Trending

HomeBlog
85,000 MySQL Databases On Sale in Darkweb
85,000 MySQL Databases On Sale in Darkweb

85,000 MySQL Databases On Sale in Darkweb

A threat actor with the alias of “Trollx” has posted over 85,000 MySQL databases for sales in one of Russian-speaking hacking forum.

What appears to be an advertisement on the forum, the hacker has also shared the URL where databases are auctioned. The URL is hn4wg4o6s5nc7763.onion. In order to browse to this website, you will need a TOR browser access.

The advertisement is below:

Post of the Hacking Forum

Based on the above, the hacker also published the hacked database list as well. The complete list can be viewed here.

On the auction website, it appears the concept is quite straightforward – hacked customers are given a unique code through which they can buy their databases.

Tor Website

Organizations who refuse to pay these hackers, their databases are then auctioned on their website as below:

report-ad-banner

How are they able to gain access to such large number of databases?

Cyble has seen a number of tactics of cybercriminals in mass hacking scenarios such as SQL Injection attacks using dorks and tools such as SQLInject to harvest the data and then deleting them with a ransom note left behind.

Other groups have exploited misconfigured servers to break into the systems such as the group “SQLDB.TO” who breached into a number of companies who accidentally left .env files on the public internet.

People who are concerned about their information exposure can register on Cyble’s data breach monitoring and notification platform, AmiBreached.com, to ascertain the risks at no cost. Also, Android users and iOS users can gain full access to it just by downloading the mobile application.

Here are a few ways to prevent cyber-attacks:

  • Never click on unverified/unidentified links
  • Do not open untrusted email attachments
  • Only download media from sites you trust
  • Never use unfamiliar USBs
  • Use security software and keep it updated
  • Backup your data periodically
  • Keep passwords unique and unpredictable
  • Keep Software and Systems up to date
  • Train employees on Cyber Security
  • Set up Firewall for your internet
  • Take a Cyber Security assessment
  • Update passwords regularly

About Cyble

Cyble is a global threat intelligence SaaS provider that helps enterprises protect themselves from cybercrimes and exposure in the darkweb. Cyble’s prime focus is to provide organizations with real-time visibility into their digital risk footprint. Backed by Y Combinator as part of the 2021 winter cohort, Cyble has also been recognized by Forbes as one of the top 20 Best Cybersecurity Startups To Watch In 2020. Headquartered in Alpharetta, Georgia, and with offices in Australia, Singapore, and India, Cyble has a global presence. To learn more about Cyble, visit www.cyble.io.     

Disclaimer: This blog is based on our research and the information available at the time of writing. It is for informational purposes only and does not constitute legal, financial, or professional advice. While we strive for accuracy, we do not guarantee the completeness or reliability of the content. If any sensitive information has been inadvertently included, please contact us for correction. Cyble is not responsible for any errors, omissions, or decisions made based on this content. Readers should verify findings and seek expert advice where necessary. All trademarks, logos, and third-party content belong to their respective owners and do not imply endorsement or affiliation. All content is presented “as is” without any guarantee that it is free of confidential, proprietary, or otherwise sensitive information. If you believe any portion of this content contains inadvertently shared or sensitive data, please contact us immediately so that we may address and rectify the issue. No Liability for Errors or Omissions Due to the dynamic nature of cyber threat activity, this [blog/report/article] may include partial, outdated, or otherwise incorrect information due to unverified sources, evolving security threats, or human error. We expressly disclaim any liability for errors or omissions or any potential consequences arising from the use, misuse, or reliance on this information.

Get Threat Assessment Report

Identify External Threats Targeting Your Business​
Free

Threat Landscape Reports 2025

Upcoming Webinars

CISO's Guide to Threat Intelligence 2024

CISO’s Guide to Threat Intelligence 2024: Best Practices

Stay Ahead of Cyber Threats with Expert Insights and Strategies. Download Free E-Book Now

Share the Post:
Scroll to Top

Discover more from Cyble

Subscribe now to keep reading and get access to the full archive.

Continue reading