AGL52.97▼ -0.19 (0.00%)AIRLINK146.64▼ -1.8 (-0.01%)BOP13.08▲ 0.08 (0.01%)CNERGY7.12▲ 0 (0.00%)DCL14.34▼ -0.33 (-0.02%)DFML36.75▲ 0.76 (0.02%)DGKC170.76▲ 1.95 (0.01%)FCCL46.76▲ 0.59 (0.01%)FFL15.82▼ -0.1 (-0.01%)HUBC144.18▲ 2.27 (0.02%)HUMNL12.68▼ -0.24 (-0.02%)KEL5.07▼ -0.05 (-0.01%)KOSM6.69▼ -0.2 (-0.03%)MLCF84.73▲ 0.66 (0.01%)NBP121.82▼ -0.56 (0.00%)OGDC227.89▲ 1.27 (0.01%)PAEL43.46▲ 1.28 (0.03%)PIBTL8.93▼ -0.06 (-0.01%)PPL169.94▼ -0.01 (0.00%)PRL33.11▲ 0.24 (0.01%)PTC24.26▼ -0.33 (-0.01%)SEARL103.72▲ 1.38 (0.01%)TELE8.08▼ -0.09 (-0.01%)TOMCL34.31▼ -0.32 (-0.01%)TPLP10.47▲ 0.14 (0.01%)TREET23.97▼ -0.18 (-0.01%)TRG58.05▼ -0.8 (-0.01%)UNITY26.64▼ -0.03 (0.00%)WTL1.52▼ -0.03 (-0.02%)

Cyber Alert: Pakistanis asked to change passwords of Google, Apple, Facebook accounts

Share
Tweet
WhatsApp
Share on Linkedin
[tta_listen_btn]

ISLAMABAD – A significant global cybersecurity incident has exposed more than 184 million account credentials linked to major platforms including Google, Microsoft, Apple, Facebook, Instagram, and government and banking services.

The breach stemmed from a publicly accessible, unencrypted file believed to have been compiled using “infostealer malware,” the National Cyber Emergency Response Team of Pakistan has issued an advisory.

The database, which lacked any form of protection, included usernames, passwords, emails, and URLs. Experts warn the exposed data may fuel identity theft, phishing attacks, account takeovers, and unauthorized access to critical systems.

Security agencies urge users to change passwords, activate multi-factor authentication (MFA), and avoid password reuse. Organizations are advised to enhance employee awareness, monitor suspicious activities, and reinforce security protocols.

“Immediate action is recommended to mitigate associated risks and to secure systems potentially impacted by this breach,” read the advisory.

Impact

Successful exploitation of the leaked credentials may result in:

  1. Credential Stuffing Attacks – Automated login attempts across services using reused credentials.
  2. Account Takeovers (ATO) – Unauthorized access to user accounts and personal services.
  3. Identity Theft & Fraud – Theft of digital identity for committing scams or impersonation.
  4. Ransomware Deployment & Espionage – Targeted attacks on individuals and enterprises.
  5. Government & Critical Sector Compromise – Unauthorized access to sensitive government systems.
  6. Targeted Phishing & Social Engineering – Tailored scams using personal communication history.

Immediate Remediation

The response team has urged Pakistanis to change all passwords, especially if reused across accounts.

“Activate Multi-Factor Authentication (MFA) on all services, especially financial, email, and administrative accounts. Notify affected users if internal addresses or user accounts may be in the leaked dataset”.

Related Posts

Get Alerts

© 2024 All rights reserved | Pakistan Observer