Author

Topic: 5 million google accounts leaked (Read 5630 times)

hero member
Activity: 544
Merit: 500
September 12, 2014, 12:26:36 AM
#16
For a moment there i thought my wallet could have been compromised. Two factor authentication for ya!  Roll Eyes
sr. member
Activity: 308
Merit: 250
September 11, 2014, 10:17:30 PM
#15
That's the one without the passwords.
My account is in the list, but it would be interesting to see if it was really compromised, or if the list is just a net-scrub of publicly-available email addresses...
Anyway, 2-factor is the thing.  Cool
You can ask tvskit(https://bitcointalksearch.org/user/tvskit-163342)
what the password was in database for your email. (He deleted passwords that hackers do not use this database)

I did so. He gave me a two letters from the start and end of the password - enough for me to see that it's my old password that I changed about 3 years ago (+-1 year). So the list seems to be valid, but dated. That password wasn't used anywhere else, so it definitely came from Google.
I think the list of passwords were likely sold many times on the darknet and eventually when the list had no more value it was published on the "internet". The hacker that got into satoshi's email address claimed that his information was being sold on the darknet.
legendary
Activity: 952
Merit: 1005
--Signature Designs-- http://bit.ly/1Pjbx77
legendary
Activity: 1680
Merit: 1014
September 10, 2014, 09:04:42 AM
#13
That's the one without the passwords.
My account is in the list, but it would be interesting to see if it was really compromised, or if the list is just a net-scrub of publicly-available email addresses...
Anyway, 2-factor is the thing.  Cool
You can ask tvskit(https://bitcointalksearch.org/user/tvskit-163342)
what the password was in database for your email. (He deleted passwords that hackers do not use this database)

I did so. He gave me a two letters from the start and end of the password - enough for me to see that it's my old password that I changed about 3 years ago (+-1 year). So the list seems to be valid, but dated. That password wasn't used anywhere else, so it definitely came from Google.
hero member
Activity: 826
Merit: 504
September 10, 2014, 05:05:36 AM
#12
Probably a bot that made five million Google accounts, or some bored kid who hired his friends to do it over the summer.
legendary
Activity: 1400
Merit: 1000
September 10, 2014, 04:49:36 AM
#11
That's the one without the passwords.
My account is in the list, but it would be interesting to see if it was really compromised, or if the list is just a net-scrub of publicly-available email addresses...
Anyway, 2-factor is the thing.  Cool
You can ask tvskit(https://bitcointalksearch.org/user/tvskit-163342)
what the password was in database for your email. (He deleted passwords that hackers do not use this database)
legendary
Activity: 1267
Merit: 1000
legendary
Activity: 1540
Merit: 1000
September 10, 2014, 04:38:33 AM
#9
This is why you always use disposable email addresses when conversing with people publicly and have entirely separate and different passwords on your financial and personal addresses.
hero member
Activity: 672
Merit: 502
September 10, 2014, 03:39:05 AM
#8
I have 2fa enabled as well but I think it would be a good idea to change password now just to be on the safer side.
legendary
Activity: 1680
Merit: 1014
September 10, 2014, 03:25:13 AM
#7
That's the one without the passwords.
My account is in the list, but it would be interesting to see if it was really compromised, or if the list is just a net-scrub of publicly-available email addresses...
Anyway, 2-factor is the thing.  Cool
hero member
Activity: 1005
Merit: 500
September 10, 2014, 03:09:47 AM
#5
In the web published database with addresses and passwords to 4,930,000 mailboxes GMail. According to forum user Bitcoin Sesurity tvskit, first saying about the appearance of this database, more than 60% of couples login and password in the file are valid.
A cursory examination of the file with compromised records showed that it soedrzhatsya logins as the Russian-speaking and English-and Spanish-speaking users of the mail service Google. In addition to logins GMail database contains several thousand addresses of "Yandex".
GMail mailbox names and passwords to them can serve as a login and password to access not only to the post but to all services of Google.
Currently, the Bitcoin forum Sesurity available purified version of the password text file containing 4,930,000 accounts GMail.
The representative of the Russian office of Google Svetlana Anurova to which CNews asked to comment on the incident, told CNews, that "experts now understand what happened in this case," and advised users to "select strong passwords and be sure to use a two-step authentication." She recalled that Google is constantly developing new levels of security to protect user accounts and encrypts the information flow
legendary
Activity: 3108
Merit: 1359
September 10, 2014, 02:59:14 AM
#4
It worked 10-20 minutes ago, but now seems too busy with requests, 502 and 503 errors there. Roll Eyes

I'll soon try upload this file to my google drive.
legendary
Activity: 952
Merit: 1005
--Signature Designs-- http://bit.ly/1Pjbx77
September 10, 2014, 02:57:09 AM
#3
And the russian forum is down or too busy. Can't verify whether this file does contain a database of username and passwords. I am worried my username is in there  Sad
hero member
Activity: 544
Merit: 500
September 10, 2014, 02:53:54 AM
#2
A database of what appears to be some 5 million login and password pairs for Google accounts has been leaked to a Russian cyber security internet forum. It follows similar leaks of account data for popular Russian web services.

The text file containing the alleged compromised accounts data was published late on Tuesday on the Bitcoin Security board. It lists 4.93 million entries, although the forum administration has since purged passwords from it, leaving only the logins.

The accounts are mostly those of Google users and give access to Gmail mail service, G+ social network and other products of the US-based internet giant. The forum user tvskit, who published the file, claimed that 60 percent of the passwords were valid, with some users confirming that they found their data in the base, reports CNews, a popular Russian IT news website.

Google Russia said it is investigating the alleged leak, adding that it advises customers to use strong passwords and enable two-step login verification to protect their accounts.

The leak comes just days after similar leaks affected Mail.ru and Yandex, both popular Russian internet services. The previous leaks contained 4.66 and 1.26 million accounts respectively.

Both companies said that an overwhelming majority of the accounts listed were either obsolete, suspended for suspicious behavior or non-existent. They insisted that their own databases were not compromised and suggested that the leaked data was accumulated over years through phishing and other forms of hacking attacks on users.

Here's the news for those too lazy to click the link xD
legendary
Activity: 3108
Merit: 1359
September 10, 2014, 02:43:12 AM
#1
http://rt.com/news/186580-millions-google-accounts-leaked/

List file size is 28.7 MB, downloading it now Roll Eyes
Jump to: