2012 LinkedIn hack

LinkedIn hack

LinkedIn leaked out approximately 6.5 million passwords as of June 8, 2012.
Location Globally
Cause Hack
Website www.linkedin.com

The social networking website LinkedIn was hacked on 5 June 2012, and passwords for nearly 6.5 million user accounts were stolen by Russian cybercriminals.[1][2] Owners of the hacked accounts were no longer able to access their accounts, and the website repeatedly encouraged its users to change their passwords after the incident.[3] Vicente Silveira, the director of LinkedIn,[4] confirmed, on behalf of the company, that the website was hacked in its official blog. He also said that the holders of the compromised accounts would find their passwords were no longer valid on the website.[5]

The stolen passwords, which were in an encrypted format, were decrypted and posted on a Russian password decryption forum later on that day. By the morning of June 6, passwords for thousands of accounts were available online in plain text. Graham Cluley of the internet security firm Sophos warned that the leaked passwords could be in the possession of criminals by 6 June.[6] LinkedIn said, in an official statement, that they would email all its members with security instructions and instructions on how they could reset their passwords.[7]

Reaction by communities and users

Rep. Mary Bono Mack of the United States Congress commented on the incident, "How many times is this going to happen before Congress finally wakes up and takes action? This latest incident once again brings into sharp focus the need to pass data protection legislation." Senator Patrick Leahy said, "Reports of another major data breach should give pause to American consumers who, now more than ever, share sensitive personal information in their online transactions and networking ... Congress should make comprehensive data privacy and cybercrime legislation a top priority."[8][9] Marcus Carey, a security researcher for Rapid7, said that the hackers had penetrated the databases of LinkedIn in the preceding days.[10] He expressed concerns that they may have had access to the website even after the attack. Michael Aronowitz, Vice President of Saveology said, "Everyday hundreds of sites are hacked and personal information is obtained. Stealing login information from one account can easily be used to access other accounts, which can hold personal and financial information." Security experts indicated that the stolen passwords were encrypted in a way that was fairly easy to decrypt, which was one of the reasons for the data breach.[11] Katie Szpyrka, a long time user of LinkedIn from Illinois, USA, filed a $5 million lawsuit against LinkedIn, complaining that the company did not keep their promises to secure connections and databases. Erin O’Harra, a spokeswoman working for LinkedIn, when asked about the lawsuit, said that lawyers were looking to take advantage of that situation to again propose the bills SOPA and PIPA in the United States Congress.[12] An amended complaint was filed on Nov. 26, 2012 on behalf of Szpyrka and another premium LinkedIn user from Virginia, USA, named Khalilah Gilmore–Wright, as class representatives for all LinkedIn users who were affected by the breach.[13] The lawsuit sought injunctive and other equitable relief, as well as restitution and damages for the plaintiffs and members of the class.[13]

Response from LinkedIn

LinkedIn apologized immediately after the data breach, and asked its users to immediately change their passwords.[1] The Federal Bureau of Investigation assisted the LinkedIn Corporation in investigating the theft. As of 8 June 2012, the investigation was still in its early stages, and the company said it was unable to determine whether the hackers were also able to steal the email addresses associated with the compromised user accounts as well.[14] LinkedIn said that the users whose passwords are compromised would be unable to access to their LinkedIn accounts using their old passwords.[15]

Controversy

Internet security experts said that the passwords were easy to unscramble because of LinkedIn's failure to use a salt when hashing them, which is considered an insecure practice because it allows attackers to quickly reverse the scrambling process using existing standard rainbow tables, pre-made lists of matching scrambled and unscrambled passwords.[16] Another issue that sparked controversy was the iOS app provided by LinkedIn, which grabs personal names, emails, and notes from a mobile calendar without the user's approval.[17] Security experts working for Skycure Security said that the application collects a user's personal data and sends it to the LinkedIn server. LinkedIn claimed the permission for this feature is user-granted, and the information is sent securely using the Secure Sockets Layer (SSL) protocol. The company added that it had never stored or shared that information with a third party.[18]

References

  1. 1.0 1.1 "An update on the hack". Linkedin. Retrieved June 8, 2012.
  2. "Hackers steal 6.5 million passwords from LinkedIn". Herald Sun. Retrieved June 8, 2012.
  3. "LinkedIn Confirms, Apologizes for Stolen Password Breach". Mashable.com. Retrieved June 8, 2012.
  4. "LinkedIn busy to investigate". The Economic Times. June 10, 2012. Retrieved July 20, 2012.
  5. "Update:Linked in confirms it is hacked". Pc world.com. Retrieved June 8, 2012.
  6. Waugh, Rob (June 7, 2012). "I wish I was dead: Every LinkedIn User". London: Dailymail.co.uk. Retrieved June 8, 2012.
  7. "Data breach at LinkedIn". NDTV Profit. Retrieved June 8, 2012.
  8. "LinkedIn Passwords Leaked... Congress Immediately Wants To 'Do Something!'". Techdirt.com. Retrieved June 8, 2012.
  9. Sasso, Brendan (6 June 2012). "Lawmakers concerned by report that LinkedIn passwords were stolen". Hillicon Valley. Retrieved 25 July 2012.
  10. "Hacker claims to have stolen millions of passwords". The Mercury News. Retrieved June 7, 2012.
  11. "Over 6 million encrypted LinkedIn passwords leaked online" (Press release). Margate, FL: PRWeb. Retrieved April 18, 2013.
  12. "LinkedIn sued for $5 million over hacked passwords". The News Tribe.com. Retrieved June 23, 2012.
  13. 13.0 13.1 Constantin, Lucian (March 6, 2013). "LinkedIn wins dismissal of lawsuit seeking damages for massive password breach". PC World. IDG News Service. Retrieved April 3, 2012.
  14. "FBI to help LinkedIn". Gadgets.NDTV.com. Retrieved June 8, 2012.
  15. "LinkedIn gets hacked". Fox10TV.com. Retrieved June 8, 2012.
  16. "LinkedIn suffers data breach-security experts". Reuters. June 6, 2012. Retrieved June 8, 2012.
  17. Kingsley-Hughes, Adrian. "LinkedIn ios app grabs names, emails, notes- from your calendar.". Forbes.com. Retrieved June 8, 2012.
  18. "LinkedIn iOS app privacy issues concern people". Mashable.com. Retrieved June 8, 2012.