Information security
fromThe Hacker News
2 weeks agoNo Exploit Needed: How Attackers Walk Through the Front Door via Identity-Based Attacks
Stolen credentials remain the primary entry point for attackers, despite advancements in cybersecurity.
A credit-based economy and reputation-driven user system helped build trust among offenders and sustain a thriving underground forum. One of the forum's notable internal rules prohibited the sale or publication of any data related to Russia, hinting at the origin of LeakBase's operators.
LeakBase has been operating since 2021, the authorities said, and had a continuously maintained archive of hacked databases, including hundreds of millions of account credentials, credit card numbers, and banking account and routing information.
The Information Commissioner's Office (ICO) looked at 215 data breach cases at schools between January 2022 and August 2024, noting that 57 percent were caused by students, and almost a third (30 percent) were caused by stolen login details. In the case of stolen logins - either by students seeing others input credentials and remembering, or simply reading them noted down on paper - pupils were behind 97 percent of these attacks.
Students acting maliciously - often for fun - are increasingly the cause of cyber attacks affecting schools and colleges in the UK, according to new data from the Information Commissioner's Office, which today warned that the culprits may be setting themselves up for a life of cyber crime.