Study Shows 30% of CEOs Have Been “Pwned,” Passwords Exposed

Email exposure study also shows 81% of the world’s top CEOs have had their personal information exposed in spam lists or leaked marketing databases.

Buckinghamshire, UK – 25th October, 2017: Nearly one in three major CEOs has been “pwned” using their company email address, according to a new F-Secure study of CEO email exposure. In other words, a service they access using their company email has been hacked and the password they use for that service has leaked. Without proper password practices, this potentially increases their susceptibility to targeted attacks.

The study, CEO Email Exposure: Passwords and Pwnage, delves into known company email addresses used by top executives from more than 200 of the biggest companies in ten countries. Researchers compared those addresses with F-Secure’s database of credentials leaked from breaches of online services. Among other findings:

• The most common previously breached services for CEOs to link their company email with are LinkedIn and Dropbox. • The countries with the highest percentages of CEOs who’ve linked their email to these breached services are Denmark, at 62%, and the Netherlands, at 43%. • 81% of CEOs have had their email address and other personal information such as birthdates, addresses, and phone numbers exposed online in the form of spam lists or leaked marketing databases. • The countries with the greatest level of CEO info exposed on spam and marketing lists are the Netherlands, the UK and the USA, all at 95%. • Just 18% of CEOs have no leaks associated with their email address.

“This study once again underscores the importance of proper password hygiene,” said Erka Koivunen, Chief Information Security Officer at F-Secure. “The CEO’s credentials may have leaked even when they have done nothing wrong. We can assume that a many of the services we’ve created an account in have already been compromised and the old passwords are out there on the internet, just waiting for targeted, motivated attackers to try them against other services.”

By using poor password habits, a top executive is putting their own accounts at risk – but not only that, company data as well. According to the 2016 Verizon Data Breach Investigations Report, 63% of confirmed data breaches involved weak, default, or stolen passwords.* A breach caused by unauthorised use of a CEO’s credentials would be difficult to spot for most companies, who are ill-prepared to handle breaches, according to data from F-Secure risk management assessments.

Using a unique, strong password for each online account is fundamental to keeping hackers at bay – and experts recommend using a password manager to make it seamless and easy. F-Secure Password Protection, the only available password manager that comes integrated with endpoint security clients, is a brand new component of F-Secure Protection Service for Business. It will be released on November 1.

For more details, password advice from a white hat hacker, and to find out when CEOs should link social accounts with their company email, download the full report, CEO Email Exposure: Passwords and Pwnage.

*Source: 2016 Verizon Data Breach Investigations Report, http://www.verizonenterprise.com/resources/reports/rp_DBIR_2016_Report_en_xg.pdf More Information REPORT - CEO Email Exposure: Passwords and Pwnage

About F-Secure

Nobody has better visibility into real-life cyber attacks than F-Secure. We’re closing the gap between detection and response, utilizing the unmatched threat intelligence of hundreds of our industry’s best technical consultants, millions of devices running our award-winning software, and ceaseless innovations in artificial intelligence. Top banks, airlines, and enterprises trust our commitment to beating the world’s most potent threats. Together with our network of the top channel partners and over 200 service providers, we’re on a mission to make sure everyone has the enterprise-grade cyber security we all need.

Founded in 1988, F-Secure is listed on the NASDAQ OMX Helsinki Ltd.

f-secure.com | twitter.com/fsecure | linkedin.com/f-secure

F-Secure media relations

Adam Pilkey

PR Content Manager

+358 40 637 8859
adam.pilkey@f-secure.com

Press list

Sign up for media information from F-Secure.

We process the personal data you share with us in accordance with our Corporate Business Privacy Policy.

Press archive

By year

Browse through our news by year.

By category

Browse through our news by category.