Tag / 49 entries / page 5 of 5 / feed available

Personal Information (PII)

49 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

014

2014 Uber Data Breach

In 2014, Uber experienced a data breach impacting approximately 50,000 individuals, exposing personal information such as names and driver’s license numbers. Unauthorized access was facilitated through a publicly exposed AWS access key on GitHub, underscoring critical flaws in credential management and cloud security. No specific threat actors were identified, but the incident highlighted significant vulnerabilities in Uber’s data protection practices.

012

eBay Data Breach Analysis

Prevented by: HSF, EGR

In early 2014, eBay experienced a significant data breach affecting approximately 145 million user records. The compromised data included names, encrypted passwords, email addresses, physical addresses, phone numbers, and birth dates. Cyber attackers used stolen employee credentials, likely acquired through sophisticated phishing tactics, to gain unauthorized access to eBay’s network. While the encrypted passwords were compromised, PayPal’s financial information remained secure due to separate storage protocols.

011

Target Data Breach 2013

Prevented by: HSF, PEC, EGR

The Target data breach of 2013 exposed approximately 110 million customer records, including 40 million credit and debit card numbers and 70 million sets of personal data. The breach occurred when attackers gained unauthorized access through compromised credentials from a third-party vendor, using RAM scraping malware to extract data from point-of-sale systems. This incident highlights significant security vulnerabilities in vendor management and network segmentation.

009

Court Ventures (Experian) Data Breach

In October 2013, a Vietnamese threat actor accessed Court Ventures’ database, compromising approximately 200 million personal records including Social Security numbers and credit card details. The breach occurred through exploitation of data-sharing vulnerabilities and inadequate verification processes, highlighting a major security lapse in third-party partnerships.

008

Yahoo Data Breach August 2013

Prevented by: HSF, PEC, EGR

In August 2013, Yahoo suffered one of the largest data breaches in history, compromising the account information of approximately 3 billion users. The exposed data included usernames, email addresses, telephone numbers, hashed passwords using MD5, and both encrypted and unencrypted security questions and answers. The attack was attributed to state-sponsored actors from Russian intelligence, highlighting a significant cyber-espionage operation.

007

MySpace Data Breach

In June 2013, over 360 million user accounts on MySpace were compromised, exposing usernames, email addresses, and passwords due to inadequate security practices. The passwords were stored using weak SHA-1 hashes without salting, making them vulnerable to cracking. A Russian hacker known as “Peace” was linked to this major breach. MySpace subsequently improved its security by adopting double-salted hashing techniques.

004

California Department of Child Support Services Data Breach

In 2012, the California Department of Child Support Services experienced a data breach when magnetic tapes were lost in transit, compromising the personal data of 800,000 individuals, including names, addresses, and Social Security numbers. This incident highlighted vulnerabilities in physical media security and the absence of encryption, with no involvement of external threat actors.

RSS feed for this tag →

Now playing Bandcamp