Tag / 50 entries / page 3 of 5 / feed available

Data Exfiltration

50 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

050

PharMerica Data Breach March 2023

Prevented by: PEC, EGR

In March 2023, PharMerica experienced a major data breach affecting approximately 5.8 million individuals. The incident involved the compromise of extensive patient data, including Social Security numbers, health records, and insurance information. The breach was executed by the Money Message ransomware group using double extortion tactics, leading to significant privacy risks and identity theft concerns.

048

Consumer Financial Protection Bureau Data Breach

The Consumer Financial Protection Bureau experienced a data breach in February 2023 caused by an employee transferring sensitive records to a personal email account, exposing the personally identifiable information of approximately 256,000 individuals. This breach involved data exfiltration from government systems, highlighting severe insider threat risks and deficiencies in internal data protection protocols. The compromised data originated from several financial institutions, posing potential privacy risks, although no misuse has been confirmed.

047

Google Fi Data Breach Linked to T-Mobile Incident

Prevented by: HSF

In February 2023, a data breach compromised Google Fi customers’ phone numbers and SIM card serial numbers due to vulnerabilities in T-Mobile’s infrastructure. The breach involved unauthorized data access, posing risks of SIM swap attacks and unauthorized account access. No specific threat actors were attributed to the breach, but it showcased potential organized cybercriminal activities focusing on telecom vulnerabilities.

046

NCB Management Services Data Breach February 2023

In February 2023, NCB Management Services experienced a major data breach compromising sensitive personal and financial information of over 1 million individuals. The breach occurred due to unauthorized access through a misconfigured database, lacking adequate security measures such as password protection and multifactor authentication. This data, including Social Security numbers and financial details, was extracted by unidentified external hackers, highlighting severe vulnerabilities in third-party vendor security.

044

MailChimp January 2023 Data Breach

Prevented by: HSF

In January 2023, MailChimp experienced a data breach caused by a social engineering attack, allowing unauthorized access to internal customer support tools. The breach affected 133 customer accounts, exposing names, store web addresses, and email addresses, while passwords and financial data remained secure. The attack involved unidentified individuals exploiting employee credentials, revealing vulnerabilities in phishing defenses.

041

Los Angeles Unified School District (LAUSD) Ransomware Breach

Prevented by: HSF, PEC, EGR

In September 2022, the Los Angeles Unified School District (LAUSD) suffered a ransomware attack by the Vice Society, which impacted over 1,000 schools and around 600,000 students. The breach compromised approximately 500 GB of data, including sensitive personal and educational records, due to exploited vulnerabilities such as lack of multi-factor authentication.

039

Yahoo Intellectual Property Theft

In February 2022, a former Yahoo employee allegedly stole approximately 570,000 pages of source code and strategic documents for financial gain at a competitor. This breach involved critical intellectual property and had significant competitive and financial impact on Yahoo.

038

Cash App Data Breach - April 2022

In December 2021, the Cash App experienced a significant data breach where a former employee accessed and downloaded sensitive financial information of approximately 8.2 million users. The compromised data included brokerage account numbers and details of stock trading activities, underscoring an insider threat and deficiencies in access management controls. This incident did not involve the leak of social security numbers or passwords.

037

South Georgia Medical Center Data Theft

In November 2021, South Georgia Medical Center experienced a data breach when a former employee, exploiting retained access, downloaded approximately 41,692 patient records onto a USB drive without authorization. The compromised data included protected health information such as patient names, birth dates, and test results. This incident underscores the threat posed by insiders and highlights vulnerabilities in data access management and removable media controls.

RSS feed for this tag →

Now playing Bandcamp