HR News Update – Grand hack, hauls 1.2 billion personal details

HR News Update – Grand hack, hauls 1.2 billion personal details

Russian hacker mob accumulated the largest known collection of emails, passwords and usernames, with the haul consisting of 1.2 billion username and password combinations, along with over half a billion email addresses.

TK Keanini, CTO at Lancope: “There is a glutton of credentials always floating around the black market and because of this fact, security professionals need more than just traditional detection signatures looking for exploits and attacks because the adversary is just going to login to your network normally.  In particular, defenders need anomaly detection methods as it is the only way to discovery this abuse in its early stages”.

Mark Bower,  VP at Voltage Security: “This sounds all too familiar: weakly secured sites, preventable vulnerabilities that aren’t patched, and automated botnets to exploit them yielding massive troves of identity data suitable for a ruthless secondary online system attacks at tremendous scale. Yet more evidence the bad guys are winning big at consumers’ expense who will foot the bill for this in the end like a hidden tax. Clearly it’s time to change the game in data-security and neutralize data-breach risks instead of paying the heavy price when sensitive data falls into the wrong hands all too easily.”

Michael Sutton, VP of security research at Zscaler: “With 420,000 sites infected, it will be impossible to work with all of the impacted companies and ensure that the vulnerabilities that led to the breaches are ultimately patched. Many will remain vulnerable for some time, if not indefinitely. The attackers crowd sourced the hacking, leveraging botnet infected computers to do the heavy lifting for them and identify sites vulnerable to SQL injection attacks. This is yet another warning of the dangers of using the same credentials on multiple sites. Consumers should assume that sites they trust will be breached at some point. If they use different credentials on all sites, at least they can limit the damage. Fortunately, there are many tools/services available so that users don't have to remember dozens of different passwords.”

Read more

Latest News

Read More

How to foster a culture of learning

27 November 2024

Newsletter

Receive the latest HR news and strategic content

Please note, as per the GDPR Legislation, we need to ensure you are ‘Opted In’ to receive updates from ‘theHRDIRECTOR’. We will NEVER sell, rent, share or give away your data to third parties. We only use it to send information about our products and updates within the HR space To see our Privacy Policy – click here

Latest HR Jobs

About the Company: Fortress is a purpose driven organisation. “Saving lives by providing the best safety solutions” is at the heart of decision making and

Maru is seeking an enthusiastic and knowledgeable HR Coordinator to join our global HR Team and work alongside our UK HR Manager. This role is

Reporting into the HR Manager, this role is integral to the UK people function in providing a first class, business focused HR solution, in all

About Leader Engineering Leader Engineering is on a mission to transform energy recruitment. For nearly 20 years, we’ve built real, lasting partnerships in the oil

Read the latest digital issue of theHRDIRECTOR for FREE

Read the latest digital issue of theHRDIRECTOR for FREE