Hacker Leaks Full Database Of 77 Million Nitro PDF User Records

Hacker Leaks Full Database Of 77 Million Nitro PDF User Records

A stolen database containing the email addresses, names, and passwords of more than 77 million records of Nitro PDF service users was leaked today for free.

The 14GB leaked database contains 77,159,696 records with users’ email addresses, full names, bcrypt hashed passwords, titles, company names, IP addresses, and other system-related information.

The database has also been added to the Have I Been Pwned service which allows users to check if their info has also been compromised in this data breach and leaked on the Internet.

Nitro is an application that helps create, edit, and sign PDFs and digital documents, an app that Nitro Software claims to have over 10,000 business customers and roughly 1.8 million licensed users.

Nitro also provides a cloud service that customers can use to share documents with coworkers or any other organizations involved in the document creation process.

Also Read: Going Beyond DPO Meaning: Ever Heard Of Outsourced DPO?

Nitro PDF user records’ contents

Nitro’s data breach

The massive Nitro PDF data breach BleepingComputer first reported last year also impacts many well-known organizations, including Google, Apple, Microsoft, Chase, and Citibank.

Nitro Software disclosed a “low impact security incident” on October 21, 2020, in an advisory to the Australia Stock Exchange, stating that no customer data was impacted.

However, as BleepingComputer later found, a database containing alleged info on 70 million Nitro PDF user records got auctioned together with 1TB of documents for a starting price set at $80,000.

BleepingComputer was able to determine the stolen database’s authenticity after confirming that known email addresses of Nitro accounts were present in the auctioned database.

Stolen user records leaked for free

Now, a threat actor claiming to be a part of ShinyHunters has leaked the full database for free on a hacker forum — the threat actor has set a price of $3 for access to the download link.

ShinyHunters is a notorious threat actor known for hacking online services and selling stolen information via data breach brokers or in private sales.

Previously, ShinyHunters said they were behind breaches at HomechefWattpadMintedTokopediaDavePromoChatbooksMathway, and many others; the information proved to be true.

Nitro PDF database leaked for free

As malicious actors can use the leaked user details to launch more credible phishing attacks or for credential stuffing, affected Nitro PDF users are strongly advised to change their passwords to a strong, unique password.

Also Read: Limiting Location Data Exposure: 8 Best Practices

Users should switch to a unique and strong password that they don’t use for any other website or online service.

Using a password manager is also recommended as it helps manage and generate unique and for different sites.

Privacy Ninja

Recent Posts

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications

Role of Enhanced Access Controls in Safeguarding Personal Data in Telecommunications that every Organisation in…

5 days ago

Role of Effective Incident Response Procedures in Strengthening Data Security

Effective Incident Response Procedures in Strengthening Data Security that every Organisation in Singapore should know…

6 days ago

Strengthening Your Cyber Defenses: The Crucial Role of Regular Vulnerability Scanning

Crucial Role of Regular Vulnerability Scanning that every Organisation in Singapore should know. Strengthening Your…

1 week ago

Enhancing Data Security with Multi-Factor Authentication

Enhancing Data Security with Multi-Factor Authentication that every Organisation in Singapore should know. Enhancing Data…

2 weeks ago

A Strong Password Policy: Your Organization’s First Line of Defense Against Data Breaches

Strong Password Policy as a first line of defense against data breaches for Organisations in…

2 weeks ago

Enhancing Website Security: The Importance of Efficient Access Controls

Importance of Efficient Access Controls that every Organisation in Singapore should take note of. Enhancing…

3 weeks ago