Tag / 16 entries / page 1 of 2 / feed available

Financial Data

16 of the 76 analyses in Data Breaches carry this tag. All 16 are scored against the four invariants; the matrix below is that evidence.

How this tag scores against the four invariants

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

068

American Express Data Breach March 2024

Prevented by: EGR

In March 2024, American Express disclosed a data breach caused by unauthorized access to a third-party merchant processor, exposing customer names, account numbers, and expiration dates. The breach resulted from a point-of-sale attack, impacting vendor management systems, without directly compromising American Express’s internal databases. While the specific threat actors remain unidentified, the breach underscores potential risks to customer data integrity.

051

ChatGPT Data Breach

Contained by: SCA

In March 2023, a data breach on OpenAI’s ChatGPT platform exposed sensitive user data, including names, email addresses, payment information, and partial credit card details due to a bug in the Redis-py library. Approximately 1.2% of ChatGPT Plus users were affected. The breach was caused internally, stemming from an open-source library vulnerability, highlighting the risks associated with external dependencies.

049

Chick-fil-A Data Breach March 2023

Prevented by: HSF

In March 2023, Chick-fil-A experienced a significant data breach due to unauthorized login activities via a credential stuffing attack. The incident exposed personal information of approximately 71,473 users, including names, email addresses, membership details, and partial payment information. This breach was facilitated by credential reuse and highlights the vulnerabilities in login security protocols.

046

NCB Management Services Data Breach February 2023

In February 2023, NCB Management Services experienced a major data breach compromising sensitive personal and financial information of over 1 million individuals. The breach occurred due to unauthorized access through a misconfigured database, lacking adequate security measures such as password protection and multifactor authentication. This data, including Social Security numbers and financial details, was extracted by unidentified external hackers, highlighting severe vulnerabilities in third-party vendor security.

038

Cash App Data Breach - April 2022

In December 2021, the Cash App experienced a significant data breach where a former employee accessed and downloaded sensitive financial information of approximately 8.2 million users. The compromised data included brokerage account numbers and details of stock trading activities, underscoring an insider threat and deficiencies in access management controls. This incident did not involve the leak of social security numbers or passwords.

030

Capital One Data Breach 2019

Prevented by: EGR

In July 2019, Capital One experienced a major breach compromising over 100 million customer records due to a misconfigured Web Application Firewall exploited by a former Amazon Web Services employee. The attack led to unauthorized access to personal information including names, addresses, Social Security Numbers, and banking details, heightening the risk of identity theft and financial fraud. The incident emphasized vulnerabilities in cloud security configurations and poor application of the least privilege principle.

029

First American Financial Corp Data Breach

In May 2019, First American Financial Corp. suffered a major data breach that exposed approximately 885 million file records due to a security flaw. The breach involved bank account details and mortgage-related documents, which were accessible through unsecured URLs without authentication. The vulnerability was attributed to insufficient security measures, and there were no specific threat actors identified.

026

Marriott International Data Breach of 2018

Prevented by: HSF, PEC, EGR

In 2018, Marriott International experienced a data breach affecting approximately 500 million guests with compromised personal information including names, addresses, and passport numbers. The breach, linked to the Starwood reservation system acquired by Marriott, involved unauthorized access dating back to 2014, facilitated by malware known as remote access trojans (RATs). The incident raised concerns about potential involvement of state-sponsored actors and resulted in significant regulatory scrutiny, including fines under GDPR.

025

Copay Cryptocurrency Wallet Data Breach

Prevented by: SCA

In November 2018, the Copay cryptocurrency wallet, developed by BitPay, suffered a data breach due to a malicious version of the event-stream Node.js library. The breach involved unauthorized access to users’ private keys and cryptocurrency assets through dependency injection of malicious code by threat actors, significantly affecting wallets with considerable holdings. The attack highlighted vulnerabilities in third-party dependencies within the open-source software ecosystem.

023

2017 Equifax Data Breach

Prevented by: EGR · Contained by: PEC

The Equifax data breach in 2017 exposed sensitive personal and financial information of approximately 145.5 million individuals, including Social Security numbers and birthdates. Attackers exploited a vulnerability in the Apache Struts framework (CVE-2017-5638) to gain unauthorized access. The breach highlighted significant deficiencies in Equifax’s data protection and vulnerability management processes.

RSS feed for this tag →

Now playing Bandcamp