Tag / 71 entries / page 4 of 8 / feed available

Major Breach

71 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

045

Norton Life Lock Credential Stuffing Data Breach

Prevented by: HSF

In January 2023, Norton LifeLock experienced a data breach impacting over 6,000 customer accounts due to a credential stuffing attack. The attackers used previously compromised passwords from dark web datasets to gain unauthorized access. Exposed data included personal information such as names, phone numbers, and addresses, increasing the risk of identity theft. Although approximately 925,000 accounts were targeted, only a fraction was breached.

044

MailChimp January 2023 Data Breach

Prevented by: HSF

In January 2023, MailChimp experienced a data breach caused by a social engineering attack, allowing unauthorized access to internal customer support tools. The breach affected 133 customer accounts, exposing names, store web addresses, and email addresses, while passwords and financial data remained secure. The attack involved unidentified individuals exploiting employee credentials, revealing vulnerabilities in phishing defenses.

043

Activision HR Data Breach 2023

Prevented by: HSF

In December 2022, a data breach occurred at Activision due to an SMS phishing attack targeting an HR employee. The breach resulted in unauthorized access to sensitive employee data, including names, phone numbers, job titles, and email addresses. Approximately 19,444 records were compromised, with no known breach of game source codes or player information. The attack underscores the risks of social engineering and highlights vulnerabilities in employee cybersecurity awareness.

041

Los Angeles Unified School District (LAUSD) Ransomware Breach

Prevented by: HSF, PEC, EGR

In September 2022, the Los Angeles Unified School District (LAUSD) suffered a ransomware attack by the Vice Society, which impacted over 1,000 schools and around 600,000 students. The breach compromised approximately 500 GB of data, including sensitive personal and educational records, due to exploited vulnerabilities such as lack of multi-factor authentication.

040

Pegasus Airlines Data Exposure

In March 2022, Pegasus Airlines faced a major data breach caused by a cloud misconfiguration of an AWS S3 bucket, resulting in the exposure of approximately 23 million files. The breached data contained Personally Identifiable Information (PII) and sensitive operational details, posing significant risks including identity theft and operational disruptions. No direct external threat actors were confirmed to have exploited this vulnerability.

038

Cash App Data Breach - April 2022

In December 2021, the Cash App experienced a significant data breach where a former employee accessed and downloaded sensitive financial information of approximately 8.2 million users. The compromised data included brokerage account numbers and details of stock trading activities, underscoring an insider threat and deficiencies in access management controls. This incident did not involve the leak of social security numbers or passwords.

037

South Georgia Medical Center Data Theft

In November 2021, South Georgia Medical Center experienced a data breach when a former employee, exploiting retained access, downloaded approximately 41,692 patient records onto a USB drive without authorization. The compromised data included protected health information such as patient names, birth dates, and test results. This incident underscores the threat posed by insiders and highlights vulnerabilities in data access management and removable media controls.

036

LinkedIn Data Scraping Incident

In April 2021, LinkedIn experienced a massive data scraping incident, exposing approximately 700 million user records. The breach involved personal information such as full names, email addresses, and professional details extracted through LinkedIn’s public API by a threat actor named ‘GOD User TomLiner.’ Although passwords and financial details were not compromised, the incident highlights significant risks for identity theft and phishing attacks.

RSS feed for this tag →

Now playing Bandcamp