Tag / 24 entries / page 2 of 3 / feed available

Third-Party Vendor Compromise

24 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

051

ChatGPT Data Breach

Contained by: SCA

In March 2023, a data breach on OpenAI’s ChatGPT platform exposed sensitive user data, including names, email addresses, payment information, and partial credit card details due to a bug in the Redis-py library. Approximately 1.2% of ChatGPT Plus users were affected. The breach was caused internally, stemming from an open-source library vulnerability, highlighting the risks associated with external dependencies.

050

PharMerica Data Breach March 2023

Prevented by: PEC, EGR

In March 2023, PharMerica experienced a major data breach affecting approximately 5.8 million individuals. The incident involved the compromise of extensive patient data, including Social Security numbers, health records, and insurance information. The breach was executed by the Money Message ransomware group using double extortion tactics, leading to significant privacy risks and identity theft concerns.

047

Google Fi Data Breach Linked to T-Mobile Incident

Prevented by: HSF

In February 2023, a data breach compromised Google Fi customers’ phone numbers and SIM card serial numbers due to vulnerabilities in T-Mobile’s infrastructure. The breach involved unauthorized data access, posing risks of SIM swap attacks and unauthorized account access. No specific threat actors were attributed to the breach, but it showcased potential organized cybercriminal activities focusing on telecom vulnerabilities.

046

NCB Management Services Data Breach February 2023

In February 2023, NCB Management Services experienced a major data breach compromising sensitive personal and financial information of over 1 million individuals. The breach occurred due to unauthorized access through a misconfigured database, lacking adequate security measures such as password protection and multifactor authentication. This data, including Social Security numbers and financial details, was extracted by unidentified external hackers, highlighting severe vulnerabilities in third-party vendor security.

044

MailChimp January 2023 Data Breach

Prevented by: HSF

In January 2023, MailChimp experienced a data breach caused by a social engineering attack, allowing unauthorized access to internal customer support tools. The breach affected 133 customer accounts, exposing names, store web addresses, and email addresses, while passwords and financial data remained secure. The attack involved unidentified individuals exploiting employee credentials, revealing vulnerabilities in phishing defenses.

031

SolarWinds Supply Chain Attack

Prevented by: PEC, EGR

The SolarWinds Supply Chain Attack involved the compromise of SolarWinds Orion software, leading to malicious updates that were installed by over 18,000 customers. This allowed the attackers, attributed to state-sponsored groups, to steal data and spy on organizations including U.S. government departments. The attack exploited software development vulnerabilities to insert SUNBURST malware, affecting multiple sectors globally.

025

Copay Cryptocurrency Wallet Data Breach

Prevented by: SCA

In November 2018, the Copay cryptocurrency wallet, developed by BitPay, suffered a data breach due to a malicious version of the event-stream Node.js library. The breach involved unauthorized access to users’ private keys and cryptocurrency assets through dependency injection of malicious code by threat actors, significantly affecting wallets with considerable holdings. The attack highlighted vulnerabilities in third-party dependencies within the open-source software ecosystem.

022

NotPetya Ransomware Attack

Prevented by: PEC

The NotPetya ransomware attack in June 2017 caused extensive financial damage exceeding $10 billion by utilizing a compromised software update from MeDoc, a Ukrainian accounting software. The malware employed the EternalBlue exploit to propagate widely, primarily acting as a wiper rather than traditional ransomware. It severely disrupted corporate operations globally, affecting numerous high-profile organizations such as Maersk and FedEx, and has been attributed to state-sponsored actors linked to Russian military intelligence.

021

Deep Root Analytics Data Breach

In 2017, a misconfigured Amazon Web Services (AWS) S3 bucket at Deep Root Analytics exposed sensitive data of nearly 200 million U.S. voters. The breach involved personal information such as names, addresses, birth dates, and political affiliations. This incident was primarily due to cloud storage misconfiguration without any evidence of external hacking, highlighting vulnerabilities in data handling practices by third-party vendors.

018

Office of Personnel Management Data Breach 2015

Prevented by: HSF, EGR

In 2015, the Office of Personnel Management (OPM) suffered a major data breach that exposed personal information, including Social Security Numbers and biometric data of approximately 21.5 million individuals. The breach involved sophisticated data exfiltration methods believed to be executed by state-sponsored actors, specifically linked to Chinese hackers. Vulnerabilities in OPM’s legacy systems, coupled with compromised contractor credentials, allowed attackers unauthorized access to sensitive data.

RSS feed for this tag →

Now playing Bandcamp