Connect with us

Hi, what are you looking for?

OPINIONS

My data was leaked. What should I do?

Experts at Kaspersky Lab said numerous leaks have been appearing over the past few years and a lot more are expected to happen in the future.

Following the emergence last week of a massive database of exposed emails and passwords dubbed as Collection #1, Kaspersky Lab strongly urged internet users to apply unique passwords for each of their online accounts to minimize the chances of being affected by data breaches.

According to the global cybersecurity company, leaks and breaches happen quite often and sometimes these are huge in terms of risks and possible damages for account holders.

In the Philippines, over the weekend, financial services firm Cebuana Lhuillier confirmed that about 900,000 people were affected in a data breach involving their email server used for marketing purposes.

Malefactors collect the leaked information, creating databases with logins and passwords. Some of them try to add information from every leak to these databases, and that effort results in the creation of gigantic databases such as what www.troyhunt.com called Collection #1. This database contains more than 700 million unique email addresses and more than 1.1 billion unique login-password pairs from more than 2000 different leaks, some dating as far back as 2008 to most recent ones.

Advertisement. Scroll to continue reading.

Surprisingly, Collection #1 does not seem to include logins and passwords from well-known leaks such as LinkedIn’s in 2012 and both Yahoo breaches.

“This massive collection of data harvested through data breaches had been built up over a long period of time, so some of the account details are likely to be outdated now. However, it is no secret that despite growing awareness of the danger, people stick to the same passwords and even re-use them on multiple websites,” says Sergey Lozhkin, security expert at Kaspersky Lab.

“What’s more, this collection can be easily be turned into a single list of emails and passwords and then all that attackers need to do is to write a relatively simple software program to check if the passwords are working. The consequences of account access can range from very productive phishing, as criminals can automatically send malicious emails to a victim’s list of contacts, to targeted attacks designed to steal victims’ entire digital identity or money or to compromise their social media network data,”  he adds.

Experts at Kaspersky Lab said numerous leaks have been appearing over the past few years and a lot more are expected to happen in the future.

Lozhkin strongly recommends everyone who uses email credential for online activities to take the following steps as soon as possible:

Advertisement. Scroll to continue reading.

1. Use strong passwords for your most important or sensitive accounts (such as internet banking, online payment or social media networks) and change them regularly.

2. Use long and unique passwords for each and every account. This way, if a service is breached, you’ll need to change just one password.

3. Check if your email account has been exposed online by going to  https://haveibeenpwned.com/  Type-in the e-mail address that your accounts are associated with and you will find out if that address was included in any of the leaked databases that haveibeenpwned.com is aware of.

4. Enable two-factor authentication wherever it is possible. It will not allow hackers into your account even if they managed to obtain your login and password.

5. Use security solutions such as Kaspersky Security Cloud that can warn you about recent breaches.

Advertisement. Scroll to continue reading.

6. Consider switching to a password manager such as Kaspersky Password Manager that can help create many unique and strong passwords with no need to memorize them. Password managers can also help change the passwords faster whenever you need it.

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

Trend's 2025 predictions report warns of the potential for malicious "digital twins," where breached/leaked personal information (PII) is used to train an LLM to...

HEADLINES

The findings show that platform security – securing the hardware and firmware of PCs, laptops and printers – is often overlooked, weakening cybersecurity posture...

HEADLINES

In rigorous evaluations conducted by prestigious cybersecurity testing organizations, Kaspersky Plus (starting in Q4 2024, Kaspersky Premium), Kaspersky Endpoint Security for Business (KESB), and...

HEADLINES

"Given the Philippines' high exposure to cyber threats, it's important for both individuals and businesses to stay vigilant," said Adrian Hia, Managing Director for...

White Papers

When compared to 2023, Sophos saw a 51% increase in abusing “Living off the Land” binaries or LOLbins; since 2021, it’s increased by 83%.

HEADLINES

Someone illegally acquires or uses personal information such as bank account or credit card numbers of another person to obtain money, goods or services....

HEADLINES

To stay ahead of these challenges, organizations need to invest in AI-driven defenses, transition to quantum-safe encryption, and adopt a Zero Trust approach to...

HEADLINES

There was a 121% Year-on-Year (YoY) increase in identity fraud in 2024 across the region, with significant surges recorded in Singapore (207%), Thailand (206%)...

Advertisement