Washington Post Hacked: 1,270,000 Emails and User IDs Compromised
washingtonpost.com
washingtonpost.com
I would be concerned about more targeted phishing attacks: I tend towards using my real name as my username on job websites, and given a list of usernames and emails, I'm very sure you could produce some more believable phishing emails than regularly received.
Edit: Thinking more on this, it would be reasonable in any of these email + username exposures to simply apply a filter of common names, and then use them in a more legitimate looking email. I don't see much of this in my spam (my email address is firstnamelastname@domain.com, and my first name is common), so I would take a stab and say that perhaps the number of people likely to fall for this would not significantly increase with improvement in the quality of the initial email.
From: security@washingtonpost.com
To: [your email]
Subject: Washington Post Vulnerability Update
Dear [name],
Our initial investigation revealed that an unauthorized third party managed
to retrieve the list of user IDs and email addresses associated with
Washington Post Jobs accounts, of which yours was one. Our security team
has performed a more thorough audit of the attack which resulted in the
exposure of your information and has determined that the unauthorized third
party was also able to gain access to encrypted passwords.
Because the passwords were encrypted, it is unlikely that the attackers will
be able to access your Jobs account. However, due to the very small chance
that this unauthorized third party may be able to decrypt your password, we
are requiring every Jobs account holder to change their password within the
next 48 hours. Failure to change your password will result in your account
being permanently locked out.
To further enhance the security of our Jobs site, you will need to specify
your existing password as well as your new password. Your new password must
be at least eight characters long and have one or more upper case letters,
one or more lower case letters, and one or more numbers or symbols. Please
change your password at the following URL:
[link to phishing site that looks like Washington Post's Jobs site with a
realistic password change form that will dutifully accept your email and
current password and enforce the new password requirement for good
appearances]
Sincerely,
Washington Post Jobs Customer Service we are requiring every Jobs account holder to change their password within the
next 48 hours. Failure to change your password will result in your account
being permanently locked out.
That's the bit that got me thinking, but more on the lines of "WTF?!" than recognizing this as a phishing attempt.SPAM is a trademark of Hormel. A synonym for junk email is 'spam'. Whoever wrote this doesn't even recognize the difference. Hell, the author turned 'junk mail' into a proper noun! ("SPAM, aka. Junk Mail ...")
Granted, the WP has a newsroom that is probably entirely separate from whatever org runs their jobs site, but reputation is shared both ways. They're an editorial power-house and should know better.
- Do not sign up at sites with poor site security
Every site will be hacked (eventually). Just use strong passphrase, maybe a password generator like: SuperGenPass when you can, multiple emails, and you should be (relatively) safe.
EG - seed your DB w/known email addresses, see what junk hits them all, follow the money?
http://www.washingtonpost.com/wp-srv/special/politics/electi...
or