Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • Networking

    Cyber-Attacker Dumps Log-ins for 20,000 Customers, U.S. Employees

    Written by

    Fahmida Y. Rashid
    Published August 24, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      A solo attacker has hacked into an events management company and obtained sensitive information belonging to 20,000 individuals, many of whom were United States government employees or contractors.

      The cyber-attacker posted an Excel spreadsheet containing log-in credentials and personal information for 20,000 people obtained from allianceforbiz.com, according to a blog post signed by “Thehacker12” on Aug. 22. Allianceforbiz.com is a professional trade show management company that manages conferences, meetings and trade shows for customers, according to the company Website.

      The list has been made public on Pastebin and Mediafire and a message posted on Twitter: “20,000 email-passwords had been leaked consisting mostly of US Mill Army, Govern. & corporate giants.”

      The spreadsheet contains usernames, passwords, email addresses. company name, and also whether the individual works for a government agency, Catalin Cosoi, head of Bitdefender Online Threats Lab, told eWEEK. Identity Finder, a data loss prevention software vendor, ran the file through its software and found 13,322 passwords and 17,590 email addresses in the file. Only 11,358 of the passwords had a username associated with them, Todd Feinman, CEO of Identity Finder, told eWEEK.

      The file also contained 17,668 company names, of which 14,739 were unique, and most had only one email address associated with each name, according to the analysis. This means more than 14,000 organizations may be affected by Thehacker12’s breach of allianceforbiz.com.

      Since allianceforbiz.com managed events for customers, it is likely that the list contained the person in each organization who was working directly with the provider. However, there were some organizations with 10 or more email addresses associated with the name, Identity Finder found in its analysis.

      “Interesting to note most of these are government entities,” Feinman said.

      The U.S. Small Business Administration had 70 entries, followed by 42 from the U.S. General Services Administration, 37 from the U.S. Department of Commerce, 34 from the U.S. General Services Administration and 33 from the U.S. Department of State. Other affected organizations include the Federal Aviation Administration, U.S. Army Corps of Engineers, national nonprofit agency NISH, U.S. Department of Housing & Urban Development, U.S. Environmental Protection Agency and the VA Medical Center. Defense and government contractors Honeywell, BAE Systems, WP Hickman Systems and CH2m Hill were also on the list.

      Considering the high incidence of password reuse by Internet users, it is possible that the information could lead to identity fraud, said Identity Finder’s Feinman. “Passwords are a digital identity,” and the victims will not know if an identity thief is testing out username or email address and password combinations to try to login to the online bank, online retailers or other services, Feinman said.

      Bitdefender’s Cosoi noted that most of the email addresses on the list are work accounts, which means a malicious third party now has login credentials that may work when trying to breach one of the affected organizations’ network and systems or the corporate email server. This level of access can “lead to blackmail, extortion or selling private data to third parties” or targeted emails sent to other employees within the organization from the victims’ accounts, he said.

      Noting the “significant number of government agencies” in the leaked file, “we can conclude that this data leak will have serious unpleasant consequences,” Cosoi said.

      Identity Finder’s software allows organizations to prevent identity theft and data leakage by searching and securing sensitive data that could be used to commit identity fraud. The software can look at both structured and unstructured data and find instances where sensitive information such as Social Security numbers or credit card information are stored. With the software, organizations can identify all the places where the information is located and protect them accordingly.

      The perpetrator claims to be “an AntiSec supporter” but not a member of the hackers collective Anonymous. AntiSec is a movement initially launched by the cyber-group LulzSec earlier this summer to hack into government systems and expose secrets and documents. Anonymous has recently breached a number of defense contractor and law enforcement Websites under the AntiSec banner.

      “His or her deeds actually support the same side of the story, which is hacking for the sake of publicly making an anti-establishment point,” said Cosoi. Both the media and law enforcement authorities are focused on Anonymous and LulzSec, leaving the “door open to other small groups to make a stand and show their skills” and continue the AntiSec activities without drawing too much attention, Cosoi said.

      Thehacker12 has been busy over the past week, mining and dumping three other files containing a total of 16,500 other email and password combinations stolen from unknown targets. His method of attack remains unclear.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.