- January 23, 2021
- Posted by: administrator
- Category: Security News
A hacker is selling a database with login details for two million high-paying users of the MyFreeCams adult video streaming and chat service.
The seller says that they obtained the database recently, following a successful SQL injection attack and that it can be used to steal the funds of premium members.
Selling in unique batches
MyFreeCams is a popular adult video chat platform with tens of millions of users. The service provides free access to chat rooms of a large number of models.
Free users can upgrade to a premium member account by purchasing tokens that can unlock otherwise restricted features or spent to tip the models.
On January 14, a hacker offered to sell a database containing usernames, plain text passwords, and emails belonging to two million paying MyFreeCams users.
The seller was offering 10,000 records for $1,500 in Bitcoin, saying that the logins guarantee a profit of at least $10,000 in tokens.
Despite the “generous” offer, buyers did not form a line and asked instead if they could purchase smaller increments, 1,000 records for $150. By the attention it got, it is safe to assume that at least a few thousand records have been sold.
In trying to increase sales, the hacker announced a few days ago that they would sell the records only one time, meaning that buyers would get different account logins.
According to CyberNews, who obtained a sample of the records, the database contains usernames, email addresses, passwords in plain text, and the balance of MyFreeTokens for each account.
According to the publication, the seller’s Bitcoin wallet recorded 45 transactions that accumulated a little over $21,000 worth of cryptocurrency (BTC 0.60222754) at the time of the check.
CyberNews says that they contacted MyFreeCams for a statement and received confirmation that the database is genuine. The adult video chat platform proceeded to notify affected users and reset their passwords.
NOTE:: This article is copyright by bleepingcomputer.com and we are using it for educational or Information purpose only