Skip to content
View in the app

A better way to browse. Learn more.

Security Installer Community

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

22 million records exposed in mystery "db8151dd" breach

Featured Replies

Concerning thing here is the way this data is structured with interactions between people as well as private information like job titles and phone numbers.

https://www.troyhunt.com/the-unattributable-db8151dd-data-breach/

  • Author

Indeed, the source is still TBD too.

I would say that UUID on the data will make it traceable to somewhere, it may transpire where and how it got leaked in the near future.

The suggestion was that the data was related to linkedin as people could only find their 'special' linkedin email in the breach.

 

I do the same - linkedin@domain.com as I do for everything e.g. securitywarehouse@domain.co.uk which means compromise on one only hands over the keys to all if the passwords are the same

(sometimes they are, sometimes not) and a switched on human spots that they need to substitute the recipient part of the email - and it is not always as plain and obvious. My paypal login for example,

is NOT paypal@domain.com.

 

I've tried on the 'Have I Been Pwned' site and cannot find anything for any of my domains let alone the linkedin one

 

In fact, searching my surname suprisingly only brings up a single result I know isn't me as it relates to a single ancient exploit of a forum on a weed smoking enthusiasts site!

Edited by datadiffusion
Forgot this was public, domain redacted

So, I've decided to take my work back underground.... to stop it falling into the wrong hands

 

  • Author

I feel it's source is from some social platform like that or something like a calender app that links all these together e-mail, meetings with contact details etc. Even having separate email usernames only narrows it down so far.

Don't think it's right to speculate TBH you can cause an unnecessary panic, people that are around these breaches have been trying to find the source for several months now, it's taken that long to add it all on to HIBP.

The one piece of information to take away from these breaches is don't re-use passwords.

 

Create an account or sign in to comment

Recently Browsing 0

  • No registered users viewing this page.

Important Information

By using this site, you agree to our Terms of Use.

Account

Navigation

Search

Search

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.