Live data from Hacker News

773M Password ‘Megabreach’ Is Years Old

krebsonsecurity.com

21–30 of 177 posts

Re: 773M Password ‘Megabreach’ Is Years Old

#21

In the first image with the telegram id the other id is for discord. I don't recall discord being e2e encrypted so that is an interesting choice to offer. Especially since discord is known to have access to all data since they regularly remove chats/servers that don't follow their tos.

The seller may be using a VPN to mitigate this.

Re: 773M Password ‘Megabreach’ Is Years Old

#22
post #20
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I've received the same emails, for livejournal accounts. They seem to reuse bitcoin addresses. Bitcoin blockchain explorers show that the addresses are recently created, and that people have sent them money.

> Bitcoin blockchain explorers show that the addresses are recently created, and that people have sent them money.

I find it difficult to reconcile someone tech savey enough to use bitcoin falling for a scam of this nature.

On the otherhand, it might explain a lot about the crypto space!

Re: 773M Password ‘Megabreach’ Is Years Old

#23
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I had exactly that email. I can't remember where the password was from, but it seems to be in old format that I used to use maybe 10 years back, if not more.

Re: 773M Password ‘Megabreach’ Is Years Old

#24

So the seller shows a screenshot with browser tabs, a date and a time. One of the tabs is really very specific, looking at a particular disqus profile. I'm not familiar with Windows; is there anything in the screenshot to suggest its torbrowser or anything like that? Presumably the miscreant's ISP and e.g. the Russian government can guess real easy whom generated that screenshot...? Of course what they'd do with that…

The screenshot has a tab open on this article: https://www.troyhunt.com/the-773-million-record-collection-1... I don't think it's from the seller - looks like it was taken by the author of this article.

In the screenshot [0] there is also a tab viewing someone's Disqus profile, and you can also see the time and date. I think the suggestion was there may be ways to track down who the hacker is based on this. Of course he could very well be using a VPN (highly likely). Or at the very least a public/free WiFi, although in Russia you have to register with a phone number to access them.

[0] https://krebsonsecurity.com/wp-content/uploads/2019/01/sanix...

Re: 773M Password ‘Megabreach’ Is Years Old

#25

So the seller shows a screenshot with browser tabs, a date and a time. One of the tabs is really very specific, looking at a particular disqus profile. I'm not familiar with Windows; is there anything in the screenshot to suggest its torbrowser or anything like that? Presumably the miscreant's ISP and e.g. the Russian government can guess real easy whom generated that screenshot...? Of course what they'd do with that…

The screenshot has a tab open on this article: https://www.troyhunt.com/the-773-million-record-collection-1... I don't think it's from the seller - looks like it was taken by the author of this article.

It addresses that in the article: "...notice the open Web browser tab behind his purloined password trove (which is apparently stored at Mega.nz): Troy Hunt’s published research on this 773 million Collection #1"

Re: 773M Password ‘Megabreach’ Is Years Old

#26
post #19

I can't remember if it was haveibeenpwned.com or some other site, but I seem to recall once a few years ago checking my email on a site which also showed you the first two characters of the password which had been compromised. Maybe it has since been discontinued because of security concerns, but I found it really useful at the time because it let me know that the leaked password was an old one that I hadn't used in…

I was so sure it was haveibeenpwned.com that showed the password as well, but alas they do not, at least not for the last two years.

The way I use to recognize which service has been compromised is using unique email addresses. Most providers let you do either a catchall address, or xyz+alias@provider.com, meaning you should have a user+hn@domain.com for your Hacker News user account. Makes both knowing which services has been hacked easy, but also who sells your contact information to spammers easy! :)

Edit: actually, using random passwords from a manager, you should be able to identify it through https://haveibeenpwned.com/Passwords

Re: 773M Password ‘Megabreach’ Is Years Old

#27
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

> recorded watching porn

What a damning position to be in, in 2019.

Re: 773M Password ‘Megabreach’ Is Years Old

#28
post #20

Earlier quoted context omitted.

I've received the same emails, for livejournal accounts. They seem to reuse bitcoin addresses. Bitcoin blockchain explorers show that the addresses are recently created, and that people have sent them money.

> Bitcoin blockchain explorers show that the addresses are recently created, and that people have sent them money. I find it difficult to reconcile someone tech savey enough to use bitcoin falling for a scam of this nature. On the otherhand, it might explain a lot about the crypto space!

The email contains:

> You will make the payment by Bi‌tco‌in (if you do not know this, search 'how to buy b‌itcoi‌n' in Google).

The top result is from coinbase [1]. I would say everyone capable of online banking is capable of following these steps.

[1] https://www.coinbase.com/buy-bitcoin

Re: 773M Password ‘Megabreach’ Is Years Old

#29
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

> recorded watching porn What a damning position to be in, in 2019.

Unless it's a black mirror twist. Next thing you're following some trolls orders to kill people to conceal your dark secret

Re: 773M Password ‘Megabreach’ Is Years Old

#30
post #18

Since a few weeks ago I receive spam emails threatening me with an old password I no longer use. I wonder if it's related to this collection. It starts with: > I am well aware [old password I think I swapped out everywhere, but definitely in all important places, when I started to use random keepass pws two years ago] is your pass words. Lets get straight to the point. None has compensated me to check about you. You…

I received the same email to "myspace@" my domain. I wouldn't have used that email anywhere else..
Post reply on HN