Another day, another online accounts data breach story.

These sorts of stories come with such frequency, unfortunately, that we may collectively have become jaded about their impact. In some cases the stories are reported as breaches when they are nothing of the sort.

Online access accounts are essentially the lifeblood of the internet-based economy. Whether it’s online banking, booking an airline flight, or buying a product through Amazon, those online accounts make it all possible.

A recent and somewhat murky story about a massive trove of some 16 billion user accounts having been briefly exposed online has led to all sorts of speculation. Clearly this doesn’t mean every account on the planet has been exposed. After all, 16 billion is roughly twice Earth’s population.

If you are like me you probably have dozens of online accounts. I have around 200, although not all are actively used. Some in fact are dormant, extinct even, in the sense the services to which they belonged are no longer in existence.

Exactly what is in this supposed trove of 16 billion accounts is not at all clear. User login names? User names? Passwords? Encrypted or clear text? Is this a new trove or is it an amalgamation of previous leaks and hacks? Did it belong to a government agency or a state-sponsored actor?

So much murkiness. Yes, there are articles suggesting the sky is falling in and that those with online accounts should change any and all of their passwords. Was it even a breach? After all, the Metas, Googles, and Microsofts of the tech world aren’t issuing warnings to their users. They say they haven’t suffered specific breaches that can be linked to the current story.

For now, all we have is an article by a company known as CyberNews describing this particularly large collection of user account data. Speculation is that the data itself may have been amassed by so-called infostealers, small software packages stealthily installed through dubious downloads, often as part of free online games, or through clicks on sketchy links.

Such infostealers can quietly run in the background, collecting login credentials and other sensitive data that can later be used to specifically target potential victims. Presumably such data is then amassed somewhere for subsequent use.

Much remains unknown about this incident. Who was behind the amassing of so much data in one place? How long was the data exposed on the public internet? Is the data in the hands of cyber criminals and is it actively being exploited? What is the age of newest entries in the trove?

In the absence of the answer to these questions it is prudent to assume the worst; yes, the data is in the hands of nefarious types, and yes, it will be exploited. The nature of such exploits is yet to be seen. So far there is no indication that the data includes actual login name and password combinations. If there were such pairings then surely we’d be reading about large numbers of users complaining they can no longer access their accounts.

Although it isn’t perfect, if you haven’t already, turn on a two-factor authentication process for your most important accounts. Perhaps even consider using something like the Google Authenticator app. Such apps bypass the easily exploited SMS form of two-factor authentication.

To repeat another cybersecurity adage, be sure you are using unique passwords for your online accounts. If you aren’t, and your login credentials are part of this trove, or of any other for that matter, it’s too easy for the nasty guys to simply try a password linked to you across say the top 10 online services. A login account/password manager can be a tremendous help with this.

I recently ran a check for unusual activity at account.live.com/activity on my Microsoft user account, the one accompanying this column. It showed a spate of unsuccessful access attempts on May 22/23 of this year, from locations such as Iraq, Brazil, Turkey, Russia, Mexico, and the United States. It’s quite unnerving to see this. Kudos to Microsoft for providing this tool.

Consider checking your main email address account at haveIbeenpwned.com, the site run by Australian researcher Troy Hunt (“pwn”, pronounced “pone”, is leetspeak, or hacker speak, an intentional misspelling of “own”). You will quickly see any data breach your email address may have been part of, with the exception of the current one.

For instance, I find that my oldest email address, going back to 1992, has been part of 17 online breaches. The most recent, in 2024, referred to as the Hopamedia breach, exposed email addresses, geographic locations, names, phone numbers, and telecommunications carriers, more than enough to carry out a typical phishing scam.

Presumably we will learn more about the current trove of user data. Even if we don’t, be sure to take advantage of the best practices and tools available to you to help secure your online presence.

Follow me on Twitter/X (@PeterVogel) or on Bluesky (@petervogel.bsky.social).

pvogel@outlook.com

Your voice matters! Join the conversation by submitting a Letter to the Editor here.