Wishbone hack – data of 40 million users up for sale
A database of 40 million users of the popular Wishbone application has been put for sale on the dark web.
ZDNet discovered Wishbone user accounts were available on underground forums for 0.85 bitcoin – currently around $8000. The popular mobile app allows users to compare two or more items in voting polls.
The hacking attempt appears to have taken place earlier this year, with the criminals able to get access to details including usernames, emails, phone numbers, city/state/country and hashed passwords.
Since Wishbone is popular among children, the presence of personally identifiable details like profile pictures and profiles URLs may pose a serious threat to their safety.
Wishbone hack
In a prepared statement, Mammoth Media, the parent company of Wishbone, stated, “Protecting data is of the utmost importance. We are investigating this matter and will share any significant developments.”
According to the report, the passwords were not encrypted properly and were stored in a weak MD5 hashing format. Unlike SHA1 hashing, passwords stored in MD5 format can be easily cracked with the help of various tools freely available on the Internet.
Experts believe the poster may be a reseller or a broker who is looking to make money by reselling the data. Apart from Wishbone, the hacker has also put databases of other companies up for sale, with over 1.5 billion records available, many of which from companies which reported a data breach in the recent past.
Wishbone was previously attacked in 2017, when hackers were able to steal the data of over 2.2 million users. However, the sample data shared by the hacker in this instance did not match any listed online, seemingly confirming this is a new hack.
Via: ZDNet
A database of 40 million users of the popular Wishbone application has been put for sale on the dark web. ZDNet discovered Wishbone user accounts were available on underground forums for 0.85 bitcoin – currently around $8000. The popular mobile app allows users to compare two or more items in…
Recent Posts
- Dell cracks down on hybrid working again — computing giant is going to start color-coding employees to show who is coming back to the office
- Microsoft is ‘turning everyone into a prompt engineer’ with new Copilot AI features
- The Morning After: Apple’s new iPad Pro is thinner than an old iPod nano
- Top security guard firm exposed over a million files online
- UK details requirements to protect children from ‘toxic algorithms’
Archives
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023
- May 2023
- April 2023
- March 2023
- February 2023
- January 2023
- December 2022
- November 2022
- October 2022
- September 2022
- August 2022
- July 2022
- June 2022
- May 2022
- April 2022
- March 2022
- February 2022
- January 2022
- December 2021
- November 2021
- October 2021
- September 2021
- August 2021
- July 2021
- June 2021
- May 2021
- April 2021
- March 2021
- February 2021
- January 2021
- December 2020
- November 2020
- October 2020
- September 2020
- August 2020
- July 2020
- June 2020
- May 2020
- April 2020
- March 2020
- February 2020
- January 2020
- December 2019
- November 2019
- December 2011