+

Cookies on the Business Insider India website

Business Insider India has updated its Privacy and Cookie policy. We use cookies to ensure that we give you the better experience on our website. If you continue without changing your settings, we\'ll assume that you are happy to receive all cookies on the Business Insider India website. However, you can change your cookie setting at any time by clicking on our Cookie Policy at any time. You can also see our Privacy Policy.

Close
HomeQuizzoneWhatsappShare Flash Reads
 

Personal data of 40 million Wishbone app users hacked

May 24, 2020, 12:01 IST
IANS
San Francisco, May 23 (IANS) Personal data from nearly 40 million users of popular voting app Wishbone has been hacked which is available for free download on a hacking forum.
Advertisement

The Wishbone user database has been leaked in full, according to a ZDNet report, and a hacker known as ShinyHunters has taken credit for the hacking.

Earlier, the data was being offered for 0.85 bitcoin ($8,000) on the Dark Web.

The data contains usernames, emails, phone numbers, city/state/country and hashed passwords.

"The data also included links to Wishbone profile pictures. URLs included in the sample data loaded images depicting minors, an age category the Wishbone app has always been historically popular," according to the report.

Advertisement

The passwords were not stored in plain text but hashed using the MD5 algorithm.

MD 5 was declared "cryptographically broken" by the experts in 2010.

A moderately-complex password hashed with MD5 could be cracked in 30 minutes or less.

ShinyHunters is currently selling databases from tens of other companies, totaling more than 1.5 billion records.

The companies include online dating app Zoosk, US newspaper Star Tribune and food delivery service Chef that contains over 73 million user records over the Dark Web for $18,000 (nearly Rs 13.6 lakh) .

Advertisement
Other companies are printing service Chatbooks, South Korean fashion platform SocialShare, online marketplace Minted, online newspaper Chronicle of Higher Education, South Korean furniture magazine GGuMim, health magazine Mindful and Indonesia online store Bhinneka.

ShinyHunters is the same group behind breaching private repositories on Microsoft-owned GitHub (the hacker is believed to have acquired around 1,200 private repositories) and Tokopedia, Indonesia's largest online store where a database of over 90 million user records was sold.

On May 20, our team became aware of a security issue where we believe an unauthorized individual may have had access to Wishbone’s database through stolen credentials. Personal information for some of our users was compromised. No financial or other sensitive information was involved. We have since invalidated any current access methods to user information and updated keys accordingly, and we've also ensured that all employees or services which require access use cybersecurity approved multi-factor authentication or similar methods. Across the board, we are implementing stronger security and encryption of personal information to ensure the safety of all of our users’ data. We value our users' privacy and deeply regret that this has happened.
You are subscribed to notifications!
Looks like you've blocked notifications!
Next Article