Research Team Analysis

WEEKLY REVIEW FROM THE BREACHAWARE RESEARCH TEAM
Share this analysis

53,569,722 leaked accounts discovered by the BreachAware® Research Team last week.

15 May 2022

A total of 11 breaches were found and analysed resulting in 53,569,722 leaked accounts containing a total of 19 different data types. The breaches found publicly and freely available included Acxiom, BizAway, Path 2 USA, Ebay and Channel Navigator. Sign in to view the full BreachAware Breach Index which includes, where available, reference articles relating to each breach.

COMMENTARY

A breach that caught our eye was a South African travel website. We're not sure how long the breach has been flying around. The passwords had already been de-hashed, resulting in a file with the email addresses and plain text passwords being dumped on an underground forum and quickly beginning to circulate. The breach consisted of 133,000 compromised credentials however this is a good example of how people use their work email address to book travel and holiday, as the number of companies caught up with this small breach was disproportionately high.

Other news, a ransomware gang had their own security breached when login details and an onion address for their affiliate site were posted on an underground forum. We’re not sure who was the original user, but after reading the thread, someone's in trouble. The login details gave access to the affiliate section of the site.

A proxy provider has experienced a large data breach, and section of their user-base has been exposed online with a sizeable amount of datasets. The website states they provide seven million different proxy's. Spooning through the data we’ve seen lot of emails with a list of IP address’s attached. This could be a gold mine for anyone conducting any OSINT work.

Another interesting set of data compromised came from an eBay store. Not a large number of compromised accounts but different data types compared to the last reported breach incident from 2014 where some 145 million user records were compromised.

And our week would not be complete without a bitcoin company's data being compromised. This time it was company called BitHoven with exposed email addresses and passwords. Other companies last week impacted were business intelligence, marketing (massive), education, IT, media and gaming companies/forums.

DATA CATEGORIES DISCOVERED

Contact Data, Financial Data, Usage Data, Socia-Demographic Data, Social Relationships Data, Locational Data, Technical Data, Behavioural Data.

  • Key Statistics
  • Breaches Discovered
    11
  • ACCOUNTS DISCOVERED
    53,569,722
  • DATA TYPES DISCOVERED
    19