
සිද්ධිය සිදුවූ ආකාරය
2025 ජූනි 19 දින, threat intelligence community එකට අනාවරණය වුණේ credentials බිලියන 16කට ආසන්න වශයෙන් එකතු වූ multi-source aggregate leak එකකි.
මෙය සෘජුවෙන් Google, Microsoft, Meta වැනි service providers හැක් කිරීමක් නොවෙයි. එය වන්නේ:

Infostealer malware logs, credential stuffing data, leaked database dumps, and browser scraping logs එකට යටත් වූ central data exposure එකකි.

තාක්ෂණික රීතිවලින් සිදුවූ හැටි

1. InfoStealer Malware Ecosystem
මෙම leak එකේ ප්රධාන මූලාශ්රය වන්නේ InfoStealer malware ලෙස හැඳින්වෙන client-side credential harvesting tools වේ.
උදා:

RedLine Stealer

Racoon Stealer

Vidar

LummaC2
මෙවන් malware තොරතුරු ගෙන

browser-stored credentials (Chrome, Edge, Firefox)

auto-fill login fields

session tokens & cookies

clipboard content

crypto wallets (e.g. Metamask, Exodus)
වලින්
අවසානයේ ලද data .txt or .csv formats වලින් log files ලෙස save කරයි. ඒවා ZIP එකකින් Telegram bots, C2 servers, හෝ underground forums වලට upload කරයි.

2. Aggregation & Public Exposure
Attackers හෝ third-party aggregators මේ logs වලින් massive combo lists සකස් කරයි.
මෙම credentials එකතු කරලා අසුරක්ෂිත NoSQL DB (e.g. Elasticsearch, MongoDB) හෝ exposed AWS S3 bucket / FTP මත public-facing හෝ misconfigured access control හරහා ලෝකයට පෙන්වනු ලැබේ.

දැක්වෙන තර්ජන මට්ටම

Credential StuffingAutomated brute-force attacks using leaked username-password pairs on high-value services (esp. banking, email, cloud storage)

Account Takeovers (ATO)If no MFA is present, attackers can directly gain control of user identities.
🪪 Identity TheftPII & credentials combo can be used to impersonate users in fraud schemes.

Business Email Compromise (BEC)Session cookies/token reuse enables bypassing MFA to hijack corporate emails and social engineering.

Phishing AmplificationLeaked data enables hyper-targeted phishing attacks via spear-phishing and clone phishing.

Initial Access BrokersCredential marketplaces (Genesis, RussianMarket) sell access to organizations for ransomware operators.

Mitigation Strategies – Enterprise & Personal

For Users
🪻Migrate from password-based auth to FIDO2/passkeys wherever possible.
🪻Use long passphrases + unique passwords per site, managed via offline-capable password managers (Bitwarden, KeePassXC).
🪻Enable App-based or Hardware-backed MFA (Yubikey, Titan Key).
🪻Regularly perform leak monitoring via HIBP, IntelligenceX, and GhostProject.

For Enterprises

Deploy Credential Stuffing Protection at WAF/IDP layer (Cloudflare Bot Mgmt, Akamai, Imperva).

Enforce user re-authentication policies upon detection of session reuse from anomalous locations/IPs.

Integrate SOC automation (SOAR) to trigger containment playbooks upon leaked credential detections.

Apply Zero Trust Architecture + Conditional Access Policies (Geo IP, Device Trust).

Monitor for initial access brokers activity on known underground channels.

මෙයින් ඔබට ඇති අවදානම් මොනවාද?

ඔබගේ Gmail, Facebook, Instagram, Zoom, Office 365, LinkedIn වැනි ඕනිම ගිණුම් අවසරයකින් තොරව ලොග් වීම.

ඔබට 2FA (Two-Factor) අරින්නත්, session cookies තිබුණොත් ඒවාත් පාවිච්චි කරලා ඒවාම avoid කරගන්න.

Phishing, identity theft, business email compromise වැනි ප්රහාර.
මෙම leak එක තුළ තිබුණේ මීට පෙර leaked වී තිබුණු credentials වල විශාල එකතුවක් බැවින්, ඒවායේ බොහෝ විට duplications ඇත.

ඔබ මේ වෙනකොටම කළ යුතු වැදගත් ක්රියාමාර්ග

1. සියලුම වැදගත් ගිණුම් සඳහා මුරපද (passwords) මාරු කරන්න.
– වචන කිහිපයක් මිශ්රව (passphrase), numbers, symbols සහ uppercase chars එක්ක use කරන්න.

2. Two-Factor Authentication (2FA) සක්රිය කරන්න.
– SMS නොව Google Authenticator, Authy, Microsoft Authenticator වැනි apps භාවිතා කරන්න.

3. Password Manager භාවිතා කරන්න.
– උදාහරණ: Bitwarden, 1Password, KeePassXC

4. “Have I Been Pwned” වැනි සේවාවකින් ඔබගේ Email එක leaked වෙලාද කියලා පරීක්ෂා කරන්න.
https://haveibeenpwned.com/
සහ
https://cybernews.com/personal-data-leak-check/

5. ඔබේ PC, Laptop, Mobile වල Anti-Malware Scan එකක් කරන්න.
– Malwarebytes, ESET, Kaspersky වැනි tools

6. Passkeys යටතේ login ක්රම භාවිතයට මාරු වන්න.
– Google, Microsoft, Apple දැන් passkeys (biometric-based login) system එකට full support ලබා දී ඇත.

නිගමනය
මෙම leak එක attack surface එක අතිශය පුළුල් කිරීමක් වෙනුවෙන් උපකාරී වේ. Credential-based attacks සඳහා මෙවැනි breaches සැලකිය යුතු "Initial Access Intelligence Feed" එකක් වන අතර, ransomware-as-a-service (RaaS) operators සහ BEC syndicates සඳහා අතිවිශාල වාසියක් ලබා දේ.

For Threat Briefings / CIS Benchmarks / Red-Blue Team Advisory