Hackers stole 2M Facebook, Twitter, and Google passwords – here’s how to stay safe

123456 remains the worlds most used and worst password
JMik/Shutterstock

“Criminal botnet” sounds like something from a forgotten sci-fi serial from the 1970s, but turns out they’re real, and they’ll steal your passwords.

A botnet called Pony recently stole 2 million passwords for major online destinations like Facebook, Yahoo, Google, and Twitter, as well as payroll service Automated Data Processing. The security research team at Trustwave’s Spiderlabs discovered the massive data heist this week and outlined how the botnet works its dirty magic on their blog

The passwords were welched off devices infected with malware that gave something called the Pony Botnet Controller access to information. This version of Pony rounds up passwords with frightening efficiency; even more disturbingly, since it has successfully obtained information from a large payroll company, this criminal hack could have immediate financial repercussions for people impacted. Yikes. 

There’s no way to make your information absolutely 100 percent safe, because the collectives behind this sort of attack tend to be pretty smart at inventing new ways to get at our personal information. But there are a few steps you can take to avoid falling prey to this kind of hack. 

First, assess the situation. 

Find out if you were one of the unlucky victims at HaveIBeenPwned – the site lets you enter as many email accounts as you want and will tell you if you’ve been hacked. It might even give some follow up information about what particular security breach was responsible. If any of your accounts turn up a warning, you’d best go change that password immediately. 

Don’t choose an obvious, simple password. 

You’d think people would know by now not to use passwords like “123456” but I guess not. This kind of “chocolate teapot” password (meaning: they’re completely useless) was the most commonly stolen. Other commonly stolen passwords: 123456789, 1111111, and “admin.” Just get more creative (your birthday and name aren’t recommended, either). Setting a longer password seems like too simple a solution, but most of the passwords stolen were just that — too simple. Pony Botnet Password Chart

For Facebook, take advantage of additional security. 

Facebook told the BBC that people could safeguard their passwords by activating Login Approvals and Login Notifications in their security settings. Turning the Login Notifications on will alert you anytime someone attempts to sign in from an unknown location, and using Login Approval will generate a unique password that gets sent to your mobile phone — and both security measures could keep your Facebook information out of the hands of botnets. 

This isn’t the first time a widespread security breach has happened. This is on a notably large scale, yes, but passwords get stolen all the time. The best thing you can do is come up with a complicated, long, unique password that won’t be easy to guess, and take the time to set your security settings to notify you when unusual activity occurs. 

Social Media

Tumblr promises it fixed a bug that left user data exposed

A bug on blogging site Tumblr left user data exposed. The company says that once it learned of the flaw, it acted quickly to fix it, adding that it's confident no data linked to its users' accounts was stolen.
Mobile

Find out how to keep tabs on your phone with these helpful tracking tips

Need to keep tabs on the location of your cell phone or smartphone? Consult this guide for tips and tricks on how to track a phone, whether you're currently rocking Android, iOS, or something more old-school.
Computing

Protecting your PDF with a password isn't difficult. Just follow these steps

If you need to learn how to password protect a PDF, you have come to the right place. This guide will walk you through the process of protecting your documents step by step, whether you're running a MacOS or Windows machine.
Deals

The best accounting software for your small business

Small business owners looking for accounting software have a variety of options at their disposal. And this guide will help them find the best solutions, from Quickbooks Online and Freshbooks to AccountEdge and Zoho Books.
Social Media

These are the best ways to make an animated GIF

Love sharing GIFs with your friends and peers, but wish you could make your own? Here's how to do so in Photoshop, or using a few other methods that don't require you to shell out a premium fee with each calendar year.
Mobile

Hinge's new feature wants to know who you've gone out on dates with

With its new "We Met" feature, Hinge wants to learn how your dates are going with matches in its app. That way, it can inject the information into its algorithm to provide future recommendations that better suit its users' preferences.
Social Media

Like a pocketable personal stylist, Pinterest overhauls shopping tools

Pinterest shopping just got a bit better with a trio of updates now rolling out to Pinterest. The first replaces Buyable Pins with Product Pins for more features, including knowing whether or not a product is in stock.
Smart Home

Facebook’s new Portal device can collect your data to target your ads

Facebook confirmed that its new Portal smart displays, designed to enable Messenger-enabled video calls, technically have the capability to gather data on users via the camera and mic onboard.
Social Media

YouTube is back after crashing for users around the world

It's rare to see YouTube suffer serious issues, but the site went down around the world for a period of time on October 16. It's back now, and we can confirm it's loading normally on desktop and mobile.
Social Media

Twitter has sorted out those weird notifications it was sending

Twitter started churning out weird notifications of seemingly nonsensical letters and numbers to many of its users on Tuesday morning. The bizarre incident even prompted Twitter boss Jack Dorsey to get involved.
Photography

Adobe MAX 2018: What it is, why it matters, and what to expect

Each year, Adobe uses its Adobe MAX conference to show off its latest apps, technologies, and tools to help simplify and improve the workflow of creatives the world over. Here's what you should expect from this year's conference.
Home Theater

Facebook might be planning a streaming box for your TV that watches you back

Facebook is reportedly working on a piece of streaming media hardware for your living room with a built-in camera for video calls, something people may not want given the company's recent controversies.
Computing

Adobe’s craziest new tools animate photos, convert recordings to music in a click

Adobe shared a glimpse behind the scenes at what's next and the Creative Cloud future is filled with crazy A.I.-powered tools, moving stills, and animation reacting to real-time tweets.
Social Media

Over selfies and an onslaught of ads? Here's how delete your Instagram account

Despite its outstanding popularity and photo-sharing dominance, Instagram isn't for everyone. Thankfully, deleting your account is as easy as logging into the site and clicking a few buttons. Here's what you need to do.