Section / 76 analyses / page 6 of 8

Data Breaches

Explore our collection of data breach case studies and learn from past incidents to improve your organization’s security posture.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

026

Marriott International Data Breach of 2018

Prevented by: HSF, PEC, EGR

In 2018, Marriott International experienced a data breach affecting approximately 500 million guests with compromised personal information including names, addresses, and passport numbers. The breach, linked to the Starwood reservation system acquired by Marriott, involved unauthorized access dating back to 2014, facilitated by malware known as remote access trojans (RATs). The incident raised concerns about potential involvement of state-sponsored actors and resulted in significant regulatory scrutiny, including fines under GDPR.

025

Copay Cryptocurrency Wallet Data Breach

Prevented by: SCA

In November 2018, the Copay cryptocurrency wallet, developed by BitPay, suffered a data breach due to a malicious version of the event-stream Node.js library. The breach involved unauthorized access to users’ private keys and cryptocurrency assets through dependency injection of malicious code by threat actors, significantly affecting wallets with considerable holdings. The attack highlighted vulnerabilities in third-party dependencies within the open-source software ecosystem.

024

Aadhaar Data Breach

The Aadhaar breach in January 2018 resulted in the unauthorized exposure of personal and biometric data of 1.1 billion Indian citizens. This was due to system vulnerabilities like unsecured API endpoints, allowing attackers access to sensitive data including bank account information. While specific threat actors remain unconfirmed, the large-scale data compromise highlights significant security lapses within the government’s database management.

023

2017 Equifax Data Breach

Prevented by: EGR · Contained by: PEC

The Equifax data breach in 2017 exposed sensitive personal and financial information of approximately 145.5 million individuals, including Social Security numbers and birthdates. Attackers exploited a vulnerability in the Apache Struts framework (CVE-2017-5638) to gain unauthorized access. The breach highlighted significant deficiencies in Equifax’s data protection and vulnerability management processes.

022

NotPetya Ransomware Attack

Prevented by: PEC

The NotPetya ransomware attack in June 2017 caused extensive financial damage exceeding $10 billion by utilizing a compromised software update from MeDoc, a Ukrainian accounting software. The malware employed the EternalBlue exploit to propagate widely, primarily acting as a wiper rather than traditional ransomware. It severely disrupted corporate operations globally, affecting numerous high-profile organizations such as Maersk and FedEx, and has been attributed to state-sponsored actors linked to Russian military intelligence.

021

Deep Root Analytics Data Breach

In 2017, a misconfigured Amazon Web Services (AWS) S3 bucket at Deep Root Analytics exposed sensitive data of nearly 200 million U.S. voters. The breach involved personal information such as names, addresses, birth dates, and political affiliations. This incident was primarily due to cloud storage misconfiguration without any evidence of external hacking, highlighting vulnerabilities in data handling practices by third-party vendors.

020

2016 Uber Data Breach

Prevented by: HSF

On November 14, 2016, Uber suffered a data breach exposing the personal information of 57 million users and 600,000 driver license numbers. Hackers accessed Uber’s data by exploiting credential mismanagement and accessing unsecured AWS S3 buckets, following infiltration of Uber’s GitHub repositories. The perpetrators, identified as Brandon Charles Glover and Vasile Mereacre, demanded a ransom disguised as a bug bounty program to avoid public disclosure.

019

AdultFriendFinder Data Breach

Contained by: EGR

The 2016 AdultFriendFinder data breach exposed approximately 412 million user accounts due to vulnerabilities in Local File Inclusion (LFI). Compromised data included usernames, email addresses, and passwords, mostly stored in plaintext or hashed with weak SHA-1, making them vulnerable to cracking. While the exact perpetrators remain unidentified, discussions suggest involvement from actors on Russian forums.

018

Office of Personnel Management Data Breach 2015

Prevented by: HSF, EGR

In 2015, the Office of Personnel Management (OPM) suffered a major data breach that exposed personal information, including Social Security Numbers and biometric data of approximately 21.5 million individuals. The breach involved sophisticated data exfiltration methods believed to be executed by state-sponsored actors, specifically linked to Chinese hackers. Vulnerabilities in OPM’s legacy systems, coupled with compromised contractor credentials, allowed attackers unauthorized access to sensitive data.

017

Anthem Data Breach Incident Analysis

Prevented by: PEC, EGR · Contained by: HSF

The Anthem Data Breach in 2015 exposed approximately 78.8 million records, including sensitive Personal Identifiable Information (PII) such as names, birthdates, medical IDs, and Social Security numbers. The breach was executed via a phishing campaign linked to a state-sponsored group, reportedly associated with Chinese cyberespionage activities. The attackers utilized sophisticated malware including Mivast and Sakula to infiltrate the network and execute data exfiltration without detection.

Now playing Bandcamp