05/09/2018
The below is Thanks to Ares Risk Management. Please contact Anna M Heim if you need immediate help
*******************************************
BREAKING NEWS:
This just crossed my desk and is too important to hold off posting till tomorrow... I don't know how many in the UK might be using an app with origins in New Zealand, notwithstanding the www is a global place and we all use apps from across the world... so
If you are using Chrome browser extension from the MEGA file storage service, uninstall it right now.
The official Chrome extension for the MEGA.nz cloud storage service had been compromised and replaced with a malicious version that can steal users' credentials for popular websites like Amazon, Microsoft, Github, and Google, as well as private keys for users' cryptocurrency wallets.
On 4 September at 14:30 UTC, an unknown attacker managed to hack into MEGA's Google Chrome web store account and upload a malicious version 3.39.4 of an extension to the web store, according to a blog post published by the company.
Malicious MEGA Chrome Extension Steals Passwords!
Please note this ONLY affects Chrome users which use the Mega Chrome Extension!
Mega have updated their app to a clean version within 4 hours of the attack, please go to their website to get a clean version. (https://mega.nz)
Google removed the infected app from their app store within 5 hours of being notified of the attack and as yet, the app has not been republished to the Google App Store.
The Bottom line:
Users who had installed the malicious extension should uninstall the MEGA extension version 3.39.4 right now, and change passwords for all your accounts, especially for those you may have used while having the malicious extension.
MEGA provides free cloud storage with convenient and powerful always-on privacy. Claim your free 50GB now