New York warns over a million users of top websites may have had data stolen

password_theft_india
(Image credit: Raj N)

New York's lawmakers have warned some of the top online companies that customers may have had login information stolen, and urged them to notify those affected immediately.

The New York State Office of the Attorney General (NY OAG) notified 17 “well-known” companies that more than a million of their customers have had their accounts compromised in credential stuffing attacks. These include online retailers, restaurant chains, and food delivery services, although no specific names were revealed.

While conducting a “sweeping investigation” that lasted many months, OAG monitored multiple online forums where malicious actors shared valid login credentials stolen in previously unknown stuffing attacks. 

Businesses' responsibility

"In all, the OAG collected credentials for more than 1.1 million customer accounts, all of which appeared to have been compromised in credential stuffing attacks,” OAG allegedly said.

"Following discovery of the attacks, the Office of the Attorney General (OAG) alerted the relevant companies so that passwords could be reset and consumers could be notified."

New York Attorney General Letitia James added that businesses have the responsibility to move and protect their customers’ online activities. 

“We must do everything we can to protect consumers’ personal information and their privacy," she concluded.

Credential stuffing is a type of cyberattack in which the attackers “stuff” the target service, such as a social media platform, with millions of accounts stolen elsewhere (for example, if a e-retailer's database gets infected with malware ). They are able to submit millions of credentials almost instantly, thanks to automated solutions. The attacks are used to different ends, including identity theft, or even ransomware attacks.

The practice is extremely widespread, due to countless credentials circulating around the web, as well as the fact that many people often use the same login information (usernames, emails, as well as passwords) across numerous services, as it’s easier to remember and more convenient to use. According to James, there are currently 15 billion stolen credentials that circulate online.

Via: BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Cartoon Phishing
One of the largest data leaks ever sees info on 1.5 billion people leaked online
Cartoon Phishing
Over a billion credentials stolen were stolen in malware attacks in 2024
A man looking at a tablet with a brown Best Buy package on the desk in front of him
Huge Christmas data breach - 14 million shipping records leaked, putting shoppers at risk
Someone checking their credit card details online.
Millions of credit card details leaked online - watch out if you're paying for Christmas
Security padlock and circuit board to protect data
Foh&Boh data leak leaves millions of CVs exposed - KFS, Taco Bell, Nordstrom applicants at risk
Password
Millions of airline customers possibly affected by OAuth security flaw
Latest in Security
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
An option to add Ambient Music buttons to the iOS 18.4 Control Center.
Apple fixes dangerous zero-day used in attacks against iPhones and iPads
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
Nation-state threats are targeting UK AI research
Scam alert
Fake jobs and phone calls: How Americans lost $12.5 bn to fraud in 2024
Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
Google bug bounty payments hit nearly $12 million in 2024
Latest in News
Google Pixel 9
Android 16 could bring an improved Samsung DeX-style desktop mode to more phones
AI writing
ChatGPT just wrote the most beautiful short story, and I wonder what I'm even doing here
Project Moohan prototype at Samsung Galaxy Unpacked, an XR goggles headset on display in a show area
Samsung's Android XR headset could avoid the Apple Vision Pro's biggest mistake, according to this leak
Avast cybersecurity
UK cybersecurity sector could be worth £13bn, research shows
Rivian R1T
Big Rivian update delivers hands-off driving to rival Tesla Autopilot – and a new 'Rally' mode
Google Pixel 9 in Wintergreen showing back camera bar
The Google Pixel 10 could get a big camera boost if this new leak is legit