The expert named the main mistakes of users after the data leak
After information about a personal data leak appears, it is important to verify the authenticity of the message, change the compromised password, and end all active account sessions. However, you should not follow links from emails that require you to immediately change your login information. Alexander Gusev, HASPBOX's CTO, told Izvestia about this on July 26.
According to him, panic after reporting a leak can lead to rash actions and make the user a victim of an additional attack. Fraudsters often use news about hacks to send phishing emails on behalf of the affected service.
HASPBOX's CTO is Alexander Gusev
If a letter arrives in the spirit of: "It's urgent! Your account is compromised, change your password using the link below," this is 99% likely phishing, not concern for your safety. Real hacking notifications do not create an artificial rush, they do not ask you to enter a password using a link from an email. They indicate the specific incident, the date, and which data is affected.
You can verify the leak using the Have I Been Pwned service, the Password Checkout function built into the browser, the darknet monitoring system in the password manager, as well as through the official channels of the company that owns the compromised service.
After confirming the leak, you should change the password for the corresponding account. The new password must be unique, so adding a single digit or character to the previous combination will not provide the necessary protection.
Gusev advised using a password manager to create and store complex combinations. Then you need to end all active sessions via the "Log out from all devices" feature. This will allow you to revoke previously issued access tokens and deprive attackers of the opportunity to stay in the account even after changing the password.
The next step should be to enable two-factor authentication. It is better to give preference to an authenticator application or a physical security key.
"SMS in 2026 is more of a compromise option than reliable protection. But it's better than nothing," Gusev said.
In addition, the user should examine the login history and check if there are any unfamiliar devices, other people's geolocations, or changes in access recovery settings. Special attention should be paid to cases where the same password has been used on multiple sites.
According to the expert, it is the reuse of combinations that often causes a larger-scale hack. Attackers can automatically verify leaked usernames and passwords on other services. Manually searching for duplicate combinations among dozens of accounts is ineffective, whereas password managers allow you to generate a report on weak and identical passwords.
The login information should be changed in order of priority. First of all, you need to protect your email, because it usually restores access to other services. Then you should check the banking applications, the Gosuslugi portal, and work accounts. After that, you can switch to social networks, online stores, and other sites. It is not necessary to automatically block bank cards or change the phone number after any leak. The decision depends on which information is publicly available.
If the leak only affected the email address and password, it is enough to change the login information, check the rest of the accounts and monitor banking transactions more closely for several weeks. If the array contains the card number, CVV code, or passport data, you should contact the bank and discuss the reissue of the card. The key criterion is whether the information that has fallen into the wrong hands can be directly used to steal money or fraud on behalf of the owner.
Gusev called a minor change of the previous password one of the most common mistakes. For example, replacing the Ivan2020 combination with Ivan2021 or adding an exclamation mark formally creates a new password, but practically does not increase its stability. Modern search tools are able to quickly recognize such patterns.
It is equally dangerous to change the password only on the service that reported the leak and continue using the same combination on other sites. In this case, attackers can gain access to several accounts at once.
If the work credentials are publicly available, the employee should not limit himself to changing the password on his own. The incident must be immediately reported to the information security service or the IT department through the channel established in the company.
It is not necessary to conduct an investigation on your own or remove traces of activity before the specialists react.: this may destroy information necessary to establish the circumstances of the attack. Further actions should be carried out in accordance with the corporate incident response plan, including the deadlines stipulated by it for notifying the regulator.
Anton Nemkin, a member of the State Duma Committee on Information Policy and federal coordinator of the Digital Russia project, reported on July 23 that the attackers began calling citizens under the guise of mail employees, allegedly to clarify information about parcels and lure victims into fake chatbots in messengers.
Переведено сервисом «Яндекс Переводчик»