CSIDB logo
Incident

LSDroid

Incident posture

Attack window
Mar 2014
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-04 00:48

Linked entities

Victim
LSDroid
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Cerberus reported a data breach affecting its anti‑theft application for Android in which usernames and SHA‑1 password hashes stored in a legacy log file were accessed by attackers. The exposed data covered about 96,500 accounts, though only three of those accounts showed any sign of unauthorized access. The company said the passwords had been hashed and uniquely salted multiple times, disabled the legacy logging, deleted the file, and announced plans to migrate to bcrypt for future password storage. No other personal information such as email addresses or device details was taken, and there is no evidence that the stolen data has been made public. The company is working with law enforcement on the incident.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

The only source material supplied in the prompt describes a security incident affecting the Cerberus anti‑theft application for Android. According to the article dated March 28 2014, Cerberus discovered suspicious activity on its servers and blocked it. The investigation revealed that usernames and SHA‑1 password hashes from a legacy log file covering logins between March 1 and March 21 2014 had been accessed. Approximately 96,564 user accounts were impacted by the exposure, although only three accounts showed evidence of actual access by the attackers. No other personal data such as email addresses or device information was reported to have been compromised. Cerberus responded by disabling legacy logging, deleting the file, advising users to change passwords, and planning to migrate to bcrypt for password storage.

The supplied article does not contain any reference to an entity, malware, or incident named “LSDroid”. Consequently, there are no factual details available from the source about the origin, timeline, or scope of an LSDroid‑related event. Without mention of LSDroid in the provided evidence, it is impossible to construct a chronological narrative of any actions taken by attackers targeting that specific subject. Likewise, the source offers no information on impacts attributed to LSDroid, such as numbers of affected users or types of data exposed. Because the incident details for LSDroid are absent from the material, any attempt to describe response actions, containment measures, or consequences would be unsupported speculation. Therefore, based solely on the information given, a detailed narrative of an LSDroid incident cannot be provided.

Sources

Sources available to members: 1 source.

CSIDB