🇯🇵 Japan - Keio University & University of Tokyo Student Databases
1,739 Student Records Allegedly Offered for Sale
A threat actor is advertising the sale of two allegedly compromised databases associated with Japanese university-focused platforms, claiming to contain personal information, photographs, and account credentials belonging to students from some of Japan's most prestigious academic institutions.
According to the forum post, the dataset allegedly includes records from:
* https://t.co/TlsuDEvtP1 (Keio University community platform)
* UTopia / https://t.co/ypw5izg3Il (University of Tokyo student platform)
The actor claims the combined dataset contains:
* 1,739 user accounts
* Email addresses
* Plaintext passwords
* Profile photographs
* Personal profile information
* Student-related identity information
Alleged Keio University Dataset Details:
* Approximately 1,600 users
* 1,596 email addresses
* 1,356 plaintext passwords
* 484 Gmail accounts
* 1,587 profile photographs
* Name, gender, date of birth, school, company, biography, city, and photo data
Alleged University of Tokyo Dataset Details:
* 139 users
* KYC-related identity verification information
* Student identification data
* Profile photographs
* Email addresses
* Names
* Gender and age information
* University affiliation
* Additional personal profile attributes
Potential Risks:
* Credential stuffing attacks against university and personal accounts
* Identity theft targeting students and alumni
* Social engineering and spear-phishing campaigns
* Exposure of student photographs and sensitive personal information
* Reputational harm and privacy violations
* Long-term intelligence collection against future government, academic, and business leaders
Analyst Note: Although the total number of records is relatively small compared to large commercial breaches, the alleged presence of plaintext passwords, student identity information, and profiles linked to elite academic institutions significantly increases the intelligence value of the dataset. Such records can be leveraged for targeted recruitment, espionage, social engineering, and long-term profiling activities.
#DDW #Intelligence #DarkWeb #Japan
Apple ❌ zignorowało zgłoszenie dziury (0day). Więc jejznalazca użył tej dziury do podpięcia się pod video calla pracowników Apple oceniających zgłaszane dziury. I załączył zgłoszenie dziury jeszcze raz, ale ze screenshotem z tego video calla 🤭
Epickie! No ale Apple nie miało poczucia humoru i zaczęło mu grozić prawnikami 🤡