I don't think we need to make a great effort to conclude that computer security is going through a disastrous stage. We are still picking up the trash scattered by WannaCry, but now a database with more than 560 million credentials has been discovered online. Most of those credentials had already been leaked in previous incidents, however, the worrying thing is that such a volume of information remains loose on the Web without proper protection.
In recent years we have reported multiple password thefts. It doesn't matter if the size of the database is large or small, the point is that it hasn't lost its profile of "tempting target" for malicious elements. Even if an attacker doesn't obtain passwords, the truth is that email addresses carry significant value, especially among those focused on spam distribution, phishing campaigns, and the ransomware that continues to rise. The latest news comes through the Kromtech Security Research Center. A simple security scan performed on Shodan led to the detection of an exposed device with 560 million credentials, which remains active and unprotected.
The identity of the creator of that database is still unknown, but researcher Bob Diachenko nicknamed it "Eddie", a name that appears inside. Diachenko contacted Troy Hunt, the administrator of the site "Have I Been Pwned", which stores credentials leaked in previous attacks so that users know which services require a password change. Hunt's comparison determined that more than 243 million credentials are based on unique email addresses, and the vast majority was already registered in Have I Been Pwned. In other words, it is a compilation of accounts extracted from old attacks on services such as LinkedIn, Dropbox, Last.fm, MySpace, Adobe, Neopets, Tumblr, and others..
In any case, our recommendation to change passwords on compromised services remains firm. All you need to do is visit Have I Been Pwned, enter your email, and compare the date of the attacks with the age of the password. If you haven't replaced it since then, you know what to do.