Google
The information was collected when users submitted suspected phishing sites through the Google Toolbar

Google admits to user data disclosure

Anti-phishing list logged user names and passwords

Written by Shaun Nichols in California

Google has confirmed that it unwittingly disclosed sensitive login and password information pertaining to more than a dozen users. 

The information was disclosed three weeks ago as part of Google's freely accessible anti-phishing blacklist.

Google said in a written statement that the problem has since been fixed, and that procedures have been put in place to strip login information from future submissions.

The information was collected when users submitted suspected phishing sites through the Google Toolbar browser extension. Several of the URLs that were submitted also contained login and password information.

Security firm Finjan said that it first notified Google of the problem on 3 January, and confirmed that the list has since been cleaned of any sensitive user information. 

A Google spokesman told vnunet.com that all users who had information disclosed had been notified "weeks ago". 

The disclosure of usernames and passwords on the internet can be especially dangerous because many people use the same password for every site they visit, explained Finjan.

An attacker who obtained the password for one site could access more sensitive information on other sites, such as credit card numbers or bank account information.

Finjan advised users to avoid using the same password for several accounts, and to install security software and disable URL sharing in their browsers in order to avoid having sensitive data from URLs recorded.

Tags:

Further reading

Related articles

Virus and phishing attacks soar in September

Second surge of email attacks targeted at executives   More...

Government loses Standard Life customer details

Courier leaves 15,000 accounts at risk   More...

China accused of Trojan onslaught

Trail leads back to China-based operations including a government website   More...

Hackers set up stolen FTP account trading floor

Database discovered containing more than 8,700 harvested FTP account details   More...

Do you agree?

Advertisement

Job of the week

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Hiring now on ComputingCareers:

Related IT jobs

Search thousands of IT jobs :

Search thousands of IT jobs:

Advanced search

Advertisement

Watch

25 Jul 2008

7.85 MBPodcast Special: Views from the Valley More...

24 Jul 2008

3.68 MBSpammer jailed, Esquire e-cover, and network passwords More...

23 Jul 2008

2.99 MBSmall time security, official 'spying' requests and a spammer jail break More...

Poll

EUROPEAN E-COMMERCE

EUROPEAN E-COMMERCE

Are you happy making an online purchase from another European country?

Previous poll results

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Enter email address to edit your newsletter preferences

Spotlight

Credit card transaction

Credit card fraud rampant in the UK

Attempted frauds go unreported and ignored, analysts claim   More...

Intel

Intel rolls out new embedded line-up

System-on-a-chip offerings promise footprint and power saving   More...

Advertisement

Network cables

Tech giants collaborate on wireless HD

Another attempt at cable-free transmission in the home   More...

iPhone fever fills AT&T coffers

US provider cashes in on Apple smartphone   More...

Advertisement