Tag / 25 entries / page 3 of 3 / feed available

Network Security

25 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

022

NotPetya Ransomware Attack

Prevented by: PEC

The NotPetya ransomware attack in June 2017 caused extensive financial damage exceeding $10 billion by utilizing a compromised software update from MeDoc, a Ukrainian accounting software. The malware employed the EternalBlue exploit to propagate widely, primarily acting as a wiper rather than traditional ransomware. It severely disrupted corporate operations globally, affecting numerous high-profile organizations such as Maersk and FedEx, and has been attributed to state-sponsored actors linked to Russian military intelligence.

017

Anthem Data Breach Incident Analysis

Prevented by: PEC, EGR · Contained by: HSF

The Anthem Data Breach in 2015 exposed approximately 78.8 million records, including sensitive Personal Identifiable Information (PII) such as names, birthdates, medical IDs, and Social Security numbers. The breach was executed via a phishing campaign linked to a state-sponsored group, reportedly associated with Chinese cyberespionage activities. The attackers utilized sophisticated malware including Mivast and Sakula to infiltrate the network and execute data exfiltration without detection.

015

JPMorgan Chase Data Breach

Prevented by: HSF, EGR

In June 2014, a data breach at JPMorgan Chase compromised the accounts of over 76 million households and 7 million small businesses. The attackers accessed names, addresses, phone numbers, and email addresses, leveraging phishing and exploiting network vulnerabilities. The breach has been linked to cybercriminals Gery Shalon, Ziv Orenstein, and Joshua Aaron, emphasizing gaps in network security and authentication procedures.

013

Home Depot Data Breach April 2014

Prevented by: HSF, PEC, EGR

The Home Depot data breach, occurring in April 2014, resulted in the theft of over 56 million payment card records through custom-built malware targeting point-of-sale systems across the US and Canada. Organized cybercriminal groups deployed POS-scraping malware using stolen vendor credentials, exfiltrating high volumes of financial data. This incident highlights significant vulnerabilities in third-party access management and the effectiveness of traditional security measures against advanced threats.

001

TJX Companies Inc. Data Breach

Prevented by: PEC, EGR

The TJX Companies Inc. data breach, discovered in January 2007 but originating in July 2005, compromised 94 million records, including credit card data and personal information such as driver’s license numbers. Attackers exploited outdated WEP encryption on TJX’s wireless networks, leading to a major security incident impacting numerous customers.

RSS feed for this tag →

Now playing Bandcamp