Hacked police forum accounts for sale on the dark web

1

https://thearabianpost.com/wp-content/uploads/2017/02/1486166620_998_www.zdnet.com

(Image: file photo)

A data broker is selling hundreds of thousands of accounts used by police and federal agents from a hacked law enforcement forum.

The database is said to have been stolen in 2015, and contains 715,000 records on members who have registered with PoliceOne.com, a news site and community for police officers and law enforcement professionals.

ADVERTISEMENT

According to a posting on a dark web marketplace, the stolen data includes usernames, passwords stored in MD5 (an algorithm that nowadays is easy to crack), email addresses, dates of birth, and other forum data, such as if a member is a verified law enforcement officer.

Many of the forums are private and can only be accessed by members, or in some cases verified law enforcement officials who have submitted their badge numbers or other identifying information, but this does not appear to be part of the leaked database.

The data is being sold for $400, according to the listing, which we are not linking to.

https://thearabianpost.com/wp-content/uploads/2017/02/1486166620_998_www.zdnet.com

(Screenshot: ZDNet)

The seller of the data, who went by the name Berkut, reached out to me over encrypted chat and provided a sample of data for verification.

We reached out to a couple of dozen members by email who were listed in the breach, but we didn’t immediately hear back. (We will update the story if that changes.)

Many of the accounts in the database included email addresses associated with the FBI and Homeland Security.

Berkut said the SQL database was dumped by using a known exploit for the forum software.

At the time of writing, the forums are powered by vBulletin software dating back to 2014, which is known to contain several easily exploitable vulnerabilities known by hackers.

The forums were pulled offline late on Friday after we informed the site of the breach.

A spokesperson for PoliceOne said it had “confirmed the credibility of a purported breach,” but was working on verification.

“We have confirmed the credibility of a purported breach of the PoliceOne forums in which hackers were potentially able to obtain usernames, emails and hashed passwords for a portion of our members,” the spokesperson said.

“While we have not yet verified the claim, we are taking immediate steps to secure user accounts and our forums, which are currently offline while we investigate and gather more information.”

The site said it will be notifying affected users and require them to change passwords.

(via PCMag)

ADVERTISEMENT

ADVERTISEMENT
Just in:
UAE and Ecuador Set Course for Economic Pact // Zayed Center Unveils Roadmap for Global Heritage Preservation // Migrity Business Talent Academy Announces Innovative AI Entrepreneurship // Emirates Red Crescent Recognizes Seniors’ Contributions // Russian Luxury Spa in Dubai // New Report from Sinergia Animal Reveals Financial Institution’s Lag in Animal Welfare and Food System Sustainability Policies // Brazilian Fintech Giant Nubank Embraces Cryptocurrencies // LUX Celebrates A Century Of Unmatched Fragrance With “Still There” Campaign // Empty Promises Haunt DAO Maker Hack Victims After Three Years // Landmark Border Deal Between Azerbaijan and Armenia Welcomed by UAE // Leading the innovation in cryptocurrency trading, Qmiax Exchange has updated its OTC fiat exchange process // PM Narendra Modi’s Frustration Mounting On His Stronghold Too // Ten Perish in Mid-Air Collision of Malaysian Navy Helicopters // Shaping the future crypto trading of compliance, Qmiax has launched a brand-new user interface and trading process // Municipalities Strengthen Ties Through New Secretariat // Sasin Impact Entrepreneurship Week 2024: Inspire, Connect, Transform for a better, smarter, sustainable world // Crypto Exchange Crypto.com Delays South Korean Launch for Regulatory Discussions // China Railway Construction Corporation: Breakthroughs in Early 2024 Drive the Railways Modernisation // SEC Targets Terraform Labs, Do Kwon in $5.3 Billion Fraud Case // Crypto Advocacy Groups Challenge SEC Rule //