People are selling compromised credentials from organisations everywhere. How do they get them in the first place?

Seems like alot of notorious ransomware groups are essentially buying access through stolen credentials.

How are people obtaining creds though?

I’m assuming things like dictionary attacks against public facing servers are a very unlikely method. But maybe I’m wrong.

haveibeenpwned databases with cracking maybe?

Anyone with actual experience with Blackhat care to share some light?

submitted by /u/thehunter699
[link] [comments]

Read More >>