Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - The Perfect Hacker Storm in CyberVor’s Wake
News & Analysis

The Perfect Hacker Storm in CyberVor’s Wake

ISBuzz TeamBy ISBuzz TeamAugust 12, 2014Updated:July 3, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Hold Security recently announced that a Russian “hacker gang” its teams have dubbed “CyberVor” succeeded in accumulating over 1.2 billion unique user credentials from over 420,000 web services, ranging from smaller sites to major household names. While there is no doubt this is a shockingly massive breach, and CyberVor’s amassed collection of user identifies is surely the largest publically disclosed trove to date, what these hackers actually created is something far larger and more dangerous. Worst still, we have yet to realize the true ramifications of this massive and unique breach.

Sure, the sheer size of the number of compromised credentials is impressive on its own. For scale – if the CyberVor hack were a box office return, it would equal the total global gross of the final Harry Potter film, as compared to the recent Target breach which would register only in the range of opening week for “Big Daddy”.

Ever heard of “Big Daddy”? No, of course not.

More than its sheer size, the CyberVor attack constitutes the flash of lightning before the deafening crack of thunder. This attack has created the perfect storm for hackers, for the continued coverage of this story stirs up feelings of fear, ambiguity, and opportunity – all of which work in the favor of social engineering.

With over 420,000 sites affected, we know that many are sites millions of people use frequently. [FEAR] But which of the many sites we use were affected? [AMBIGUITY] Finally, the fact this attack is broadcast loudly presents an unprecedented opportunity for social engineering.

If I were so inclined to take advantage of this situation, here’s precisely what I’d do.

My first step would be to determine my targets. Because of the ambiguity in the market, I don’t have to focus on small game here – everything’s on the table. Perhaps I’d start with a handful of major financial institutions, some cloud storage providers, a couple of email platforms, and an assortment of major corporate remote access gateways. After I’ve decided which firms to target, I’d assemble a very convincing email using the appropriate company logo. The email would read:

“In light of recent news regarding the attack on 1.2 billion identities, we strongly encourage you to change your password to prevent any malicious action against your account. Please feel free to login normally through our website, or find a link below for your convenience.”

I can imagine a striking percentage of users mistakenly clicking on the link that would route them to a convincing phishing site, which would compromise any multi-factor authentication solution that relies on generating a one-time passcode.

The crash of thunder is not the fact that so many credentials were compromised. No, the true roar is felt as the current situation is leveraged to gain access to corporate networks, bank accounts, and sensitive documents. Clearly the CyberVor attack is the shot across the bow, as cyber security has leveled up from being the responsibility of just the technical architects and CISOs; with the ramifications immediately available for would-be bad actors, cyber security is now a liability for CEOs and the rest of the Executive Board. CEOs should be hyper-aware that despite the great work of most CIO and CISOs, they’re one attack away from missing estimates next quarter. And if the CEO is not having this conversation with their lead security officer, then his or her Board should help make it a priority. Remember, it took a matter of hours for CodeSpaces to effectively disappear as a company.

So – how can we best prepare for the coming storm?

Passwords. Despite what is written and said (ad nauseam), passwords need not die. All the same, they cannot be relied upon as the only form of authentication. We need to supplement passwords with multi-factor authentication that secures services against the attacks levied against it and simultaneously does not affect the user’s experience.

Using better multi-factor authentication throughout the ecosystem, both internally and externally for an enterprise, makes it much more difficult for hackers to take advantage of the banquet table set before them. Providing multi-factor authentication that does not affect user experience will actually enable users to use it and create stickier relationships for enterprises.

CyberVor presented the first lightening strike of a frighteningly large and fast moving storm. While there may not be much we can do to change the weather, we can benefit from the use of multi-factor authentication to get off the flood plain.

To help enable CEO and Boards have the right conversations and ask the right questions, demystifying the obfuscation surrounding security, please visit our website at www.toopher.com/guide.

By Josh Alexander, CEO, Toopher

About Toopher

toopher_logoToopher virtually eliminates online fraud and identity theft by providing out of band, automated two-factor authentication. It offers better security without any of the hassle entrenched in existing two-factor solutions. Toopher uses the location awareness of your smartphone to add another layer of security to passwords—all without leaving your pocket. The company’s product suite is the rare security tool that users actually want to use.

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

New Phishing Kit Starkiller Defeats Multi-Factor Authentication

February 23, 20264 Mins Read

ReliaQuest Uncovers Social Media Phishing Campaign Built on Trusted Tools

January 22, 20266 Mins Read

What Happens after a Phishing Email Lands in Your Inbox?

January 5, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}