Thousands of Ring Doorbell Passwords Surface on Dark Web

A security researcher discovers over 1,500 unique Ring doorbell credentials leaked on a dark web site, granting potential access to customer cameras and personal data. Despite Ring denying a breach and claiming affected users are notified, contacted individuals report receiving no such warning.

A security researcher uncovers a cache of 1,562 unique email addresses and passwords associated with Ring doorbell accounts on an anonymous dark web text-sharing site. This compromised data allows anyone to log into a Ring account, view the customer's address, phone number, payment information, and access live or historical camera footage. The discovery follows a similar report by BuzzFeed News earlier the same day regarding a cache of over 3,600 Ring credentials.

The exact method of the exposure remains unknown, but the relatively simple nature of the compromised passwords suggests hackers potentially obtain them through credential stuffing or password spraying techniques. TechCrunch contacts several individuals whose credentials appear in the leak, and all confirmed the passwords belong to them. Following this notification, these users change their passwords and enable two-factor authentication to secure their smart home devices.

Although Amazon-owned Ring denies experiencing a data breach and claims it notifies all affected customers while resetting their passwords, this statement contradicts the experiences of the individuals contacted by the media. None of the affected users spoken to by TechCrunch report receiving any prior communication from Ring regarding their compromised accounts. Meanwhile, the dark web listing containing the sensitive login information remains accessible to the public.

Read More at the original source →