On a password leak from an e-shop

When the news broke about a password leak from xzone.cz, I felt uneasy.

I know I shopped there at some point… but I have no record of it anywhere in my KeePass. The server emailed users with information about the leak, a password reset (a new one is created by clicking a link), and last but not least we were warned to change our passwords on any other services where we'd used the same password.

The problem arises, however, when you have absolutely no idea what password you were using on that service. You don't know what it was, and there's no way to find out after the fact…

What do you do?

Other Related Posts:

Collection #1

Collection #1

The biggest leak yet... of usernames and credentials.

I was curious what's actually in the largest collection of leaked data so far — Collection #1. I downloaded just under 40 GB of data. After extraction it came to just under 100 GB. I fired up Splunk and started indexing. It took almost the enti...

17th Jan 2019

Data Box Password

Not like this…

The data box system got a new look. And with that they also dropped the CAPTCHA verification on login. My primary goal was to send my tax return, but I had an expired password. So: log in, change it, send. Except... I generated a password in my password manager, entered it in th...

28th Jan 2019