Tag / 49 entries / page 2 of 5 / feed available

Personal Information (PII)

49 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

059

Indian Council of Medical Research Data Breach 2023

Prevented by: HSF, EGR

In October 2023, the Indian Council of Medical Research experienced a major data breach that led to the exposure of 815 million records, including Aadhaar IDs, passport details, names, phone numbers, and addresses. The data was compromised by a hacker identified as pwn0001, who made the information available for sale on the dark web. The breach involved significant security vulnerabilities, particularly in access controls and encryption practices, indicating a need for improved data protection measures.

056

MOVEit Data Breach June 2023

Contained by: PEC

The June 2023 MOVEit data breach began with the exploitation of a zero-day SQL injection vulnerability (CVE-2023-34362) in the MOVEit Transfer software; over 200 organizations were confirmed affected within the first weeks, a toll that climbed to more than 2,700 organizations and over 95 million individuals as disclosures continued into 2024. The Clop ransomware group was responsible, utilizing web shell deployment and data exfiltration methods to access and steal personal and sensitive information, highlighting substantial risks in application security and third-party systems.

055

Tesla Massive Data Breach

The Tesla Massive Data Breach, revealed in May 2023, involved the unauthorized disclosure of sensitive data by two former employees who leaked approximately 100 gigabytes of personal records and corporate secrets to a German news outlet. This incident compromised personal information including social security numbers, corporate secrets, and sensitive vehicle safety data. The attack vector identified was an insider threat, highlighting significant vulnerabilities in access control and insider management.

053

Yum! Brands Ransomware Data Breach

Prevented by: PEC, EGR · Contained by: HSF

In January 2023, Yum! Brands, owner of KFC, Taco Bell, and Pizza Hut, experienced a data breach following a ransomware attack. The breach exposed sensitive employee information, including names and Social Security Numbers. While corporate data was compromised, no customer data was initially reported as affected. Unknown cybercriminals were responsible for the attack, which led to temporary closures of restaurants in the UK.

052

Discord Data Breach March 2023

Prevented by: HSF

In March 2023, a data breach occurred at Discord due to security vulnerabilities at a third-party service provider, compromising sensitive personal information of approximately 180 users including names and driver’s license numbers. The breach was facilitated through unauthorized access, likely achieved via compromised credentials due to phishing or social engineering. No specific threat actors were identified in the report.

051

ChatGPT Data Breach

Contained by: SCA

In March 2023, a data breach on OpenAI’s ChatGPT platform exposed sensitive user data, including names, email addresses, payment information, and partial credit card details due to a bug in the Redis-py library. Approximately 1.2% of ChatGPT Plus users were affected. The breach was caused internally, stemming from an open-source library vulnerability, highlighting the risks associated with external dependencies.

050

PharMerica Data Breach March 2023

Prevented by: PEC, EGR

In March 2023, PharMerica experienced a major data breach affecting approximately 5.8 million individuals. The incident involved the compromise of extensive patient data, including Social Security numbers, health records, and insurance information. The breach was executed by the Money Message ransomware group using double extortion tactics, leading to significant privacy risks and identity theft concerns.

049

Chick-fil-A Data Breach March 2023

Prevented by: HSF

In March 2023, Chick-fil-A experienced a significant data breach due to unauthorized login activities via a credential stuffing attack. The incident exposed personal information of approximately 71,473 users, including names, email addresses, membership details, and partial payment information. This breach was facilitated by credential reuse and highlights the vulnerabilities in login security protocols.

048

Consumer Financial Protection Bureau Data Breach

The Consumer Financial Protection Bureau experienced a data breach in February 2023 caused by an employee transferring sensitive records to a personal email account, exposing the personally identifiable information of approximately 256,000 individuals. This breach involved data exfiltration from government systems, highlighting severe insider threat risks and deficiencies in internal data protection protocols. The compromised data originated from several financial institutions, posing potential privacy risks, although no misuse has been confirmed.

RSS feed for this tag →

Now playing Bandcamp