Skip to main content

A Paris-Based Researcher Spotted 711 million Email Accounts Lying In Plain Text Files On A Server Hosted In Netherlands


The researcher mentioned his findings in a blog post. The said server was used by a spambot known as ‘Onliner’. And the text files, amounting to 40+ GBs, also contain other details like passwords and details of the email servers used to send the spam.

It has been known that this massive “biggest of its kind” spamming campaign is a launch pad to spread a banking malware called Ursnif. As of now, more than 100,000 different infections have occurred, ZDNet reports.
It’s hard to point out the exact source from where the email accounts and data was collected. But, previous breaches like that of Linkedin did make a considerable contribution.
The unsorted list discovered by Benkow, analyzed by Troy Hunt, contained 80 million emails which were then used to send spams to another 630 million. The hackers used the SMTP servers and ports linked to these email accounts to spread the spam in a way that looks legitimate. In fact, the user credentials were verified against the SMTP servers; the one which didn’t authenticate were not used.
Online data dump 1
Image: List of data dump files.
Hunt operates the site Have I Been Pwned?. You can visit the same to know if your email is included in the breach. Hunt said that this is the “largest single set of data I’ve ever loaded into HIBP.”
“Just for a sense of scale, that’s almost one address for every single man, woman, and child in all of Europe.”
Also, a considerable number of entries from the email data was already present in HIBP’s existing database. In his blog post, Hunt says that the findings can be filtered into two categories:
  • Email addresses used to deliver the spams to.
  • Email addresses and passwords for which the hackers abused their SMTP server to deliver the spam.
There was one “uncomfortable truth” waiting for Hunt, his own email address was present in the list. Thankfully, I have not been pwned.
The irregular construct of the data, mainly sourced from the web, makes the 711 million figure “technically inaccurate” and he said the actual number of humans involved might be somewhat less.
Visit Have I Been Pwned to check your email. Read Hunt’s blog post for more details using this link.

Comments

Follow Us

WHAT'S HOT

Best Gaming Linux Distros You Need To Try In 2017

Gaming on Linux scene is improving each year with better hardware support and increasing support from game developers. Apart from established distros like Ubuntu and Arch Linux, gamers are using gaming Linux distros like Steam OS to get a better experience. The other It’s gaming operating systems are Sparky Linux – Gameover

Learn How To Activate iOS 11 Dark Mode

Apart from all the major iOS 11 features and changes, there are some hidden and minor features as well. In this release, Apple has included a feature named Smart Invert Colors, which is the closest you can get while looking for an iOS 11 dark mode.

Microsoft Set To Put Fingerprint Sensor In Keyboard Keys

According to a new patent titled “ Keyset Fingerprint Sensor ,” Microsoft might be working to integrate the fingerprint sensor in keyboard keys. The fingerprint recognition might be done

Latest Linux Distribution Releases List

This list is prepared with the inputs from different Linux distro developers and the official release notes. But, before going ahead and taking a look at latest releases, don’t forget to check out our useful lists of best Linux distros of 2017: Best Linux Distro For Beginners Best Linux Distro For Gamers Best Lightweight Linux Distros Best Operating Systems For Ethical Hacking Linux Distribution Releases (July 2017) Linux Mint 18.2 Release Date: July 2nd, 2017 You can read about Linux Mint 18.2 Sonya in detail  on 9jabreezeland . 4MLinux 22.0 Release Date: July 1st, 2017 4MLinux 22.0 is the latest stable release. It comes loaded with LibreOffice 5.4.0.1, GIMP 2.8.22, Dropbox 28.4.14, Firefox 54.0, Chromium 59.0.3071.86, etc. The biggest change comes with 4MLinux Server, which is a lightweight and fast server Linux distro. You can read more about 4MLinux 22.0  here . Netrunner 17.06 Release Date: July 1st, 2017 Netrunner 17.06, codenamed Daed...