Hackers published large amounts of stolen data for free on the dark web just days before Christmas, cybersecurity company Resecurity said in a recent report. The leaked trove includes over 50 million records, like phone numbers, national identity card numbers, financial data, and other personally identifiable information.
“Numerous leaks disseminated in the underground world were tagged with ‘Free Leaksmas,’ indicating that these significant leaks were shared freely among various cybercriminals as a form of mutual gratitude,” Resecurity said in its report on Dec. 27.
Leak Affects People From Different Parts of the World
The leak affects individuals across the world, most notably (34.02%), the U.S. (22.18%), and the Philippines (17.90%). While some of the leaked data was stolen in breaches from previous years, they had not been shared for free on the dark web until now. And, it’s unlikely victims have updated their personal information since then, Resecurity said.
The largest leaked datasets were from Peruvian telecom company Movistar, with 22 million records published, and 15.77 GB of data from a major credit service in the Philippines. Cybercriminals also shared data from a French company, a Swedish fintech project, a Vietnam-based fashion store, an online military gear shop in Italy, and even a sushi restaurant in Russia, among others.
According to Resecurity, the winter holidays usually mark a period of intensified activity on the dark web. “During this period, there is an expected increase in financial fraud and activities driven by financial motives, as these actors take advantage of the festive season to escalate their illicit operations,” Resecurity explained.
While cybercriminals have mainly targeted individuals and organizations in North America in the past, they’re increasingly broadening their scope to include other regions, like Latin America and Asia Pacific.
“These areas are experiencing a rapid evolution in the digital economy, marked by the emergence of new fintech products and marketplaces. The growth, however, is also attracting malicious actors who aim to exploit these developments to defraud customers,” Resecurity said, emphasizing the need for “robust Digital Identity Protection programs.”
How to Keep Your Personal Information From Cybercriminals
Cybercriminals can exploit leaked data to conduct other nefarious exploits. The leaks “will inevitably result in them [victims] facing a host of adverse effects, such as account takeovers (ATO), business email compromises (BEC), identity theft, and financial fraud,” Resecurity warned.
It’s important to take steps to protect your data from falling into the hands of cybercriminals and strengthen your security measures if your data is exposed. Some ways to stay safe online include:
- Using strong, unique passwords for your online accounts, mixing different characters, and avoiding easily guessable information.
- Enabling two-factor authentication (2FA) wherever possible to add an extra layer of security to your accounts.
- Regularly updating your operating system, applications, and antivirus software to patch known vulnerabilities.
- Exercising caution with unsolicited emails, especially those requesting personal information or containing suspicious links or attachments.
- Routinely reviewing your bank and credit card statements for any unauthorized transactions.
- Using a solid virtual private network (VPN), like NordVPN, when accessing the internet, particularly when you’re on public Wi-Fi networks, to encrypt your connection.
For more news, follow us on X (Twitter), Threads, and Mastodon!
