Menu
Browse

Cyber Incident Victim: MEGA

Date:

Jun 2018

Location:

Viet Nam

Summary

A cloud storage service experienced a significant data exposure when thousands of user credentials and file listings were leaked online, compromising email addresses, passwords, and stored file names. The breach stemmed from credential stuffing attacks, with analysis revealing that the vast majority of exposed credentials matched those from prior unrelated breaches. Some compromised accounts were found to contain illegal content, which was subsequently reported to law enforcement. In response to the incident, the company announced plans to implement two-factor authentication to enhance account security.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 5 motives 2 techniques
Threat Actor Type Location
1 actor Available to members Available to members

Description

In mid-2018, security researcher Patrick Wardle discovered a publicly accessible text file containing over 15,500 user credentials and associated file metadata from cloud storage service Mega.nz. The dataset, which Wardle provided to ZDNet for verification, included email addresses, passwords, and lists of file names stored in user accounts, with records dating back to 2013. Independent verification through contacted users confirmed the authenticity of the exposed credentials. Analysis by security expert Troy Hunt revealed that 87% of the compromised credentials matched previously breached username-password combinations from unrelated data breaches, indicating that attackers likely gained access through credential stuffing attacks rather than a direct breach of Mega's systems. The exposed information did not include actual file contents but revealed sensitive metadata about stored files, potentially allowing attackers to identify accounts containing valuable or compromising information for targeted attacks.

Cyber Incident Image

Mega chairman Stephen Hall publicly attributed the incident to credential stuffing, emphasizing there was no evidence of a vulnerability in Mega's infrastructure. During their investigation, Mega identified several compromised accounts containing child sexual abuse material, which they reported to relevant law enforcement agencies. The company announced plans to implement two-factor authentication as a security enhancement following the incident. The exposure lasted for an undetermined period before discovery, leaving affected users vulnerable to account takeover and potential exploitation of their stored file metadata. While the incident did not involve unauthorized access to file contents through Mega's platform, it highlighted risks associated with password reuse across multiple services.

Sources
Sources available to members
1 source