article thumbnail

US charges hacker for breaching brokerage accounts, securities fraud

Bleeping Computer

Department of Justice (DoJ) has charged Idris Dayo Mustapha for a range of cybercrime activities that took place between 2011 and 2018, resulting in financial losses estimated to over $5,000,000. [.].

article thumbnail

SEC Sanctions Several Companies over Email Account Hacking

Hacker Combat

SEC penalized Cambridge Investment Research because more than 121 of their email accounts were hacked between 2018 January and 2021 July. SEC reiterated that Cambridge Investment Research discovered the first breach in 2018 January but took no action to boost email account security until 2021. .

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

T-Mobile customers were hit with SIM swapping attacks

Security Affairs

.” The exposed information may have included customers’ full name, address, email address, account number, social security number, customer account personal identification number (PIN), account security questions and answers, date of birth, plan information, and the number of lines subscribed associated with the account.

Mobile 90
article thumbnail

Analyzing attacks conducted by North Korea-linked ARCHIPELAGO APT group

Security Affairs

ARCHIPELAGO “browser-in-the-browser” phishing page The ARCHIPELAGO group has shifted its phishing tactics over time to avoid detection, the attackers use phishing messages posing as Google account security alerts.

article thumbnail

Pwned Passwords, Version 5

Troy Hunt

I wrote about a bunch of them last year in my post on Pwned Passwords in Practice , but it's the work they've done at EVE Online that really stands out: More @EveOnline account security improvements are now live with some nice things from our friends at @1Password. Consistently, I'm hearing the results of this exercise are.

Passwords 234
article thumbnail

LastPass: ‘Horse Gone Barn Bolted’ is Strong Password

Krebs on Security

LastPass officially instituted this change back in 2018, but some undisclosed number of the company’s earlier customers were never required to increase the length of their master passwords. In February 2018, LastPass changed the default to 100,100 iterations. LastPass sent this notification to users earlier this week.

Passwords 265
article thumbnail

Trick or Treat: The Choice is Yours with Multifactor Authentication

Thales Cloud Protection & Licensing

In 2018, the Timehop app suffered a serious breach that resulted in data belonging to 21 million users being compromised. Some security experts believe that passwords should be consigned to a place in the cybersecurity graveyard. Here are three terrifying examples. A Grave Outlook For Passwords: Is the Future Passwordless?