Tag / 50 entries / page 4 of 5 / feed available

Data Exfiltration

50 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

031

SolarWinds Supply Chain Attack

Prevented by: PEC, EGR

The SolarWinds Supply Chain Attack involved the compromise of SolarWinds Orion software, leading to malicious updates that were installed by over 18,000 customers. This allowed the attackers, attributed to state-sponsored groups, to steal data and spy on organizations including U.S. government departments. The attack exploited software development vulnerabilities to insert SUNBURST malware, affecting multiple sectors globally.

026

Marriott International Data Breach of 2018

Prevented by: HSF, PEC, EGR

In 2018, Marriott International experienced a data breach affecting approximately 500 million guests with compromised personal information including names, addresses, and passport numbers. The breach, linked to the Starwood reservation system acquired by Marriott, involved unauthorized access dating back to 2014, facilitated by malware known as remote access trojans (RATs). The incident raised concerns about potential involvement of state-sponsored actors and resulted in significant regulatory scrutiny, including fines under GDPR.

025

Copay Cryptocurrency Wallet Data Breach

Prevented by: SCA

In November 2018, the Copay cryptocurrency wallet, developed by BitPay, suffered a data breach due to a malicious version of the event-stream Node.js library. The breach involved unauthorized access to users’ private keys and cryptocurrency assets through dependency injection of malicious code by threat actors, significantly affecting wallets with considerable holdings. The attack highlighted vulnerabilities in third-party dependencies within the open-source software ecosystem.

024

Aadhaar Data Breach

The Aadhaar breach in January 2018 resulted in the unauthorized exposure of personal and biometric data of 1.1 billion Indian citizens. This was due to system vulnerabilities like unsecured API endpoints, allowing attackers access to sensitive data including bank account information. While specific threat actors remain unconfirmed, the large-scale data compromise highlights significant security lapses within the government’s database management.

023

2017 Equifax Data Breach

Prevented by: EGR · Contained by: PEC

The Equifax data breach in 2017 exposed sensitive personal and financial information of approximately 145.5 million individuals, including Social Security numbers and birthdates. Attackers exploited a vulnerability in the Apache Struts framework (CVE-2017-5638) to gain unauthorized access. The breach highlighted significant deficiencies in Equifax’s data protection and vulnerability management processes.

020

2016 Uber Data Breach

Prevented by: HSF

On November 14, 2016, Uber suffered a data breach exposing the personal information of 57 million users and 600,000 driver license numbers. Hackers accessed Uber’s data by exploiting credential mismanagement and accessing unsecured AWS S3 buckets, following infiltration of Uber’s GitHub repositories. The perpetrators, identified as Brandon Charles Glover and Vasile Mereacre, demanded a ransom disguised as a bug bounty program to avoid public disclosure.

018

Office of Personnel Management Data Breach 2015

Prevented by: HSF, EGR

In 2015, the Office of Personnel Management (OPM) suffered a major data breach that exposed personal information, including Social Security Numbers and biometric data of approximately 21.5 million individuals. The breach involved sophisticated data exfiltration methods believed to be executed by state-sponsored actors, specifically linked to Chinese hackers. Vulnerabilities in OPM’s legacy systems, coupled with compromised contractor credentials, allowed attackers unauthorized access to sensitive data.

015

JPMorgan Chase Data Breach

Prevented by: HSF, EGR

In June 2014, a data breach at JPMorgan Chase compromised the accounts of over 76 million households and 7 million small businesses. The attackers accessed names, addresses, phone numbers, and email addresses, leveraging phishing and exploiting network vulnerabilities. The breach has been linked to cybercriminals Gery Shalon, Ziv Orenstein, and Joshua Aaron, emphasizing gaps in network security and authentication procedures.

014

2014 Uber Data Breach

In 2014, Uber experienced a data breach impacting approximately 50,000 individuals, exposing personal information such as names and driver’s license numbers. Unauthorized access was facilitated through a publicly exposed AWS access key on GitHub, underscoring critical flaws in credential management and cloud security. No specific threat actors were identified, but the incident highlighted significant vulnerabilities in Uber’s data protection practices.

RSS feed for this tag →

Now playing Bandcamp