Skip to main content

Report: Hacker puts data from 167 million LinkedIn accounts up for sale

linkedIn
A hacker is attempting to sell a package containing account records for 167 million LinkedIn users. The data set reportedly contains user IDs, email addresses and SHA1 password hashes — and the asking price is a measly five bitcoins, which roughly converts to about $2,200 based on current market rates.

The sale is being advertised through a dark market website known as TheRealDeal, according to a report from MacWorld. The listing confirms that the package doesn’t contain the entire LinkedIn userbase, which is more than double the 167 million entries being advertised.

It’s believed that this data was stolen during a major breach of LinkedIn’s security that took place in 2012. At the time, only 6.5 million passwords were released to the internet, but the administrators of security breach indexer LeakedSource have stated in a blog post that there’s evidence that this sale is using records accessed in that attack.

Of the 167 million accounts affected, some 117 million contain hashed passwords; the rest are thought to have been set up via a Facebook login, or another similar process. However, the protection applied to these passwords leaves a lot to be desired.

The passwords were hashed using the SHA1 function, which has long since been cracked and is no longer considered to be secure. The data was not salted, adding to the likelihood that whoever purchases the package will be able to decrypt the information, and potentially access the affected accounts.

If you haven’t changed your LinkedIn password in several years, now is the time to do so — and it might be worth enabling the site’s two-factor authentication process while you’re at it. Of course, if you use the same email address and password combination across several sites and services, you’ll need to make the change across the board.

Editors' Recommendations

Brad Jones
Brad is an English-born writer currently splitting his time between Edinburgh and Pennsylvania. You can find him on Twitter…
Millions of Instagram influencers reportedly had private data exposed online
instagrams new explore grid tempts you to open your wallet mobile technology applications

Tens of millions of Instagram influencers have reportedly had their private data exposed in an online database. The records were hosted by Amazon Web Services and apparently had no password protection.

The database contained information such as phone numbers and email addresses for around 49 million Instagram influencers, celebrities, and brand accounts, according to a TechCrunch report on Monday, May 20. It also listed public data such as profile pictures and user locations.

Read more
LinkedIn: Now you can express love, curiosity, and more with new Reactions
The LinkedIn logo is seen on an android mobile phone.

LinkedIn likes to go at its own pace. In 2018, the social network for professionals finally got around to launching its own version of Snapchat’s Stories (not that it had to, of course) while in February it managed to knock together a live video tool, albeit in beta and by invitation only.

This week, three years after Facebook did something similar, LinkedIn has seen fit to add more reactions alongside its "like" button, giving you more ways to express how you feel about posts that turn up in your feed.

Read more
After fourth attack, hacker puts personal records of 26M people up for sale
Privacy security stock photo.

A hacker going by the name of "Gnosticplayers" is selling the personal data of 26 million people who have been using the services of six different companies from across the world. The information is up for sale on the dark web for a value of up to 1.4231 bitcoin, or around $4,940. This marks the fourth time the hacker is selling people's personal information.

According to ZDNet, the companies impacted by this hack include GameSalad, Estante Virtual, Coubic, LifeBear, Bukalapak, and Youthmanual. While most of these companies are not based in the United States. a noteworthy name on the list is GameSalad, a game-development platform that powers 75 games that reached the top 100 in Apple's App Store.

Read more