FTSE 100 Credentials Stolen, Nearly Half A Million Now For Sale

Date:

Share post:

It’s never good to read about compromised passwords, whether they are included in a newly published and easily searchable list, an analysis of 800 million stolen credentials, or trawls of the dark web revealing exactly which passwords have been exfiltrated. But when an article, this article in fact, concerns almost half a million stolen credentials that belong to employees of FTSE 100 companies, then your business had better pay attention. And quickly. Here’s what you need to know and do.

ForbesHe Hacked Biden, Obama And Musk. Now He’s Lost $4 Million Bitcoin

‘FTSE 100 For Sale’ Report Reveals 460,000 Stolen Credentials On The Dark Web

Your business is not as secure as you might think. That’s the takeaway from a new report, a result of a research collaboration between analysts at Socura and Flare, which has revealed what it called “the alarming scale of stolen employee credentials” across FTSE 100 companies.

The FTSE 100 For Sale report found more than 460,000 stolen credentials associated with FTSE 100 companies form sale on the dark web, and even available on the surface web that anyone can access. “The FTSE 100 includes some of the largest and most trusted brands in the UK”, Andy Kays, the Socura CEO, warned, adding that they still struggle with “the same core cyber security concerns as other businesses.” In particular, Kays pointed out, the rise in infostealer malware that has resulted in credential theft on an industrial scale.

ForbesLogitech Data Breach — What We Know As 0-Day Hack Attack Confirmed

Key Findings From The FTSE 100 For Sale Report

I would heartily recommend that every board member, every executive, every employee, and not only those in FTSE 100 companies, read the full report. Read it, absorb what it says, and heed the warnings it presents. The key takeaways, however, can be summarized as follows:

  • 15 FTSE companies have more than 10,000 instances of stolen credentials available online.
  • One company has over 45,000 instances.
  • 8,000 instances of corporate credentials from FTSE 100 businesses were leaked via infostealer logs.
  • 59% of FTSE 100 companies have at least one employee using ‘password’ as a password.

Anne Heim, the threat intelligence lead at Socura, reiterated the warnings by telling me that most cybercriminals “won’t waste precious time hacking for credentials when they can easily find or buy them online.” As such, companies should implement multi-factor authentication, use passkeys where available, and monitor for potential threat exposure in new data leaks.

I have reached out to the London Stock Exchange Group for any additional advice it can offer to FTSE 100 companies and will update this article with anything that becomes available.

ForbesAmazon CISO Confirms Hacker Exploit Used 2 Zero-Day Attacks

Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Related articles

Why Apple TV’s ‘Severance’ Is The Only Return-To-Office Employees Want

Apple TV's 'Severance' Season 3 is eagerly awaited. Courtesy of Apple TVBen Stiller recently announced the start of...

Nara Smith’s ‘Tradwife’ Controversy, Explained

Nara Smith pushes back against the 'tradwife' label.(Photo by Daniele Venturelli/Getty Images for Valentino)Getty Images for ValentinoNara Smith...

Today’s Wordle #1869 Hints, Clues And Bonus Wordle, Saturday August 1

How to solve today's Wordle.SOPA Images/LightRocket via Getty ImagesLooking for help with today’s Wordle? In this guide, we...

Today’s Wordle #1869 Answer, Wordle Bot And Explanation, Saturday August 1

How to solve today's Wordle.SOPA Images/LightRocket via Getty ImagesIf you’re looking for clues and hints to help you...