Menu
A hacker is selling 167 million LinkedIn user records

A hacker is selling 167 million LinkedIn user records

The data includes hashed passwords for 117 million accounts and likely dates back to 2012

A hacker is trying to sell a database dump containing account records for 167 million LinkedIn users.

The announcement was posted on a dark market website called TheRealDeal by a user who wants 5 bitcoins, or around $2,200, for the data set that supposedly contains user IDs, email addresses and SHA1 password hashes for 167,370,940 users.

According to the sale ad, the dump does not cover LinkedIn's complete database. Indeed, LinkedIn claims on its website to have over 433 million registered members.

Troy Hunt, the creator of Have I been pwned?, a website that lets users check if they were affected by known data breaches, thinks that it's highly likely for the leak to be legitimate. He had access to around 1 million records from the data set.

"I've seen a subset of the data and verified that it's legit," Hunt said via email.

linkedin leak sale data breach Lucian Constantin

A hacker is selling 167 million stolen LinkedIn account records on a dark market website.

LinkedIn suffered a data breach back in 2012, which resulted in 6.5 million user records and password hashes being posted online. It's highly possible that the 2012 breach was actually larger than previously thought and that the rest of the stolen data is surfacing now.

LinkedIn did not immediately respond to a request for comment.

Attempts to contact the seller failed, but the administrators of LeakedSource, a data leak indexing website, claim to also have a copy of the data set and they believe that the records do originate from the 2012 LinkedIn breach.

"Passwords were stored in SHA1 with no salting," the LeakedSource administrators said in a blog post. "This is not what internet standards propose. Only 117m accounts have passwords and we suspect the remaining users registered using FaceBook or some similarity."

Best security practices call for passwords to be stored in hashed form inside databases. Hashing is a one-way operation that generates unique, verifiable cryptographic representations of a string that are called hashes.

Hashing is useful for validating passwords, because running a password through the same hashing process should always result in the same hash, allowing its comparison with one previously stored in a database.

Converting a hash back into the original password should be impossible, which is why it's safer to store hashes instead of plain text passwords. However, there are old hashing functions, such as MD5 and SHA1, that are vulnerable to various cracking techniques and should no longer be used.

When the 6.5 million LinkedIn password hashes were leaked in 2012, hackers managed to crack over 60 percent of them. The same thing is likely true for the new 117 million hashes, so they cannot be considered safe.

Worse still, it's very likely that many LinkedIn users that were affected by this leak haven't changed their passwords since 2012. Hunt was able to verify that for at least one HIBP subscriber whose email address and password hash was in the new data set that is now up for sale.

Many people affected by this breach are also likely to have reused their passwords in multiple places on the Web, Hunt said via email.

LinkedIn users who haven't changed their passwords in a long time, are advised to do so as soon as possible. Turning on LinkedIn's two-step verification is also recommended. If the LinkedIn password has been used on other websites, it should be changed there as well.


Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Tags securityhacking

Featured

Slideshows

Sizing up the NZ security spectrum - Where's the channel sweet spot?

Sizing up the NZ security spectrum - Where's the channel sweet spot?

From new extortion schemes, outside threats and rising cyber attacks, the art of securing the enterprise has seldom been so complex or challenging. With distance no longer a viable defence, Kiwi businesses are fighting to stay ahead of the security curve. In total, 28 per cent of local businesses faced a cyber attack last year, with the number in New Zealand set to rise in 2017. Yet amidst the sensationalism, media headlines and ongoing high profile breaches, confusion floods the channel, as partners seek strategic methods to combat rising sophistication from attackers. In sizing up the security spectrum, this Reseller News roundtable - in association with F5 Networks, Kaspersky Lab, Tech Data, Sophos and SonicWall - assessed where the channel sweet spot is within the New Zealand channel. Photos by Maria Stefina.

Sizing up the NZ security spectrum - Where's the channel sweet spot?
Kiwi channel comes together for another round of After Hours

Kiwi channel comes together for another round of After Hours

The channel came together for another round of After Hours, with a bumper crowd of distributors, vendors and partners descending on The Jefferson in Auckland. Photos by Maria Stefina.​

Kiwi channel comes together for another round of After Hours
Consegna comes to town with AWS cloud offerings launch in Auckland

Consegna comes to town with AWS cloud offerings launch in Auckland

Emerging start-up Consegna has officially launched its cloud offerings in the New Zealand market, through a kick-off event held at Seafarers Building in Auckland.​ Founded in June 2016, the Auckland-based business is backed by AWS and supported by a global team of cloud specialists, leveraging global managed services partnerships with Rackspace locally.

Consegna comes to town with AWS cloud offerings launch in Auckland
Show Comments