started · updated
Data breach lookup bots exploit stolen personal information
Cybercriminals are increasingly utilizing inexpensive “lookup” bots to exploit massive quantities of stolen personal data. These services, which claim access to billions of email addresses, passwords, and phone numbers, allow users to search for sensitive information such as IBANs, postal addresses, and social security numbers for a low fee.
Recent breaches, including the theft of 44.3 million personal records from France Travail, provide the raw data for these engines. Hackers have used credentials stolen via infostealer malware to infiltrate organizations lacking multi-factor authentication, including Iberia airlines and the Brazilian military police.
In response to frequent data leaks from various institutions, victims in France have several avenues for recourse. Legal experts suggest filing complaints with the CNIL (Commission Nationale de l'Informatique et des Libertés) to trigger administrative audits and verify if organizations have violated GDPR regulations.
Entities
CNIL · France Travail · Iberia