The Register Home Page

back to article Here's why cloud credentials are the hottest item on criminal marketplaces

Stolen cloud credentials cost about the same as a dozen donuts, according to IBM X-Force, whose threat intel team says logins make up almost 90 percent of goods and services for sale on dark web marketplaces. However, in many instances criminals don't even need to shell out the 10 bucks. X-Force also discovered plaintext …

  1. Doctor Syntax Silver badge

    "And that's a terribly high number relative to what the industry should know at this point about safekeeping of secrets and passwords in particular,"

    And there's the problem. Given that using somebody else's computer has been sold as a means of not needing to employ someone from "the industry" it's quite possible that these are set up by people lacking that knowledge.

    1. Anonymous Coward
      Facepalm

      "Three clicks and you can set up a website and the required infrastructure! No need to code a single line!".

      When ease of use is available you can gaurantee a nasty compromise has been made somewhere to make it so easy. In this case security, the inteligence and attention to detail of a good IT team. if you think you know all about IT 'cos you watched a few YouTube vids on a how IT works then good luck when you get handed the keys to your new cloud account!

      Just like pluimbers and builders called out on emergencies, we IT people will all be waiting with our £500/hour contracts in hand ready for you to sign when you realise what you've done and can't fix it!

    2. FrogsAndChips Silver badge

      Quote me one single cloud provider that pretended you could get rid of your IT Security department when migrating to the cloud. Securing IAM is and has always been the customer's responsibility.

      And frankly, credentials security is not rocket science. Implement Federation authentication so that your users don't need another set of username/password. Use MFA. Use roles (i.e short-lived access rights) in your cloud infra instead of long term credentials. If you do need long-term credentials, rotate them regularly. Block all public access (now the default for most CSPs anyway). Monitor all accesses. The tools are there, just use them!

  2. Blackjack Silver badge

    [X-Force also discovered plaintext credentials on user endpoints in a third (33 percent) of all the cloud-related incidents it responded to]

    Wow just wow, hopefully the full list of companies that still use plaintext credentials leaks online.

  3. OhForF'
    Trollface

    Credentials

    >Stolen cloud credentials cost about the same as a dozen donuts<

    Can anyone point me to the proper site in the dark web to buy working credentials?

    Might get me back on the company cloud faster than waiting for our admins to work on my ticket to reset the password.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like