cyber-crime
Armed with password hashes and salts, attackers could already be kraken those creds
Cybercriminals have reeled in password hashes and corresponding salts belonging to users of popular fishing app Fishbrain, opening the door to cracking attempts.
Fishbrain AB, which says its eponymous app serves more than 20 million anglers, disclosed the August 19 breach to the California Attorney General's Office this week.
The unknown perpetrators helped themselves to a trawl of user data, including names, dates of birth, email addresses, phone numbers, Fishbrain usernames, country information, password hashes, and salts.
"Fishbrain passwords were not stored in plaintext; however, Fishbrain has determined that the compromised password hashes for some users may be susceptible to being decoded," the company said in its disclosure [PDF].
It added: "If you use your Fishbrain password for any other online accounts, you should promptly update those passwords and any associated security questions or answers.
"You should also take other appropriate steps to protect any online accounts that use the same username or email address and password combination. We recommend using a strong, unique password for each of your accounts."
With the hashes and salts in hand, attackers can make password guesses using their own hardware until they potentially recover the original credentials.
Whether those attempts succeed depends on the strength of each password and the hashing algorithm Fishbrain used, which the company did not disclose.
Fishbrain did not comment on the scale of the breach or how many of its claimed 20 million-plus users were affected.
The Register asked Fishbrain for more information.
After discovering the intrusion and conducting an initial forensic investigation, Fishbrain patched the vulnerability and reset every user's password. Customers must create a new one the next time they log in.
Fishbrain also said it "restricted access to the affected environment," strengthened its security controls, and initiated "a broader review of our data security measures" while the investigation continues.
Fisherfolk should also keep an eye out for phisherfolk using the stolen personal data to bait follow-on attacks. ®

2 hours ago
7






English (US) ·