Tag / 17 entries / page 1 of 2 / feed available

Data Leak

17 of the 76 analyses in Data Breaches carry this tag. All 17 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

069

National Public Data Breach of April 2024

Prevented by: HSF

In April 2024, National Public Data experienced a significant breach that exposed Social Security Numbers, addresses, and phone numbers of hundreds of millions of Americans. This breach, attributed to a security lapse involving administrative credential exposure, allowed unauthorized access to up to 2.9 billion records. The threat actor identified as USDoD exploited this vulnerability, selling the compromised data on the dark web.

063

23andMe Data Breach

Prevented by: HSF

In December 2023, a data breach at genetic testing company 23andMe exposed the personal data of approximately 6.9 million users to unauthorized access. The breach, executed through credential stuffing, compromised user profiles and familial connections, leaving sensitive personal data vulnerable. It underscored the need for robust password practices and security measures such as multi-factor authentication.

061

Samsung Data Breach November 2023

A vulnerability in a third-party application used by Samsung led to a data breach affecting UK customers who made purchases via the Samsung UK online store. The breach exposed personal information including names, phone numbers, postal addresses, and emails. The unauthorized access was the result of exploiting the vulnerability, with the specifics around the threat actors and exact details remaining undisclosed.

055

Tesla Massive Data Breach

The Tesla Massive Data Breach, revealed in May 2023, involved the unauthorized disclosure of sensitive data by two former employees who leaked approximately 100 gigabytes of personal records and corporate secrets to a German news outlet. This incident compromised personal information including social security numbers, corporate secrets, and sensitive vehicle safety data. The attack vector identified was an insider threat, highlighting significant vulnerabilities in access control and insider management.

051

ChatGPT Data Breach

Contained by: SCA

In March 2023, a data breach on OpenAI’s ChatGPT platform exposed sensitive user data, including names, email addresses, payment information, and partial credit card details due to a bug in the Redis-py library. Approximately 1.2% of ChatGPT Plus users were affected. The breach was caused internally, stemming from an open-source library vulnerability, highlighting the risks associated with external dependencies.

043

Activision HR Data Breach 2023

Prevented by: HSF

In December 2022, a data breach occurred at Activision due to an SMS phishing attack targeting an HR employee. The breach resulted in unauthorized access to sensitive employee data, including names, phone numbers, job titles, and email addresses. Approximately 19,444 records were compromised, with no known breach of game source codes or player information. The attack underscores the risks of social engineering and highlights vulnerabilities in employee cybersecurity awareness.

040

Pegasus Airlines Data Exposure

In March 2022, Pegasus Airlines faced a major data breach caused by a cloud misconfiguration of an AWS S3 bucket, resulting in the exposure of approximately 23 million files. The breached data contained Personally Identifiable Information (PII) and sensitive operational details, posing significant risks including identity theft and operational disruptions. No direct external threat actors were confirmed to have exploited this vulnerability.

036

LinkedIn Data Scraping Incident

In April 2021, LinkedIn experienced a massive data scraping incident, exposing approximately 700 million user records. The breach involved personal information such as full names, email addresses, and professional details extracted through LinkedIn’s public API by a threat actor named ‘GOD User TomLiner.’ Although passwords and financial details were not compromised, the incident highlights significant risks for identity theft and phishing attacks.

RSS feed for this tag →

Now playing Bandcamp