Tag / 6 entries / feed available

Cloud Storage Misconfiguration

6 of the 76 analyses in Data Breaches carry this tag. All 6 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

040

Pegasus Airlines Data Exposure

In March 2022, Pegasus Airlines faced a major data breach caused by a cloud misconfiguration of an AWS S3 bucket, resulting in the exposure of approximately 23 million files. The breached data contained Personally Identifiable Information (PII) and sensitive operational details, posing significant risks including identity theft and operational disruptions. No direct external threat actors were confirmed to have exploited this vulnerability.

030

Capital One Data Breach 2019

Prevented by: EGR

In July 2019, Capital One experienced a major breach compromising over 100 million customer records due to a misconfigured Web Application Firewall exploited by a former Amazon Web Services employee. The attack led to unauthorized access to personal information including names, addresses, Social Security Numbers, and banking details, heightening the risk of identity theft and financial fraud. The incident emphasized vulnerabilities in cloud security configurations and poor application of the least privilege principle.

028

Facebook Data Breach 2019

In April 2019, Facebook experienced a major data breach exposing the personal information of over 530 million users from two datasets. The breach involved cloud storage misconfiguration and data scraping vulnerabilities, resulting in the leak of phone numbers and account names. The attack did not involve specific threat actors but exploited weaknesses in the Facebook contact importer and third-party AWS storage configurations.

021

Deep Root Analytics Data Breach

In 2017, a misconfigured Amazon Web Services (AWS) S3 bucket at Deep Root Analytics exposed sensitive data of nearly 200 million U.S. voters. The breach involved personal information such as names, addresses, birth dates, and political affiliations. This incident was primarily due to cloud storage misconfiguration without any evidence of external hacking, highlighting vulnerabilities in data handling practices by third-party vendors.

014

2014 Uber Data Breach

In 2014, Uber experienced a data breach impacting approximately 50,000 individuals, exposing personal information such as names and driver’s license numbers. Unauthorized access was facilitated through a publicly exposed AWS access key on GitHub, underscoring critical flaws in credential management and cloud security. No specific threat actors were identified, but the incident highlighted significant vulnerabilities in Uber’s data protection practices.

RSS feed for this tag →

Now playing Bandcamp