Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search

dixiegrrrrl

(60,010 posts)
Thu Jan 17, 2019, 06:12 PM Jan 2019

Massive 'Collection #1' breach hits 773 million email accounts


Here is where you might be able to check to see if you are on the list of accounts:
https://haveibeenpwned.com/

Here is list of sites that were affected:
https://pastebin.com/UsxU4gXA

Here is story of it:

It may be the biggest dump of personal login credentials in history, affecting some 773 million unique accounts.

Cybersecurity researcher Troy Hunt revealed today in a blog post that the massive collection of login information appeared last week on the cloud sharing service MEGA. Hunt runs the website Have I Been Pwned, a database of breaches where anyone can see if their information has been exposed in this dump or others.

Cybersecurity experts have called the database among the largest collections of usernames and passwords yet, more than twice the size of the recent Marriott breach. Dubbed "Collection #1," the dump includes information from thousands of websites —
t’s still unknown who collected the information or where the breach originated. The information appears to come from a random assortment of sites, ranging from botanyconference.org to organic.org.
https://www.politico.com/story/2019/01/17/collection-breach-email-accounts-1108851
7 replies = new reply since forum marked as read
Highlight: NoneDon't highlight anything 5 newestHighlight 5 most recent replies
Massive 'Collection #1' breach hits 773 million email accounts (Original Post) dixiegrrrrl Jan 2019 OP
Good time to remember to change your passwords Midnightwalk Jan 2019 #1
Thanks for this. Qutzupalotl Jan 2019 #4
I would not follow a link like that Midnightwalk Jan 2019 #5
So what does it mean it it shows "pwned" but "not pasted"? hlthe2b Jan 2019 #2
That's what mine said. Kittycow Jan 2019 #3
What is a "paste" and why include it on this site? Celerity Jan 2019 #6
I don't know...sorry. n/t dixiegrrrrl Jan 2019 #7

Midnightwalk

(3,131 posts)
1. Good time to remember to change your passwords
Thu Jan 17, 2019, 06:29 PM
Jan 2019

Use non-trivial but easy to remember passwords. Dupassw0rd sucks. K1ssmywh@t is better. 1haveredfle@s is good

Change your passwords periodically.

Use different passwords for each site as much as you can.

Your email password should be different than any other. I don’t care if i forget the password to something i use once a year, but the way you reset passwords often uses an email exchange. Your email password can unlock your other ones.

Lecture over. Behave.

Midnightwalk

(3,131 posts)
5. I would not follow a link like that
Fri Jan 18, 2019, 12:01 AM
Jan 2019

I should have thought of saying that. I just remembered i didn’t change my email password since and changed it. I haven’t seen any other account notifications in texts or email. I also enable 2 tiered authentication where you get a text with a number you have to enter on the “reset your password “ link you get in your email wherever i can.

You can hover over a link and see where it really goes (it doesn’t necessarily match the blue text$. Never give a site you don’t recognize personal information like your email address I don’t recognize those sites so i would have not gone there if it even crossed my mind

The other thing I should have said is never put personal information in your password. I don’t have red fleas so that is a good phrase for me. Iseeoinkelephants” might not be

Edit: I don’t know how to the hover trick on my phone.

Celerity

(43,130 posts)
6. What is a "paste" and why include it on this site?
Fri Jan 18, 2019, 12:14 AM
Jan 2019

A "paste" is information that has been "pasted" to a publicly facing website designed to share content such as Pastebin. These services are favoured by hackers due to the ease of anonymously sharing information and they're frequently the first place a breach appears.

HIBP searches through pastes that are broadcast by the @dumpmon Twitter account and reported as having emails that are a potential indicator of a breach. Finding an email address in a paste does not immediately mean it has been disclosed as the result of a breach. Review the paste and determine if your account has been compromised then take appropriate action such as changing passwords.

Latest Discussions»General Discussion»Massive 'Collection #1' b...