Security Management
Published on Security Management (http://www.securitymanagement.com)
Millions of Passwords Lost in LinkedIn Breach
By Laura Spadanuta
Created 06/06/2012 - 13:29



    
Wrap-Up?: 
No
Weight: 
0
Lead Headline?: 
No
Date: 
06/06/2012
By Line: 
By Laura Spadanuta
Teaser: 

LinkedIn has suffered a massive data breach and passwords have been hacked.

Professional social networking site LinkedIn has been hacked and has suffered a major data breach resulting in the loss of millions of user passwords.

According to the company's twitter account (@LinkedIn [1]), the company is looking into the reports of stolen passwords and continues to investigate.

However, other companies and news outlets are coming forward to confirm the breach. It has been reported on MSNBC.com [2] that security firm Sophos has confirmed the breach, with a Sophos report stating that "files posted on a Russian hacker site do contain LinkedIn passwords." The latest articles are listing the number at 6.5 million passwords leaked. And the Wall Street Journal reports [3] that Sophos and security firm Rapid7 told CIO Journal that "they were able to confirm the breach by searching for the known passwords of colleagues within the massive file they say has been spreading through other hacker forums."

According to WSJ, the leaked passwords would represent about 4 percent of LinkedIn users. There is no evidence yet that the passwords have been linked with e-mail addresses.

Experts are advising that users change their LinkedIn and e-mail passwords. However, WSJ reports that Rapid7 researcher Marcus Carey has warned that doing that may not be enough:  "“The vulnerability hasn’t yet been worked out, so the attackers may still be in the system and you may need to change your password again, once the flaw is worked out,” Carey said. “This may be a two time thing.”

 

Related Resources: 

Comments


Security Management is the award-winning publication of ASIS International, the preeminent international
organization for security professionals, with more than 38,000 members worldwide.

ASIS International, Inc. Worldwide Headquarters, 1625 Prince Street, Alexandria, Virginia 22314-2818 U.S.A.
703.519.6200 | fax 703.519.6299 | www.asisonline.org

ASIS

© 2013 Security Management
This site is protected by copyright and trade mark laws under U.S. and International law.
No part of this work may be reproduced without the written permission of Security Management.

Powered by: Phase2 Technology

Source URL: http://www.securitymanagement.com/news/millions-passwords-lost-linkedin-breach-009951

Links:
[1] http://twitter.com/#!/LinkedIn
[2] http://www.technolog.msnbc.msn.com/technology/technolog/6-5-million-linkedin-passwords-leaked-report-816238
[3] http://blogs.wsj.com/digits/2012/06/06/two-security-firms-say-they-verified-linkedin-breach/