Cyber Experts Uncover 2M Stolen Passwords to Global Web Accounts
Researchers with Trustwave’s SpiderLabs said they discovered the credentials while investigating a server in the Netherlands that cyber criminals use to control a massive network of compromised computers known as the “Pony botnet.”
The company told Reuters on Wednesday that it has reported its findings to the largest of more than 90,000 websites and Internet service providers whose customers’ credentials it had found on the server.
The data includes more than 326,000 Facebook Inc accounts, some 60,000 Google Inc accounts, more than 59,000 Yahoo Inc accounts and nearly 22,000 Twitter Inc accounts, according to SpiderLabs. Victims’ were from the United States, Germany, Singapore and Thailand, among other countries.
Representatives for Facebook and Twitter said the companies have reset the passwords of affected users. A Google spokeswoman declined comment. Yahoo representatives could not be reached.
SpiderLabs said it has contacted authorities in the Netherlands and asked them to take down the Pony botnet server.
An analysis posted on the SpiderLabs blog showed that the most-common password in the set was “123456,” which was used in nearly 16,000 accounts. Other commonly used credentials included “password,” “admin,” “123” and “1.”
Graham Cluley, an independent security expert, said it is extremely common for people to use such simple passwords and also re-use them on multiple accounts, even though they are extremely easy to crack.
“People are using very dumb passwords. They are totally useless,” he said.
(With assistance from Dakin Campbell in New York. Editors: Dan Kraut, Steve Dickson)
- After 62 Years, Florida Appeals Court Drops the Expert Witness Rule on Attorney Fees
- Chubb Names Kevin Rampe Global Head of Claims
- Secret Codes and Yuan Fees Get Ships Through Iran’s Hormuz Tollbooth
- Public Adjuster Accused of Swiping $600,000 in Hurricane Ian Insurance Payments