Five hackers indicted for largest known financial data breach in US history

Five hackers get indicted for largest known financial data breach in US history

There are your everyday run-of-the-mill hackers, and then there are the hackers who set the bar for everyone else. Though we’d hardly call them exemplary individuals, the five culprits recently indicted for the largest known financial hack in US history would certainly belong in the latter category. Comprised of four Russians and a Ukrainian, the quintet’s unsavory accomplishments include breaking into networks belonging to major corporations like Nasdaq, Dow Jones, 7-Eleven and JCPenney — siphoning more than 160 million credit card numbers and bringing about millions of dollars in losses. They did so with SQL injection attacks to install malware that let them crack passwords and snag other sensitive data. Two of them — Vladimir Drinkman and Dmitriy Smilianets — have been arrested, while the rest — Alexandr Kalinin, Roman Kotov and Mikhail Rytikov — remain at large. All five could be behind bars for decades if found guilty. For the nitty gritty as to just how and which companies were affected, hit up the source link below. It’s enough to make you want to change your password several times over.

Filed under:

Comments

Via: Ars Technica

Source: US Department of Justice

Yahoo confirms server breach, over 400k accounts compromised

Yahoo confirms server breach, over 400k accounts compromised

Online account security breaches are seemingly commonplace these days — just ask LinkedIn or Sony — and now we can add Yahoo’s name to the list of hacking victims. The company’s confirmed that it had the usernames and passwords of over 400,000 accounts stolen from its servers earlier this week and the data was briefly posted online. The credentials have since been pulled from the web, but it turns out they weren’t just for Yahoo accounts, as Gmail, AOL, Hotmail, Comcast, MSN, SBC Global, Verizon, BellSouth and Live.com login info was also pilfered and placed on display. The good news? Those responsible for the breach said that the deed was done to simply show Yahoo the weaknesses in its software security. To wit:

We hope that the parties responsible for managing the security of this subdomain will take this as a wake-up call, and not as a threat. There have been many security holes exploited in Web servers belonging to Yahoo Inc. that have caused far greater damage than our disclosure. Please do not take them lightly. The subdomain and vulnerable parameters have not been posted to avoid further damage.

In response, Yahoo’s saying that a fix for the vulnerability is in the works, but the investigation is ongoing and its system has yet to be fully secured. In the meantime, the company apologized for the breach and is advising users to change their passwords accordingly. You can read the official party line below.

At Yahoo! we take security very seriously and invest heavily in protective measures to ensure the security of our users and their data across all our products. We confirm that an older file from Yahoo! Contributor Network (previously Associated Content) containing approximately 400,000 Yahoo! and other company users names and passwords was stolen yesterday, July 11. Of these, less than 5% of the Yahoo! accounts had valid passwords. We are fixing the vulnerability that led to the disclosure of this data, changing the passwords of the affected Yahoo! users and notifying the companies whose users accounts may have been compromised. We apologize to affected users. We encourage users to change their passwords on a regular basis and also familiarize themselves with our online safety tips at security.yahoo.com.

Filed under:

Yahoo confirms server breach, over 400k accounts compromised originally appeared on Engadget on Thu, 12 Jul 2012 14:41:00 EDT. Please see our terms for use of feeds.

Permalink   |  sourceTechCrunch, New York Times  | Email this | Comments