Hostinger Resets Passwords After Hackers Access Database of 14 Million Users
Web hosting company Hostinger forces password resets after an unauthorized access token exposes the usernames, emails, and hashed passwords of 14 million customers. The company insists no financial data is compromised while an active investigation continues.
Web host Hostinger resets customer passwords as a precautionary measure after it detects unauthorized access to a database containing information on approximately 14 million users. The breach occurs when a hacker uses an unauthorized access token found on a server to gain entry to an API database, which stores usernames, email addresses, and passwords scrambled with the vulnerable SHA-1 algorithm.
The company states that no financial data, website files, or additional customer data suffer compromise during the incident. However, a customer support chat log seen by reporters shows a representative admitting that financial data is technically retrievable by the API, prompting Hostinger's chief executive to dismiss the remarks as misleading and reaffirm that no payment information is stored or exposed.
Hostinger currently upgrades its password hashing to the stronger SHA-2 algorithm and sends email notifications to all affected users requiring them to change their credentials. The web hosting giant, which boasts over 29 million total customers, confirms it contacts the respective authorities as its internal investigation into the exact scope of the breach remains ongoing.