The biggest leak yet... of usernames and credentials.

I was curious what's actually in the largest collection of leaked data so far — Collection #1. I downloaded just under 40 GB of data. After extraction it came to just under 100 GB. I fired up Splunk and started indexing. It took almost the entire morning; just over 300 GB of data was indexed. I should mention I was parsing email, domain, user credentials (password/hash), and I also created a field with the credential type (plain text, MD5, SHA1, bcrypt). Not all the data could be processed this way — tables (DBs) and other formats I didn't parse.

Now for the statistics. Since I previously worked for GovCERT.CZ, I was interested in government institutions. First up: which institutions are most represented. I only searched for ministries and central government bodies. Almost a quarter belong to the justice sector, followed by finance and then social affairs.

![Government institutions in Collection #1](Screenshot 2019-01-21 at 16.09.48.png)

Of course I also looked at password length distribution. A password length of eight characters is clearly still popular. Interestingly, more than 5/6 of users have a password between 3 and 8 characters. That's fairly valuable information for attackers.

![Password length distribution in government](Screenshot 2019-01-22 at 16.30.52.png)

And finally, how many passwords are in plaintext versus hashed form. From this statistic you can't draw conclusions about the quality of the breached websites, but you can say that passwords in the bcrypt column are almost safe. The same can't be said for MD5-hashed ones unless they're longer than 12 characters, as Michal Špaček writes here. But as noted above, not many people will have that.

![Plaintext vs. hash distribution for government](Screenshot 2019-01-23 at 14.38.19.png)

As for the Czech domain (the chart shows the TOP 10), the results are fairly clear. Domains belonging to Seznam.cz together account for almost 3/4. The chart shows the popularity of Seznam's services.

![Overview of .cz domains in Collection #1](Screenshot 2019-01-25 at 09.58.04.png)

And I saved the stats for the general public — i.e. excluding government — for last. Yes, password length 8 characters. However, what's interesting is the representation of longer passwords. Almost 1/6 have ten or more characters. It could be better, of course. But this takes time.

![Password length excluding government](Screenshot 2019-01-24 at 12.47.21.png)

What's the takeaway from all of this? Use a password manager: KeePass, Bitwarden, or 1password. Check your email on haveibeenpwned from time to time. Some password managers will do this for you, or you can set up alerts on the aforementioned website.

P.S. This is only the first part — there are 4 more collections out there...

Other Related Posts:

Data Box Password

Not like this…

The data box system got a new look. And with that they also dropped the CAPTCHA verification on login. My primary goal was to send my tax return, but I had an expired password. So: log in, change it, send. Except... I generated a password in my password manager, entered it in th...

28th Jan 2019