HR News Update – Grand hack, hauls 1.2 billion personal details

HR News Update – Grand hack, hauls 1.2 billion personal details

Russian hacker mob accumulated the largest known collection of emails, passwords and usernames, with the haul consisting of 1.2 billion username and password combinations, along with over half a billion email addresses.

TK Keanini, CTO at Lancope: “There is a glutton of credentials always floating around the black market and because of this fact, security professionals need more than just traditional detection signatures looking for exploits and attacks because the adversary is just going to login to your network normally.  In particular, defenders need anomaly detection methods as it is the only way to discovery this abuse in its early stages”.

Mark Bower,  VP at Voltage Security: “This sounds all too familiar: weakly secured sites, preventable vulnerabilities that aren’t patched, and automated botnets to exploit them yielding massive troves of identity data suitable for a ruthless secondary online system attacks at tremendous scale. Yet more evidence the bad guys are winning big at consumers’ expense who will foot the bill for this in the end like a hidden tax. Clearly it’s time to change the game in data-security and neutralize data-breach risks instead of paying the heavy price when sensitive data falls into the wrong hands all too easily.”

Michael Sutton, VP of security research at Zscaler: “With 420,000 sites infected, it will be impossible to work with all of the impacted companies and ensure that the vulnerabilities that led to the breaches are ultimately patched. Many will remain vulnerable for some time, if not indefinitely. The attackers crowd sourced the hacking, leveraging botnet infected computers to do the heavy lifting for them and identify sites vulnerable to SQL injection attacks. This is yet another warning of the dangers of using the same credentials on multiple sites. Consumers should assume that sites they trust will be breached at some point. If they use different credentials on all sites, at least they can limit the damage. Fortunately, there are many tools/services available so that users don't have to remember dozens of different passwords.”

Read more

Latest News

Read More

“Back to work versus hybrid models: Which way forward in 2025?”

15 January 2025

Newsletter

Receive the latest HR news and strategic content

Please note, as per the GDPR Legislation, we need to ensure you are ‘Opted In’ to receive updates from ‘theHRDIRECTOR’. We will NEVER sell, rent, share or give away your data to third parties. We only use it to send information about our products and updates within the HR space To see our Privacy Policy – click here

Latest HR Jobs

University of Salford – HRSalary: £32,296 to £36,924

University of Cambridge – Human Resources DivisionSalary: £62,098 to £65,814 per annum

King's College London – People ServicesSalary: £38,232 to £42,999 per annum, including London Weighting Allowance

London School of Hygiene & Tropical Medicine – DirectorateSalary: £62,928 to £72,092 per annum (inclusive of London Weighting), Grade 8

Read the latest digital issue of theHRDIRECTOR for FREE

Read the latest digital issue of theHRDIRECTOR for FREE