Frame-14

Privacy Ninja

        • DATA PROTECTION

        • CYBERSECURITY

        • Secure your network against various threat points. VA starts at only S$1,000, while VAPT starts at S$4,000. With Price Beat Guarantee!

        • API Penetration Testing
        • Enhance your digital security posture with our approach that identifies and addresses vulnerabilities within your API framework, ensuring robust protection against cyber threats targeting your digital interfaces.

        • On-Prem & Cloud Network Penetration Testing
        • Boost your network’s resilience with our assessment that uncovers security gaps, so you can strengthen your defences against sophisticated cyber threats targeting your network

        • Web Penetration Testing
        • Fortify your web presence with our specialised web app penetration testing service, designed to uncover and address vulnerabilities, ensuring your website stands resilient against online threats

        • Mobile Penetration Testing
        • Strengthen your mobile ecosystem’s resilience with our in-depth penetration testing service. From applications to underlying systems, we meticulously probe for vulnerabilities

        • Cyber Hygiene Training
        • Empower your team with essential cybersecurity knowledge, covering the latest vulnerabilities, best practices, and proactive defence strategies

        • Thick Client Penetration Testing
        • Elevate your application’s security with our thorough thick client penetration testing service. From standalone desktop applications to complex client-server systems, we meticulously probe for vulnerabilities to fortify your software against potential cyber threats.

        • Source Code Review
        • Ensure the integrity and security of your codebase with our comprehensive service, meticulously analysing code quality, identifying vulnerabilities, and optimising performance for various types of applications, scripts, plugins, and more

        • Email Spoofing Prevention
        • Check if your organisation’s email is vulnerable to hackers and put a stop to it. Receive your free test today!

        • Email Phishing Excercise
        • Strengthen your defense against email threats via simulated attacks that test and educate your team on spotting malicious emails, reducing breach risks and boosting security.

        • Cyber Essentials Bundle
        • Equip your organisation with essential cyber protection through our packages, featuring quarterly breached accounts monitoring, email phishing campaigns, cyber hygiene training, and more. LAUNCHING SOON.

Popular Stock Photo Service Hit By Data Breach, 8.3M Records For Sale

Popular Stock Photo Service Hit By Data Breach, 8.3M Records For Sale

Stock photo site 123RF has suffered a data breach after a hacker began selling a database containing 8.3 million user records on a hacker forum.

123RF is a popular stock photo and vector site that sells royalty-free images, videos, and audio to be used on websites, printed content, and videos. According to SimilarWeb, 123RF receives over 26 million visitors per month.

Over the past weekend, a known data breach broker began selling a database containing 8.3 million user records stolen from 123RF.com during a data breach.

Also Read: Limiting Location Data Exposure: 8 Best Practices

123RF database sold on a hacker forum
123RF database sold on a hacker forum

From the samples of the database seen by BleepingComputer, the stolen data includes a 123RF members’ full name, email address, MD5 hashed passwords, company name, phone number, address, PayPal email if used, and IP address. There is no financial information stored in the database.

Sample of the stolen 123RF user database
Sample of the stolen 123RF user database

123RF confirms data breach

After emailing 123RF earlier this week, BleepingComputer received an email from Inmagine Group, the owner of 123RF, stating that a server located at their data center was breached and the hackers “proceeded to copy the membership data.”

Based on the site of the sold database, Inmagine Group states that the database is likely outdated and is not the latest version from 2020. In the samples seen by BleepingComputer, the newest record date is from October 27th, 2019.

While the company states that the passwords are encrypted, the passwords are MD5 hashes. Unfortunately, using online MD5 cracking tools, BleepingComputer could easily retrieve the plain-text passwords for numerous accounts.

Inmagine Group states that they are working with law enforcement and have begun notifying affected 123RF members.

Also Read: 10 Practical Benefits of Managed IT Services

“We are actively notifying the necessary authorities and 123RF.com members to work with them to remedy the situation. We are also tightening the security policies to include tighter passwords and IP detection to combat suspicious log-ins.”

“Our security infrastructure is always under a constant state of security testing, penetration and development, especially in the past year.”

“We wish to reiterate that we take the privacy and data of our customers seriously and have at all times been vigilant with the handling of our customer’s data,” Inmagine Group shared with BleepingComputer.

What 123RF customers should do

While the passwords leaked in this data breach were hashed, as explained, it is possible to crack the stolen passwords using brute force tools, word lists, and even online dehashing sites.

After a user’s password is cracked, threat actors would be able to use them to log in to other sites you may have an account.

Therefore, if you are a 123RF customer, you should immediately change your password to a strong and unique one.

If that same password was used at another site, you should change it at any other site that also uses it.

When changing your passwords, be sure to use a unique and strong password at every site so that a data breach does not affect your account at other companies.

A password manager can make it much easier to use unique passwords at every site and is highly recommended.

0 Comments

KEEP IN TOUCH

Subscribe to our mailing list to get free tips on Data Protection and Data Privacy updates weekly!

Personal Data Protection

REPORTING DATA BREACH TO PDPC?

We have assisted numerous companies to prepare proper and accurate reports to PDPC to minimise financial penalties.
×

Hello!

Click one of our contacts below to chat on WhatsApp

× Chat with us