Rate Us:

Company Notification – Important: CyberVor Data Breach

Share this post

What you should know:

On August 5th, it was reported by Hold Security that a Russian hacker group they call CyberVor has amassed over 1.2 billion unique sets of login credentials in the form of email address/username and password combos. These credentials were harvested from 400,000+ websites that were identified as vulnerable to SQL injection attacks and were subsequently compromised. This appears to be the largest breach of user credentials to date and represents a threat worse than Heartbleed. Given the scale of the breach it’s not unlikely that a site you or your users have visited was compromised. Note that this breach affected large and small websites alike; CyberVor attacked any site they could find that was vulnerable to a SQL injection attack. A complete list of compromised sites is not currently available, nor is the list of email addresses CyberVor collected.

For more information about the breach you can read:

Hold Security’s original posting here: http://www.holdsecurity.com/news/cybervor-breach/

And the New York Times report here: http://www.nytimes.com/2014/08/06/technology/russian-gang-said-to-amass-more-than-a-billion-stolen-internet-credentials.html

What to do:

Envision Consulting recommends that all users change their passwords for any websites that are important to them; this includes financial sites, e-commerce sites with stored payment information, web-based email sites and any other site of personal or commercial importance. Note: It is very important to avoid reusing the same password across multiple sites, especially on financial or email accounts. Wherever available Envision also recommends enabling 2-factor authentication as an extra security measure.

If you have any further question or concerns please contact engineering@wordpress-564672-3764011.cloudwaysapps.com and we will be happy to assist.

Thank you,

Envision Consulting

Share this post

Other Related Blogs

Articles, Blog
The biggest HIPAA rewrite in more than a decade slipped to 2027. The rule you are already bound by did not change. Here is what HIPAA compliant IT services actually means, and what to ask any provider before you sign.
Articles, Blog, Compliance
Most of what CMMC Level 2 costs comes from how much of your company is in scope. If CUI only touches part of your business, an enclave can shrink that footprint — and the bill with it.
Articles, Blog
Looking for IT support in Northern Virginia? Envision Consulting shares real lessons from 25 years serving Arlington, Fairfax, and Tysons businesses.

Support Ticket

What can we do better?

We love to hear from our clients, please let us know if there are any areas that you think we could improve upon.