Menu
Browse

Cyber Incident Victim: lookbook.nu

Date:

May 2016

Location:

United States of America

Summary

A hacker known as Peace of Mind offered approximately 1.1 million user accounts from the fashion and community platform Lookbook.nu for sale on the dark net, listing emails alongside plaintext passwords for a cryptocurrency payment equivalent to roughly $102. The dataset was reportedly purchased multiple times, with one buyer highlighting its value for spam campaigns and credential reuse attacks due to the platform's fashion-oriented user base. While the breach raised concerns about potential secondary compromises of linked Facebook accounts—given the site's Facebook login integration—no evidence confirmed mass Facebook account breaches stemming from this incident. The exact method of data acquisition remained unclear, including whether the platform itself was directly hacked or if the company acknowledged the compromise.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

In May 2016, a hacker using the alias "Peace of Mind" advertised the sale of 1.1 million Lookbook.nu user accounts on the dark net. The compromised data included email addresses and plaintext passwords, priced at BTC 0.1519 (approximately $102.23 USD). By June 2016, the dataset had been sold six times, with one buyer under the pseudonym "6969" confirming the data's validity and usefulness for spam campaigns, scams, and credential reuse attacks due to Lookbook.nu's fashion-focused user base. The breach posed additional risks because Lookbook.nu permitted users to authenticate via Facebook credentials, raising concerns that compromised Lookbook accounts could facilitate unauthorized access to linked Facebook profiles. However, no corroborated reports confirmed whether Facebook accounts were exploited through this vector or whether Lookbook.nu users had experienced direct account takeovers at that time.

Cyber Incident Image

The origin and timeline of the data compromise remained unclear, with no public confirmation from Lookbook.nu regarding the breach's occurrence, attack methodology, or detection. The article did not specify whether company representatives acknowledged the incident or initiated containment measures such as password resets, user notifications, or system audits. The exposure of plaintext passwords indicated potential security deficiencies in Lookbook.nu's credential storage practices, as industry standards typically mandate cryptographic hashing. The sale's persistence on dark net markets suggested ongoing dissemination of the dataset, amplifying risks of credential-stuffing attacks against users who reused passwords across multiple platforms. No technical details about affected systems or intrusion methods were disclosed in the available reporting.

Sources
Sources available to members
1 source