LinkedIn hit by 6.5m password leak

Powered by SC Magazine

Users warned of phishing attempts.

Social networking site LinkedIn has confirmed claims of a breach to user accounts on the social network after a file containing almost 6.5 million passwords for the site was leaked to a Russian internet forum.

After initially investigating reports of the breach at about 11pm AEST, LinkedIn director Vincente Silveira confirmed that "some of the passwords that were compromised correspond to LinkedIn accounts".

Some users reported finding their password as hashes on the leaked list, a 118 MB ZIP file posted online sometime overnight.

BBC News reported that the alleged hackers were seeking help to decrypt the password file.

Silveira said affected users would be prompted to change their passwords when they next logged into the social network and would receive further information on the issue in near future.

"It is worth noting that the affected members who update their passwords and members whose passwords have not been compromised benefit from the enhanced security we just recently put in place," Silveira said.

The enhanced security, he said, included hashing and salting of password databases, a measure security researchers said was not available on the passwords leaked overnight.

Both Silveira and F-Secure's Mikko Hypponen warned users to "prepare for scam emails about Linkedin password changes, linking to phishing sites".

iOS security

The breach comes less than a day after researchers discovered poor security practices in LinkedIn’s iOS app, which appeared to send detailed calender entries entered by users – including times, addresses and personal meeting notes – to its servers without encryption.

Adi Sharabani and Yair Amit said transmission of the calendar entries took place without prompting or warning users.

LinkedIn denied the notion of information being transmitted without user approval.

"In order to provide our calendar service to those who choose to use it, we need to send information about your calendar events to our servers so we can match people with LinkedIn profiles," mobile product head Joff Redfern said.

"That information is sent securely over SSL and we never share or store your calendar information."

The social network committed to stop sending data from user-added meeting notes in the iOS app to LinkedIn servers, Redfern said.

LinkedIn reports some 150 million users currently.

Copyright © . All rights reserved.

LinkedIn hit by 6.5m password leak
Top Stories
Westpac interim CIO resigns
Group CIO yet to be appointed.
Earning the right to innovate
Breaking down the barriers to innovation is a long, but rewarding process, says Bank of Queensland Group CIO, Julie Bale.
A call for timely reporting
[Blog post] Businesses need incentives to keep customer data secure.
Sign up to receive iTnews email bulletins
Latest Comments
What is delaying adoption of public cloud in your organisation?

   |   View results
Lock-in concerns
Application integration concerns
Security and compliance concerns
Unreliable network infrastructure
Data sovereignty concerns
Lack of stakeholder support
Protecting on-premise IT jobs
Difficulty transitioning CapEx budget into OpEx