AI-native security platform company AhnLab on Thursday issued security guidelines that users and service operators should check, citing a series of account and personal data leak incidents.
It recommended using different, independent passwords for each service. The company said using the same password across multiple services could allow account information leaked from one site to lead to account takeovers on other services.
It also advised enabling multi-factor authentication (MFA) and two-step verification. Users are advised to activate additional authentication methods such as an authentication app or one-time password (OTP) in a service’s account or security settings. With MFA enabled, even if a password is exposed, an additional verification step is required, which can lower the risk of account takeover.
Login history and account security settings need regular checks. Users should turn on login alerts and periodically review recent login records and the list of devices used to access the account. AhnLab recommended that if access from an unknown device is detected or a password-change alert arrives that the user did not request, the user should avoid using links in messages or emails and instead go directly to the official app or website to check account status and change the password.
Users should be cautious about clicking links of unclear origin and entering personal information. In particular, after a personal data leak incident, phishing and smishing messages that exploit user anxiety may be distributed under the pretext of “confirming a personal data leak,” “applying for compensation,” or “protecting an account.”
It also called for managing accounts saved in web browsers and keeping security updates current. AhnLab stressed that users should not use a browser’s password-saving or auto-login functions on shared PCs and should log out after use.
For service operators, API authentication, access control and monitoring for abnormal behavior are important. AhnLab said service operators should apply detailed access permission verification for each API request, in addition to user authentication, to prevent customer information leaks through application programming interfaces (APIs).
Security checks should cover not only customer-facing websites and apps but also admin pages used by employees and partners, business support systems and internal business systems. Customer information should be retained only within the scope needed for work, and information should be destroyed in line with relevant laws and internal standards once the retention purpose is met or the retention period has expired.
Ha-young Yang (양하영), head of AhnLab ASEC, said attackers can attempt further attacks using leaked account or personal information, making it important to strengthen basic security measures in advance. He said using different passwords for each service and enabling MFA can help reduce the risk of account takeovers and secondary damage. He urged service users to check security settings for services they use regularly, and said service operators should review access control and abnormal-behavior monitoring systems not only for customer-facing services but also for APIs and internal business systems.