📜 ⬆️ ⬇️

Data more than 100 million Vkontakte accounts are sold online for 1 bitcoin

A random sample showed the validity of 92 out of 100 (!) Accounts



Resource LeakedSource, engaged in monitoring and analysis of leaks, reported a leak in the Network data about 100 million accounts of the social network "Vkontakte". This data is not posted for free access, but sold. For sale they put a hacker with the nickname Peace.
')
Experts who analyzed the leakage report that the database contains 100,544,934 records. These are not only logins and passwords, but also names, email addresses, phone numbers of users. All this is sold for only 1 Bitcoin, about $ 570 at the rate. The lot is for sale in the dark web, on one of the marketplaces.

As for the base, which is obtained by the resource LeakedSource, it was provided by the user Tessa88. According to the hacker Peace, the user database was obtained during the hacking of a social network. This hacking was carried out between 2011 and 2013, which explains the lack of a phone number next to the username in the database. As mentioned above, the validity of the database is high, a random sample showed the correctness of 92 out of 100 records.

Interestingly, Peace is the nickname used by the attacker who sold millions of MySpace accounts. At the end of May, data from more than 400 million accounts of this social network were included in the Network.

When analyzing account passwords, it turned out that most often users set the number 123456 as a password.

Item numberPasswordFrequency
one123456709,067
2123456789416,591
3qwerty291,645
four111111189,151
five1234567890156,614
61234567141,620
712345678107,799
eight12332193,048
900000091,981
ten12312389,461
eleven777777787,022
12qwertyuiop77,256
1366666677,048
14123qwe68,800
1555555566,208
sixteenzxcvbnm64,066
171q2w3e62,903
18gfhjkm57,386
nineteenqazwsx56,465
201q2w3e4r55,251
2165432151,680
2298765432150,306
2312121244,652
24zxcvbn44,209
2577777742,279
261q2w3e4r5t41,141
27qazwsxedc39,287
28123456a37,611
2911223336,795
thirtyqwe12336,447
31ghbdtn36,302
32PolniyPizdec021133,236
3315975332,939
34123456q32,123
35asdfgh31,722
36111111131,621
37samsung31,544
38qweasdzxc30,459
39qwertyu29,354
401234qwer29,132
411111111128,904
4222222228,881
43asdfghjkl28,175
441qaz2wsx28,142
45qweqwe27,045
46111111111126,826
4712365425,947
48marina24,309
4912312312324,176
50098765432123,749
5112345q23,673
5299999923,464
53qwerty12322,937
54123456789a22,749
5512345a22,730

Among the e-mail addresses, e-mail from mail.ru was the most common.

Item numberDomain e-mailFrequency
one@ mail.ru41,132,524
2e-mail not specified21,877,927
3@ yandex.ru11,604,169
four@ rambler.ru7,416,993
five@ bk.ru2,183,690
6@ gmail.com2,033,429
7@ list.ru1,586,503
eight@ ukr.net1,509,641
9@ inbox.ru1,411,841
ten@ yahoo.com586,902
eleven@ i.ua523,155
12@ hotmail.com522,182
13@ ya.ru518,710
14@ bigmir.net413,599
15@ yandex.ua319,155
sixteen@ meta.ua308,771
17@ tut.by227,743
18@ e-mail.ru147,319
nineteen@ pochta.ru138,758
20@ qip.ru123,094
21@ inbox.lv106,310
22@ vkontakte.ru105,614
23@ yndex.ru94,643
24@ e1.ru84,581
25@ meil.ru82,608
26@ ngs.ru82,202
27@ email.ru79,524
28@ sibmail.com71,916
29@ mai.ru71,692
thirty@ spaces.ru71,008
31@ km.ru70,307
32@ gmail.ru64,141
33@ ua.fm60,568
34@ abv.bg56,825
35@ narod.ru55,076
36@ mail.com53,297
37@ live.ru52,698
38@ web.de50,339
39@ ro.ru49,454
40@ e-mail.ua45,403
41@ online.ua44,118
42@ mail.ry43,043
43@ nm.ru35,446
44@ gala.net34,613
45@ gmx.de34,535
46@ seznam.cz31,700
47@ mail.ua31,143
48@ email.ua30,951
49@ pisem.net30,044
50@ live.com27,386
51@ il.ru26,947
52@ voliacable.com25,347
53@ aport.ru24,104
54@ hotbox.ru23,636
55@ mail.by22,556

The large-scale leakage of these user accounts on Vkontakte is a continuation of the “May plum”, when data from millions of Mail.ru, MySpace, LinkedIn accounts appeared on the Web. However, in the current case, the percentage of valid accounts is much higher - it can probably be explained by the fact that Vkontakte users rarely change the data of their accounts. Peace claims that he still has data for about 70 million Vkontakte accounts, but he is not going to sell them yet.

As for the history of Mail.ru, in May, invalid data entered the Network, more than 99% of accounts from the database were irrelevant. “22.56% of the analyzed accounts contain an email address that never existed at all, another 64.27% contains the wrong password, the database also contains records that are specified without a password at all (0.74%). The remaining 12.42% of accounts already pass in Mail.Ru Mail as suspicious (that is, according to our system, there are reasons to believe that they were either hacked or created by a robot) and blocked. This means that it is impossible to enter them with a password, and the owner must go through the procedure for restoring access, ”the company said in a press release.

But the base LinkedIn and MySpace accounts were genuine, this is no ordinary stuffing. The data of many accounts from the database were already different, but, nevertheless, many of the accounts were correct, and with them it was possible to log in to the specified sites.

So far, there are no comments on this incident from Vkontakte.

Source: https://habr.com/ru/post/394973/


All Articles