Research Team Analysis

WEEKLY REVIEW FROM THE BREACHAWARE RESEARCH TEAM
Share this analysis

15,278,874 leaked accounts discovered by the BreachAware® Research Team last week.

17 April 2022

A total of 12 breaches were found and analysed resulting in 15,278,874 leaked accounts containing a total of 12 different data types. The breaches found publicly and freely available included Hurb, Fraud Watch International, Bahigo, HighExp and Curtea Veche. Sign in to view the full BreachAware Breach Index which includes, where available, reference articles relating to each breach.

COMMENTARY

Straight into what 'The Researchers' have quoted as 'the leak of the week' is the French health insurance company, EMOA Mutuelle du Var. Data associated with the health industry is always rich in data types. Typically with an insurance company, you would see date of birth, full name, account information, physical address, phone number but with this set of data we saw device information, username and IP addresses. Email address and passwords is a given. This breach has not been verified or acknowledged.

A question a team member asked, when is a breach worth recording? Even though the data recorded for the insurance company only amounted to 2.4mb of plain text data, any publicly available data needs to be assessed for risk management purposes, whether to the individual, the impact to the organisation and of course the supply chain.

The most notable breach the researchers identified is FraudWatch, an established threat hunting, intelligence and detection service. It is understood from the forums, FraudWatch took it upon themselves to annoy a well-known and well skilled threat actor. After engaging with said person online, they quickly became the victim of a security breach involving a range of their clients' personal information leaked with a promise of more to come. This incident proves that everyone is vulnerable, even those who are well established in the industry.

Moving on, a Turkish gambling site took a battering after suffering a data breach, The national identity card numbers were among some of the credentials which were included in this leak. We did note that the betting company HQ is in the Isle of Man, UK, where they have seen an increase a 30% increase gambling licenses for companies issued due to as quoted by the Isle of Man authorities, "proposed changes to regulation and structure in some jurisdictions."

DATA CATEGORIES DISCOVERED

Technical Data, Contact Data, Usage Data, Locational Data, Socia-Demographic Data, National Identifiers.

  • Key Statistics
  • Breaches Discovered
    12
  • ACCOUNTS DISCOVERED
    15,278,874
  • DATA TYPES DISCOVERED
    12