Tag / 25 entries / page 2 of 3 / feed available

Network Security

25 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

053

Yum! Brands Ransomware Data Breach

Prevented by: PEC, EGR · Contained by: HSF

In January 2023, Yum! Brands, owner of KFC, Taco Bell, and Pizza Hut, experienced a data breach following a ransomware attack. The breach exposed sensitive employee information, including names and Social Security Numbers. While corporate data was compromised, no customer data was initially reported as affected. Unknown cybercriminals were responsible for the attack, which led to temporary closures of restaurants in the UK.

047

Google Fi Data Breach Linked to T-Mobile Incident

Prevented by: HSF

In February 2023, a data breach compromised Google Fi customers’ phone numbers and SIM card serial numbers due to vulnerabilities in T-Mobile’s infrastructure. The breach involved unauthorized data access, posing risks of SIM swap attacks and unauthorized account access. No specific threat actors were attributed to the breach, but it showcased potential organized cybercriminal activities focusing on telecom vulnerabilities.

046

NCB Management Services Data Breach February 2023

In February 2023, NCB Management Services experienced a major data breach compromising sensitive personal and financial information of over 1 million individuals. The breach occurred due to unauthorized access through a misconfigured database, lacking adequate security measures such as password protection and multifactor authentication. This data, including Social Security numbers and financial details, was extracted by unidentified external hackers, highlighting severe vulnerabilities in third-party vendor security.

045

Norton Life Lock Credential Stuffing Data Breach

Prevented by: HSF

In January 2023, Norton LifeLock experienced a data breach impacting over 6,000 customer accounts due to a credential stuffing attack. The attackers used previously compromised passwords from dark web datasets to gain unauthorized access. Exposed data included personal information such as names, phone numbers, and addresses, increasing the risk of identity theft. Although approximately 925,000 accounts were targeted, only a fraction was breached.

043

Activision HR Data Breach 2023

Prevented by: HSF

In December 2022, a data breach occurred at Activision due to an SMS phishing attack targeting an HR employee. The breach resulted in unauthorized access to sensitive employee data, including names, phone numbers, job titles, and email addresses. Approximately 19,444 records were compromised, with no known breach of game source codes or player information. The attack underscores the risks of social engineering and highlights vulnerabilities in employee cybersecurity awareness.

041

Los Angeles Unified School District (LAUSD) Ransomware Breach

Prevented by: HSF, PEC, EGR

In September 2022, the Los Angeles Unified School District (LAUSD) suffered a ransomware attack by the Vice Society, which impacted over 1,000 schools and around 600,000 students. The breach compromised approximately 500 GB of data, including sensitive personal and educational records, due to exploited vulnerabilities such as lack of multi-factor authentication.

035

Microsoft Exchange Server Breach

Prevented by: PEC, EGR

In January 2021, over 30,000 U.S. companies experienced a cyberattack on Microsoft Exchange email servers. The breach exploited several zero-day vulnerabilities, resulting in unauthorized email access and potentially sensitive data exposure. The attack was primarily attributed to the state-sponsored Hafnium group from China, leveraging server-side request forgery and other sophisticated methods.

034

Twitter 2020 Data Breach Incident

Prevented by: HSF

In July 2020, a 17-year-old hacker and his accomplices compromised Twitter’s internal systems through social engineering, taking control of approximately 130 high-profile accounts. These accounts were used to perpetrate a Bitcoin scam that led to financial losses of over $117,000. The attack highlighted significant vulnerabilities in Twitter’s protection against social engineering and demonstrated the persistent risk of insider threats.

027

Norsk Hydro Ransomware Attack - March 2019

Prevented by: HSF, PEC

In March 2019, Norsk Hydro, one of the world’s largest aluminum producers, was hit by the LockerGoga ransomware attack. This incident caused significant operational disruptions and financial losses due to the encryption of critical systems and manual operation deployments. The attack exploited Active Directory vulnerabilities, although the exact perpetrators remain unidentified.

023

2017 Equifax Data Breach

Prevented by: EGR · Contained by: PEC

The Equifax data breach in 2017 exposed sensitive personal and financial information of approximately 145.5 million individuals, including Social Security numbers and birthdates. Attackers exploited a vulnerability in the Apache Struts framework (CVE-2017-5638) to gain unauthorized access. The breach highlighted significant deficiencies in Equifax’s data protection and vulnerability management processes.

RSS feed for this tag →

Now playing Bandcamp