Attacks/Breaches

4/29/2014
01:40 PM
50%
50%

AOL Subscriber Data Stolen: You've Got Pwned

Change passwords and security questions now, AOL warns subscribers. For everyone else, treat all emails from AOL addresses with suspicion.

Warning to AOL users: Beware a security intrusion that resulted in the theft of subscribers' information, and don't click on links or attachments in any suspicious-looking emails.

That warning was sounded Monday by AOL's security team, which said in a security update that third-party digital forensic investigators hired by the company found "unauthorized access to information regarding a significant number of user accounts." The information accessed by attackers "included AOL users' email addresses, postal addresses, address book contact information, encrypted passwords, and encrypted answers to security questions that we ask when a user resets his or her password, as well as certain employee information."

The theft of contact information from AOL subscribers means that anyone who receives an email that appears to be from an AOL email address should treat it as suspicious, until proven otherwise.

What should AOL users do now in response to the breach? "We suggest you take some routine security precautions," said Internet for Dummies author John R. Levine in a blog post. "Specifically, we recommend that you change your postal address, phone number, employer, date of birth, and spouse. Oh, and you might as well change your password, too."

The breach is a further reminder that people should never reuse the same password on multiple sites. In the wake of the AOL breach, accordingly, "if you were using the same password for any other online account -- which is, as we have discussed many times before, very bad practice -- then you need to change those passwords too," said independent computer security analyst Graham Cluley in a blog post.

"And it's not just passwords that you have to worry about," he added. "AOL says that address books have also been accessed, which means that online criminals now know who you are friends with, and how to contact them -- making it easy for them to create convincing scam emails or attempt to send out phishing campaigns."

While an AOL "you've got mail" email address today may lack its 90s cachet, last year the company said that 2.5 million people still subscribe to one of its services. "[I'm] bemused by people who say they're surprised AOL is still around," said Cluley via Twitter. "They're the company who bought TechCrunch and the Huffington Post."

AOL said the breach seems to be tied to the flood of spam that appeared to emanate from AOL's servers last week. "We believe that spammers have used this contact information to send spoofed emails that appeared to come from roughly 2% of our email accounts," AOL said. But the company said the emails weren't actually sent via its servers or subscribers' accounts. Instead, it said attackers used contact information stolen from AOL subscribers and spoofed the email addresses to make it appear as if they'd originated from the AOL subscriber.

What about the encrypted data stolen by attackers? AOL also said that to date, there's "no indication that the encryption on the passwords or the answers to security questions was broken." But an AOL spokeswoman, contacted via email, wasn't immediately able to comment about how exactly the stolen information was encrypted. As some past breaches have highlighted -- for example at LinkedIn -- not all businesses implement what information security experts would describe as "minimal standards" for implementing password encryption.

Furthermore, now that attackers have managed to obtain the AOL subscriber data tranche, they can attempt to crack it offline. That means that attackers may gain access to -- or may have already accessed -- people's security questions and answers, which would create problems of the variety to which Levine alluded.

"Looks like I'll have to ask my mother to change her maiden name again," said Virus Bulletin editor Martijn Grooten via Twitter. "Awkward."

Mathew Schwartz served as the InformationWeek information security reporter from 2010 until mid-2014. View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
JyotiS948
50%
50%
JyotiS948,
User Rank: Apprentice
11/2/2015 | 3:35:17 AM
computer problems
The information for AOL password recovery contains good content. Anyway I have tried and tested 25dollarsupport.com which has proved the best till date to fix my computer problems . My first preference.
Mathew
50%
50%
Mathew,
User Rank: Apprentice
5/1/2014 | 5:02:03 AM
Re: AIM?
Great question. I'm not an AOL user, but according to the company's website, AIM users can sign into their account using their AOL password. So the short answer is: Yes.

In terms of bigger-picture questions about exactly what type of encryption (and if password hashes were salted, and so on) AOL might have used, AOL has yet to provide those details. (Stay tuned.)
securityaffairs
50%
50%
securityaffairs,
User Rank: Ninja
4/30/2014 | 4:27:33 PM
Re: AIM?
I'm waiting for further information on the real extension of the data breach. I'm afraid that the number of affected accounts could be impressive, in this case let's be prepared for a series of further attacks which will exploit the stolen/spoofed identities.

Regards
Kelly Jackson Higgins
50%
50%
Kelly Jackson Higgins,
User Rank: Strategist
4/30/2014 | 4:20:47 PM
AIM?
Mat, was AIM also affected by this breach?
121 Pieces of Malware Flagged on NSA Employee's Home Computer
Kelly Jackson Higgins, Executive Editor at Dark Reading,  11/16/2017
Mobile Malware Incidents Hit 100% of Businesses
Dawn Kawamoto, Associate Editor, Dark Reading,  11/17/2017
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Managing Cyber-Risk
An online breach could have a huge impact on your organization. Here are some strategies for measuring and managing that risk.
Flash Poll
The State of Ransomware
The State of Ransomware
Ransomware has become one of the most prevalent new cybersecurity threats faced by today's enterprises. This new report from Dark Reading includes feedback from IT and IT security professionals about their organization's ransomware experiences, defense plans, and malware challenges. Find out what they had to say!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.