News: 1653522255

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Millions of people's info stolen from MGM Resorts dumped on Telegram for free

(2022/05/26)


Miscreants have dumped on Telegram more than 142 million customer records stolen from MGM Resorts, exposing names, postal and email addresses, phone numbers, and dates of birth for any would-be identity thief.

The vpnMentor research team [1]stumbled upon the files, which totaled 8.7 GB of data, on the messaging platform earlier this week, and noted that they "assume at least 30 million people had some of their data leaked." MGM Resorts, a hotel and casino chain, did not respond to The Register 's request for comment.

The researchers reckon this information is linked to the [2]theft of millions of guest records, which included the details of Twitter's Jack Dorsey and pop star Justin Bieber, from MGM Resorts in 2019 that was subsequently distributed via underground forums.

[3]

But while crooks initially [4]sold those 142 million records on a dark-web marketplace for about $3,000 as a packaged deal, this time the data is freely available on Telegram, which vpnMentor rightly describes as "much more accessible for even the least tech-savvy people."

[5]

[6]

Perhaps the recent [7]takedown of stolen-data market RaidForums and the Hydra [8]dark-web souk has something to do with this? Or that the info is no longer worth selling, or no one's interested in buying it, perhaps.

According to the VPN services company, the data dumped on Telegram includes the following customer information from before 2017:

Full names

Postal addresses

Over 24 million unique email addresses

Over 30 million unique phone numbers

Dates of birth

In other words: everything an identity theft would need to get started. No unencrypted payment details, we note, but still not great.

As the researchers noted: "Bad actors could send phishing messages and scams to exposed users via SMS and email, using the victims' full names and home or business addresses to build trust."

[9]We know what you did last summer: MGM's hotel spinoff lost 10.7m guest records and now they're on hacker forums

[10]Stolen-data market RaidForums taken down in domain seizure

[11]Ukrainian crook jailed in US for selling thousands of stolen login credentials

[12]FBI: Cyber-scams cost victims $6.9b-plus worldwide in 2021

Since that MGM Resorts security breach is two-plus-years-old, the customers' whose data has been exposed (again) may not expect to be targeted, the cyberexperts explained. Additionally, miscreants may "target elderly people (thanks to the detail regarding the date of birth) and try to scam them as an easier target," vpnMentor warned.

The hotel guests' data leak comes as automaker General Motors this week [13]confirmed the credential-stuffing attack it suffered last month exposed customers' names, personal email addresses, and destination data, as well as usernames and phone numbers for family members tied to customer accounts.

[14]

And once again, identity theft made the top-five list for the most reported cyberscams, according to the FBI's annual Internet Crime Report.

The [15]report with 2021's statistics, which was published earlier this month, recorded 51,629 identity-theft complaints last year, compared to 43,330 in 2020 — that's a 19 percent increase. These crimes cost businesses and individuals more than $278 million in losses last year, according to the bureau. ®

Speaking of violated privacy... Twitter has [16]settled with America's FTC and Dept of Justice, and agreed to cough up $150 million, for allegedly breaking consumer-protection law by "misrepresenting how it would make use of users’ nonpublic contact information."

Specifically, between 2013 and 2019, Twitter asked for users' email addresses and phone numbers to secure their accounts and [17]didn't tell anyone it was using that information for targeted advertising, prosecutors said on Wednesday. That drew the ire of the FTC and the DoJ, leading to a lawsuit and today's proposed settlement.

Get our [18]Tech Resources



[1] https://www.vpnmentor.com/blog/mgm-leaked-on-telegram/

[2] https://www.theregister.com/2020/02/20/mgm_loses_ten_million_guest_details/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yo77aJiQNDP@0VqkU0d8ZgAAAA0&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://www.zdnet.com/article/a-hacker-is-selling-details-of-142-million-mgm-hotel-guests-on-the-dark-web/

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yo77aJiQNDP@0VqkU0d8ZgAAAA0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yo77aJiQNDP@0VqkU0d8ZgAAAA0&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[7] https://www.theregister.com/2022/04/12/raidforums_market_arrest/

[8] https://www.theregister.com/2022/04/05/us_germany_hydra/

[9] https://www.theregister.com/2020/02/20/mgm_loses_ten_million_guest_details/

[10] https://www.theregister.com/2022/04/12/raidforums_market_arrest/

[11] https://www.theregister.com/2022/05/13/ukrainian_credentials_botnet/

[12] https://www.theregister.com/2022/05/05/fbi_cyber_scams/

[13] https://www.theregister.com/2022/05/25/gm-credential-stuffing-attack/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yo77aJiQNDP@0VqkU0d8ZgAAAA0&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[15] https://www.theregister.com/2022/05/05/fbi_cyber_scams/

[16] https://www.justice.gov/opa/pr/twitter-agrees-doj-and-ftc-pay-150-million-civil-penalty-and-implement-comprehensive

[17] https://www.theregister.com/2019/10/09/twitter_data_leak/

[18] https://whitepapers.theregister.com/



Yet again

HildyJ

I have two identity protection services as settlements for two different breaches years ago. From their scans, at this point, everything needed for a phishing attack is available for purchase or free.

Stories like this are interesting to me only to see who got hit this time.

While I assume everybody reading this takes appropriate precautions, the masses have yet to be convinced that they need to change their behavior.

This isn't the old internet (if it ever was).

DOB?

Rustbucket

Why the hell do you need date of birth to check into an hotel or resort?

They wouldn't listen to the fact that I was a genius,
The man said "We got all that we can use",
So I've got those steadily-depressin', low-down, mind-messin',
Working-at-the-car-wash blues.
-- Jim Croce