Section / 76 analyses / page 5 of 8

Data Breaches

Explore our collection of data breach case studies and learn from past incidents to improve your organization’s security posture.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

036

LinkedIn Data Scraping Incident

In April 2021, LinkedIn experienced a massive data scraping incident, exposing approximately 700 million user records. The breach involved personal information such as full names, email addresses, and professional details extracted through LinkedIn’s public API by a threat actor named ‘GOD User TomLiner.’ Although passwords and financial details were not compromised, the incident highlights significant risks for identity theft and phishing attacks.

035

Microsoft Exchange Server Breach

Prevented by: PEC, EGR

In January 2021, over 30,000 U.S. companies experienced a cyberattack on Microsoft Exchange email servers. The breach exploited several zero-day vulnerabilities, resulting in unauthorized email access and potentially sensitive data exposure. The attack was primarily attributed to the state-sponsored Hafnium group from China, leveraging server-side request forgery and other sophisticated methods.

034

Twitter 2020 Data Breach Incident

Prevented by: HSF

In July 2020, a 17-year-old hacker and his accomplices compromised Twitter’s internal systems through social engineering, taking control of approximately 130 high-profile accounts. These accounts were used to perpetrate a Bitcoin scam that led to financial losses of over $117,000. The attack highlighted significant vulnerabilities in Twitter’s protection against social engineering and demonstrated the persistent risk of insider threats.

031

SolarWinds Supply Chain Attack

Prevented by: PEC, EGR

The SolarWinds Supply Chain Attack involved the compromise of SolarWinds Orion software, leading to malicious updates that were installed by over 18,000 customers. This allowed the attackers, attributed to state-sponsored groups, to steal data and spy on organizations including U.S. government departments. The attack exploited software development vulnerabilities to insert SUNBURST malware, affecting multiple sectors globally.

030

Capital One Data Breach 2019

Prevented by: EGR

In July 2019, Capital One experienced a major breach compromising over 100 million customer records due to a misconfigured Web Application Firewall exploited by a former Amazon Web Services employee. The attack led to unauthorized access to personal information including names, addresses, Social Security Numbers, and banking details, heightening the risk of identity theft and financial fraud. The incident emphasized vulnerabilities in cloud security configurations and poor application of the least privilege principle.

029

First American Financial Corp Data Breach

In May 2019, First American Financial Corp. suffered a major data breach that exposed approximately 885 million file records due to a security flaw. The breach involved bank account details and mortgage-related documents, which were accessible through unsecured URLs without authentication. The vulnerability was attributed to insufficient security measures, and there were no specific threat actors identified.

028

Facebook Data Breach 2019

In April 2019, Facebook experienced a major data breach exposing the personal information of over 530 million users from two datasets. The breach involved cloud storage misconfiguration and data scraping vulnerabilities, resulting in the leak of phone numbers and account names. The attack did not involve specific threat actors but exploited weaknesses in the Facebook contact importer and third-party AWS storage configurations.

027

Norsk Hydro Ransomware Attack - March 2019

Prevented by: HSF, PEC

In March 2019, Norsk Hydro, one of the world’s largest aluminum producers, was hit by the LockerGoga ransomware attack. This incident caused significant operational disruptions and financial losses due to the encryption of critical systems and manual operation deployments. The attack exploited Active Directory vulnerabilities, although the exact perpetrators remain unidentified.

Now playing Bandcamp