India’s cyber security agency CERT-In has issued a big warning, saying that more than 16 billion passwords have been leaked worldwide. This is considered one of the biggest data leak incidents ever and could affect millions of internet users in India, especially those who use Apple, Google, Facebook, Telegram, GitHub and VPN services.
According to CERT-In report, these leaked passwords have been collected from more than 30 data dumps, the main source of which are data-stealing malware that infects users’ computers or browsers. Misaligned databases, such as open Elasticsearch servers. The leak includes not only passwords, but also usernames and passwords, session cookies, authentication tokens, and account- metadata information.
• Why are these threats so serious?
Due to this data breach, CERT-In has predicted four major cyber threats:
Filling out the identity card: Hackers may try the same password on multiple sites.
Phishing and Social Engineering: Fake but credible scams can be carried out using leaked information.
account takeover: Hackers can gain complete control over your bank, social media or business account.
Business Fraud and Ransomware Attacks: Companies can be targeted and harassed.