An anonymous reader quotes a report from Bleeping Computer: Over 500,000 Zoom accounts are being sold on the dark web and hacker forums for less than a penny each, and in some cases, given away for free. These credentials are gathered through credential stuffing attacks where threat actors attempt to login to Zoom using accounts leaked in older data breaches. The successful logins are then compiled into lists that are sold to other hackers. Some of these Zoom accounts are offered for free on hacker forums so that hackers can use them in zoom-bombing pranks and malicious activities. Others are sold for less than a penny each.

Cybersecurity intelligence firm Cyble told BleepingComputer that around April 1st, 2020, they began to see free Zoom accounts being posted on hacker forums to gain an increased reputation in the hacker community. These accounts are shared via text sharing sites where the threat actors are posting lists of email addresses and password combinations. The purchased accounts include a victim’s email address, password, personal meeting URL, and their HostKey. Cyble has told BleepingComputer that these accounts include ones for well-known companies such as Chase, Citibank, educational institutions, and more. You can use Have I Been Pwned and Cyble’s AmIBreached to check if your email address has been leaked in a data breach.

of this story at Slashdot.

…read more

Source:: Slashdot