Data breach Cit0day: HIBP notifications arrive

Data breach Cit0day: HIBP notifications arrive
A couple of weeks ago, the Cit0day.in data breach led to the sharing of archives containing a total of over 23,000 compromised databases on various forums dedicated to hacking and Telegram channels. One of the consequences is that these days many are receiving a notification from the well-known Have I Been Pwned service by researcher Troy Hunt.

Have I Been Pwned: Cit0day data breach alerts

By who was not aware of it, Cit0day (now no longer operational) offered paid access to usernames, email addresses, passwords and other confidential data. In short, a service from cybercriminals for cybercriminals, similar to what LeakedSource and WeLeakInfo have been closed in the past in 2018 and this year respectively. Packages were available for daily or monthly use. Opened in January 2018, it remained online until September 2020 when affected by a seizure order executed by the FBI and the US Department of Justice.

The notice sent by HIBP speaks of a total of 226.8 million Compromised accounts.



The email contains details of the affected profiles. Credentials are currently circulating freely, so for the sake of your security and that of your data, the least you can do is change your password as soon as possible.



Troy Hunt himself who conducted the analysis of the information contained in the archives states that a good percentage of the credentials had never been stolen, not even in the mega-collection called Collection # 1- # 6 circulated at the beginning of last year.

Source: Troy Hunt