Z9U3

Other devices

Oneplus One 64GB Sandstone

Surface Pro 3 - i7 - 256Gb

Surface RT

Server:

SuperMicro something - Xeon e3 1220 V2 - 12GB RAM - 16TB of Seagates 

Link to comment
Share on other sites

Link to post
Share on other sites

Yeah, you're probably right. I bet they enjoy the thrill and attention they receive after doing stuff like this.

 

Still a shame though.

I know right? Like, imagine what you could accomplish in computer tech/OS/program advancements if you could take say the top 10 hackers in the world and have them work together for just one year!

 

I hate humans. Like so much. People can be cool, but humans are fucking assholes. I wish we would be visited by aliens so that we could finally move past all the stupid petty differences in the world and actually move forward together towards a common "man-kind" goal. Kinda like in Star Trek. :unsure:

END OF LINE

-- Project Deep Freeze Build Log --

Quote me so that I always know when you reply, feel free to snip if the quote is long. May your FPS be high and your temperatures low.

Link to comment
Share on other sites

Link to post
Share on other sites

I know right? Like, imagine what you could accomplish in computer tech/OS/program advancements if you could take say the top 10 hackers in the world and have them work together for just one year!

 

I hate humans. Like so much. People can be cool, but humans are fucking assholes. I wish we would be visited by aliens so that we could finally move past all the stupid petty differences in the world and actually move forward together towards a common "man-kind" goal. Kinda like in Star Trek. :unsure:

 

 

The is the most glorious solution to ending international issues that I have ever read. We should be funding this

 

You seriously think the governments would set them to work on that (or anything like that?)? More like put to use for military applications. Immediate gratification rather than long term world goals (unless it involves money making) is the mandate of most governments.

 Motherboard  ROG Strix B350-F Gaming | CPU Ryzen 5 1600 | GPU Sapphire Radeon RX 480 Nitro+ OC  | RAM Corsair Vengeance DDR4 3000MHz 2x8Gb | OS Drive  Crucial MX300 525Gb M.2 | WiFi Card  ASUS PCE-AC68 | Case Switch 810 Gunmetal Grey SE | Storage WD 1.5tb, SanDisk Ultra 3D 500Gb, Samsung 840 EVO 120Gb | NAS Solution Synology 413j 8TB (6TB with 2TB redundancy using Synology Hybrid RAID) | Keyboard SteelSeries APEX | Mouse Razer Naga MMO Edition Green | Fan Controller Sentry LXE | Screens Sony 43" TV | Sound Logitech 5.1 X530

Link to comment
Share on other sites

Link to post
Share on other sites

You seriously think the governments would set them to work on that (or anything like that?)? More like put to use for military applications. Immediate gratification rather than long term world goals (unless it involves money making) is the mandate of most governments.

Like a said, humans are fucking ass-holes....

END OF LINE

-- Project Deep Freeze Build Log --

Quote me so that I always know when you reply, feel free to snip if the quote is long. May your FPS be high and your temperatures low.

Link to comment
Share on other sites

Link to post
Share on other sites

I like how the security firm started a service to protect the credentials whatever after it happened.

 

Shady af.

Someone told Luke and Linus at CES 2017 to "Unban the legend known as Jerakl" and that's about all I've got going for me. (It didn't work)

 

Link to comment
Share on other sites

Link to post
Share on other sites

I like how the security firm started a service to protect the credentials whatever after it happened.

 

Shady af.

Security Firm:

 

*hires hacker to steal shit

*hacker sells stolen shit for mega profits

*security firm gets a cut

*security firm creates "service" to protect things like this happening

*sells licenses to everyone ensuring they make more money

 

Wouldn't be surprised if this is how it happened lol.

 Motherboard  ROG Strix B350-F Gaming | CPU Ryzen 5 1600 | GPU Sapphire Radeon RX 480 Nitro+ OC  | RAM Corsair Vengeance DDR4 3000MHz 2x8Gb | OS Drive  Crucial MX300 525Gb M.2 | WiFi Card  ASUS PCE-AC68 | Case Switch 810 Gunmetal Grey SE | Storage WD 1.5tb, SanDisk Ultra 3D 500Gb, Samsung 840 EVO 120Gb | NAS Solution Synology 413j 8TB (6TB with 2TB redundancy using Synology Hybrid RAID) | Keyboard SteelSeries APEX | Mouse Razer Naga MMO Edition Green | Fan Controller Sentry LXE | Screens Sony 43" TV | Sound Logitech 5.1 X530

Link to comment
Share on other sites

Link to post
Share on other sites

Security Firm:

 

*hires hacker to steal shit

*hacker sells stolen shit for mega profits

*security firm gets a cut

*security firm creates "service" to protect things like this happening

*sells licenses to everyone ensuring they make more money

 

Wouldn't be surprised if this is how it happened lol.

 

Precisely my thinking

Someone told Luke and Linus at CES 2017 to "Unban the legend known as Jerakl" and that's about all I've got going for me. (It didn't work)

 

Link to comment
Share on other sites

Link to post
Share on other sites

I read that as 1.2 million first and then realized I needed to get my eyes checked.

Ye ole' train

Link to comment
Share on other sites

Link to post
Share on other sites

I find it crazy that the FBI or CIA don't hire people like him/her. Put those skills towards a moral cause and get paid a good amount of moola, too

They do, when they find them. But you've got to catch them first.

Intel i7 5820K (4.5 GHz) | MSI X99A MPower | 32 GB Kingston HyperX Fury 2666MHz | Asus RoG STRIX GTX 1080ti OC | Samsung 951 m.2 nVME 512GB | Crucial MX200 1000GB | Western Digital Caviar Black 2000GB | Noctua NH-D15 | Fractal Define R5 | Seasonic 860 Platinum | Logitech G910 | Sennheiser 599 | Blue Yeti | Logitech G502

 

Nikon D500 | Nikon 300mm f/4 PF  | Nikon 200-500 f/5.6 | Nikon 50mm f/1.8 | Tamron 70-210 f/4 VCII | Sigma 10-20 f/3.5 | Nikon 17-55 f/2.8 | Tamron 90mm F2.8 SP Di VC USD Macro | Neewer 750II

Link to comment
Share on other sites

Link to post
Share on other sites

I find it crazy that the FBI or CIA don't hire people like him/her. Put those skills towards a moral cause and get paid a good amount of moola, too

These types of people usually have a reason to go against the government and public society.

4690K // 212 EVO // Z97-PRO // Vengeance 16GB // GTX 770 GTX 970 // MX100 128GB // Toshiba 1TB // Air 540 // HX650

Logitech G502 RGB // Corsair K65 RGB (MX Red)

Link to comment
Share on other sites

Link to post
Share on other sites

LOL that guy... But its 1.2Billion over how many years... The guy just scanned and scanned for weaknesses... This is exactly why passwords should always be encrypted in a strong way when stored on a server

Passwords shouldn't be encrypted though, because that allows the attacker to decrypt every password by stealing the encryption key.

Instead they should be hashed (think of it like irreversible encryption).

15" MBP TB

AMD 5800X | Gigabyte Aorus Master | EVGA 2060 KO Ultra | Define 7 || Blade Server: Intel 3570k | GD65 | Corsair C70 | 13TB

Link to comment
Share on other sites

Link to post
Share on other sites

Passwords shouldn't be encrypted though, because that allows the attacker to decrypt every password by stealing the encryption key.

Instead they should be hashed (think of it like irreversible encryption).

Well yeah that is what I meant ofc

"Great minds discuss ideas; average minds discuss events; small minds discuss people."

Main rig:

i7-4790 - 24GB RAM - GTX 970 - Samsung 840 240GB Evo - 2x 2TB Seagate. - 4 monitors - G710+ - G600 - Zalman Z9U3

Other devices

Oneplus One 64GB Sandstone

Surface Pro 3 - i7 - 256Gb

Surface RT

Server:

SuperMicro something - Xeon e3 1220 V2 - 12GB RAM - 16TB of Seagates 

Link to comment
Share on other sites

Link to post
Share on other sites

I find it crazy that the FBI or CIA don't hire people like him/her. Put those skills towards a moral cause and get paid a good amount of moola, too

if I read correctly it was emails and passwords not necessarily bank accounts
Link to comment
Share on other sites

Link to post
Share on other sites

I...just...that picture. Why would you want your mouse directly in front of your monitor in dead center?

  Christian 

 

Use the following style specs in your sig to spread the LTT revolution!

Rig Specs:

Screeninator: Gigabyte GeForce GTX960

Powermathingy: Corsair CX600W

Stickiminator: 2x G.Skill ARES 4GB DDR3-1866

Procrastinator: AMD FX-8350 @4.1GHz 1.3V

Holdametalicizor: DIYPC Gamemax-BK

Noisoundacreator: Cyber Acoustics CA-3072 (loudamagargle) Onn Wireless FM Radio Headset (earamagargle)

Attachamathingy: ASRock 990FX Extreme9

Remembrerthing: Western Digital 1TB Blue, Western Digital 40GB Blue

Flat-Colorful-Thing: Acer K272HL

See-A-Move-O: Logitech Hyperion Fury G402

ButtonBoard: Cooler Master CMSTORM Devastator Blue

Talkamagargle: Blue Snowball Ice

 

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

Well, IIRC, all you need is an email and password to sign into online checking accounts.

yeah I know what I meant want it wasn't necessarily the passwords to 1.2 billion bank accounts, it be a fair bet to say a decent percentage of the 1.2 billion are kids
Link to comment
Share on other sites

Link to post
Share on other sites

I find it crazy that the FBI or CIA don't hire people like him/her. Put those skills towards a moral cause and get paid a good amount of moola, too

they do...

 

generally these people get two choices...

Work or guantanamo (or whatever equivalent FBI/CIA has hidden somewhere else that the media doesnt know about yet)

Link to comment
Share on other sites

Link to post
Share on other sites

Well yeah that is what I meant ofc

I know, it was more for other people reading the thread and don't :)

15" MBP TB

AMD 5800X | Gigabyte Aorus Master | EVGA 2060 KO Ultra | Define 7 || Blade Server: Intel 3570k | GD65 | Corsair C70 | 13TB

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×