Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Wednesday, 3 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

MySpace breach could be the biggest ever – half a BILLION passwords!

by The Gurus
June 2, 2016
in This Week's Gurus
Share on FacebookShare on Twitter

 
Not two weeks ago, LinkedIn made big data breach news when hackers claimed to have more than 100 million usernames and passwords up for sale.
Fortunately, the data wasn’t new, coming from a breach that happened four years ago.
What was new was the size of the list that was up for sale, nearly 20 times the size of the 6.5 million passwords that were reported to have been stolen back in June 2012.
The LinkedIn breach was made worse by the way the passwords were stored, using unsalted SHA-1 hashes.
What that means is that although LinkedIn didn’t keep your actual password, it didn’t do enough to secure it against a breach.
Not tough enough
LinkedIn simply computed a SHA-1 cryptographic hash of your password and stored the hash instead, so that anyone who chose PASSWORD, for example, would end up with a hash of 112b b791 3047 91dd cf69 2e29 fd5c f149 b35f ea37.
Even though attackers can’t use a mathematical algorithm to go backwards automatically from a hash to its input value, they can go forwards at enormous speed, trying out passwords from a huge list by churning out their hashes one after the other.
Modestly-priced cracking servers (modest for nation-states and cybercriminal gangs, at least) can process hundreds of thousands of millions of SHA-1 calculations per second.
That’s fast enough to try out all possible 10-character upper case passwords in well under an hour.
Also, modern password cracking software doesn’t blindly go from AAAAA­AAAAA to ZZZZZ­ZZZZZ, but knows that PASSWORD is more likely than OSTEOPATH, which is in turn more likely than VNNQM­VHZJL.
Current best practice is to “stretch” each password before storing it by hashing it repeatedly, typically thousands or tens of thousands of times, so that any sort of try ’em all attack takes correspondingly longer to pull off.
Worse still, hashing raw passwords directly means that as soon as one cracker knows that OSTEOPATH comes out as 075b 3a59 32b4 8df1 13e3 9ba4 df41 954b 2419 e705, he can tell everyone else, so that cracking a password for the second time is as simple as looking it up in a giant list of known hashes.
Current best practice is to generate a random “salt” (so called because it spices up the output) that is combined with the password before you start hashing, so that even identical passwords produce different outputs, and so every salt-plus-password combination has to be cracked independently.
MySpace’s turn
Well, it’s happened again.
This time, the breach is said to come from MySpace, and the number of passwords claimed is an eye-popping 427 million.
Apparently, there are only 360 million users on the list, but some accounts have more than one password listed, for reasons that aren’t explained.
Once again, the passwords allegedly exposed in this breach were simple, unsalted SHA-1 hashes, vulnerable to just the same sort of high-speed try ’em all attack as in the LinkedIn breach of 2012.
According to Leaked Source, lots of passwords have already been cracked, with the top 50 choices so far accounting for more than 6 million passwords, or 1.5% of the total.
Interestingly, password1, abc123 and the entirely-expected 123456 come in second, third and fourth respectively.
Top place is the unusual (but nevertheless easily-cracked) password homelesspa, attached to more than 850,000 accounts that Leaked Source suggests were created by some sort of automated process, presumably orchestrated by a gang of scammers to use for nefarious purposes.
Is it true?
Of course, password breach stories aren’t always all they seem to be.
We recently wrote about a claim that more than 250 million accounts were breached, allegedly belonging to users of services from Mail.ru (Russia’s most popular email provider), Google, Yahoo and Microsoft.
In the end, it looks as though the data in this breach was either so out-of-date as to be useless, or made up in the first place.
But journalists at Motherboard claim to have sent Leaked Source five email addresses of MySpace accounts to which they knew the passwords…
…and to have received the actual passwords back in return, implying that at least some of the leaked data is both genuine and current.
What to do?

  • Change your password as soon as you suspect that an account may have been breached, either because the password was stolen from you, or because a hash of the password was stolen from the service provider and could be cracked. The sooner you change it, the shorter the window during which crooks can attack your account.
  • Pick proper passwords. Even if a service provider doesn’t salt-hash-and-stretch your passwords properly, a strongly-chosen password will hold out against crackers longer than obvious choices such as dictionary words with digits tacked on the end.
  • If you run an online service, store your users’ passwords securely. Your authentication database shouldn’t get breached in the first place, of course, but you should nevertheless make things much harder for crackers in case you do get breached.
  • Patch early, patch often. If you’re a user, a patched system is less likely to be infected by malware that steals your passwords as you type them in; if you’re a service provider, a patched system is less likely to be penetrated by hackers looking for internal “trophy data” such as authentication databases.
  • Consider using two-factor authentication (2FA) if it’s available. 2FA typically involves a one-time code that you use along with your password when you log in.

2FA codes might be sent to you via SMS, or generated by a dedicated app on your phone, and they’re different every time, so your password alone just isn’t enough to access the account.
Generally speaking, 2FA is a minor hassle to use, but a major obstacle for the crooks, so we recommend it.

ShareTweet
Previous Post

93% of phishing emails are now ransomware

Next Post

Taking it all in: what typing does to listening and leadership

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol