丹麦IT公司Pays ApS因使用弱密码"123456"遭黑客入侵,导致大规模数据泄露事件1。黑客利用该公司至少三个账户(包括管理员账户)的该弱密码获得访问权限,约880万份丹麦CPR中央民事登记数据库记录因此遭到泄露1。黑客的访问权限从9月10日起持续了21天17小时1。
Pays ApS公司管理总监Sophie Laursen确认了公司遭到攻击1。黑客声称初始访问是通过获得的前员工密码实现的,并向媒体Politiken表示没有计划出售或发布这些信息1。奥胡斯大学教授Jens Myrup Pedersen评价该公司的安全措施状况,指出"没有真正的安全措施,这是一扇敞开的门"1。根据丹麦中央商业登记处的数据,Pays ApS截至2026年7月仅有两名员工1。
Danish IT company Pays ApS fell victim to a cyberattack that exposed approximately 8.8 million CPR (Central Civil Registration) records, with the breach facilitated by the use of a simple password across multiple accounts.1 The attackers gained access through at least three company accounts—including an administrator account—that all used the password "123456," according to security investigations.1 The unauthorized access persisted for 21 days and 17 hours beginning September 10, 2024.1
Company management director Sophie Laursen confirmed the attack on Pays ApS.1 Security researchers characterized the organization's password security practices as inadequate, with Aarhus University professor Jens Myrup Pedersen describing the situation as having "no real security measures" and calling it "an open door."1 The initial breach reportedly occurred through credentials belonging to a former employee, as claimed by the attackers.1 However, the threat actors told Danish publication Politiken that they have no plans to sell or publicly release the compromised data.1
评论
还没有评论,欢迎留下第一条。