Tag / 16 entries / page 2 of 2 / feed available

Financial Data

16 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

013

Home Depot Data Breach April 2014

Prevented by: HSF, PEC, EGR

The Home Depot data breach, occurring in April 2014, resulted in the theft of over 56 million payment card records through custom-built malware targeting point-of-sale systems across the US and Canada. Organized cybercriminal groups deployed POS-scraping malware using stolen vendor credentials, exfiltrating high volumes of financial data. This incident highlights significant vulnerabilities in third-party access management and the effectiveness of traditional security measures against advanced threats.

011

Target Data Breach 2013

Prevented by: HSF, PEC, EGR

The Target data breach of 2013 exposed approximately 110 million customer records, including 40 million credit and debit card numbers and 70 million sets of personal data. The breach occurred when attackers gained unauthorized access through compromised credentials from a third-party vendor, using RAM scraping malware to extract data from point-of-sale systems. This incident highlights significant security vulnerabilities in vendor management and network segmentation.

010

Adobe 2013 Data Breach

Prevented by: EGR

In October 2013, Adobe suffered a significant data breach compromising 153 million user records, including encrypted credit card information and user account details such as usernames and email addresses. The breach, one of the largest in cybersecurity history, was executed by exploiting vulnerabilities in Adobe’s systems, notably through outdated encryption practices and unpatched ColdFusion servers. The attack was attributed to financially motivated cybercriminals, likely from Eastern Europe or Russia, aiming to sell the stolen data on the black market.

009

Court Ventures (Experian) Data Breach

In October 2013, a Vietnamese threat actor accessed Court Ventures’ database, compromising approximately 200 million personal records including Social Security numbers and credit card details. The breach occurred through exploitation of data-sharing vulnerabilities and inadequate verification processes, highlighting a major security lapse in third-party partnerships.

002

Heartland Payment Systems Data Breach

Prevented by: PEC, EGR

The Heartland Payment Systems data breach in 2008 compromised approximately 130 million payment card records. The breach was executed using SQL injection attacks to install malware, capturing sensitive financial data such as credit card numbers over a prolonged period. Albert Gonzalez, a known cybercriminal, was attributed as the architect of this breach. The incident revealed significant vulnerabilities in Heartland’s transaction processes leading to substantial financial and reputational damage.

001

TJX Companies Inc. Data Breach

Prevented by: PEC, EGR

The TJX Companies Inc. data breach, discovered in January 2007 but originating in July 2005, compromised 94 million records, including credit card data and personal information such as driver’s license numbers. Attackers exploited outdated WEP encryption on TJX’s wireless networks, leading to a major security incident impacting numerous customers.

RSS feed for this tag →

Now playing Bandcamp