Breaking
education newsA 42-year old Science and ICT tutor of the T I Ahamadiya Senior High School in K.. 11
politics newsJoe Biden just took the oath of office. He was sworn in by Chief Supreme Court J.. 54
extra newsTwitter has suspended President Donald Trump from its platform, the company said.. 46
extra newsFacebook CEO Mark Zuckerberg said in a post that the social media giant was bann.. 80
politics newsThis was after he beat Professor Aaron Mike Quaye, the Speaker of the Seventh Pa.. 75
politics newsNana Akufo-Addo took the Presidential Oath and the Oath of Allegiance administer.. 77
  • Photo Gallery
  • Contact us
  • Login
  • Covid19 Cases
  • Confirmed
  • Deaths
  • Recovered
  • Recovery(%)
Weather Ghana, °C
392 954 118 1.9k
Show Menu
  • Home
  • News
    • Financial
    • Business
    • Social
    • Extra
    • Politics
    • Health
    • Education
    • Opinion
    • Religion
    • Science
    • Technology
  • Sports
  • Entertainment
    • Music
    • Movie
    • Gossip
  • Institutions
  • Blogs
  • Classifieds
    • Events
    • Auto
    • Real Estate
    • Announcement
  • Lifestyle
    • Gadgets
    • Recipes
  • Ghana
    • eDocuments
  • Jobs
  • Contact us

Over 300,000 Spotify Accounts Compromised in Credential-Stuffing Attack

Alina Bizga 23 Nov 2020 97 news, technology

An Elasticsearch database with over 380 million records, including login credentials, was used to target Spotify accounts, according to vpn Mentor researchers.


An Elasticsearch database with over 380 million records, including login credentials, was used to target Spotify accounts, according to vpnMentor researchers.

Although the origin and owners of the leaked database are unknown, researchers speculate that hackers may have collected the data from previously breached platforms, and used it in credential-stuffing attacks against Spotify platform users.

“The incident didn’t originate from Spotify,” researchers said. “The exposed database belonged to a 3rd party that was using it to store Spotify login credentials. These credentials were most likely obtained illegally or potentially leaked from other sources that were repurposed for credential stuffing attacks against Spotify.”

The database contained over 72 GB of data, such as verified Spotify account usernames, passwords, email addresses, country of residence and, in some instances, IP addresses. However, the IP addresses are believed to have originated from “proxy servers belonging to the operators of the network on which the database was hosted.”

Researchers notified Spotify on July 9, which immediately prompted a mandatory password reset for all affected users.

“Working with Spotify, we confirmed that the database belonged to a group or individual using it to defraud Spotify and its users,” the report said. “We also helped the company isolate the issue and ensure its customers were safe from attack.”

Risks associated with the leak

As with any credential-stuffing attacks and data breaches, affected users should be wary of any phishing emails sent to trick them into exposing additional personal or financial information.

It’s also recommended to reset the passwords for all online accounts that shared the login credential combination with Spotify, to avoid account takeover, fraud, and identity theft. “Fraudsters could use the exposed emails and names from the leak to identify users across other platforms and social media accounts,” the researchers added. “With this information, they could build complex profiles of users worldwide and target them for numerous forms of financial fraud and identity theft.”






Source: Hot For Security



Prev article
Next article

0 Comments

view all comments

Related

technology news

Cybercriminals are using Google reCAPTCHA to hide their phishing attacks 397

technology news

WHO Admits to Leaked Credentials, Says Number of Cyberattacks Increased Fivefold 304

technology news

NASA has developed an experimental fully electric plane with 14 motors on its wings 42

technology news

Facebook is getting a major redesign, and you can switch to it right now 56

technology news

Renault unveils shapeshifting Morphoz concept car 292

Gadget Reviews

Bevy photo-sharing device 223

Gadget Votes: 1 |5 out of 5
1/7/2016

Samsung's Family Hub Fridge 263

Gadget Votes: 1 |5 out of 5
1/7/2016

oombrella 250

Gadget Votes: 1 |3 out of 5
1/29/2016
View more articles

Tag Cloud

social politics business opinion sports education health technology religion extra science Classifieds Jobs

Photo Gallery

Send Email

Write a Comment


Resident Manager

All Ghana Data, P. O. Box Ah 9182, Ahinsan, Ashanti, Ghana
+233 27 872 7027
i-desk@allghanadata.com

Popular Articles

Idris Elba almost died in Ghana466

27 Nov 2015

Lucky Dube’s Daughter To Rock Ghana1686

16 Nov 2011
View more articles

Popular Categories

  • news
  • institutions
  • entertainment
  • blogs
  • recipes
  • classifieds

Random Selfies Feed

View Gallery
  • Home
  • Privacy
  • Classifieds
  • Lifestyle
  • Jobs
  • Sitemap
  • Contact us

©Copyright 2002-2021 All Ghana Data All Rights Reserved | Powered by SASCMS