Tag / 21 entries / page 2 of 3 / feed available

Sensitive Information

21 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

041

Los Angeles Unified School District (LAUSD) Ransomware Breach

Prevented by: HSF, PEC, EGR

In September 2022, the Los Angeles Unified School District (LAUSD) suffered a ransomware attack by the Vice Society, which impacted over 1,000 schools and around 600,000 students. The breach compromised approximately 500 GB of data, including sensitive personal and educational records, due to exploited vulnerabilities such as lack of multi-factor authentication.

038

Cash App Data Breach - April 2022

In December 2021, the Cash App experienced a significant data breach where a former employee accessed and downloaded sensitive financial information of approximately 8.2 million users. The compromised data included brokerage account numbers and details of stock trading activities, underscoring an insider threat and deficiencies in access management controls. This incident did not involve the leak of social security numbers or passwords.

037

South Georgia Medical Center Data Theft

In November 2021, South Georgia Medical Center experienced a data breach when a former employee, exploiting retained access, downloaded approximately 41,692 patient records onto a USB drive without authorization. The compromised data included protected health information such as patient names, birth dates, and test results. This incident underscores the threat posed by insiders and highlights vulnerabilities in data access management and removable media controls.

035

Microsoft Exchange Server Breach

Prevented by: PEC, EGR

In January 2021, over 30,000 U.S. companies experienced a cyberattack on Microsoft Exchange email servers. The breach exploited several zero-day vulnerabilities, resulting in unauthorized email access and potentially sensitive data exposure. The attack was primarily attributed to the state-sponsored Hafnium group from China, leveraging server-side request forgery and other sophisticated methods.

024

Aadhaar Data Breach

The Aadhaar breach in January 2018 resulted in the unauthorized exposure of personal and biometric data of 1.1 billion Indian citizens. This was due to system vulnerabilities like unsecured API endpoints, allowing attackers access to sensitive data including bank account information. While specific threat actors remain unconfirmed, the large-scale data compromise highlights significant security lapses within the government’s database management.

019

AdultFriendFinder Data Breach

Contained by: EGR

The 2016 AdultFriendFinder data breach exposed approximately 412 million user accounts due to vulnerabilities in Local File Inclusion (LFI). Compromised data included usernames, email addresses, and passwords, mostly stored in plaintext or hashed with weak SHA-1, making them vulnerable to cracking. While the exact perpetrators remain unidentified, discussions suggest involvement from actors on Russian forums.

018

Office of Personnel Management Data Breach 2015

Prevented by: HSF, EGR

In 2015, the Office of Personnel Management (OPM) suffered a major data breach that exposed personal information, including Social Security Numbers and biometric data of approximately 21.5 million individuals. The breach involved sophisticated data exfiltration methods believed to be executed by state-sponsored actors, specifically linked to Chinese hackers. Vulnerabilities in OPM’s legacy systems, coupled with compromised contractor credentials, allowed attackers unauthorized access to sensitive data.

012

eBay Data Breach Analysis

Prevented by: HSF, EGR

In early 2014, eBay experienced a significant data breach affecting approximately 145 million user records. The compromised data included names, encrypted passwords, email addresses, physical addresses, phone numbers, and birth dates. Cyber attackers used stolen employee credentials, likely acquired through sophisticated phishing tactics, to gain unauthorized access to eBay’s network. While the encrypted passwords were compromised, PayPal’s financial information remained secure due to separate storage protocols.

008

Yahoo Data Breach August 2013

Prevented by: HSF, PEC, EGR

In August 2013, Yahoo suffered one of the largest data breaches in history, compromising the account information of approximately 3 billion users. The exposed data included usernames, email addresses, telephone numbers, hashed passwords using MD5, and both encrypted and unencrypted security questions and answers. The attack was attributed to state-sponsored actors from Russian intelligence, highlighting a significant cyber-espionage operation.

007

MySpace Data Breach

In June 2013, over 360 million user accounts on MySpace were compromised, exposing usernames, email addresses, and passwords due to inadequate security practices. The passwords were stored using weak SHA-1 hashes without salting, making them vulnerable to cracking. A Russian hacker known as “Peace” was linked to this major breach. MySpace subsequently improved its security by adopting double-salted hashing techniques.

RSS feed for this tag →

Now playing Bandcamp