Total Tests:

Murky Details Surround Bed, Bath and Beyond Breach

By Tara Seals for Threatpost
Wednesday, October 30, 2019

According to a report on stolen credentials and Fortune 500 companies from ImmuniWeb released this week (Bed, Bath and Beyond is No. 258 on the Fortune list), millions of stolen corporate credentials available in the Dark Web are exploited by cybercriminals for spearphishing and password re-use attacks.

ImmuniWeb’s analysis of the quality and quantity of stolen credentials accessible on the Dark Web found there to be over 21 million (21,040,296) credentials belonging to Fortune 500 companies, amid which over 16 million (16,055,871) were compromised during the last 12 months. As many as 95 percent of the credentials contained unencrypted, or bruteforced and cracked by the attackers, plaintext passwords.

The most common sources of the exposures and breaches were third parties (e.g. websites or other resources of unrelated organizations); trusted third parties (partners, suppliers or vendors); and the the companies themselves (e.g. their own websites or in-house other resources). Read Full Article


Book a Call Ask a Question
Close
Talk to ImmuniWeb Experts
ImmuniWeb AI Platform
Have a technical question?

Our security experts will answer within
one business day. No obligations.

Have a sales question?
Email:
Tel: +41 22 560 6800 (Switzerland)
Tel: +1 720 605 9147 (USA)
*
*
*
Your data will stay private and confidential