Threat Intelligence Brief
Curated summary with source attribution
Source: haveibeenpwned.com
Threat Risk: Medium
Victim: Fanlore users
Incident: Unauthorized access to the Fanlore wiki resulting in a data leak.
Impact: Exposure of 145k email addresses and password hashes.
Attacker: Unidentified threat actors
Analysis: Threat actors gained unauthorized access to the Fanlore wiki, compromising approximately 145k unique email addresses. The leak includes usernames and password hashes, with some stored using the weak MD5 algorithm, significantly increasing the risk of successful credential cracking.
Recommendations: Update passwords immediately for any account sharing credentials used on Fanlore; Enable multi-factor authentication (MFA) on all sensitive accounts; Adopt a password manager to ensure unique, complex passwords for every service
Source: Have I Been Pwned
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source