article thumbnail

Experian, You Have Some Explaining to Do

Security Boulevard

In both cases the readers used password managers to select strong, unique passwords for their Experian accounts. Twice in the past month KrebsOnSecurity has heard from readers who've had their accounts at big-three credit bureau Experian hacked and updated with a new email address that wasn't theirs.

article thumbnail

Experian, You Have Some Explaining to Do

Krebs on Security

In both cases the readers used password managers to select strong, unique passwords for their Experian accounts. Turner said he created the account at Experian in 2020 to place a security freeze on his credit file, and that he used a password manager to select and store a strong, unique password for his Experian account.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Fla. Man Charged in SIM-Swapping Spree is Key Suspect in Hacker Groups Oktapus, Scattered Spider

Krebs on Security

On August 25, 2022, the password manager service LastPass disclosed a breach in which attackers stole some source code and proprietary LastPass technical information, and weeks later LastPass said an investigation revealed no customer data or password vaults were accessed. According to an Aug.

article thumbnail

Does Your Domain Have a Registry Lock?

Krebs on Security

In cases where passwords are used, pick unique passwords and consider password managers. -Use 2-factor authentication, and require it to be used by all relevant users and subcontractors. -In

DNS 266
article thumbnail

How to Shop Online Like a Security Pro

Krebs on Security

You might even take a minute to explain the perils of re-using passwords across multiple sites, and see if they’re interested in using a password manager. While you’re at it, ask your friends and family if they’ve frozen their credit files at the major consumer credit bureaus.

Scams 273
article thumbnail

LastPass: ‘Horse Gone Barn Bolted’ is Strong Password

Krebs on Security

The password manager service LastPass is now forcing some of its users to pick longer master passwords. But critics say the move is little more than a public relations stunt that will do nothing to help countless early adopters whose password vaults were exposed in a 2022 breach at LastPass. . ”

Passwords 263
article thumbnail

Experts Fear Crooks are Cracking Keys Stolen in LastPass Breach

Krebs on Security

In November 2022, the password manager service LastPass disclosed a breach in which hackers stole password vaults containing both encrypted and plaintext data for more than 25 million users. I’ve never been comfortable recommending password managers, because I’ve never seriously used them myself.