Freecycle gives users the gift of a data breach notice
- Reference: 1693923853
- News link: https://www.theregister.co.uk/2023/09/05/freecycle_becomes_the_latest_data/
- Source link:
The charity became aware on August 30 that user data had been "exposed" and [1]issued urgent advice to all members that passwords would need to be changed. It also warned users to beware of an uptick in spam emails due to the details extracted.
Executive director Deron Beal [2]said : "The data breach includes usernames, User IDs, email addresses and hashed passwords."
[3]
Although hashed – Freecycle did not elaborate on the hashing technique used – the exposure of the passwords means that a change would be prudent regardless.
[4]
[5]
Also, if – heaven forbid – that same password has been used elsewhere, those should also be changed. Don't reuse passwords, ok?
Beal went on to say the breach had been closed and regulatory authorities notified. In a separate notification, Freecycle said UK data watchdog ICO and "the appropriate US authorities" were informed.
[6]
While Freecycle did not immediately respond to a request for comment regarding how the data was accessed, Beal warned members: "Please remain vigilant of phishing emails, avoid clicking on links in emails, and don't download attachments unless you are expecting them."
Data from the breach, including Beal's own credentials, [7]reportedly turned up on hacking forums before Freecycle posted its notification.
[8]Attackers accessed UK military data through high-security fencing firm's Windows 7 rig
[9]Apple opens annual applications for free hackable iPhones
[10]More UK cops' names and photos exposed in supplier breach
[11]Health, payment info for 1.2M people feared stolen from Purfoods in IT attack
Beal kicked off US-based Freecycle in 2003, aimed at recycling items for free rather than throwing them away. It began in Tuscon, Arizona and has since spread to more than 110 countries. It is made up of more than 5,000 local town groups with over 9 million members around the world.
The organization has yet to confirm how many of those nine million members have had their details exposed in the attack – although some reports put the figure at seven million. Its advice therefore stands – all members should change their passwords as soon as possible.
Just don't recycle an old one. ®
Get our [12]Tech Resources
[1] https://freecycle.helpscoutdocs.com/article/319-data-breach-august-2023#
[2] https://newswire.freecycle.org/2023/09/01/freecycle-data-breach/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZPdQo7ePCC--odqg2uuGVwAAA0g&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPdQo7ePCC--odqg2uuGVwAAA0g&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZPdQo7ePCC--odqg2uuGVwAAA0g&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cybercrime&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPdQo7ePCC--odqg2uuGVwAAA0g&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://www.bleepingcomputer.com/news/security/freecycle-confirms-massive-data-breach-impacting-7-million-users/
[8] https://www.theregister.com/2023/09/04/zaun_breach_windows_7/
[9] https://www.theregister.com/2023/09/04/infosec_in_brief/
[10] https://www.theregister.com/2023/08/29/met_police_data_breach/
[11] https://www.theregister.com/2023/08/28/purfoods_meal_data_theft/
[12] https://whitepapers.theregister.com/
I've had an email - yesterday, IIRC.
I've changed my password. But, no, I didn't get an email about the breach from Freegle, either.
"...Beal warned members: "Please remain vigilant of phishing emails, avoid clicking on links in emails, and don't download attachments unless you are expecting them.""
Er, with email, that's not how it works. Attachments are part of the email.
You won't normally get bits of an email, you'll get the whole thing, if for no other reason than that it might have a signature - and you can't verify the signature without having the entire email...
Having received it, it's then up to you to do whatever you wish with any attachments that might be in it.
Generally thesedays they're Windows executables, compressed and archived with Zip into a file which is renamed 'something.rar', and which is then archived *again* with zip.
Which was all a waste of time if you then send it to somebody who only runs Linux boxes, but then the average criminal isn't the sharpest tool in the drawer or he wouldn't be your average criminal.
Most of the time, for me at least, all this just means I report them to at least half a dozen organizations who explicitly ask to see copies of spammy and/or malicious messages.
If you're downloading via IMAP you can download attachments separately from the main body.
all members should change their passwords as soon as possible
I wonder when they're going to tell members that. I've been a Freecycle member for years, but I've not seen any emails form them to warn me about this data breach.