Skip to content
October 5, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Free Tools
    • CVSS 3.1 Calculator
    • Certificate Viewer
    • DNS Lookup
    • Encoder & Hash Generator
    • IP / Subnet Calculator
    • Whois Lookup
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • News
  • Data Leak
  • Login information for a large number of Mega accounts has been compromised
  • Data Leak

Login information for a large number of Mega accounts has been compromised

Do Son July 17, 2018 3 minutes read
Add Daily CyberSecurity as a preferred source on Google

Mega, a company founded in New Zealand that provides online cloud storage and files hosting services, is currently found to have thousands of account credentials on its platform that have been publicly posted online. The leaked information is provided as a text file. It is understood that this text file contains more than 15,500 usernames, passwords, and file names, which means that these accounts have been abnormally logged in, and the file name in the account is also crawled.

This text file was first discovered by Patrick Wardle, chief research officer and co-founder of Digita Security, on the malware analysis website VirusTotal in June, the document was uploaded a few months ago by a user allegedly in Vietnam.

ZDNet said that they have verified these accounts and confirmed that the data comes from Mega. By contacting multiple users, it is also determined that these emails, passwords and some files are used on the Mega.
According to Troy Hunt, administrator of the “Have I Been Pwned” website, the data was not obtained by directly invading the Mega, but was crashed. He said that 98% of the email addresses in the file already exist in his database (collected in previous vulnerabilities).
ZDNet also said that five of the people they contacted said they used the same password on different websites. He doesn’t know who created this list or how it was crawled. Although Mega provides end-to-end encryption, it does not use two-factor authentication when logging in, so an attacker can log in to each account using the login credentials and fetch the file name of the file in the account.
Stephen Hall, chairman of Mega, said that:
“Mega has zero tolerance for child sexual abuse materials. Any reports result in links being deactivated immediately, the user’s account closed and the details provided to the authorities.
Mega can’t act as censor by examining content as it is encrypted at the user’s device before being transferred to Mega. As well as it being technically impossible, it is also practically infeasible for Mega and other major cloud storage providers, with 100s of files being uploaded each second.”
This is not the first time Mega has encountered a security issue. In 2016, hackers claimed to have acquired internal Mega documents by exploiting security vulnerabilities in their servers. The hacker also stated that he had obtained seven email addresses associated with the administrative account. Stephen Hal stated that no user data was compromised at the time.
Source: ZDNet

Related coverage

  • Protecting Malaysians’ Data: New Breach Notification System in Place
  • Avast Privacy Breach: FTC Refunds Open Until June 2025
  • Popular Chrome Extensions Caught Leaking Sensitive User Data via Unencrypted HTTP
  • The “Vibe Coding” Disaster: How a Simple Bug Exposed 4.75 Million Records on the AI Social Network Moltbook
  • TikTok Faces Civil Lawsuit for COPPA Violations, Millions of Children Affected
  • Purdue University data breach: 26,000 students personal details leaked
Track all actively exploited CVEs →

Support Our Threat Intelligence

Find our threat intelligence and malware analysis helpful? Support our work today and unlock a 100% ad-free reading experience!

Buy Me a Coffee Logo Buy Me a Coffee
Select your plan
Free Pro Team

Hover over a plan to see its benefits.

Get Zero-Hour Vulnerability Alerts

Critical CVEs, CVSS scores, and PoC updates — straight to your inbox every week.

We respect your inbox. Unsubscribe anytime.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Written by
@DdoS · Security Researcher

Do Son

Do Son is the Founder and Editor of SecurityOnline.info. Working in cybersecurity since 2013, he reports on vulnerabilities, malware, and emerging threats, providing timely analysis to help organizations and individuals stay ahead of evolving risks.

Tags: Mega accounts

Search

Translation

CVE ALERTS
📈

EPSS Spike Alerts
Catch risk spikes before they make headlines.

🎯

Custom EPSS/CVSS
Set score thresholds to effectively filter noise.

🛡️

Exploit Intel
Real-world exploit signals beyond the KEV catalog.

🐙

GitHub Issues
Auto-create alert tickets without duplication.

📬

Weekly Digest
Clean summaries, eliminating email spam.

🏷️

Watchlist Groups
Tag vulnerabilities by team (Infra/AppSec/SOC).

🔀

Smart Routing
Route chat channels based on severity levels.

🚨

RBP Tracker
Early warning detection and tracking system.

Subscribe – $7/mo or try free for 14 days →

🚨 Active Exploits in the Wild

  • CVE-2026-88779CVSS 8.7
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: before 14.1-73.41, before 13.1-64.28, before 14.1-73.41 FIPS,...
    Admin intelCISA KEV📅 Added to KEV: Oct 4, 2026📅 Updated: Oct 4, 2026
  • CVE-2026-102490CVSS 8.5
    All versions of Zammad including the latest alpha enable the local zammad user to escalate privileges to root.
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-102489CVSS 8.7
    Zammad versions 6.3.0 to 6.5.4 are vulnerable a session hijack vulnerability that leads to remote code execution as...
    Admin intelCISA KEV📅 Added to KEV: Oct 2, 2026📅 Updated: Oct 2, 2026
  • CVE-2026-100382CVSS 10.0
    Improper Neutralization of Special Elements used in an OS Command (\'OS Command Injection\') vulnerability in Wikimedia Foundation Mediawiki...
    Admin intel📅 Updated: Oct 1, 2026
  • CVE-2026-104286CVSS 9.8
    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through...
    CISA KEV📅 Added to KEV: Oct 1, 2026
  • CVE-2026-76504CVSS 9.8
    A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote...
    Admin intelCISA KEV📅 Added to KEV: Sep 30, 2026📅 Updated: Sep 30, 2026
  • CVE-2026-86950CVSS 8.8
    An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and...
    Admin intelCISA KEV📅 Added to KEV: Sep 29, 2026📅 Updated: Sep 29, 2026
  • CVE-2026-88772
    Memory overflow vulnerability leading to remote code execution or denial of service.
    Admin intelCISA KEV📅 Added to KEV: Sep 27, 2026📅 Updated: Sep 27, 2026
Powered by CVE Watchtower

Critical Vulnerabilities

  • CVE-2026-100781CVSS 9.6
    Sandbox escape due to incorrect boundary conditions in the Graphics: WebRender component. This vulnerability was fixed in Firefox...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105293CVSS 9.2
    Legcord 1.1.0 through 1.3.0 contains a path traversal vulnerability in theme IPC handlers that allows script in the...
    📅 Updated: Oct 5, 2026
  • CVE-2026-100551CVSS 9.0
    OpenClaw for iOS versions >= 2026.7.1 and < 2026.8.11 do not enforce saved Gateway TLS pins in the...
    📅 Updated: Oct 5, 2026
  • CVE-2026-105218CVSS 9.1
    gopay before 1.5.119 disables TLS certificate verification in defaultClient() in pkg/xhttp/client.go, allowing man-in-the-middle attackers to impersonate payment provider...
    📅 Updated: Oct 5, 2026
  • CVE-2026-82042CVSS 9.3
    UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access...
    📅 Updated: Oct 5, 2026
  • CVE-2026-79820CVSS 9.0
    A remote user validation failure vulnerability exists in HPE Integrated Lights-Out (iLO) 7 firmware.
    📅 Updated: Oct 5, 2026
  • CVE-2026-105223CVSS 9.1
    maclof kubernetes-client 0.17.0 before 0.32.0 disables TLS certificate verification in parseKubeconfig() and parseKubeconfigFile() when a kubeconfig lacks certificate-authority-data,...
    📅 Updated: Oct 5, 2026
  • CVE-2025-6544CVSS 9.8
    A deserialization vulnerability exists in h2oai/h2o-3 versions
    📅 Updated: Oct 5, 2026
Powered by CVE Watchtower

Daily CyberSecurity

  • About SecurityOnline.info
  • Advertise with us
  • Announcement
  • Contact
  • Contributor Register
  • Login
  • Disclaimer
  • DCMA
  • Privacy Policy
  • About SecurityOnline.info
  • Advertise on SecurityOnline.info
  • Contact Us

When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

  • CVE Watchtower
  • CVE Statistics by Vendor 2026
  • Q2 2026 Report
  • Top Exploited CVEs
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube
© 2017 - 2026 Daily CyberSecurity. All Rights Reserved.