<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>User Data on Security Blueprints</title>
    <link>https://securityblueprints.io/tags/user-data/</link>
    <description>Recent content in User Data on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:44 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/tags/user-data/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Qantas Airways Customer Data Breach (June 2025)</title>
      <link>https://securityblueprints.io/data-breaches/qantas-airways-customer-data-breach-june-2025/</link>
      <pubDate>Sat, 28 Jun 2025 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/qantas-airways-customer-data-breach-june-2025/</guid>
      <description>Executive Summary On 30 June 2025, Qantas detected unusual activity on a third-party platform used by an overseas airline contact centre. The OAIC’s later account states that an agent had been socially engineered on 28 June and that the attacker used the agent’s legitimate CRM access to connect a third-party data-extraction application; Qantas froze and revoked the associated account on 30 June. (oaic.gov.au ) Qantas publicly disclosed the incident on 2 July and subsequently reported approximately 5.</description>
    </item>
    <item>
      <title>Salt Typhoon Intrusions into U.S. Telecommunications Carriers (2024)</title>
      <link>https://securityblueprints.io/data-breaches/salt-typhoon-intrusions-into-us-telecommunications-carriers-2024/</link>
      <pubDate>Wed, 25 Sep 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/salt-typhoon-intrusions-into-us-telecommunications-carriers-2024/</guid>
      <description>Executive Summary Salt Typhoon was a China-linked cyber-espionage campaign against U.S. telecommunications providers. The incident is dated 2024-09-25 for this report only; this is report metadata/designation, not a source-confirmed forensic breach date. Public reporting first described the broader compromise in September 2024, while later government statements said the campaign had likely operated for one to two years before disclosure (therecord.media ). By December 2024, officials said at least eight U.S. providers had been targeted; a ninth U.</description>
    </item>
    <item>
      <title>National Public Data Breach of April 2024</title>
      <link>https://securityblueprints.io/data-breaches/national-public-data-breach-of-april-2024/</link>
      <pubDate>Mon, 01 Apr 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/national-public-data-breach-of-april-2024/</guid>
      <description>Executive Summary In April 2024, National Public Data (NPD) became the subject of a significant data breach, compromising sensitive personal information of hundreds of millions of Americans. The breach was attributed to a security oversight, specifically the inadvertent publication of administrative credentials, leading to unauthorized access to NPD&amp;rsquo;s databases. This event highlights substantial gaps in cybersecurity practices and emphasizes the critical need for robust protection and risk management strategies.&#xA;Incident Overview Chronological Sequence of Events December 2023</description>
    </item>
    <item>
      <title>American Express Data Breach March 2024</title>
      <link>https://securityblueprints.io/data-breaches/american-express-data-breach-march-2024/</link>
      <pubDate>Mon, 04 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/american-express-data-breach-march-2024/</guid>
      <description>Executive Summary On March 4, 2024, American Express announced a data breach resulting from unauthorized access through a third-party merchant processor. This incident compromised customer information, including names, account numbers, and expiration dates, due to a point-of-sale attack affecting systems associated with American Express Travel Related Services Company. It highlights the vulnerabilities within third-party vendor systems in the financial sector. Source Severity of Impact The breach presented significant risks, potentially compromising critical cardholder information.</description>
    </item>
    <item>
      <title>Fujitsu Malware Attack 2024</title>
      <link>https://securityblueprints.io/data-breaches/fujitsu-malware-attack-2024/</link>
      <pubDate>Fri, 01 Mar 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/fujitsu-malware-attack-2024/</guid>
      <description>Executive Summary In March 2024, Fujitsu identified a malware infection on its corporate network, indicating a notable cybersecurity breach that potentially compromised customer information. Details of the breach were made public on March 15, 2024, highlighting unauthorized access achieved using advanced malware techniques (source , source , source ).&#xA;Severity of Impact The incident is classified as severe, as it may involve sensitive customer data exposure. Although certain data access was confirmed, no misuse evidence has emerged so far (source ).</description>
    </item>
    <item>
      <title>23andMe Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/23andme-data-breach/</link>
      <pubDate>Fri, 01 Dec 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/23andme-data-breach/</guid>
      <description>Executive Summary In December 2023, 23andMe, a leader in consumer genetic testing, disclosed a data breach resulting from credential stuffing attacks, compromising the personal data of approximately 6.9 million users. This type of attack utilized stolen credentials from unrelated data breaches, impacting user accounts by exploiting weak password practices.&#xA;Key Dates Breach Discovery: Initial indications arose on October 4, 2023, with public acknowledgment on October 6, 2023. Formal Disclosure: Comprehensive disclosure of the breach&amp;rsquo;s details occurred in December 2023.</description>
    </item>
    <item>
      <title>DuoLingo Data Breach August 2023</title>
      <link>https://securityblueprints.io/data-breaches/duolingo-data-breach-august-2023/</link>
      <pubDate>Tue, 01 Aug 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/duolingo-data-breach-august-2023/</guid>
      <description>Executive Summary In August 2023, DuoLingo experienced a significant data exposure incident caused by a data scraping attack targeting an exposed Application Programming Interface (API). The breach affected approximately 2.6 million users, with personal data such as names, email addresses, and other identifiable information being posted online (source 1 , source 4 ).&#xA;Severity of Impact The exposure compromised personal information of approximately 2.6 million users, including critical identifiers like login names and email addresses, heightening risks for phishing and other cyber threats (source 3 , source 6 ).</description>
    </item>
    <item>
      <title>Microsoft Email Accounts Security Breach</title>
      <link>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</link>
      <pubDate>Mon, 01 May 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/microsoft-email-accounts-security-breach/</guid>
      <description>Executive Summary In May 2023, a data breach occurred at Microsoft when China-based hackers, identified as Storm-0558, used forged authentication tokens to gain unauthorized access to customer email accounts. This incident highlighted vulnerabilities in Microsoft&amp;rsquo;s authentication systems and raised concerns over national security implications.&#xA;Key Dates and Timeline Breach Date: May 2023 Discovery Date: June 2023, by the U.S. Department of State source . Public Disclosure Date: April 2024, following a thorough review by the Cyber Safety Review Board source .</description>
    </item>
    <item>
      <title>Yum! Brands Ransomware Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/yum-brands-ransomware-data-breach/</link>
      <pubDate>Thu, 06 Apr 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/yum-brands-ransomware-data-breach/</guid>
      <description>Executive Summary In January 2023, Yum! Brands, which owns KFC, Taco Bell, and Pizza Hut, fell victim to a ransomware attack, resulting in a data breach. This incident compromised corporate and employee data and was publicly disclosed by Yum! Brands in April 2023. Formal notifications to employees and potentially affected individuals about the data compromise began around the same time.&#xA;Discovery and Disclosure The ransomware attack was first identified in January 2023.</description>
    </item>
    <item>
      <title>Discord Data Breach March 2023</title>
      <link>https://securityblueprints.io/data-breaches/discord-data-breach-march-2023/</link>
      <pubDate>Wed, 29 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/discord-data-breach-march-2023/</guid>
      <description>Executive Summary Incident Overview In March 2023, Discord faced a data breach due to security vulnerabilities at a third-party service provider. This led to the compromise of customer data. The breach was identified on March 29, 2023, publicly disclosed by May 12, 2023, and user notifications commenced on August 21, 2023 (BleepingComputer ).&#xA;Severity of Impact The breach exposed sensitive personal information of approximately 180 users, including names and state or driver&amp;rsquo;s license numbers, highlighting privacy concerns despite its limited scope relative to Discord&amp;rsquo;s extensive user base (HackRead ; Economic Times ).</description>
    </item>
    <item>
      <title>Chick-fil-A Data Breach March 2023</title>
      <link>https://securityblueprints.io/data-breaches/chick-fil-a-data-breach-march-2023/</link>
      <pubDate>Wed, 01 Mar 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/chick-fil-a-data-breach-march-2023/</guid>
      <description>Executive Summary In March 2023, Chick-fil-A confirmed a data breach resulting from unauthorized login activity via a credential stuffing attack. This attack, utilizing previously leaked credentials, enabled access to customer accounts through Chick-fil-A&amp;rsquo;s mobile application (TechRadar ).&#xA;Breach Details Unauthorized access occurred between December 18, 2022, to February 12, 2023, impacting approximately 71,473 accounts (less than 2% of users). The exposed information included names, email addresses, Chick-fil-A One membership details, and partial payment information (ClassAction.</description>
    </item>
    <item>
      <title>Consumer Financial Protection Bureau Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/consumer-financial-protection-bureau-data-breach/</link>
      <pubDate>Tue, 14 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/consumer-financial-protection-bureau-data-breach/</guid>
      <description>Executive Summary In 2023, the Consumer Financial Protection Bureau (CFPB) experienced a significant data breach due to internal security lapses. An employee transferred confidential records via email to a personal account, compromising the data of approximately 256,000 individuals. This incident underscores critical deficiencies in CFPB&amp;rsquo;s data protection protocols and has raised considerable concerns over internal security measures. Source Severity of Impact The breach affected records from seven financial institutions; however, some reports suggest this number could be higher.</description>
    </item>
    <item>
      <title>Google Fi Data Breach Linked to T-Mobile Incident</title>
      <link>https://securityblueprints.io/data-breaches/google-fi-data-breach-linked-to-t-mobile-incident/</link>
      <pubDate>Wed, 01 Feb 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/google-fi-data-breach-linked-to-t-mobile-incident/</guid>
      <description>Executive Summary Incident Overview: In February 2023, Google Fi suffered a data breach due to vulnerabilities originating from a prior T-Mobile security incident. This breach exposed Google Fi customers&amp;rsquo; phone numbers and related technical details, posing significant risks such as SIM swap attacks and unauthorized account activities (source ).&#xA;Key Dates: The association with T-Mobile&amp;rsquo;s broader data breach was identified on January 19, 2023. Affected individuals received notifications in early February 2023 (source ).</description>
    </item>
    <item>
      <title>Norton Life Lock Credential Stuffing Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/norton-life-lock-credential-stuffing-data-breach/</link>
      <pubDate>Fri, 13 Jan 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/norton-life-lock-credential-stuffing-data-breach/</guid>
      <description>Executive Summary In January 2023, Norton LifeLock reported a data breach due to a credential stuffing attack, allowing attackers to exploit previously compromised passwords to access over 6,000 customer accounts. The incident highlighted vulnerabilities within password management services, raising concerns about the security of stored credentials [source1 ].&#xA;Severity of Impact The breach exposed personal data, including names, phone numbers, and mailing addresses, and potentially compromised credentials stored in the Norton Password Manager.</description>
    </item>
    <item>
      <title>MailChimp January 2023 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/mailchimp-january-2023-data-breach/</link>
      <pubDate>Wed, 11 Jan 2023 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/mailchimp-january-2023-data-breach/</guid>
      <description>Executive Summary Incident Overview In January 2023, MailChimp was subjected to a data breach due to a social engineering attack that affected its internal customer support tool. This breach, the second in a span of six months, indicates potential weaknesses in MailChimp&amp;rsquo;s defensive measures.&#xA;Key Dates and Discovery Details The breach was discovered on January 11, 2023, during a routine security review and was publicly disclosed on January 19, 2023. This prompt notification ensured that stakeholders were adequately informed.</description>
    </item>
    <item>
      <title>Activision HR Data Breach 2023</title>
      <link>https://securityblueprints.io/data-breaches/activision-hr-data-breach-2023/</link>
      <pubDate>Sun, 04 Dec 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/activision-hr-data-breach-2023/</guid>
      <description>Executive Summary In December 2022, Activision, a leading video game developer, encountered a data breach caused by a sophisticated SMS phishing attack targeting a Human Resources (HR) employee. This breach resulted in unauthorized access to internal data, including employee names, phone numbers, email addresses, job titles, and workplace locations. Despite discrepancies regarding the exact public disclosure date, the breach became widely acknowledged in February 2023, highlighting substantial risks to employee data security [TechCrunch ] [Intrix ].</description>
    </item>
    <item>
      <title>T-Mobile January 2023 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/t-mobile-january-2023-data-breach/</link>
      <pubDate>Fri, 25 Nov 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/t-mobile-january-2023-data-breach/</guid>
      <description>Executive Summary In January 2023, T-Mobile disclosed a significant data breach that affected approximately 37 million current customers. The breach, initiated through unauthorized access to an API, began in late November 2022. T-Mobile detected the breach on January 5, 2023, and publicly disclosed it on January 19, 2023.&#xA;Technical Details The breach was facilitated through a vulnerability in an API, which allowed attackers to access personal data, including names, billing addresses, email addresses, phone numbers, and dates of birth.</description>
    </item>
    <item>
      <title>Pegasus Airlines Data Exposure</title>
      <link>https://securityblueprints.io/data-breaches/pegasus-airlines-data-exposure/</link>
      <pubDate>Tue, 01 Mar 2022 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/pegasus-airlines-data-exposure/</guid>
      <description>Executive Summary Incident Overview In March 2022, Pegasus Airlines faced a data exposure due to a misconfiguration in an AWS S3 bucket by a system administrator. This incident led to the exposure of approximately 23 million files, containing Personally Identifiable Information (PII) and critical operational data (source ).&#xA;Severity of Impact The breach involved 6.5 terabytes of sensitive data, including sensitive operational information, crew identification details, plaintext passwords, secret keys, insurance documents, and safety guidelines.</description>
    </item>
    <item>
      <title>Cash App Data Breach - April 2022</title>
      <link>https://securityblueprints.io/data-breaches/cash-app-data-breach/</link>
      <pubDate>Fri, 10 Dec 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/cash-app-data-breach/</guid>
      <description>Executive Summary In April 2022, Block, the parent company of Cash App, disclosed a significant data breach involving unauthorized access by a former employee, who downloaded sensitive financial information from approximately 8.2 million users. This exposure included brokerage account details and stock trading activities. The breach was publicly announced on April 4, 2022 (source ). Despite the breadth of affected data, no personally identifiable information such as usernames, passwords, or Social Security numbers was compromised (source ).</description>
    </item>
    <item>
      <title>South Georgia Medical Center Data Theft</title>
      <link>https://securityblueprints.io/data-breaches/south-georgia-medical-center-data-theft/</link>
      <pubDate>Fri, 12 Nov 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/south-georgia-medical-center-data-theft/</guid>
      <description>Executive Summary The November 2021 data breach at South Georgia Medical Center (SGMC) was caused by a former employee downloading patient data onto a USB drive without authorization. This incident underscores the risks associated with insider threats and highlights the necessity for stringent data security protocols.&#xA;Incident Details Breach Type: Insider data theft involving unauthorized transfer of patient information. Compromised Data: Included protected health information such as patient names, birth dates, and test results.</description>
    </item>
    <item>
      <title>LinkedIn Data Scraping Incident</title>
      <link>https://securityblueprints.io/data-breaches/linkedin-data-scraping-incident/</link>
      <pubDate>Thu, 01 Apr 2021 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/linkedin-data-scraping-incident/</guid>
      <description>Executive Summary In April 2021, LinkedIn reported a significant data scraping incident involving approximately 700 million user records, totaling over 93% of its user base. The breach was disclosed in June 2021 after data was discovered being sold on dark web forums by the hacker known as &amp;ldquo;GOD User TomLiner,&amp;rdquo; who intended to sell the dataset for an estimated $5,000 to $6,600.&#xA;Severity of the Impact The breach&amp;rsquo;s significance lies in the vast volume of exposed personal information, such as full names, email addresses, phone numbers, LinkedIn IDs, and sensitive data like gender, industry, and inferred salaries.</description>
    </item>
    <item>
      <title>Twitter 2020 Data Breach Incident</title>
      <link>https://securityblueprints.io/data-breaches/twitter-2020-data-breach-incident/</link>
      <pubDate>Wed, 15 Jul 2020 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/twitter-2020-data-breach-incident/</guid>
      <description>Executive Summary In July 2020, a critical cybersecurity breach, termed the Twitter 2020 Data Breach, occurred, wherein a 17-year-old hacker, Graham Ivan Clark, along with accomplices, exploited vulnerabilities in Twitter’s security infrastructure. They gained unauthorized access to Twitter&amp;rsquo;s internal network, commandeering numerous high-profile accounts to disseminate a Bitcoin scam.&#xA;Key Dates Breach Occurrence: July 15, 2020 Public Disclosure: July 15, 2020 Severity of Impact The breach affected highly influential accounts such as those of Barack Obama and Elon Musk, resulting in fraudulent tweets promoting a Bitcoin scam.</description>
    </item>
    <item>
      <title>Sina Weibo Data Breach 2020</title>
      <link>https://securityblueprints.io/data-breaches/sina-weibo-data-breach-2020/</link>
      <pubDate>Thu, 19 Mar 2020 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/sina-weibo-data-breach-2020/</guid>
      <description>Executive Summary In March 2020, Sina Weibo, a leading Chinese microblogging platform, experienced a significant data breach impacting approximately 538 million users. The breach was publicly acknowledged when an attacker leveraged a logic flaw in the Sina Weibo API to access and sell personal user information on the dark web for about USD 250. This breach exposed sensitive details such as real names, usernames, gender, location, and phone numbers for 172 million users, though passwords were not compromised.</description>
    </item>
    <item>
      <title>Alibaba Taobao Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/alibaba-taobao-data-breach/</link>
      <pubDate>Fri, 01 Nov 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/alibaba-taobao-data-breach/</guid>
      <description>Executive Summary In November 2019, Alibaba&amp;rsquo;s Taobao platform experienced a breach involving unauthorized data scraping activities by a developer. This breach involved collecting 1.1 billion pieces of user data, including usernames and mobile numbers, over several months until discovered in July 2020. Officially acknowledged on June 16, 2021, the breach stands as significant due to its volume and impact.&#xA;Severity of Impact The breach is one of the largest data leaks recorded, affecting approximately 710 million Taobao users.</description>
    </item>
    <item>
      <title>First American Financial Corp Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/first-american-financial-corp-data-breach/</link>
      <pubDate>Fri, 24 May 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/first-american-financial-corp-data-breach/</guid>
      <description>Executive Summary In May 2019, a data breach at First American Financial Corp. resulted in the exposure of approximately 885 million file records due to inadequate security measures on their web portal. The breach came to light when a real estate developer discovered the vulnerability, and cybersecurity journalist Brian Krebs publicly disclosed it on May 24, 2019. The exposed records included sensitive financial documents such as bank account numbers, mortgage-related documents, and Social Security numbers, with records dating back to 2003.</description>
    </item>
    <item>
      <title>Facebook Data Breach 2019</title>
      <link>https://securityblueprints.io/data-breaches/facebook-data-breach-2019/</link>
      <pubDate>Mon, 01 Apr 2019 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/facebook-data-breach-2019/</guid>
      <description>Executive Summary In April 2019, a significant data breach affected Facebook, exposing the personal information of over 530 million users across 106 countries. The breach involved the improper access and sharing of two datasets, revealing sensitive information such as phone numbers, account names, Facebook ID numbers, and email addresses. The exposure occurred due to the misuse of Facebook&amp;rsquo;s &amp;lsquo;contact importer&amp;rsquo; feature and improperly secured third-party applications hosted on Amazon Web Services (AWS) servers.</description>
    </item>
    <item>
      <title>Aadhaar Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/aadhaar-data-breach/</link>
      <pubDate>Mon, 01 Jan 2018 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/aadhaar-data-breach/</guid>
      <description>Executive Summary In January 2018, a significant data breach compromised Aadhaar, the world&amp;rsquo;s largest identification database, managed by the Unique Identification Authority of India (UIDAI). The breach affected personal information—biometric and financial data—of approximately 1.1 billion Indian citizens. The affected information was allegedly retailed for as little as ₹500 via WhatsApp, pointing to extensive security flaws (Legal Service India , FirstPost ).&#xA;Severity of Impact The exposure of biometric details like fingerprints and iris scans poses severe risks related to identity theft and fraud, thus threatening the privacy and security of citizens.</description>
    </item>
    <item>
      <title>2016 Uber Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/2016-uber-data-breach/</link>
      <pubDate>Mon, 14 Nov 2016 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/2016-uber-data-breach/</guid>
      <description>Executive Summary On November 14, 2016, a data breach exposed records of approximately 57 million Uber users and 600,000 driver license numbers. The breach occurred when hackers exploited Uber&amp;rsquo;s systems by using stolen credentials to access its GitHub repository, subsequently gaining entry into an AWS S3 bucket containing sensitive user data such as names, email addresses, and phone numbers. For further details, refer to this source .&#xA;Key Events November 14, 2016: Attackers demanded a ransom for stolen data deletion.</description>
    </item>
    <item>
      <title>AdultFriendFinder Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/adultfriendfinder-data-breach/</link>
      <pubDate>Thu, 20 Oct 2016 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/adultfriendfinder-data-breach/</guid>
      <description>Executive Summary The AdultFriendFinder data breach, a significant incident in 2016, compromised approximately 412 million user accounts across platforms under FriendFinder Networks, including AdultFriendFinder.com, Cams.com, and Penthouse.com. This breach unveiled notable security vulnerabilities within the company&amp;rsquo;s systems.&#xA;Breach Details The breach occurred in October 2016 when attackers exploited Local File Inclusion (LFI) vulnerabilities within the website&amp;rsquo;s architecture, enabling unauthorized access to sensitive information. This data was publicly posted on November 13, 2016.</description>
    </item>
    <item>
      <title>Australian Immigration Department G20 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/australian-immigration-department-g20-data-breach/</link>
      <pubDate>Fri, 07 Nov 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/australian-immigration-department-g20-data-breach/</guid>
      <description>Executive Summary In 2015, the Australian Immigration Department was involved in a data breach releasing sensitive personal details of G20 world leaders due to an administrative error. The error occurred when an employee improperly used the autocomplete function in Microsoft Outlook, resulting in sensitive information being sent to an unintended recipient. This incident compromised data such as passport numbers, visa information, and birth dates of leaders including Barack Obama, Vladimir Putin, and Angela Merkel (ABC News ).</description>
    </item>
    <item>
      <title>2014 Uber Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/2014-uber-data-breach/</link>
      <pubDate>Mon, 12 May 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/2014-uber-data-breach/</guid>
      <description>Executive Summary In 2014, Uber experienced a significant data breach, where approximately 50,000 consumers&amp;rsquo; sensitive information, particularly names and driver&amp;rsquo;s license numbers, was accessed without authorization. This incident arose from the mishandling of an unencrypted Amazon Web Services (AWS) access key that was inadvertently published on GitHub, thereby allowing attackers unauthorized system access. (source , source )&#xA;Key Dates:&#xA;May 12, 2014: Attackers gained access to Uber&amp;rsquo;s AWS account by exploiting a publicly exposed AWS access key on GitHub.</description>
    </item>
    <item>
      <title>eBay Data Breach Analysis</title>
      <link>https://securityblueprints.io/data-breaches/ebay-data-breach-analysis/</link>
      <pubDate>Fri, 28 Feb 2014 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/ebay-data-breach-analysis/</guid>
      <description>Executive Summary In early 2014, eBay, a leading online marketplace, experienced a significant data breach, which was publicly disclosed in May 2014. Unauthorized access to approximately 145 million user records occurred due to compromised employee credentials. The breach period spanned late February to early March 2014 (CRN , NY Times ).&#xA;Severity and Impact The breach is considered extensive, with unauthorized access to records including names, encrypted passwords, email addresses, physical addresses, phone numbers, and birth dates.</description>
    </item>
    <item>
      <title>Adobe 2013 Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/adobe-2013-data-breach/</link>
      <pubDate>Thu, 03 Oct 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/adobe-2013-data-breach/</guid>
      <description>Executive Summary In October 2013, Adobe became the victim of a cyberattack that compromised nearly 153 million user records, ranking as one of the largest breaches in cybersecurity history (source ). The attack resulted in the exposure of encrypted customer credit card information and user account details, prompting concerns about Adobe&amp;rsquo;s cybersecurity protocols (source ).&#xA;Key Details Breach Discovery: Internal discovery occurred on September 17, 2013, with public disclosure by Adobe on October 3, 2013 (source ).</description>
    </item>
    <item>
      <title>Yahoo Data Breach August 2013</title>
      <link>https://securityblueprints.io/data-breaches/yahoo-data-breach-august-2013/</link>
      <pubDate>Thu, 01 Aug 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/yahoo-data-breach-august-2013/</guid>
      <description>Executive Summary Incident Overview In August 2013, Yahoo experienced a substantial data breach that compromised the account information of approximately 3 billion users. The exposed data included usernames, email addresses, telephone numbers, hashed passwords (MD5), as well as both encrypted and unencrypted security questions and answers. Payment card information and bank details remained secure (Yahoo data breaches ). The breach&amp;rsquo;s public disclosure occurred in December 2016, which emphasized the delayed recognition and broadcast of its full scope (Yahoo Security Notice December 14, 2016 ).</description>
    </item>
    <item>
      <title>MySpace Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/myspace-data-breach/</link>
      <pubDate>Sat, 01 Jun 2013 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/myspace-data-breach/</guid>
      <description>Executive Summary The MySpace data breach disclosed in June 2016 affected over 360 million user accounts, underscoring substantial deficiencies in the company&amp;rsquo;s data security measures. At the time, MySpace utilized weak hashing algorithms like SHA-1 without salting, a method known for its cryptographic weaknesses. Users&amp;rsquo; widespread password reuse across different services amplified the breach&amp;rsquo;s repercussions. Consequently, MySpace updated its security practices post-breach, transitioning to double-salted hashes.&#xA;Technical Details The breach highlighted significant vulnerabilities due to inadequate security measures.</description>
    </item>
    <item>
      <title>LinkedIn Password Breach</title>
      <link>https://securityblueprints.io/data-breaches/linkedin-password-breach/</link>
      <pubDate>Fri, 01 Jun 2012 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/linkedin-password-breach/</guid>
      <description>Executive Summary In 2012, LinkedIn experienced a significant data breach affecting its user base. Initially reported to have compromised 6.5 million hashed passwords, the breach&amp;rsquo;s true extent, revealed in 2016, affected over 117 million accounts. The compromised passwords were stored using the SHA1 hashing algorithm without salting, making them vulnerable to brute force and rainbow table attacks. These inadequacies exposed LinkedIn users to substantial risks as the leaked credentials circulated on cybercrime forums like LeakedSource.</description>
    </item>
    <item>
      <title>Google Aurora Incident</title>
      <link>https://securityblueprints.io/data-breaches/google-aurora-incident/</link>
      <pubDate>Tue, 01 Dec 2009 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/google-aurora-incident/</guid>
      <description>Executive Summary The Google Aurora incident, occurring in December 2009, was a significant cybersecurity breach affecting Google and multiple other corporations in various industries, particularly technology. The attack aimed to steal intellectual property and unauthorized Gmail access of Chinese human rights activists. It is widely attributed to state-sponsored entities linked to the Chinese government, employing sophisticated cyber espionage tactics.&#xA;Major Threat Actors The attack is attributed to entities based in China, utilizing Advanced Persistent Threat (APT) techniques.</description>
    </item>
    <item>
      <title>Heartland Payment Systems Data Breach</title>
      <link>https://securityblueprints.io/data-breaches/heartland-payment-systems-data-breach/</link>
      <pubDate>Wed, 26 Dec 2007 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/data-breaches/heartland-payment-systems-data-breach/</guid>
      <description>Executive Summary Heartland Payment Systems experienced a major data breach compromising approximately 130 million payment card records, marking one of the largest breaches involving consumer credit and debit card information. The breach originated from SQL injection attacks and malware deployment starting around December 26, 2007, and was discovered by authorities in October 2008. Public disclosure followed on January 20, 2009. This information is corroborated by multiple sources (source , source , source ).</description>
    </item>
  </channel>
</rss>
