Sunday
Dec122010
Condition Set YELLOW
Sunday, December 12, 2010 at 10:48PM
Currently 1.3 million passwords, 540,000 with email addresses have been stolen from sites affiliated with Gawker Media. You can check if your password or if any users from your domain passwords have been compromised at this address. At the very least consider the following response.
- Inform users of the breach and provide them with instructions on how to check their accounts.
- Remind users that passwords they use within your organization shall not be used for any other sites.
If your organizations domain appears in the table, your organization should also consider the follow response.
- If your organization is small consider checking the hashes yourself, force password resets for those users.
- Force user password resets within your domain.
- Review Policies related to accessing and using organizations email for personal use.
There are reports that the password and email combinations are being used to compromise Twitter accounts. Users should change their password if the one used on one of the Gawker Media sites.
tagged Condition:YELLOW