All Content from Business Insider 06月21日
A massive trove of 16 billion stolen passwords was discovered — here's what to do
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

近期,研究人员发现大规模数据泄露事件,导致160亿登录凭证暴露,涉及Apple、Gmail、Facebook等多个平台。此次泄露给用户的账户安全带来了严重威胁,可能导致账户被盗、身份盗窃和定向钓鱼等风险。为了应对这一威胁,建议用户采取两步验证和使用通行密钥等安全措施。同时,文章还提供了识别账户是否受到数据泄露影响的方法,并强调了密码管理的重要性。

🛡️ 研究人员披露了一起涉及160亿登录凭证的大规模数据泄露事件,这些凭证可能来自Infostealers等恶意软件。

🔑 泄露数据包括Apple、Gmail、Facebook、GitHub等平台的登录信息,黑客可利用这些信息进行账户接管、身份盗窃和定向钓鱼等攻击。

✅ 保护措施包括使用两步验证、通行密钥以及定期检查账户是否受到数据泄露的影响。例如,用户可以使用Have I Been Pwned等网站查询自己的邮箱是否出现在数据泄露事件中。

💡 平台提供的安全工具包括Google的密码管理器和暗网报告,以及Meta的隐私检查工具,用户可以通过这些工具加强账户安全。

💬 Telegram表示其主要登录方式是通过短信发送一次性密码,因此受此次数据泄露的影响相对较小。

Facebook is one of the companies that has users who might be affected.

Researchers say they've uncovered one of the largest data leaks in history that involves many popular platforms.

The leak includes nearly 16 billion login credentials that could give cybercriminals access to social media and business platforms such as Apple, Gmail, Telegram, Facebook, GitHub, and more, researchers at Cybernews said this week.

Bad actors now have "unprecedented access to personal credentials that can be used for account takeover, identity theft, and highly targeted phishing," the researchers said.

The number of exposed people or accounts is unknown. The researchers said the data likely comes from malicious software known as infostealers.

"What's especially concerning is the structure and recency of these datasets — these aren't just old breaches being recycled. This is fresh, weaponizable intelligence at scale," the researchers said.

Cybernews said researchers uncovered the leak when the datasets were exposed for a short period of time.

It follows the May discovery of a database containing more than 184 million credentials, including Apple, Facebook, and Google logins, Wired earlier reported.

If you're nervous that your logins are at risk, there are steps you can take to make your account safer.

How to protect yourself

You can't unring the bell of an information leak. However, you can take steps to identify if your credentials have been involved in any data breaches and protect yourself in the future.

You can check sites like Have I Been Pwned to see if your email has appeared in a data breach.

Turning on two-step authentication for your accounts can also help protect them from unauthorized access.

Platforms also offer resources to help users secure their accounts.

Google encourages users to use protections that don't require a password, like a passkey. It's one of the tech giants, along with Apple, Amazon, and Microsoft, that have been working to move users away from passwords to help secure their accounts.

For those who prefer to stick with passwords, Google's password manager can store login credentials and notify users if they appear in a breach, a spokesperson told Business Insider.

There's also Google's dark web report, a free tool that tracks whether personal information is floating around in online databases.

GitHub, an online coding platform, offers developers a guide on how to implement safety measures in their organizations. The site recommends creating a security policy, having strict password guidelines, and requiring two-factor authorization.

The data leak included logs — "often with tokens, cookies, and metadata," which makes it "particularly dangerous for organizations lacking multi-factor authentication or credential hygiene practices," the Cybernews team said.

Meta offers a Privacy Checkup tool for users to review their privacy and security account settings. There, you can turn on two-factor authentication and ensure Meta alerts you of unusual logins.

Meanwhile, Telegram said its primary login method sends a one-time password to users over SMS.

"As a result, this is far less relevant for Telegram users compared to other platforms where the password is always the same," a Telegram spokesperson told BI about the data leak.

Apple, GitHub, and Meta did immediately respond to a request for comment on the data leak. Google said it was directing users to some of the security resources above.

Read the original article on Business Insider

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

数据泄露 登录凭证 网络安全 账户安全 两步验证
相关文章