Calendar An icon of a desk calendar. Cancel An icon of a circle with a diagonal line across. Caret An icon of a block arrow pointing to the right. Email An icon of a paper envelope. Facebook An icon of the Facebook "f" mark. Google An icon of the Google "G" mark. Linked In An icon of the Linked In "in" mark. Logout An icon representing logout. Profile An icon that resembles human head and shoulders. Telephone An icon of a traditional telephone receiver. Tick An icon of a tick mark. Is Public An icon of a human eye and eyelashes. Is Not Public An icon of a human eye and eyelashes with a diagonal line through it. Pause Icon A two-lined pause icon for stopping interactions. Quote Mark A opening quote mark. Quote Mark A closing quote mark. Arrow An icon of an arrow. Folder An icon of a paper folder. Breaking An icon of an exclamation mark on a circular background. Camera An icon of a digital camera. Caret An icon of a caret arrow. Clock An icon of a clock face. Close An icon of the an X shape. Close Icon An icon used to represent where to interact to collapse or dismiss a component Comment An icon of a speech bubble. Comments An icon of a speech bubble, denoting user comments. Comments An icon of a speech bubble, denoting user comments. Ellipsis An icon of 3 horizontal dots. Envelope An icon of a paper envelope. Facebook An icon of a facebook f logo. Camera An icon of a digital camera. Home An icon of a house. Instagram An icon of the Instagram logo. LinkedIn An icon of the LinkedIn logo. Magnifying Glass An icon of a magnifying glass. Search Icon A magnifying glass icon that is used to represent the function of searching. Menu An icon of 3 horizontal lines. Hamburger Menu Icon An icon used to represent a collapsed menu. Next An icon of an arrow pointing to the right. Notice An explanation mark centred inside a circle. Previous An icon of an arrow pointing to the left. Rating An icon of a star. Tag An icon of a tag. Twitter An icon of the Twitter logo. Video Camera An icon of a video camera shape. Speech Bubble Icon A icon displaying a speech bubble WhatsApp An icon of the WhatsApp logo. Information An icon of an information logo. Plus A mathematical 'plus' symbol. Duration An icon indicating Time. Success Tick An icon of a green tick. Success Tick Timeout An icon of a greyed out success tick. Loading Spinner An icon of a loading spinner. Facebook Messenger An icon of the facebook messenger app logo. Facebook An icon of a facebook f logo. Facebook Messenger An icon of the Twitter app logo. LinkedIn An icon of the LinkedIn logo. WhatsApp Messenger An icon of the Whatsapp messenger app logo. Email An icon of an mail envelope. Copy link A decentered black square over a white square.

Personal details of thousands of workers from Tayside firms being sold on dark web

Post Thumbnail

A Perth-based cyber security firm has warned that thousands of employee email addresses and passwords linked to Tayside firms are being traded anonymously on the ‘dark’ web.

Security specialist m3 Networks conducted an investigation into more than 600 businesses which are members of Dundee and Angus Chamber of Commerce.

It found almost 24,000 breaches – an average of 39 per company – on the dark web, a lawless part of the internet that is accessed by specialist software and is completely anonymous.

Mark Lamb, technical director of m3 Networks, said many firms were oblivious that their information had been compromised.

Outlining the investigation, Mr Lamb said: “The dark web is where your stolen password and personal data ends up after a data breach.

“It doesn’t need to be your own system – any website you use can be breached and your password can be leaked as a result.

Mark Lamb, Technical Director of m3 Networks.

“We have tools that can trawl more than 600,000 forums and websites on the dark web.

“We looked at Dundee and Angus Chamber of Commerce members and stripped out the sole traders and multinationals and banks. Of the 611 remaining businesses, 57% appeared on the dark web with breached credentials.”

Mr Lamb said while major data breaches make the news, many small and medium size businesses tend to try to cover up the incident, fearing damage to reputation and possible fines.

He said that typically a hacker will trade the information on eBay-style websites on the dark web to people who have the computing power required to unlock encrypted information.

“Sometimes businesses get hacked and sometimes their websites can be interrogated,” he explained.

“There are also phishing emails and key logging software.

“The people who are nimble and skilled enough to make the breach typically don’t have access to the raw computing power to break (decrypt) the information they stole and make use of it.

“So the information is then traded on the dark web.

“Some people who break information work both sides – they give the hacker the information but also publish it in other sources on the dark web to let people know their data has been stolen and broken.

“That’s one of the ways we find out. Otherwise information gets bought and traded so many times that it just gets dumped on the dark web in forums. They call those paste bins.

“That means that all the juice has been squeezed out of the data and it’s almost worthless by that point.”

The effects of a cyber attack can be devastating – with 60% of small companies going out of business within six months of an attack.

M3 Networks offers a dark web monitoring service to alert when a firm has been compromised so that passwords can be changed quickly.

“Financial loss, damage to reputation and permanent data loss are the three things that can wipe businesses out,” Mr Lamb added.

“A strong password is helpful but it’s no guarantee. You could have the strongest password in the world but if the company doesn’t store it in a strong format then it could be broken.

“Knowing your password has been breached as soon as possible is critical – you need to change it in all the locations it has been used, before it is used against you.

“I would advise people to not use the same password in multiple places.”

Mr Lamb will reveal his findings as part of a cyber security business breakfast event held by Dundee and Angus Chamber of Commerce at Forbes of Kingennie today.

Alison Henderson, chief executive of Dundee and Angus Chamber of Commerce, said many chamber members may be unaware of the information on the dark web.

She said: “The world of cyber security is constantly evolving and it can be difficult for businesses to keep up and be fully covered against all eventualities.

“There’s clearly a significant risk to many local businesses in dark web breaches and it’s very important to know if your business has a breach.”