Story image

Chinese threat actor linked to leak of more than 200 million Japanese PII datasets

21 May 2018

More than 200 million pieces of personal information harvested from Japanese website databases have been spotted for sale on underground forums.

Leaked personal information includes names, credentials, email addresses, dates of birth, phone numbers, and home addresses.

Security firm FireEye uncovered the databases for sale in December 2017 and says the information is most likely authentic.

The Japanese databases were harvested from May-July 2013 and May-June 2016 and appear to be from between 11-50 websites. The websites include those in the retail, entertainment, financial, food and beverage, and transportation sectors.

FireEye believes the data is genuine for a number of reasons, particularly because the data was varied and not available through public data sources. However, many of the datasets were duplicates.

“Out of a random sample of 200,000 leaked email addresses, the majority were previously leaked in major data leaks. This indicates that the email addresses sold in these datasets were unlikely to be fabricated specifically for this data leak,” FireEye adds.

According to a sample of more than 190,000 credentials, 36% contained duplicate values. There were also fake email addresses, suggesting that the number of genuine credentials and sets of PII is ‘significantly lower than advertised’, FireEye says.

“Due to the low-profile nature of most of these websites and possible negative effects on the actor's reputation, the actor selling the data has little incentive to falsify the data sources,” the firm adds.

The threat actor, who was asking ¥1,000 CNY ($150.96 USD), has been selling databases on Chinese underground forums since 2013. While several buyers were interested in buying the dataset, many complained that they did not get the product that was advertised.

The identity of the seller behind this latest dataset is connected to a personal living in China’s Zheijiang province, FireEye speculates.

“The actor sells data exfiltrated from websites in China, Taiwan, Hong Kong, European countries, Australia, New Zealand, and North American countries. We also found two other personas likely connected to this actor through a common QQ address. This QQ address is also connected to an individual living in China’s Zhejiang province,” FireEye explains.

“As the actor has a significant portion of negative reviews on underground forums, it is still possible that the information is fabricated or contains data previously sold by the actor. Notably, negative reviews linked to this vendor claim that the actor does not deliver data or does not provide the product that the buyer expected.”

The company warns that while the dataset will most likely not precede large-scale attacks against entities or individuals caught in the leak, the information could be used to target other entities if individuals reused credentials between the compromised websites and other personal or business-related accounts.

“The lists of leaked email addresses and PII can also facilitate identity theft, spam and malware propagation, and fraud,” FireEye concludes.

Ping Identity offerings accelerates cloud MFA and SSO adoption
90% of respondents trust MFA as an effective security control to protect identity data in public clouds, yet only 60% of organisations have formally adopted it.
Trend Micro introduces cloud and container workload security offering
Container security capabilities added to Trend Micro Deep Security have elevated protection across the DevOps lifecycle and runtime stack.
Veeam joins the ranks of $1bil-revenue software companies
It’s also marked a milestone of 350,000 customers and outlined how it will begin the next stage of its growth.
Veeam enables secondary storage solutions with technology partner program
Veeam has worked with its strategic technology alliance partners to provide flexible deployment options for customers that have continually led to tighter levels of integration.
Veeam Availability Orchestrator update aims to democratise DR
The ability to automatically test, document and reliably recover entire sites, as well as individual workloads from backups in a completely orchestrated way lowers the total cost of ownership (TCO) of DR.
Nuix eyes legal sector as eDiscovery demand skyrockets
eDiscovery must encompass so much more than email and documents. If you haven’t looked at text messages and online chats, digital images, mobile devices, data in the cloud and social media, you’re not getting the whole story.
EXCLUSIVE: Forcepoint global channel chief talks strategy
As a solution sold 100% via the channel, cybersecurity solutions company Forcepoint places a strong emphasis on its partner relationships.
Salesforce continues to stumble after critical outage
“To all of our Salesforce customers, please be aware that we are experiencing a major issue with our service and apologise for the impact it is having on you."