Cyber Incident Victim: Cerberus
Date:
Mar 2014
Location:
United States of America
Summary
Cerberus reported that a breach exposed usernames and SHA‑1 password hashes from a legacy log file affecting more than 96,500 Android users, with only three accounts showing any sign of unauthorized access. The company said the file, which contained login data from a three‑week period, has been removed and legacy logging disabled, and that the hashes were uniquely salted multiple times. It added that it is moving to bcrypt for password storage, is cooperating with law enforcement, and found no evidence that the stolen data was published.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 2 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On March 28, 2014, Cerberus sent an email to more than 96,000 users of its Android anti‑theft application informing them of a data breach that had been discovered by the company’s security team. The security team detected suspicious activity on Cerberus servers, blocked the unauthorized access, and launched an investigation into the incident. According to the investigation, the attacker had obtained usernames and SHA‑1 password hashes from a subset of users, while no other personal information such as email addresses or device details was accessed. Cerberus explicitly stated in the email that the investigation found no evidence that any individual account had been actually accessed or compromised by the intruder. The company also noted that the attacker(s) were able to gain access to usernames and encrypted passwords for a subset of its users, emphasizing that no additional personal data had been exposed.

The breach impacted a total of 96,564 accounts, with the exposed data limited to usernames and password hashes stored in a legacy log file. This log file recorded login activity between March 1 and March 21, 2014, and contained the usernames alongside the SHA‑1 password hashes that had been hashed and uniquely salted multiple times. Although the attacker gained access to the log file, only three of the affected accounts were reportedly accessed by the hackers. Cerberus described the password protection in place at the time as involving multiple rounds of hashing with unique salts, which it characterized as a security measure intended to increase the difficulty of reversing the hashes. The company confirmed that no other personal data, such as emails or device information, had been accessed during the incident.
In response to the breach, Cerberus disabled the legacy logging mechanism that had created the vulnerable file and subsequently deleted the compromised log file from its servers. The company announced its intention to migrate from the existing hashing approach to bcrypt for stronger password protection of user credentials. Affected users were advised to change their passwords, particularly if they reused the same credentials across other online services, as a precautionary measure. Cerberus also stated that there was no indication that the stolen data had been made public and confirmed that it was cooperating with law enforcement authorities regarding the investigation. The notification concluded with the reassurance that the company’s security team had blocked the suspicious activity and that the investigation had found no evidence of account compromise.
