Popular subtitle website Opensubtitles suffered a data breach where nearly seven million user accounts were leaked.
- OpenSubtitles suffered a data breach after unknown attacker gained access via an SQL injection attack.
- Nearly 7 million user accounts were leaked, despite the site allegedly paying a ransom.
- The exposed data includes email and IP address, usernames, the country of the user and passwords stored as unsalted MD5 hashes.
Popular subtitle website Opensubtitles suffered a data breach where nearly seven million user accounts were leaked.
The exposed information includes email and IP addresses, usernames, the country of the user and passwords stored as unsalted MD5 hashes.
The administrator of the website became aware of the hack in August 2021, after a hacker notified via telegram demanding the payment of a ransom. The hacker also offered his support to OpenSubtitles to fix the security flaws he had found on the website.
Administrators of the website agreed to pay the ransom as it was of low amount. After receiving the ransom, the attackers never helped them secure the website, and on 11 January 2022, they leaked the data online.
According to the administrator, the hack has been the result of poor cyber security since its launch in 2006. It seems that the attacker exploited SQL injection to extract the website's database.
The attackers did not compromise the financial data of the subscribers.
“We hardly agreed, because it was not low amount of money,” the OpenSubtitles admin said. “He explained us how he could gain access, and helped us fix the error. On the technical side, he was able to hack the low security password of a SuperAdmin, and gained access to an unsecured script, which was available only for SuperAdmins. This script allowed him to perform SQL injections and extract the data.”
Subscribers are urged to reset opensubtitles.org and opensubtitles.com and forum passwords.
For the latest cyber threats and the latest hacking news please follow us on Facebook, Linkedin, and Twitter.
You may be interested in reading: How to Survive the COVID Time Cyber Security Threats?