Select Page

Incident: Nitro Software user database put up for sale on dark web | iTWire

Incident: Nitro Software user database put up for sale on dark web | iTWire

Australian Service Provider Hacked? October 29 2020

Nitro Software user database put up for sale on dark web

TA group that uses the name Shiny Hunters appears to have put up a database exfiltrated during a data breach of ASX-listed Nitro Software, a firm that offers a service to create, edit and sign PDFs and digital documents, on the dark web for sale.

Source: Nitro Software user database put up for sale on dark web | iTWire
More reports from: iTWire.

Nitro, a company that was started in Melbourne, has been insistent that the breach is “an isolated security incident” as stated when it posted a notice to the ASX on 21 October.

However, the cyber security firm Cyble has released details about the incident, which indicate that it was much bigger than has been made out.

Alon Gal, chief technology officer of cyber crime intelligence company Hudson Rock, posted a tweet, saying that the database contained 77 million users.

“The database contains emails and hashed passwords,” he added.

Another point made by the spokesperson was that the metadata in the document database (i.e. name field) could give cyber criminals insights about who might have access to sensitive documents, such as those related to mergers and acquisitions, in an organisation.

About The Author

Steven Kirby

I provide independent and practical consultancy services through raising awareness and fostering the energy for change that delivers improved business management of information security governance, risk and compliance.

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Please follow the Source link to the original article to support the content owner. We only provide a brief summary with metadata to assist in categorisation.

More Australian News

Exclusive: The Gentlemen strikes Sharp Office as company confirms incident investigation

A ransomware group claims to have hacked a Broadmeadow-based office technology supplier that works with Newcastle Airport and Royal Life Saving … [...]

Australian Cyber Aware - As It Was 2608 - August 2026

This monthly review provides a curated summary of cybersecurity, privacy, AI, fraud, governance, risk, and compliance developments in Australia and … [...]

Australians to gain greater control over compromised identity documents with new IDLock scheme

The Albanese government will introduce a new myGov service allowing Australians to block, unblock, and monitor the use of eligible identity documents … [...]

Digital platforms to be targeted as part of NSW crackdown on organised crime operations

NSW’s Premier has announced a raft of measures to combat the facilitation of serious crimes, such as gang-related murder. • Mon, 07 Sep 2026 • … [...]

Late patching of Metabase SQLi bug claims Sydney's Mathspace

Key points Attackers exploited a critical Metabase vulnerability to breach Mathspace after the company failed to patch its self-hosted instance … [...]

ACMA fines Telstra for SIM swapping prevention misses

Key points ACMA has fined Telstra $277,000 for failing to use required identity authentication processes to prevent SIM swapping fraud. • The fraud … [...]

Vocus hit by Australia Singapore Cable break

Key points Vocus is grappling with a cable break on its Australia Singapore Cable (ASC) system between Perth and Singapore, following a shunt fault on … [...]

Tabcorp appoints new CISO

Key points Tabcorp has named Maxine Harrison as its new chief information security officer, following the former leader's departure in July. • Harrison … [...]

Hundreds of old, vulnerable Exchange servers remain in Australia

Key points 382 Australian and 56 New Zealand Exchange servers remain vulnerable to CVE-2026-62911 as of August 31, three weeks after Microsoft's … [...]

'Now measured in the millions': The common process being used to scam Australians

in brief Scammers are exploiting the growing use of CAPTCHAs to trick people into running malicious code outside their browser. • An expert has practical … [...]

Experts sound alarm on rise of fake digital IDs | 9 News Australia

There's a warning tonight about a rise in fake digital IDs being sold to teenagers. Cyber safety experts say it's putting vulnerable Victorians at risk of having their identities stolen. [...]

Shares
Share This

Discover more from Australian Cyber Aware

Subscribe now to keep reading and get access to the full archive.

Continue reading