Those accused of being spies make common, careless password mistakes A 500MB file, published by Cryptome on Tuesday and said to be sourced from Qatar National Bank (QNB), contains thousands of sensitive financial records and client details.Also included with the leak are records of high profile individuals, journalists, and some who are accused of being spies. In all, the breach exposed 1.4 GBs of data (15,460 files).In a statement, QNB wouldn’t confirm that a data breach has taken place. Instead the bank said they’re investigating the “matter in coordination with all concerned parties.”Those responsible for the leaked QNB data remain unknown, as do their motives. Based on the targeted profile information, which includes passwords, pictures, banking records, and social media data – the breach could be the work of a malicious insider, or a criminal who had persistent access to the bank and could take their time to target individuals. As mentioned, there are more than a hundred records included with the leaked data containing information on high profile individuals, some who are accused of being spies. Most of the records include PIN details and passwords, as well as the security questions and answers used for banking.The passwords, even those used by alleged spies, are weak to say the least. There were only three passwords that used special characters. The largest password of the bunch was 13 characters long (mission060612). A full breakdown of the leaked passwords is below. As for PIN data, that breakdown is below as well. It’s important to note however, that the common PINs exist for two reasons; (1) two people selected the same PIN, or (2) the same PIN was used on multiple cards issued to a single person.Thanks to Per Thorsheim, founder of PasswordsCon, for suggesting the data breakdown. Data compiled and sorted using Pipal (created by Robin Wood) and Passpal by T. Alexander Lystad. Related content news Gwinnett Medical Center investigating possible data breach After being contacted by Salted Hash, Gwinnett Medical Center has confirmed they're investigating a security incident By Steve Ragan Oct 02, 2018 6 mins Regulation Data Breach Hacking news Facebook: 30 million accounts impacted by security flaw (updated) In a blog post, Facebook’s VP of product management Guy Rosen said the attackers exploited a flaw in the website's 'View As' function By Steve Ragan Sep 28, 2018 4 mins Data Breach Security news Scammers pose as CNN's Wolf Blitzer, target security professionals Did they really think this would work? By Steve Ragan Sep 04, 2018 2 mins Phishing Social Engineering Security news Congress pushes MITRE to fix CVE program, suggests regular reviews and stable funding After a year of investigation into the Common Vulnerabilities and Exposures (CVE) program, the Energy and Commerce Committee has some suggestions as to how it can be improved By Steve Ragan Aug 27, 2018 3 mins Vulnerabilities Security Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe