Tag / 49 entries / page 4 of 5 / feed available

Personal Information (PII)

49 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

030

Capital One Data Breach 2019

Prevented by: EGR

In July 2019, Capital One experienced a major breach compromising over 100 million customer records due to a misconfigured Web Application Firewall exploited by a former Amazon Web Services employee. The attack led to unauthorized access to personal information including names, addresses, Social Security Numbers, and banking details, heightening the risk of identity theft and financial fraud. The incident emphasized vulnerabilities in cloud security configurations and poor application of the least privilege principle.

028

Facebook Data Breach 2019

In April 2019, Facebook experienced a major data breach exposing the personal information of over 530 million users from two datasets. The breach involved cloud storage misconfiguration and data scraping vulnerabilities, resulting in the leak of phone numbers and account names. The attack did not involve specific threat actors but exploited weaknesses in the Facebook contact importer and third-party AWS storage configurations.

026

Marriott International Data Breach of 2018

Prevented by: HSF, PEC, EGR

In 2018, Marriott International experienced a data breach affecting approximately 500 million guests with compromised personal information including names, addresses, and passport numbers. The breach, linked to the Starwood reservation system acquired by Marriott, involved unauthorized access dating back to 2014, facilitated by malware known as remote access trojans (RATs). The incident raised concerns about potential involvement of state-sponsored actors and resulted in significant regulatory scrutiny, including fines under GDPR.

023

2017 Equifax Data Breach

Prevented by: EGR · Contained by: PEC

The Equifax data breach in 2017 exposed sensitive personal and financial information of approximately 145.5 million individuals, including Social Security numbers and birthdates. Attackers exploited a vulnerability in the Apache Struts framework (CVE-2017-5638) to gain unauthorized access. The breach highlighted significant deficiencies in Equifax’s data protection and vulnerability management processes.

021

Deep Root Analytics Data Breach

In 2017, a misconfigured Amazon Web Services (AWS) S3 bucket at Deep Root Analytics exposed sensitive data of nearly 200 million U.S. voters. The breach involved personal information such as names, addresses, birth dates, and political affiliations. This incident was primarily due to cloud storage misconfiguration without any evidence of external hacking, highlighting vulnerabilities in data handling practices by third-party vendors.

020

2016 Uber Data Breach

Prevented by: HSF

On November 14, 2016, Uber suffered a data breach exposing the personal information of 57 million users and 600,000 driver license numbers. Hackers accessed Uber’s data by exploiting credential mismanagement and accessing unsecured AWS S3 buckets, following infiltration of Uber’s GitHub repositories. The perpetrators, identified as Brandon Charles Glover and Vasile Mereacre, demanded a ransom disguised as a bug bounty program to avoid public disclosure.

018

Office of Personnel Management Data Breach 2015

Prevented by: HSF, EGR

In 2015, the Office of Personnel Management (OPM) suffered a major data breach that exposed personal information, including Social Security Numbers and biometric data of approximately 21.5 million individuals. The breach involved sophisticated data exfiltration methods believed to be executed by state-sponsored actors, specifically linked to Chinese hackers. Vulnerabilities in OPM’s legacy systems, coupled with compromised contractor credentials, allowed attackers unauthorized access to sensitive data.

017

Anthem Data Breach Incident Analysis

Prevented by: PEC, EGR · Contained by: HSF

The Anthem Data Breach in 2015 exposed approximately 78.8 million records, including sensitive Personal Identifiable Information (PII) such as names, birthdates, medical IDs, and Social Security numbers. The breach was executed via a phishing campaign linked to a state-sponsored group, reportedly associated with Chinese cyberespionage activities. The attackers utilized sophisticated malware including Mivast and Sakula to infiltrate the network and execute data exfiltration without detection.

016

Australian Immigration Department G20 Data Breach

In a 2015 incident, the Australian Immigration Department inadvertently exposed the sensitive personal details of G20 world leaders due to an email autofill error. The breach involved the accidental email of names, birth dates, passport numbers, and visa details to an unintended recipient, raising potential diplomatic concerns despite low risk due to the recipient’s prompt deletion of the email.

015

JPMorgan Chase Data Breach

Prevented by: HSF, EGR

In June 2014, a data breach at JPMorgan Chase compromised the accounts of over 76 million households and 7 million small businesses. The attackers accessed names, addresses, phone numbers, and email addresses, leveraging phishing and exploiting network vulnerabilities. The breach has been linked to cybercriminals Gery Shalon, Ziv Orenstein, and Joshua Aaron, emphasizing gaps in network security and authentication procedures.

RSS feed for this tag →

Now playing Bandcamp