News

167 Million LinkedIn User Records For Sale by Hacker

On the dark web, a hacker has come out to be selling the account details of 167 million users of the professional social networking site LinkedIn. The hacker announced his desire to sell these user records on dark website TheRealDeal, requesting a sum of 5 bitcoins, or around $2200, for the stolen data set which is thought to contain user IDs, email addresses, and SHA1 encoded passwords for a total of 167,370,940 users.

The records that are up for sale are far from complete, though it does represent around a third of LinkedIn’s 433 million registered members, which is a significant proportion. Troy Hunt, stated via email that “I’ve seen a subset of the data and verified that it’s legit.” Hunt is the creator and owner of the site Have I been pwned? which is dedicated to allowing users to check if they have been affected by any known data leaks or breaches, which should lend a lot of credibility to his assessment.

Currently, it is thought that this data could be related to the data breach that LinkedIn suffered back in 2012, which leaked the records of only 6.5 million users by comparison. This could mean that the 2012 breach was far larger than it was previously believed to be, with the remainder of the leaked data only surfacing now. Another site, LeakedSource, which is dedicated to indexing leaked data, claims to have a copy of the data set that is up for sale and hold the belief that the records originate from the 2012 breach.

This breach also raises some questions about LinkedIn’s data security practices as LeakedSouce went on to state that the passwords were stored in SHA1 with no salting, which is against best practice for storing user details online. As over 60% of the passwords of the 6 million leaked back in 2012 were able to be cracked by hackers, it is worrying to think that the same could be expected of this far larger data set and represents a real threat to users who may not have changed their account passwords since 2012 or even reused the same email and password combination across multiple sites.

LinkedIn is yet to comment on the break, however, it is recommended that any users of the site make sure to change their password and that of any other site with the same credentials.

Alexander Neil

Disqus Comments Loading...

Recent Posts

Electronic Arts Titles Played for Over 11 Billion Hours in 2024

Electronic Arts (EA) announced today that its games were played for over 11 billion hours…

7 days ago

Just 15% of Steam Gaming Time in 2024 Was Spent on New Releases

Steam's annual end-of-year recap, Steam Replay, provides fascinating insights into gamer habits by comparing individual…

7 days ago

STALKER 2 Gets Massive 110GB Patch With 1800+ Fixes

GSC GameWorld released a major title update for STALKER 2 this seeking, bringing the game…

1 week ago

Intel Unveils Core 200H Processors Based on the Previous Raptor Lake Refresh

Without any formal announcement, Intel appears to have revealed its new Core 200H series processors…

1 week ago

Ubisoft Reportedly Developing a New Quadruple A Game

Ubisoft is not having the best of times, but despite recent flops, the company still…

1 week ago

STALKER 2: Heart of Chornobyl Update 1.1 Fixes 1,800 Issues and Revamps A-Life 2.0

If you haven’t started playing STALKER 2: Heart of Chornobyl yet, now might be the…

1 week ago