Following last week’s story on the breadth of the NPD breach, a reader alerted KrebsOnSecurity that a sister NPD property — the background search service recordscheck.net — was hosting an archive that included the usernames and password for the site’s administrator.
A review of that archive, which was available from the Records Check website until just before publication this morning (August 19), shows it includes the source code and plain text usernames and passwords for different components of recordscheck.net, which is visually similar to nationalpublicdata.com and features identical login pages.
The exposed archive, which was named “members.zip,” indicates RecordsCheck users were all initially assigned the same six-character password and instructed to change it, but many did not.
There's just not enough facepalming I can do on reading this. Just embarrassingly awful security.
Absolutely terrible! Shocked...
reply
Oh my.
reply
Idiots
reply
It's terrible!
reply
0 sats \ 0 replies \ @ez 20 Aug
I guess they were accelerationists
reply
Oh my god
reply