Timehop Breach – 21 Million users’ data stolen
The Independent is reporting that Timehop is at the centre of a huge hack
People who have used the app – which gets access to social media accounts and then flags up interesting events that happened in the past – may have had some of their most sensitive information stolen during the breach, Timehop said.
The app says 21 million of its users were caught up in the attack, and that it was still checking whether earlier breaches had occurred. Since many people use the app only in passing, many of those users may no longer be actively using the app.
But it also strongly advised that people secure their phone numbers, which were leaked in the attack. When that happens – and when it is combined with personal information – it is relatively easy for hackers to “port” the number so that they can receive text messages, potentially giving them access to a whole host of other accounts.
That can be protected against by adding a pin to your phone account, or asking the network to stop the number from being ported.
Read more from The Independent at TIMEHOP HACK: 21 MILLION USERS’ DATA STOLEN IN HUGE BREACH
Timehop have since released further information regarding the breach in their updated security report which now adds dates of birth, gender of users and country codes to the list.
The breach occurred because an access credential to our cloud computing environment was compromised. That cloud computing account had not been protected by multifactor authentication. We have now taken steps that include multifactor authentication to secure our authorization and access controls on all accounts.
Read more from Timehop at TIMEHOP SECURITY INCIDENT, JULY 4TH, 2018
PENETRATION TESTING SERVICES BASED IN EXETER, DEVON
Pentesting UK is based in Exeter, Devon helping organisations identify their vulnerabilities, through penetration testing, ASV scanning, application testing and vulnerability scanning for businesses and organisations across the UK and beyond. Contact us for more info…
