Tag / 38 entries / page 3 of 4 / feed available

User Data

38 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

036

LinkedIn Data Scraping Incident

In April 2021, LinkedIn experienced a massive data scraping incident, exposing approximately 700 million user records. The breach involved personal information such as full names, email addresses, and professional details extracted through LinkedIn’s public API by a threat actor named ‘GOD User TomLiner.’ Although passwords and financial details were not compromised, the incident highlights significant risks for identity theft and phishing attacks.

034

Twitter 2020 Data Breach Incident

Prevented by: HSF

In July 2020, a 17-year-old hacker and his accomplices compromised Twitter’s internal systems through social engineering, taking control of approximately 130 high-profile accounts. These accounts were used to perpetrate a Bitcoin scam that led to financial losses of over $117,000. The attack highlighted significant vulnerabilities in Twitter’s protection against social engineering and demonstrated the persistent risk of insider threats.

029

First American Financial Corp Data Breach

In May 2019, First American Financial Corp. suffered a major data breach that exposed approximately 885 million file records due to a security flaw. The breach involved bank account details and mortgage-related documents, which were accessible through unsecured URLs without authentication. The vulnerability was attributed to insufficient security measures, and there were no specific threat actors identified.

028

Facebook Data Breach 2019

In April 2019, Facebook experienced a major data breach exposing the personal information of over 530 million users from two datasets. The breach involved cloud storage misconfiguration and data scraping vulnerabilities, resulting in the leak of phone numbers and account names. The attack did not involve specific threat actors but exploited weaknesses in the Facebook contact importer and third-party AWS storage configurations.

024

Aadhaar Data Breach

The Aadhaar breach in January 2018 resulted in the unauthorized exposure of personal and biometric data of 1.1 billion Indian citizens. This was due to system vulnerabilities like unsecured API endpoints, allowing attackers access to sensitive data including bank account information. While specific threat actors remain unconfirmed, the large-scale data compromise highlights significant security lapses within the government’s database management.

020

2016 Uber Data Breach

Prevented by: HSF

On November 14, 2016, Uber suffered a data breach exposing the personal information of 57 million users and 600,000 driver license numbers. Hackers accessed Uber’s data by exploiting credential mismanagement and accessing unsecured AWS S3 buckets, following infiltration of Uber’s GitHub repositories. The perpetrators, identified as Brandon Charles Glover and Vasile Mereacre, demanded a ransom disguised as a bug bounty program to avoid public disclosure.

019

AdultFriendFinder Data Breach

Contained by: EGR

The 2016 AdultFriendFinder data breach exposed approximately 412 million user accounts due to vulnerabilities in Local File Inclusion (LFI). Compromised data included usernames, email addresses, and passwords, mostly stored in plaintext or hashed with weak SHA-1, making them vulnerable to cracking. While the exact perpetrators remain unidentified, discussions suggest involvement from actors on Russian forums.

016

Australian Immigration Department G20 Data Breach

In a 2015 incident, the Australian Immigration Department inadvertently exposed the sensitive personal details of G20 world leaders due to an email autofill error. The breach involved the accidental email of names, birth dates, passport numbers, and visa details to an unintended recipient, raising potential diplomatic concerns despite low risk due to the recipient’s prompt deletion of the email.

RSS feed for this tag →

Now playing Bandcamp