Tag / 24 entries / page 3 of 3 / feed available

Third-Party Vendor Compromise

24 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

013

Home Depot Data Breach April 2014

Prevented by: HSF, PEC, EGR

The Home Depot data breach, occurring in April 2014, resulted in the theft of over 56 million payment card records through custom-built malware targeting point-of-sale systems across the US and Canada. Organized cybercriminal groups deployed POS-scraping malware using stolen vendor credentials, exfiltrating high volumes of financial data. This incident highlights significant vulnerabilities in third-party access management and the effectiveness of traditional security measures against advanced threats.

011

Target Data Breach 2013

Prevented by: HSF, PEC, EGR

The Target data breach of 2013 exposed approximately 110 million customer records, including 40 million credit and debit card numbers and 70 million sets of personal data. The breach occurred when attackers gained unauthorized access through compromised credentials from a third-party vendor, using RAM scraping malware to extract data from point-of-sale systems. This incident highlights significant security vulnerabilities in vendor management and network segmentation.

004

California Department of Child Support Services Data Breach

In 2012, the California Department of Child Support Services experienced a data breach when magnetic tapes were lost in transit, compromising the personal data of 800,000 individuals, including names, addresses, and Social Security numbers. This incident highlighted vulnerabilities in physical media security and the absence of encryption, with no involvement of external threat actors.

RSS feed for this tag →

Now playing Bandcamp