What Is The Mother Of All Breaches?

7th March 2024

In January 2024, a data leak of 26 billion records was discovered by security researcher Bob Diachenko of Security Discovery. This data breach has quickly come to be known as The Mother Of All Breaches (aka MOAB) due to its size and contains 12 terabytes of user data from 3,876 domains. The largest amount of records comes from the Chinese instant messaging app Tencent QQ, with 1.4 billion records included in the breach. Other popular websites were also included in the MOAB data breach including MySpace, LinkedIn, Weibo, Twitter, Adobe, and more.

What We Know So Far About The Mother of All Breaches

  • The data leaked appears to come from a combination of many breaches, and much of the data is duplicated, old or outdated, although a significant portion appears to be new
  • The MOAB contains data from privately sold databases, reindexed leaks, and other data breaches
  • Data included in the breach is both login credentials as well as more potentially sensitive data
  • The dataset was held by the data breach search engine Leak-Lookup, which blamed a “firewall misconfiguration” for the leak
  • As well as social media sites like X (formerly Twitter) and Weibo, the leak also includes data from various government organisations from all over the world

Who is Responsible for The Mother of all Breaches?

So far, no one has been caught or claimed responsibility for the MOAB data breach. It is likely that whoever is responsible for the MOAB has a ‘vested interest’ in storing large amounts of data, and could be a data broker, a hacker or other threat actor who wishes to sell the data or leverage it for identity theft, targeted cyberattacks, or other illegal acts. Individuals whose data was included in the MOAB could find themselves victims of spear phishing attacks, or receive a large amount of spam emails. Researchers believe that an initial access broker (one who infiltrates networks and computer systems to sell access and data to other malicious actors) could have accessed and compiled the data intending to sell it on the dark web.

What is the Potential Impact of The Mother Of All Breaches?

So far the impact has been minimal, although we would strongly recommend checking to see if your data was included in this MOAB leak by going to the CyberNews Data Leak Checker or visiting haveibeenpwned.com. These databases are being updated as we speak and should soon include information about the MOAB breach. You can also search the full list of domains involved here.

How Can I Keep My Data Safe From Future Data Breaches?

Use strong, hard-to-guess passwords.

Avoid using information related to you or your family, e.g. birth dates or names. An ideal password is a mixture of letters, numbers and special characters which has no relation to you.

Sign up for alerts at haveibeenpwned.com. 

This will let you know if any of your accounts have been compromised or included in a data breach.

Do not store passwords in a browser and avoid writing down your passwords.

This includes writing them down physically in a notebook or on a post-it as well as writing them in a group chat, online or offline document or similar. If you have trouble remembering passwords, use a secure password vault such as 1Password, Nordpass, Dashlane or similar. 

Change your passwords frequently.

If someone has your password, changing it often limits their ability to log into your account and minimises any potential harm. Always change your password if you suspect it could be involved in a data breach, if someone else finds out your password, or if you lose your computer or phone.

Don’t use the same password for everything.

If you use the same password for your email as you do for your Facebook or Netflix account, or more, then if one gets leaked, someone could potentially have access to all of your online accounts.

Use 2-factor or multi-factor authentication.

This means that as well as logging in with a username or email and password, a website or system also requires another form of authentication to allow you to log in, this could be in the form of a code that gets emailed or texted to you, or the use of authentication apps like Google Authenticator. 

Sign up for a credit reference monitoring service

If any financial records have been involved sign up for one of the main credit referencing agencies monitoring services. It may cost you a small subscription fee, but it could save you thousands of pounds and if your data was involved in a breach, you may be able to claim the cost back from the relevant Controller.

Follow this story and find out more here.

 

Author: Paul Adams LLB (HONS)

Paul is an information governance specialist and one of the founder Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.

Let us ease your mind

If you have any queries, questions or requests then please get in touch. We’re always very happy to talk, you’ll find a friendly voice on the end of the line or simply fill out the form below.

    Your Contact Details