Thursday, October 10, 2024
HomePassword Attacks1.4 Billion Clear Text Credentials Discovered in Underground Community Forum

1.4 Billion Clear Text Credentials Discovered in Underground Community Forum

Published on

A largest dark web database discovered in Underground Community Forum that contains almost 1.4 billions clear text Credentials and this dumb data’s belongs to 252 previous breaches.

This is one of the biggest credentials database that ever discovered in history and previous largest credential exposure, the Exploit.in combo list that exposed 797 million records.

A depth research has been conducted in this database and researchers confirms that non of the passwords are encrypted and most of them have been verified to be true.

- Advertisement - EHA

This database consists of more scary information and its working ultimately fast response (one-second response) searches and new breach imports.

According to 4iQ Reseracher, The data is organized alphabetically, offering examples of trends in how people set passwords, reuse them and create repetitive patterns over time. 
This single file database is very fastly responding to search the passwords than ever before. for an example, searching for “admin,” “administrator” and “root” returned 226,631 passwords of admin users in a few seconds.

Database file name mentioned “imported.log” with 133 addition or new breaches apart from 252 previous breaches.

Also Read: A new Hacker Group ‘MoneyTaker’ uncovered by Group-IB Attacking Banks in the USA and Russia

These are some of breach and number of password that have been leaked from the concern breaches.

Clear Text Credentials

This Database has recently updated ad 11/29/2017 was the last time this DB has updated and 41GB dump was found on 5th December 2017.

Exactly the total amount of Clear Text Credentials (usernames/clear text password pairs) is 1,400,553,869 and 14% of exposed username/passwords pairs had not previously been decrypted by the community and are now available in clear text.

“This new breach adds 385 million new credential pairs, 318 million unique users, and 147 million passwords pertaining to those previous dumps.”

These are the top 40 passwords list that has been used by the users from previous breaches.

Given the fact that people reuse passwords across their email, social media, e-commerce, banking and work accounts, hackers can automate account hijacking or account takeover.

Balaji
Balaji
BALAJI is an Ex-Security Researcher (Threat Research Labs) at Comodo Cybersecurity. Editor-in-Chief & Co-Founder - Cyber Security News & GBHackers On Security.

Latest articles

Mozilla Warns Of Firefox Zero-Day Actively Exploited In Cyber Attacks

A critical use-after-free vulnerability affecting Firefox and Firefox Extended Support Release (ESR) is being...

SpyCloud Embeds Identity Analytics in Cybercrime Investigations Solution to Accelerate Insider and Supply Chain Risk Analysis & Threat Actor Attribution

IDLink, SpyCloud’s new automated digital identity correlation capability, is now core to its industry-leading...

Abusix and Red Sift Form New Partnership, Leveraging Automation to Mitigate Cyber Attacks

The agreement has marked over 600,000 fraudulent domains for takedown in just two months...

Hackers Exploiting Zero-day Flaw in Qualcomm Chips to Attack Android Users

Hackers exploit a zero-day vulnerability found in Qualcomm chipsets, potentially affecting millions worldwide.The flaw,...

Free Webinar

Protect Websites & APIs from Malware Attack

Malware targeting customer-facing websites and API applications poses significant risks, including compliance violations, defacements, and even blacklisting.

Join us for an insightful webinar featuring Vivek Gopalan, VP of Products at Indusface, as he shares effective strategies for safeguarding websites and APIs against malware.

Discussion points

Scan DOM, internal links, and JavaScript libraries for hidden malware.
Detect website defacements in real time.
Protect your brand by monitoring for potential blacklisting.
Prevent malware from infiltrating your server and cloud infrastructure.

More like this

10 Best WiFi Hacking Apps for Android – 2024 Edition

In this article, we are sharing the top “Wi-Fi hacking Apps“ for Android applicants....

Brutespray – Port Scanning and Automated Brute Force Tool

Brutespray is a Python script that provides a combination of both port scanning and automated...

fsociety a Complete Hacking Tools pack that a Hacker Needs – Penetration Testing Framework

fsociety is a penetration testing framework that consists of all penetration testing tools that...