Tag / 10 entries / feed available

Credential Stuffing

10 of the 76 analyses in Data Breaches carry this tag. All 10 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

063

23andMe Data Breach

Prevented by: HSF

In December 2023, a data breach at genetic testing company 23andMe exposed the personal data of approximately 6.9 million users to unauthorized access. The breach, executed through credential stuffing, compromised user profiles and familial connections, leaving sensitive personal data vulnerable. It underscored the need for robust password practices and security measures such as multi-factor authentication.

049

Chick-fil-A Data Breach March 2023

Prevented by: HSF

In March 2023, Chick-fil-A experienced a significant data breach due to unauthorized login activities via a credential stuffing attack. The incident exposed personal information of approximately 71,473 users, including names, email addresses, membership details, and partial payment information. This breach was facilitated by credential reuse and highlights the vulnerabilities in login security protocols.

045

Norton Life Lock Credential Stuffing Data Breach

Prevented by: HSF

In January 2023, Norton LifeLock experienced a data breach impacting over 6,000 customer accounts due to a credential stuffing attack. The attackers used previously compromised passwords from dark web datasets to gain unauthorized access. Exposed data included personal information such as names, phone numbers, and addresses, increasing the risk of identity theft. Although approximately 925,000 accounts were targeted, only a fraction was breached.

034

Twitter 2020 Data Breach Incident

Prevented by: HSF

In July 2020, a 17-year-old hacker and his accomplices compromised Twitter’s internal systems through social engineering, taking control of approximately 130 high-profile accounts. These accounts were used to perpetrate a Bitcoin scam that led to financial losses of over $117,000. The attack highlighted significant vulnerabilities in Twitter’s protection against social engineering and demonstrated the persistent risk of insider threats.

027

Norsk Hydro Ransomware Attack - March 2019

Prevented by: HSF, PEC

In March 2019, Norsk Hydro, one of the world’s largest aluminum producers, was hit by the LockerGoga ransomware attack. This incident caused significant operational disruptions and financial losses due to the encryption of critical systems and manual operation deployments. The attack exploited Active Directory vulnerabilities, although the exact perpetrators remain unidentified.

020

2016 Uber Data Breach

Prevented by: HSF

On November 14, 2016, Uber suffered a data breach exposing the personal information of 57 million users and 600,000 driver license numbers. Hackers accessed Uber’s data by exploiting credential mismanagement and accessing unsecured AWS S3 buckets, following infiltration of Uber’s GitHub repositories. The perpetrators, identified as Brandon Charles Glover and Vasile Mereacre, demanded a ransom disguised as a bug bounty program to avoid public disclosure.

015

JPMorgan Chase Data Breach

Prevented by: HSF, EGR

In June 2014, a data breach at JPMorgan Chase compromised the accounts of over 76 million households and 7 million small businesses. The attackers accessed names, addresses, phone numbers, and email addresses, leveraging phishing and exploiting network vulnerabilities. The breach has been linked to cybercriminals Gery Shalon, Ziv Orenstein, and Joshua Aaron, emphasizing gaps in network security and authentication procedures.

012

eBay Data Breach Analysis

Prevented by: HSF, EGR

In early 2014, eBay experienced a significant data breach affecting approximately 145 million user records. The compromised data included names, encrypted passwords, email addresses, physical addresses, phone numbers, and birth dates. Cyber attackers used stolen employee credentials, likely acquired through sophisticated phishing tactics, to gain unauthorized access to eBay’s network. While the encrypted passwords were compromised, PayPal’s financial information remained secure due to separate storage protocols.

005

LinkedIn Password Breach

Prevented by: HSF, PEC, EGR

The LinkedIn Password Breach in 2012 affected over 117 million user accounts by exposing passwords hashed with the insecure SHA1 algorithm, unsalted. The breach data was subsequently sold on cybercrime forums, with LeakedSource holding a searchable database. The exposure of user credentials posed significant risks of unauthorized account access.

RSS feed for this tag →

Now playing Bandcamp