Naz.API Leaks Data from Over 70 Million Accounts

Naz.API Leaks Data from Over 70 Million Accounts

What Happened?

A report from Troy Hunt, the creator of the website Have I Been Pwned, alerted readers to a major data leak from Naz.API, a database containing data from over 70 million accounts and over a billion unique records. Hunt’s investigation has revealed “a significant volume of new data” and newly compromised accounts, and these accounts’ owners are at risk.

Key Takeaways

According to the report, a “well-known,” unnamed technology firm discovered the dataset in a hacking forum post published in September 2023, through a bug bounty submission, and contacted Hunt with these details. 

An investigation into these findings revealed that 34.97% (over one-third) of the email addresses in this dataset were new, and not available in Have I Been Pwned’s database. The report’s findings indicate that these credentials were compiled from infostealers exfiltrating  credentials from compromised endpoints and environments, and data stolen in several credential stuffing attacks and previous breaches. (In fact, Hunt also recognized his own information from an illegal website that allowed threat actors to search for people’s data.) 

The report also shared a screenshot of the stealer logs, which contained a URL to login, an email address to log in, and the password in his findings.

In total, Hunt identified 319 files, with a total file size of 104 GB. He was also able to verify that the credentials were real by contacting several people listed in these infostealer logs, and by using website password request forms or registration forms to confirm that the email address exists in their account bases.

Why This Matters to Helpdesks

Are You Rotating Your Credentials?

The size of this data leak poses a major risk to MSPs and end users alike, and truly emphasizes the risks associated with stale or reused credentials and standing privilege, such as persistent admin accounts. 

Are You Implementing Zero Standing Privilege?

That’s why security best practices require individuals and organizations to mitigate their risk by regularly rotating critical credentials, and limiting privileged access through solutions like Just-in-Time access.

Next Steps

CyberQP’s security experts recommend that concerned MSPs and end users take the following actions to mitigate their risk:

  • Check if your data has been compromised with a service like Have I Been Pwned.
  • Add another layer of protection to your key accounts, including complex passwords or passphrases and multi-factor authentication (2FA/MFA).
  • For privileged accounts, utilize a password vault and implement additional protection, such as end user identity verification. 
  • MSPs can implement a moving target defense for their privileged accounts by regularly rotating credentials to deter threat actors and prevent them from achieving a foothold in your environment or executing lateral movement attacks.  
  • MSPs can also reduce their attack surface with Just-in-Time accounts that only grant privileged access for the amount of time a user needs it. Solutions like these also enable them to meet compliance and cyber insurance best practices by achieving zero standing privilege. 

CyberQP redefines Zero Trust Helpdesk Security with leading-edge Privileged Access Management (PAM) and End-User Access Management (EUAM) solutions. Our platform enables secure elevated access for both technicians and end users, along with robust self-serve and identity verification capabilities. Backed by SOC 2 Type 2 certification, we empower IT professionals to eliminate identity and privileged access security risks, enforce compliance, and enhance operational efficiency. Our mission is simple: “Empowering Access, Redefining Privilege” for help desks around the globe. To learn more visit: https://cyberqp.com/tours

CyberQP Releases Groundbreaking Zero Trust Helpdesk Security Platform to Eliminate Standing Privileges

CyberQP Releases Groundbreaking Zero Trust Helpdesk Security Platform to Eliminate Standing Privileges

Vancouver, B.C., CanadaCyberQP, a leading provider of access management solutions, has launched its Zero Trust Helpdesk Security Platform—combining QGuard for Privileged Access Management (PAM) and QDesk for End-User Access Management (EUAM). This unified solution helps IT teams reduce risk, improve efficiency, and eliminate standing privileges across the organization.

Game-Changing Access Control

A key innovation of the platform is End-User Elevation, which allows users to gain temporary admin access without persistent privileges. By automating approval processes and monitoring activity in real-time, CyberQP dramatically reduces attack surfaces while maintaining security and compliance. 

“We built this platform to address major security gaps caused by always-on access,” said Mateo Barraza, CEO & Co-Founder of CyberQP. “With QGuard and QDesk, businesses can finally enforce true Zero Trust principles across their environments.” 

Platform Highlights

  • Just-in-Time Access: Grant technicians and users time-limited access only when needed—no standing privileges, no exposed passwords. 
  • Credential Rotation: Automatically rotate credentials to prevent stale logins and reduce vulnerability to attacks. 
  • Self-Service Tools: End users can reset passwords and manage accounts without technician intervention, cutting down ticket volume and costs. 
  • Helpdesk Verification: Instantly verify user identities to prevent social engineering and fraud. 
  • Comprehensive Visibility: A unified dashboard delivers insights across privileged and end-user access activity. 

CyberQP integrates with PSA platforms including ConnectWise, Datto Autotask, and Halo PSA, and meets key compliance and cyber insurance requirements with SOC 2 Type 2 certification.

Availability

The CyberQP Zero Trust Helpdesk Security Platform is available now. For more information, visit www.cyberqp.com.

Zero Trust Access Management

About CyberQP

CyberQP redefines Zero Trust Helpdesk Security with leading-edge Privileged Access Management (PAM) and End-User Access Management (EUAM) solutions. Our platform enables secure elevated access for both technicians and end users, along with robust self-serve and identity verification capabilities. Backed by SOC 2 Type 2 certification, we empower IT professionals to eliminate identity and privileged access security risks, enforce compliance, and enhance operational efficiency. Our mission is simple: “Empowering Access, Redefining Privilege” for help desks around the globe.

Naz.API Leaks Data from Over 70 Million Accounts

Introducing The Future of Zero Trust Helpdesk Security: Meet the Comprehensive CyberQP Platform

When I heard this, I knew immediately how excited this one is going to make many of our partners. CyberQP has just launched its game-changing Zero Trust Helpdesk Security Platform, designed to tackle one of the biggest challenges in IT security: managing all the layers of privileged and end-user access without the headache. 

Let’s face it: cyber threats are getting smarter. Bad actors today are using sophisticated social engineering attacks like Vishing and impersonation to circumvent traditional cybersecurity tools. But with CyberQP’s platform, companies can lock down access, boost productivity, and rest easier knowing their systems are secure. 

A Powerful Duo: QGuard + QDesk

At the heart of this new platform are two powerful tools: QGuard and QDesk. 

QGuard is your go-to solution for Privileged Access Management (PAM). It eliminates standing privileges, reduces the risk of credential-based attacks, and ensures technicians get only the access they need—when they need it. No more passwords to steal or stale admin accounts floating around.

QDesk takes End-User Access Management (EUAM) to the next level. It simplifies identity verification, manages password resets, and streamlines secure access for end users. Best part? It integrates seamlessly with your existing PSA tools like ConnectWise and Autotask.  

End-User Elevation: A Game Changer

We get it—sometimes end users need admin access to get their jobs done. But granting full, unrestricted access? That’s a risk no one wants to take. That’s where End-User Elevation comes in. With this new feature, end users can request time-limited, process-based admin access that’s automatically revoked once they’re done. Technicians can approve just the applications or installations that require elevation, keeping security intact. 

  • Auto Approval Rules Engine: Customize automatic approvals for trusted applications.
  • Process-Based Elevation: Approve only what’s necessary without exposing the whole system.
  • Audit Logs: Maintain complete visibility with detailed records of all elevation requests.

Why Zero Trust Matters

The CyberQP platform is built with Zero Trust principles at its core. That means no one is trusted by default—every request is verified, every action is logged, and access is always limited to the bare minimum required. 

This approach drastically reduces the attack surface, preventing ransomware attacks, credential theft, and other malicious activities. 

See It In Action

Ready to experience a more secure, efficient helpdesk? CyberQP’s Zero Trust Helpdesk Security Platform is available now. Say goodbye to standing privileges and hello to smarter, safer access management. 

Book a Demo and see how we’re redefining privilege management.

Paul Redding

Paul Redding

SVP, Channel Marketing and Communities

Paul Redding began his career as the CEO of an MSP specializing in clients from highly regulated industries such as healthcare and US Department of Defense supply chain. Following his exit, Paul reemerged as a prominent thought leader and passionate advocate in the IT channel. Leveraging his extensive experience helping organizations navigate and maintain cybersecurity compliance, Paul now collaborates with partners worldwide to help them implement top-tier security practices, streamline support processes by eliminating repetitive tasks, and foster deeper, more profitable client relationships.

CyberQP redefines Zero Trust Helpdesk Security with leading-edge Privileged Access Management (PAM) and End-User Access Management (EUAM) solutions. Our platform enables secure elevated access for both technicians and end users, along with robust self-serve and identity verification capabilities. Backed by SOC 2 Type 2 certification, we empower IT professionals to eliminate identity and privileged access security risks, enforce compliance, and enhance operational efficiency. Our mission is simple: “Empowering Access, Redefining Privilege” for help desks around the globe. To learn more visit: https://cyberqp.com/tours

How Passwordless JIT Helps IT and Security Professionals Meet Cyber Insurance Requirements

How Passwordless JIT Helps IT and Security Professionals Meet Cyber Insurance Requirements

WHITE PAPER

How Passwordless JIT Helps IT and Security Professionals Meet Cyber Insurance Requirements

Cyber Insurance Requirements Have Changed for your Security and IT Teams

When the CyberQP team analyzed publicly available cyber insurance eligibility questionnaires, we saw that cyber insurance providers aren’t just asking for traditional Identity and Access Management (IAM) or Privileged Access Management (PAM) solutions in a business’ security program anymore. Here’s what we found…

 

MSP Incident Insights

How the CyberQP Platform Follows Least Privileges

MSP Statistics

Credential Stuffing Attacks

When a threat actor launches a credential stuffing attack, MSPs can use QGuard Pro to reduce or eliminate the amount of time a privileged account is vulnerable for, with rotating credentials, Just-in-Time access, and Passwordless MFA logins.

Malware and Ransomware

Malware and ransomware variants frequently target Active Directory and privileged accounts. By limiting privileged access, QGuard Pro limits the amount of lateral movement a threat actor can potentially take during an incident.

Insider Threats

 When a threat actor launches a credential stuffing attack, MSPs can use QGuard Pro to reduce or eliminate the amount of time a privileged account is vulnerable for, with rotating credentials, Just-in-Time access, and Passwordless MFA logins.

How IT and Security Teams Can Build A PAM Strategy:

CyberQP is prepared to help MSPs and help desks meet these cyber insurance requirements, prepare for discussions with cyber insurance providers, and have conversations about why their end users need to adopt proactive security measures. Using QGuard Pro, CyberQP Partners can issue unique Just-in-Time accounts per technician to replace persistent admin accounts and only offer privileged access when a technician needs it.

MSP Statistics

MSPs can also go one step further with Passwordless JIT Access for Technicians, which enables MSPs to secure their endpoints and servers by adding a dedicated MFA challenge and eliminating password interactions. Achieve a competitive edge in compliance management. Technicians can also use the CyberQP dashboard to enforce a culture of accountability with clean audit logs.

Are You Ready To Reduce Your Attack Surfaces?

    The Security Automation Blueprint for MSPs

    The Security Automation Blueprint for MSPs

    e-book

    The Security Automation Blueprint for MSPs

    Are manual account lockout and password reset tickets your kryptonite? Become a ticket resolution speedster without compromising your help desk’s cybersecurity, powered by CyberQP.

    Prevent Cyber Threats in Less Than 30 Seconds

    Impersonators and fraudsters are today’s supervillains. Transform your technicians into MSP superheroes with CyberQP’s MSP Security Automation Blueprint! 

    You’ll learn how help desks like yours use Customer Workforce Verification to deter modern social engineering techniques and impersonation attempts.

    MSP Incident Insights

    Empower End Users with Password Resets

    Securing a Hybrid Work Environment

    As hybrid work and Work From Anywhere policies become the norm, SMBs are no longer solely reliant on a local pool of talent. With the ability to hire professionals from the global talent pool, MSPs and SMBs may end up working with people that they’ve never met in person. Moreover, as both an MSP and their clients grow, and as employees come and go, it can be difficult for your technicians to parse through which requests are legitimate

    MSP Statistics

    Did you know?

    Password reset tickets amount to 20-30% of all help desk support tickets and cost up to $75 per incident! The right password reset tool will put the power to get back online in an end user’s hands and use modern security measures (such as biometric authentication) to eliminate frustrating phone calls and deter impersonation attacks. Moreover, a self-service experience will enable MSPs to resolve password reset tickets ten times faster.

    MSP Statistics

    Mitigate your Security Risks Today!