• phlegmy@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      13 hours ago

      I don’t think that’s guaranteed to be true.

      A very old email of mine which I haven’t used in many years was in the breach.
      None of my other email addresses were in there, so it’s highly unlikely that I was affected by this malware in the last decade.
      That email has been in many other breaches however, so I wouldn’t be surprised if somebody who had access to an old dump was infected.
      My money’s on some random skid who downloaded an old database dump and got infected when they downloaded some bad warez.

      Either that, or this includes credentials from people who had the malware 15+ years ago.

      • Manifish_Destiny@lemmy.world
        link
        fedilink
        English
        arrow-up
        1
        ·
        4 hours ago

        Then they must have tried your password and saved it to one of a specific number of places. Infostealers are by definition a class of malware, which means it’s got to be installed somewhere with access to the directory storing the credential.

        Or it was from an old computer, or mislabeled.

        https://www.youtube.com/watch?v=L3f9do5mtT8

        Here’s a good talk on infostealers for anyone curious.