Bitcoin Forum
May 07, 2024, 02:52:38 PM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1] 2 »  All
  Print  
Author Topic: 773M Emails Hacked  (Read 241 times)
greenlanternlight01 (OP)
Copper Member
Jr. Member
*
Offline Offline

Activity: 252
Merit: 6


View Profile
February 03, 2019, 06:25:41 PM
 #1

This info has been going around quite some time now but I just wanted to share with anyone who hasn't heard it yet. The article explains how was found out that 773M emails and over 21M passwords were hacked and leaked on what is thought to be the largest email hack ever. https://www.cnet.com/news/massive-breach-leaks-773-million-emails-21-million-passwords/

What does this mean for me?

Like everyone I have my email address linked with several exchanges with several open orders in buy or in sell. That being said if someone was to find my mail address and password would try and enter on those exchanges. I've activated 2FA on every exchange but it doesn't feel good to know that I might be one of those 773M hacked email. My coins are on my hardware wallets but I have some other on exchanges on buy and sell orders. With one email hack I could lose some money. Luckily there is this website  https://haveibeenpwned.com that finds out if your email has been hacked or not. I tried it and fortunately my main account I use on most exchanges is safe.
I suggest everyone to give it a try and if you find out smth that you don't like I suggest you change the email password to start with, and then to change the password on all the exchanges where you have used that email address.

Let's keep our money safe guys  Wink

1715093558
Hero Member
*
Offline Offline

Posts: 1715093558

View Profile Personal Message (Offline)

Ignore
1715093558
Reply with quote  #2

1715093558
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715093558
Hero Member
*
Offline Offline

Posts: 1715093558

View Profile Personal Message (Offline)

Ignore
1715093558
Reply with quote  #2

1715093558
Report to moderator
TryNinja
Legendary
*
Offline Offline

Activity: 2828
Merit: 6977



View Profile WWW
February 03, 2019, 06:56:18 PM
 #2

Password manager + 24 long unique password + 2FA = profit.

Never reuse your password and never pick a shit password (i.e ilovemydog123).

Never got hacked after uncountables leaks.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
HODL2090
Member
**
Offline Offline

Activity: 210
Merit: 29


View Profile
February 03, 2019, 06:57:17 PM
 #3

If you've activated 2FA on your account on exchanges then your accounts should be secured even if your email had been hacked.
This is really a large breach and would lead to loss of lots of personal information if it's true. You can also security your email address using 2FA to keep it protected.
bitmover
Legendary
*
Offline Offline

Activity: 2296
Merit: 5921


bitcoindata.science


View Profile WWW
February 03, 2019, 07:00:03 PM
 #4

Password manager + 24 long unique password + 2FA = profit.

Some password managers were hacked already, sadly. LastPass was hacked few years ago.

Nothing online is 100%

That's why bitcoin solution is amazing: keys are hold offline, unhackable.

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
TryNinja
Legendary
*
Offline Offline

Activity: 2828
Merit: 6977



View Profile WWW
February 03, 2019, 07:01:53 PM
 #5

Password manager + 24 long unique password + 2FA = profit.

Some password managers were hacked already, sadly. LastPass was hacked few years ago.

Nothing online is 100%

That's why bitcoin solution is amazing: keys are hold offline, unhackable.
Sorry, forgot to mention the word “offline”.

I actually use KeePass as my password manager and only store my db file in a few encrypted flash drives.

.
.HUGE.
▄██████████▄▄
▄█████████████████▄
▄█████████████████████▄
▄███████████████████████▄
▄█████████████████████████▄
███████▌██▌▐██▐██▐████▄███
████▐██▐████▌██▌██▌██▌██
█████▀███▀███▀▐██▐██▐█████

▀█████████████████████████▀

▀███████████████████████▀

▀█████████████████████▀

▀█████████████████▀

▀██████████▀▀
█▀▀▀▀











█▄▄▄▄
▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀▀
.
CASINSPORTSBOOK
▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄▄
▀▀▀▀█











▄▄▄▄█
btc-facebook
Legendary
*
Offline Offline

Activity: 1862
Merit: 1015


View Profile
February 03, 2019, 07:33:05 PM
 #6

Activating 2FA both on exchange and your email will be more better and more safety. Change the password of your email into the stronger one, using the combination of caps number and symbol, it would be more secure.
madnessteat
Legendary
*
Offline Offline

Activity: 2240
Merit: 2001



View Profile
February 03, 2019, 08:12:37 PM
 #7

This info has been going around quite some time now but I just wanted to share with anyone who hasn't heard it yet. The article explains how was found out that 773M emails and over 21M passwords were hacked and leaked on what is thought to be the largest email hack ever. https://www.cnet.com/news/massive-breach-leaks-773-million-emails-21-million-passwords/

What does this mean for me?

Like everyone I have my email address linked with several exchanges with several open orders in buy or in sell. That being said if someone was to find my mail address and password would try and enter on those exchanges. I've activated 2FA on every exchange but it doesn't feel good to know that I might be one of those 773M hacked email. My coins are on my hardware wallets but I have some other on exchanges on buy and sell orders. With one email hack I could lose some money. Luckily there is this website  https://haveibeenpwned.com that finds out if your email has been hacked or not. I tried it and fortunately my main account I use on most exchanges is safe.
I suggest everyone to give it a try and if you find out smth that you don't like I suggest you change the email password to start with, and then to change the password on all the exchanges where you have used that email address.

Let's keep our money safe guys  Wink

This has already been posted Pmalek on the forum on January 18th: 773 Million Hacked User Accounts are being traded on underground forums

███████████████████████████
███████▄████████████▄██████
████████▄████████▄████████
███▀█████▀▄███▄▀█████▀███
█████▀█▀▄██▀▀▀██▄▀█▀█████
███████▄███████████▄███████
███████████████████████████
███████▀███████████▀███████
████▄██▄▀██▄▄▄██▀▄██▄████
████▄████▄▀███▀▄████▄████
██▄███▀▀█▀██████▀█▀███▄███
██▀█▀████████████████▀█▀███
███████████████████████████
.
.Duelbits.
▄▄█▄▄░░▄▄█▄▄░░▄▄█▄▄
███░░░░███░░░░███
░░░░░░░░░░░░░
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░░░░███▄█░░░
░░██▌░░███░▀░░██▌
█░██░░███░░░██
█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀
.
REGIONAL
SPONSOR
███▀██▀███▀█▀▀▀▀██▀▀▀██
██░▀░██░█░███░▀██░███▄█
█▄███▄██▄████▄████▄▄▄██
██▀ ▀███▀▀░▀██▀▀▀██████
███▄███░▄▀██████▀█▀█▀▀█
████▀▀██▄▀█████▄█▀███▄█
███▄▄▄████████▄█▄▀█████
███▀▀▀████████████▄▀███
███▄░▄█▀▀▀██████▀▀▀▄███
███████▄██▄▌████▀▀█████
▀██▄█████▄█▄▄▄██▄████▀
▀▀██████████▄▄███▀▀
▀▀▀▀█▀▀▀▀
.
EUROPEAN
BETTING
PARTNER
jademaxsuy
Full Member
***
Offline Offline

Activity: 924
Merit: 220


View Profile WWW
February 03, 2019, 08:42:53 PM
 #8

This has already been posted Pmalek on the forum on January 18th: 773 Million Hacked User Accounts are being traded on underground forums
Yes and it's been discussed by pmalek and other high ranks like TryNinja and boyptc which give some tips to forum users to change their password to make their account safe to avoid breaches. Well thanks to pmalek to translate the original post - https://bitcointalk.org/index.php?topic=5098731.0.
greenlanternlight01 (OP)
Copper Member
Jr. Member
*
Offline Offline

Activity: 252
Merit: 6


View Profile
February 03, 2019, 08:52:00 PM
 #9

This has already been posted Pmalek on the forum on January 18th: 773 Million Hacked User Accounts are being traded on underground forums

To be honest I didn't go that long back in the search for any other post. But to be on the safe side I started my post with
Quote
This info has been going around quite some time now but I just wanted to share with anyone who hasn't heard it yet.

Kudos to Pmalek for having post it first and letting everyone know about this 💪

logfiles
Copper Member
Legendary
*
Offline Offline

Activity: 1974
Merit: 1653


Top Crypto Casino


View Profile WWW
February 03, 2019, 09:37:43 PM
 #10

This is why it is very important to use each unique password for each website you register for. Imagine having the one password for both your email and the website whose data has been breached.

In this case, your email can easily get compromised and will be used for resetting passwords for your important accounts in other websites and logging into them if you didn't set any 2FA.

And about 2FA, don't be too confident about it too. If the website does not implement enough protection, it too can be brute forced.
Here is a classic example of such a scenario. It happened on COSS exchange last year. The user lost over 850K in cryptos through this attack.
Reddit user describes 2FA hack on Coss Exchange, over $850k stolen

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
hatshepsut93
Legendary
*
Offline Offline

Activity: 2968
Merit: 2145



View Profile
February 03, 2019, 09:38:08 PM
Merited by TheBeardedBaby (1)
 #11

Change the password of your email into the stronger one, using the combination of caps number and symbol, it would be more secure.

The problem with numbers, special symbols, uppercase letters and other techniques is that people strongly tend to do it in predictable way, like putting numbers in the end, capital letters at the beggining, etc. If you have a really short password that is based on some popular word, it might get cracked pretty fast, even if it has numbers and special symbols. Those types of passwords are usually very hard to remember, and you can get a lot of trouble if it's your main email with no methods of resetting your password. The better approach is to use very long passwords with normal words, if you don't use a password manager, or just random strings if you do.


.BEST.CHANGE..███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
jseverson
Hero Member
*****
Offline Offline

Activity: 1834
Merit: 759


View Profile
February 04, 2019, 05:37:25 AM
 #12

So the hack's origin is apparently unknown, and could very well be just a collection of past hacks:

Q. How long ago were these sites breached?
It varies. The first site on the list I shared was 000webhost who was breached in 2015, but there's also a file in there which suggests 2008. These are lots of different incidents from lots of different time frames.

It's no reason for immediate panic, but it's a wake up call to people who reuse their passwords nonetheless. It's also worth noting that some email providers are better with security than others. Remember the Yahoo breach?

logfiles
Copper Member
Legendary
*
Offline Offline

Activity: 1974
Merit: 1653


Top Crypto Casino


View Profile WWW
February 04, 2019, 06:07:04 AM
 #13

It's also worth noting that some email providers are better with security than others. Remember the Yahoo breach?

I checked my old yahoo mail account and it's shown to have been leaked over 3 times. This is an email I barely used for signing up on different websites... My Gmail on the other side (the one I use for less secure sites) shows not to have been leaked ever. I have used these email hundreds of times to sign up on different websites. So you could be very right.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
Onuohakk
Member
**
Offline Offline

Activity: 672
Merit: 29


View Profile
February 04, 2019, 06:21:29 AM
 #14

If you are continuously following safety precautions you need not to worry about being hacked.
But always have a specific email for a specific purpose this also helps ensure business email don't get into the wrong hands

|   Facebook   |     Twitter     |                    R A N G E R S                    |    Discord    |    Medium    |
|    Telegram    |                    ─────     PROTOCOL     ─────                    |    Gitbook    |
████  ███  ██  █          VIRTUAL WORLDS BLOCKCHAIN INFRASTRUCTURE          █  ██  ███  ████
jossiel
Hero Member
*****
Offline Offline

Activity: 2982
Merit: 632


Seabet.io | Crypto-Casino


View Profile
February 04, 2019, 06:34:06 AM
 #15

Activating 2FA both on exchange and your email will be more better and more safety. Change the password of your email into the stronger one, using the combination of caps number and symbol, it would be more secure.
Nothing is safe now look at the recent news for Mac Users.

CookieMiner Mac Malware Wants Your Cookies and Your Crypto Funds

Use passwords that you never have used before and has a strong combination of characters, letters, symbols + numbers. Don't recycle old passwords that you've been using for different websites.

Kopyleft
Member
**
Offline Offline

Activity: 168
Merit: 15

Future of Security Tokens


View Profile
February 04, 2019, 06:43:44 AM
 #16

The internet is always devicing new means of funds theft and privacy leaks, one can not stay ignorant or risk falling victim. Always have more than one layer of security foe any website where you have your assets stored temporarily or permanently. And regular check the current state of your accounts.

Crypto-DesignService
Copper Member
Full Member
***
Offline Offline

Activity: 208
Merit: 256


View Profile WWW
February 04, 2019, 06:52:23 AM
 #17

You can check if your email and password is compromised.

Email: have i been pwned?
Password: Pwned Passwords
Pmalek
Legendary
*
Offline Offline

Activity: 2758
Merit: 7135



View Profile
February 04, 2019, 09:44:41 AM
 #18

Kudos to Pmalek for having post it first and letting everyone know about this 💪
Actually, I saw it in the German section and shared the info here. So credits should go to patrickrn32 for posting it in the German Local. This is the source where I saw it:
https://bitcointalk.org/index.php?topic=5098731.0

.
.BLACKJACK ♠ FUN.
█████████
██████████████
████████████
█████████████████
████████████████▄▄
░█████████████▀░▀▀
██████████████████
░██████████████
████████████████
░██████████████
████████████
███████████████░██
██████████
CRYPTO CASINO &
SPORTS BETTING
▄▄███████▄▄
▄███████████████▄
███████████████████
█████████████████████
███████████████████████
█████████████████████████
█████████████████████████
█████████████████████████
███████████████████████
█████████████████████
███████████████████
▀███████████████▀
█████████
.
r1s2g3
Sr. Member
****
Offline Offline

Activity: 742
Merit: 395


I am alive but in hibernation.


View Profile
February 04, 2019, 10:19:20 AM
 #19

I written in some other topic earlier too, best security is changing the password regularly. Even if your password is hacked you still be safe as your password is already changed.
Change the password of your email into the stronger one, using the combination of caps number and symbol, it would be more secure.

The problem with numbers, special symbols, uppercase letters and other techniques is that people strongly tend to do it in predictable way, like putting numbers in the end, capital letters at the beggining, etc. If you have a really short password that is based on some popular word, it might get cracked pretty fast, even if it has numbers and special symbols. Those types of passwords are usually very hard to remember, and you can get a lot of trouble if it's your main email with no methods of resetting your password. The better approach is to use very long passwords with normal words, if you don't use a password manager, or just random strings if you do.



I agree, more character is better.  Majority people have misconception that strong password are one that are difficult to remember but it is not the case.

I am alive
TheBeardedBaby
Legendary
*
Offline Offline

Activity: 2184
Merit: 3134


₿uy / $ell


View Profile
February 04, 2019, 10:41:53 AM
 #20

Change the password of your email into the stronger one, using the combination of caps number and symbol, it would be more secure.

The problem with numbers, special symbols, uppercase letters and other techniques is that people strongly tend to do it in predictable way, like putting numbers in the end, capital letters at the beggining, etc. If you have a really short password that is based on some popular word, it might get cracked pretty fast, even if it has numbers and special symbols. Those types of passwords are usually very hard to remember, and you can get a lot of trouble if it's your main email with no methods of resetting your password. The better approach is to use very long passwords with normal words, if you don't use a password manager, or just random strings if you do.



Damn, I start using this strategy for some years now and I even memorized my seed. (it was difficult job to keep the order) together with the Walled address.
Long ago I've reinstall my Windows XP so many times that even memorized the CD key and used it for some time as a password Cheesy
Used to mess around with IPv6 addresses so I manage to create a technique to memorize those addresses, i guess for the regular people this will difficulty.

Pages: [1] 2 »  All
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!