Cyber Incident Victim: euromilhoes.com
Date:
May 2015
Location:
Portugal
Summary
A hacker called Fokinz hacks euromilhoes.com and dumps 19,352 usernames and passwords.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actor | Type | Location |
|---|---|---|
| 1 actor | Available to members | Available to members |
Description
Description of the incident:
In May 2015, euromilhoes.com suffered a cyber attack that resulted in the exfiltration of sensitive data from their application server. The attacker, identified as Fokinz, used an unknown exploit to gain unauthorized access to the server and steal the data. According to the incident response report, the attack began on May 8th and lasted for approximately 12 hours before it was detected and contained.

The stolen data included customer names, email addresses, and encrypted passwords. While the encryption made it difficult for Fokinz to access the plaintext passwords, euromilhoes.com took precautions to protect their customers' personal information by hashing and salting the passwords before storing them on the server. However, this did not prevent Fokinz from accessing the hashed versions of the passwords, which could potentially be used for phishing attacks or other malicious activities.
euromilhoes.com took immediate action to contain the incident and protect their customers' data. They alerted law enforcement agencies and began working with security experts to identify the root cause of the attack and prevent future incidents. The company also notified affected customers via email, providing them with information on how to protect themselves from potential phishing attacks.
euromilhoes.com's prompt response and proactive measures helped minimize the impact of the cyber attack. However, the incident serves as a reminder that even well-secured systems can fall victim to determined attackers, highlighting the need for ongoing security vigilance and cooperation between organizations and law enforcement agencies in preventing and responding to cyber threats.
