- Keenetic suffered a data leakage in 2023 but the hacker said the data was destroyed and not shared
- Cybergenws scientists recently received a trial database
- Almost a million Russian households are in danger, experts say
Information about Keenetic Router users, originally stolen in March 2023 and assumed to have been deleted at that time, has emerged online, which has potentially put a million households at considerable risk.
In a security announcement published on the company’s website, Keenetic said an independent IT researcher reached out in mid-March 2023 to warn of unauthorized access to the Keenetic Mobile App database.
“After verifying the risk and credibility of the risk, we immediately decided the problem in the afternoon of March 15, 2023,” the company said. Keenetic was then told that the data had not been shared with anyone and was then destroyed. However, it seems that it was not really the case as security researchers from Cygenerws Was recently shown samples via an anonymous tip.
Names, E -Mails and PlainText -GAve Codes
Cygenerws Says the number of exposed items includes more than a million E emails, names, locations, keycloak identity management system and Network Order IDS and Telegram Code IDs.
There were also 929,501 leaked items containing WiFi SSIDs and passwords in regular text, device models, serial numbers, interfaces, Mac addresses, domain names for external access, encryption keys and more.
Then there were 558,371 Device Configuration Registers such as user access information, vulnerable MD-5-hashe passwords, assigned IP addresses and extended router settings.
Finally, extensive service logs containing over 53,869,785 items, including host names, Mac addresses, IPs, access details and even “owner_is_pirate” flag.
Most of the vulnerable users appear to be Russian-speaking (943,927), where 39,472 victims are English users and 48,384 Turkish-linguistic users.
After learning about the leak, Keenetic advised users who registered before March 16, 2023, to change their device user account passwords, WiFi passwords and VPN client password/pre-divided keys for PPTP/L2TP, L2TP/IPSEC, IPSEC Site-to-Site, SSTP.
Via Cygenerws