Popular PDF reader has database of 77 miliion users hacked and leaked online

PDF
(Image credit: Kaspersky)

Sensitive information relating to thousands of users of the Nitro PDF reader has been leaked online. Back in October, Nitro admitted to what it described as a "low impact security incident" but claimed that no customer data was impacted. This now appears to have been false.

A threat actor claiming to be part of the ShinyHunters hacking group has leaked a 14 GB database containing 77,159,696 Nitro records with users' email addresses, full names, bcrypt hashed passwords, company names, IP addresses, and other system-related information.

In fact, it’s been clear for a few months now that customer information was likely to have been affected by last October’s data breach. A database containing information relating to 70 million Nitro PDF user records, along with 1TB of documents, was auctioned shortly after the breach came to light for $80,000.

The going rate

The hacker claiming to be part of ShinyHunters is now offering the Nitro database for download on a well-known hacking forum, asking just $3 for access. The records could be used by malicious actors to carry out follow-up attacks, including phishing campaigns or credential stuffing attempts.

The ShinyHunters group gained notoriety last year after it claimed responsibility for several huge hacks and made the stolen credentials available online. The hackers also have form when it comes to giving away records for free, doing so in July last year just days after selling the same information for thousands of dollars.

If any Nitro users suspect that their details may have been compromised by the ShinyHunters hack, they are advised to change their password immediately. And, of course, if those credentials are shared with other services, they too should be changed.

Via Bleeping Computer

Barclay Ballard

Barclay has been writing about technology for a decade, starting out as a freelancer with ITProPortal covering everything from London’s start-up scene to comparisons of the best cloud storage services.  After that, he spent some time as the managing editor of an online outlet focusing on cloud computing, furthering his interest in virtualization, Big Data, and the Internet of Things. 

Latest in Security
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Code Skull
US government warns Medusa ransomware has hit hundreds of critical infrastructure targets
An American flag flying outside the US Capitol building against a blue sky
The FCC is creating a security council to bolster US defenses against cyberattacks
Latest in News
Man using iMessage on an iPhone
Apple will finally enable encrypted RCS messages between iOS and Android, and it's about time
Jason Sudeikis' Ted Lasso pointing at someone in Ted Lasso season 2
Believe it, baby: Ted Lasso season 4 is officially in development for Apple TV+ and Jason Sudeikis will reprise his role as the titular soccer coach
Quordle on a smartphone held in a hand
Quordle hints and answers for Saturday, March 15 (game #1146)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Saturday, March 15 (game #377)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Saturday, March 15 (game #643)
Wix automation
The world's leading website builder aims to save businesses time with new tool