Tag Archive for: LinkedIn

A hacker is selling 167 million LinkedIn user records

A hacker is trying to sell a database dump containing account records for 167 million LinkedIn users.

The announcement was posted on a dark market website called TheRealDeal by a user who wants 5 bitcoins, or around $ 2,200, for the data set that supposedly contains user IDs, email addresses and SHA1 password hashes for 167,370,940 users.

According to the sale ad, the dump does not cover LinkedIn’s complete database. Indeed, LinkedIn claims on its website to have over 433 million registered members.

Troy Hunt, the creator of Have I been pwned?, a website that lets users check if they were affected by known data breaches, thinks that it’s highly likely for the leak to be legitimate. He had access to around 1 million records from the data set.

To read this article in full or to leave a comment, please click here

Network World Security

LinkedIn says private bug bounty program works for it better

LinkedIn plans to continue closely vetting researchers for its bug bounty rewards program, saying it reduces the number of distracting erroneous and irrelevant reports.

The decision to keep its program private “gives our strong internal application security team the ability to focus on securing the next generation of LinkedIn’s products while interacting with a small, qualified community of external researchers,” wrote Cory Scott, LinkedIn’s director of information security, in a blog post.

Security researchers with vetted backgrounds are invited to participate, which allow them to have the same experience as if they were on LinkedIn’s internal security team, Scott wrote.

To read this article in full or to leave a comment, please click here

Network World Security

LinkedIn users sue over service’s “hacking” of contacts and spammy ways

Four users have filed a class action lawsuit over the way LinkedIn harvests email addresses without permission and then sends them marketing blurb.
Naked Security – Sophos

LinkedIn lawsuit, stealing your password via LinkedIn phishing, password reuse

The fallout over the password breach continues for LinkedIn, which is facing a $ 5 million class-action lawsuit [PDF] after 6.5 million users had their passwords stolen. Read more

Ms. Smith’s blog