The State of Data Breaches

Presently sponsored by: Push Security. Stop identity attacks with a browser-based agent that detects and prevents account takeover. Try it free now.

I’ve been harbouring some thoughts about the state of data breaches over recent months, and I feel they’ve finally manifested themselves into a cohesive enough story to write down. Parts of this story relate to very sensitive incidents and parts to criminal activity, not just on

Continue reading The State of Data Breaches

Telegram Combolists and 361M Email Addresses

Presently sponsored by: 1Password Extended Access Management: Secure every sign-in for every app on every device.

Last week, a security researcher sent me 122GB of data scraped out of thousands of Telegram channels. It contained 1.7k files with 2B lines and 361M unique email addresses of which 151M had never been seen in HIBP before. Alongside those addresses were passwords and, in many cases, the

Continue reading Telegram Combolists and 361M Email Addresses

Operation Endgame

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Today we loaded 16.5M email addresses and 13.5M unique passwords provided by law enforcement agencies into Have I Been Pwned (HIBP) following botnet takedowns in a campaign they’ve coined Operation Endgame. That link provides an excellent overview so start there then come back to this blog

Continue reading Operation Endgame

Weekly Update 401

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

Ah, episode 401, the unauthorised one! Ok, that was terrible, but what’s not terrible is finally getting some serious dev resources behind HIBP. I touch on it in the blog post but imagine all the different stuff I have to spread myself across to run this thing, and

Continue reading Weekly Update 401

Have I Been Pwned Employee 1.0: Stefán Jökull Sigurðarson

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

We often do that in this industry, the whole “1.0” thing, but it seems apt here. I started Have I Been Pwned (HIBP) in 2013 as a pet project that scratched an itch, so I never really thought of myself as an “employee”. Over time,

Continue reading Have I Been Pwned Employee 1.0: Stefán Jökull Sigurðarson

Weekly Update 400

Presently sponsored by: Kolide is an endpoint security solution for teams that want to meet SOC2 compliance goals without sacrificing privacy. Learn more here.

This is the 400th time I’ve sat down in front of the camera and done one of these videos. Every single week since the 23rd of September in 2016 regardless of location, health, stress and all sorts of other crazy things that have gone on in my life

Continue reading Weekly Update 400

Weekly Update 399

Presently sponsored by: Kolide believes that maintaining endpoint security shouldn’t mean compromising employee privacy. Check out our manifesto: Honest Security.

The Post Millennial breach in this week’s video is an interesting one, most notably because of the presence of the mailing lists. Now, as I’ve said in every piece of communication I’ve put out on this incident, the lists are what whoever defaced the

Continue reading Weekly Update 399

Weekly Update 398

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

How many different angles can you have on one data breach? Facial recognition (which probably isn’t actual biometrics), gambling, offshore developers, unpaid bills, extortion, sloppy password practices and now, an arrest. On pondering it more after today’s livestream, it’s the unfathomable stupidity of publishing

Continue reading Weekly Update 398