Tag / 38 entries / page 4 of 4 / feed available

User Data

38 of the 76 analyses in Data Breaches carry this tag.

HSF · PEC · EGR · SCA — filled where the invariant would have prevented or contained the breach

014

2014 Uber Data Breach

In 2014, Uber experienced a data breach impacting approximately 50,000 individuals, exposing personal information such as names and driver’s license numbers. Unauthorized access was facilitated through a publicly exposed AWS access key on GitHub, underscoring critical flaws in credential management and cloud security. No specific threat actors were identified, but the incident highlighted significant vulnerabilities in Uber’s data protection practices.

012

eBay Data Breach Analysis

Prevented by: HSF, EGR

In early 2014, eBay experienced a significant data breach affecting approximately 145 million user records. The compromised data included names, encrypted passwords, email addresses, physical addresses, phone numbers, and birth dates. Cyber attackers used stolen employee credentials, likely acquired through sophisticated phishing tactics, to gain unauthorized access to eBay’s network. While the encrypted passwords were compromised, PayPal’s financial information remained secure due to separate storage protocols.

010

Adobe 2013 Data Breach

Prevented by: EGR

In October 2013, Adobe suffered a significant data breach compromising 153 million user records, including encrypted credit card information and user account details such as usernames and email addresses. The breach, one of the largest in cybersecurity history, was executed by exploiting vulnerabilities in Adobe’s systems, notably through outdated encryption practices and unpatched ColdFusion servers. The attack was attributed to financially motivated cybercriminals, likely from Eastern Europe or Russia, aiming to sell the stolen data on the black market.

008

Yahoo Data Breach August 2013

Prevented by: HSF, PEC, EGR

In August 2013, Yahoo suffered one of the largest data breaches in history, compromising the account information of approximately 3 billion users. The exposed data included usernames, email addresses, telephone numbers, hashed passwords using MD5, and both encrypted and unencrypted security questions and answers. The attack was attributed to state-sponsored actors from Russian intelligence, highlighting a significant cyber-espionage operation.

007

MySpace Data Breach

In June 2013, over 360 million user accounts on MySpace were compromised, exposing usernames, email addresses, and passwords due to inadequate security practices. The passwords were stored using weak SHA-1 hashes without salting, making them vulnerable to cracking. A Russian hacker known as “Peace” was linked to this major breach. MySpace subsequently improved its security by adopting double-salted hashing techniques.

005

LinkedIn Password Breach

Prevented by: HSF, PEC, EGR

The LinkedIn Password Breach in 2012 affected over 117 million user accounts by exposing passwords hashed with the insecure SHA1 algorithm, unsalted. The breach data was subsequently sold on cybercrime forums, with LeakedSource holding a searchable database. The exposure of user credentials posed significant risks of unauthorized account access.

003

Google Aurora Incident

Prevented by: PEC, EGR

The Google Aurora Incident was a significant cyber attack in December 2009 targeting Google and other corporations. The attack, attributed to actors linked to the Chinese state, aimed to steal intellectual property and infiltrate Gmail accounts of Chinese human rights activists. Attackers exploited a zero-day vulnerability in Internet Explorer, using malware to gain unauthorized access and exfiltrate sensitive data.

002

Heartland Payment Systems Data Breach

Prevented by: PEC, EGR

The Heartland Payment Systems data breach in 2008 compromised approximately 130 million payment card records. The breach was executed using SQL injection attacks to install malware, capturing sensitive financial data such as credit card numbers over a prolonged period. Albert Gonzalez, a known cybercriminal, was attributed as the architect of this breach. The incident revealed significant vulnerabilities in Heartland’s transaction processes leading to substantial financial and reputational damage.

RSS feed for this tag →

Now playing Bandcamp