Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Spamgate: 1.37 Billion Records Exposed – Industry Reaction

by The Gurus
March 7, 2017
in Editor's News
Share on FacebookShare on Twitter

Spamming group, River City Media, led by well known spammers Alvin Slocombe and Matt Ferrisi, has had its database leaked. Yesterday, details were released of a massive, illegal spam operation. The situation presents a tangible threat to online privacy and security as it involves a database of 1.4 billion email accounts combined with names, user IP addresses, and even physical addresses. Chances are that you, or at least someone you know, is affected.
The Guru reached out to the cybersecurity industry to get thoughts on the breach.
Robert Capps, VP of business development at NuData Security:
“It’s critically important that we ensure that we continue our efforts to inform the public about their safety, and the fact that 1.4 billion records are compromised in this breach bear this out. As disheartening as this is, we saw the Yahoo! breach last year. At this point we shouldn’t be shocked. We can all assume that personal records are being shared on the dark web – sometimes years after the breach occurs.
“Any breaches of personal information are of extreme significance and concern. With just a name and email address there are out sized risks from targeted phishing. Stolen consumer data can be combined with other personally identifiable information (PII) from other hacks and breaches to amass even more detailed profiles on users that are traded and sold for high value to hackers. These ‘bundles’ contain much more complete and increasingly dangerous information around specific individuals, meaning there are more opportunities for fraud to take place. For example, with enough data collected from separate breaches a fraudster can gain access to financial and geographical information with the intent to fill out a loan application or apply for a new credit card. 
“User behaviour analytics can provide victims of this and other breaches with an extra layer of protection even after the hack has occurred. We need to put a stop to these fraudsters in a completely passive and non–intrusive way to us, the consumers. This is accomplished by learning over time how a legitimate user truly behaves in contrast to a potential fraudster using our legitimate information ripped from all these breaches.  Without even interrupting a user’s experience, fraud can be predicted and prevented from occurring. The only way we are going to stop these breaches is to devalue the data the fraudsters are going after, and we do this by truly being able to identify the identity of the user behind the device even when valid stolen credentials are used. “
Paul Calatayud, CTO, FireMon:
“In the recent River City Media Ggroup data leak, over 1.4 billion records may have been exposed. Not much information is being said as to the cause, but given that this was found by Chris Vickery, who often scans the internet for vulnerable Mongo DB assets and makes reference to lack of use of passwords, one can conclude that this data leak is a result of a misconfigured Mongo DB. Open source continues to be a critical source of innovation to many organizations. In this case, being used for motivations not so noble, the lesson to be learned here is that Mongo DB continues to be an easy exploit. Ensuring that your critical systems are secure and functioning under the policies that you intend is important. Applying intelligent security management to validate your builds – both system and firewalls – to ensure Mongo DB ports are not exposed will prevent these types of data leaks in the future.”
Steve Gates, Chief Research Intelligence Analyst, NSFOCUS:
“Slowloris, released in 2009, is a nothing more than a script designed to slowly consume all available connections on a server.  When all connections are consumed, the server cannot process any new connections; causing a denial of service condition.  Known as a “Layer 7” denial of service attack, the most effective way to defeat Slowloris is to protect servers with anti-DDoS technology, that can easily detect and block a Slowloris attack.   What is interesting here is that Slowloris was being used to help distribute as many spam emails as possible; before a victim server crashed or dropped all existing connections.  Once again, this is a demonstration of the originality and persistence of spammers – that never ceases to amaze.”
Chris Doman, Security Researcher at AlienVault:
“This is an extremely rare window into the operations of mass-spam campaigns. RCM’s apparent admission that they ran denial of service attacks against Gmail servers to trick them into accepting spam is very serious. They are talking about risking the stability of some of the internet’s core mail servers for profit. It’s bizarre these admissions are coming from chat logs that RCM themselves accidentally leaked.
Whilst the scale of data potentially lost by RCM here is massive, it’s important to note this data isn’t reported to include credentials or abused by anyone other than RCM yet.”
Matt Walmsley, EMEA director of Vectra Networks:
“Although it’s difficult to take pity on spammers, River City Media’s misfortune is a cautionary tale to business. Unsecured servers and databases are an open invitation to attackers who can use them to gain direct access to the company’s most sensitive information and important assets. Worryingly, five per cent of IPMI manageable servers are ‘secured’ by commonly-used default passwords, 30 per cent have easily guessable passwords and only 72 per cent authenticate access. What’s more, the UK is ranked 6th globally for exposed IPMI hosts, making it a tantalising target for hackers. As a baseline, businesses must password protect their confidential data, do away with default passwords and change those passwords regularly. The enforcement of password protection policies is essential.”
Ondrej Kubovič, Security Evangelist at ESET:
“The Slowloris technique was used by the attackers to spam millions of victims and is not all that uncommon in the wild, as we have seen similar attacks on our honeypots. Note, however, that this is the technique used by the spammers to send out huge amounts of spam emails, and not the cause of the leak.
Any leak of this size is a losing situation. Mainly for the victims, whose sensitive data is publicly available and can thus be misused for various malicious acts. Just by brief overview of the types of data leaked, physical addresses and names can be used for identity theft. In effect, the leak has shown that the spam operators were technically incapable to store and backup the bulk of stolen data “securely”.”

ShareTweet
Previous Post

From Shamoon to StoneDrill – Advanced New Destructive Malware Discovered in the Wild

Next Post

WikiLeaks Vault 7: 5 Fast Facts You Need to Know

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol