CSIDB logo
Incident

MEGA

Incident posture

Attack window
Jun 2018
Location
Viet Nam
Status
Historical
CIA posture
Available to members
Updated
2025-11-29 00:00

Linked entities

Victim
MEGA
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2018
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cloud storage service experienced a significant data exposure when thousands of user credentials and file listings were leaked online, compromising email addresses, passwords, and stored file names. The breach stemmed from credential stuffing attacks, with analysis revealing that the vast majority of exposed credentials matched those from prior unrelated breaches. Some compromised accounts were found to contain illegal content, which was subsequently reported to law enforcement. In response to the incident, the company announced plans to implement two-factor authentication to enhance account security.

Motives

Detailed motive labels are available to members.

5 motives

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In mid-2018, security researcher Patrick Wardle discovered a publicly accessible text file containing over 15,500 user credentials and associated file metadata from cloud storage service Mega.nz. The dataset, which Wardle provided to ZDNet for verification, included email addresses, passwords, and lists of file names stored in user accounts, with records dating back to 2013. Independent verification through contacted users confirmed the authenticity of the exposed credentials. Analysis by security expert Troy Hunt revealed that 87% of the compromised credentials matched previously breached username-password combinations from unrelated data breaches, indicating that attackers likely gained access through credential stuffing attacks rather than a direct breach of Mega's systems. The exposed information did not include actual file contents but revealed sensitive metadata about stored files, potentially allowing attackers to identify accounts containing valuable or compromising information for targeted attacks.

Mega chairman Stephen Hall publicly attributed the incident to credential stuffing, emphasizing there was no evidence of a vulnerability in Mega's infrastructure. During their investigation, Mega identified several compromised accounts containing child sexual abuse material, which they reported to relevant law enforcement agencies. The company announced plans to implement two-factor authentication as a security enhancement following the incident. The exposure lasted for an undetermined period before discovery, leaving affected users vulnerable to account takeover and potential exploitation of their stored file metadata. While the incident did not involve unauthorized access to file contents through Mega's platform, it highlighted risks associated with password reuse across multiple services.

Sources

Sources available to members: 1 source.

CSIDB