More than a billion internet credentials have been snagged by one hacking ring

hackers
Yeah, somehow don't think it's quite this easy

If there's one thing everyone should remember about the internet, it's that your data is never truly safe.

Case in point: a Russian cyber gang has made off with around 1.2 billion username and password combos and 542 million email addresses, Hold Security researchers told The New York Times. The publication noted this is the largest collection of stolen internet credentials yet known.

These credentials were reportedly gathered using botnets and SQL injections from around 420,000 different websites, ranging from the very large and to fairly small. The security firm won't name these sites, in part because of nondisclosure agreements, but it has begun alerting them.

The hackers, based in a small city in south central Russia, so far have not sold most of the stolen information, but they are posting spam to social networks in service of other groups.

Hold on for dear life

Hold Security last year discovered a similar heist, with tens of millions of records stolen from Adobe. Apparently they have a solid track record.

Just to be sure, though, the NYT had a third party analyze the data to confirm the researchers' claims.

Meanwhile many of the affected sites remain "vulnerable," Hold Security founder and Chief Information Security Officer Alex Holden said.

Let's just hope we don't have another Target hack fiasco on our hands. The real question is, when will the sites start alerting users?

Michael Rougeau

Michael Rougeau is a former freelance news writer for TechRadar. Studying at Goldsmiths, University of London, and Northeastern University, Michael has bylines at Kotaku, 1UP, G4, Complex Magazine, Digital Trends, GamesRadar, GameSpot, IFC, Animal New York, @Gamer, Inside the Magic, Comic Book Resources, Zap2It, TabTimes, GameZone, Cheat Code Central, Gameshark, Gameranx, The Industry, Debonair Mag, Kombo, and others.

Micheal also spent time as the Games Editor for Playboy.com, and was the managing editor at GameSpot before becoming an Animal Care Manager for Wags and Walks.

Latest in Security
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Dangerous new CoffeeLoader malware executes on your GPU to get past security tools
China
Notorious Chinese hackers FamousSparrow allegedly target US financial firms
A digital representation of a lock
NYU website defaced as hacker leaks info on a million students
NHS
NHS IT supplier hit with major fine following ransomware attack
Businessman holding a magnifier and searching for a hacker within a business team.
Cloud streaming hoster StreamElements confirms data breach following attack
Latest in News
Three angles of the Apple MacBook Air 15-inch M4 laptop above a desk
Apple MacBook Air 15-inch (M4) review roundup – should you buy Apple's new lightweight laptop?
Witchbrook
Witchbrook, the life-sim I've been waiting years for, finally has a release window and it's sooner than you think
Amazon Echo Smart Speaker
Amazon is experimenting with renaming Echo speakers to Alexa Devices, and it's about time
Shigeru Miyamoto presents Nintendo Today app
Nintendo Today smartphone app is out now on iOS and Android devices – and here's what it does
Nintendo Virtual Game Card
Nintendo reveals the new Virtual Game Card feature, an easier way to manage your digital Switch games
Isometric demonstrating multi-factor authentication using a mobile device.
NCSC gets influencers to sing the praises of 2FA