Tag / 6 entries / feed available

Data Privacy

6 of the 76 analyses in Data Breaches carry this tag. All 6 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

060

British Library Ransomware Attack October 2023

Prevented by: HSF, PEC · Contained by: EGR

In October 2023, the British Library was targeted by the Rhysida ransomware group, resulting in the encryption and leak of approximately 490,191 files, amounting to 573 GB of data. The breach illustrated vulnerabilities in security protocols due to compromised credentials and the absence of Multi-Factor Authentication (MFA), significantly disrupting library operations and potentially exposing sensitive internal data.

058

MGM Grand Data Breach - September 2023

Prevented by: HSF, PEC · Contained by: EGR

In September 2023, MGM Resorts International experienced a major cyberattack orchestrated by the Scattered Spider group, leading to significant operational disruptions and an estimated $80 million in financial losses. The attackers exploited social engineering methods, particularly vishing, to breach MGM’s systems and compromise personal data including names, driver’s license numbers, and Social Security numbers. This attack underscores vulnerabilities in service desk operations and highlights the use of sophisticated ransomware tactics.

057

DuoLingo Data Breach August 2023

In August 2023, DuoLingo suffered a data breach affecting over 2.6 million users due to a data scraping attack exploiting an exposed API. Compromised data included names and email addresses, posing risks for phishing attacks. The attack was carried out by unidentified threat actors utilizing automated scripts to extract data from the vulnerable API.

024

Aadhaar Data Breach

The Aadhaar breach in January 2018 resulted in the unauthorized exposure of personal and biometric data of 1.1 billion Indian citizens. This was due to system vulnerabilities like unsecured API endpoints, allowing attackers access to sensitive data including bank account information. While specific threat actors remain unconfirmed, the large-scale data compromise highlights significant security lapses within the government’s database management.

019

AdultFriendFinder Data Breach

Contained by: EGR

The 2016 AdultFriendFinder data breach exposed approximately 412 million user accounts due to vulnerabilities in Local File Inclusion (LFI). Compromised data included usernames, email addresses, and passwords, mostly stored in plaintext or hashed with weak SHA-1, making them vulnerable to cracking. While the exact perpetrators remain unidentified, discussions suggest involvement from actors on Russian forums.

004

California Department of Child Support Services Data Breach

In 2012, the California Department of Child Support Services experienced a data breach when magnetic tapes were lost in transit, compromising the personal data of 800,000 individuals, including names, addresses, and Social Security numbers. This incident highlighted vulnerabilities in physical media security and the absence of encryption, with no involvement of external threat actors.

RSS feed for this tag →

Now playing Bandcamp