Security News > 2021 > January > Hacker blunder leaves stolen passwords exposed via Google search

Hacker blunder leaves stolen passwords exposed via Google search
2021-01-21 07:12

Hackers hitting thousands of organizations worldwide in a massive phishing campaign forgot to protect their loot and let Google index the stolen passwords for public searches.

The phishing campaign has been running for more than half a year and uses dozens of domains that host the phishing pages.

Researchers at cybersecurity companies Check Point and Otorio analyzing this campaign discovered that the hackers exposed the stolen credentials to the public internet.

Researchers at the two cybersecurity companies say that the attackers also compromised legitimate WordPress servers to host the malicious PHP page delivered to victims.

The attackers used several phishing email themes to lure potential victims into loading the landing page that collected their Microsoft Office 365 username and password.

While Google indexing hackers' pages where they save stolen data is not a first, it shows that not all malicious actors are sufficiently skilled to protect their operations.


News URL

https://www.bleepingcomputer.com/news/security/hacker-blunder-leaves-stolen-passwords-exposed-via-google-search/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Google 141 995 4851 2764 1620 10230