Saturday, November 16, 2024
HomeCyber AttackShiny Hunters Hacking Group Selling 11 Companies Databases of over 73.2 Million...

Shiny Hunters Hacking Group Selling 11 Companies Databases of over 73.2 Million User Records on Dark Web

Published on

A hacker group dubbed Shiny Hunters started selling hacked databases that contain over 73.2 Million user records of 11 different companies over the dark web.

It all starts with the Tokopedia dump shared last week contains more than 90 million user records, followed by Unacademy dump and the hack of the Microsoft’s GitHub account.

It seems ‘SkyHunter’ has got some interesting business model going in the darkweb market – the actor gained initial traction via Tokopedia breach and seems to be flooding the market with new bases,” reads Cyble report.

- Advertisement - SIEM as a Service

Hackers Selling Passwords

Now the hacker group started selling passwords on the dark web that exfiltrated from various companies.

At the first stage following companies data are listed for sale; HomeChef, ChatBooks, and Chronicle.com

Among three the chronicle education data prices are lower when compared to others, the dump has more than 3M details, and the quoted price $1500.

The hackers said “that they have more databases from other breached websites. They plan on selling them in the near future.”

Shared list of user records and pricing details.

CompanyUser RecordsPrice
Tokopedia91 million$5,000
Homechef8 million$2,500
Bhinneka1.2 million$1,200
Minted5 million$2,500
Styleshare6 million$2,700
Ggumim2 million$1,300
Mindful2 million$1,300
StarTribune1 million$1,100
ChatBooks15 million$3,500
The Chronicle Of Higher Education3 million$1,500
Zoosk30 million$500

Users are recommended to change the login credentials and to use a unique login for every portal.

Tips to Stay Safe

  • Use a complex password, enforce a strong password policy.
  • Check the password regularly, Use two-factor authentication(2FA) for vital sites like managing an account and Emails, make sure all the passwords are unique.
  • Change the Manufactures’s default Password that gadgets are issued before they are conveyed to the IT Department.
  • Use password managers.

You can follow us on LinkedinTwitterFacebook for daily Cybersecurity and hacking news updates.

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Critical TP-Link DHCP Vulnerability Let Attackers Execute Arbitrary Code Remotely

A critical security flaw has been uncovered in certain TP-Link routers, potentially allowing malicious...

Chinese SilkSpecter Hackers Attacking Black Friday Shoppers

SilkSpecter, a Chinese financially motivated threat actor, launched a sophisticated phishing campaign targeting e-commerce...

Cybercriminals Launch SEO Poisoning Attack to Lure Shoppers to Fake Online Stores

The research revealed how threat actors exploit SEO poisoning to redirect unsuspecting users to...

Black Basta Ransomware Leveraging Social Engineering For Malware Deployment

Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

Black Basta Ransomware Leveraging Social Engineering For Malware Deployment

Black Basta, a prominent ransomware group, has rapidly gained notoriety since its emergence in...

Amazon Confirms Employee Data Breach Via Third-party Vendor

Amazon has confirmed that sensitive employee data was exposed due to a breach at...

Researchers Detailed Credential Abuse Cycle

Cybercriminals exploit leaked credentials, obtained through various means, to compromise systems and data, enabling...