{"id":100639,"date":"2019-08-24T11:36:15","date_gmt":"2019-08-24T15:36:15","guid":{"rendered":"http:\/\/rbach.net\/index.php\/"},"modified":"2021-07-31T16:52:14","modified_gmt":"2021-07-31T20:52:14","slug":"8200000000-data-breaches","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/8200000000-data-breaches\/","title":{"rendered":"8,200,000,000 Data Breaches"},"content":{"rendered":"<p><a href=\"https:\/\/deptofnance.blogspot.com\/2014\/03\/in-which-we-bring-our-monsters-out-from.html\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-100944\" title=\"8,200,000,000 Data Breaches\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/scary-numbers-1.jpg?resize=138%2C110&#038;ssl=1\" alt=\"8,200,000,000 Data Breaches\" width=\"138\" height=\"110\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/scary-numbers-1.jpg?resize=150%2C120&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/scary-numbers-1.jpg?resize=75%2C60&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/scary-numbers-1.jpg?w=300&amp;ssl=1 300w\" sizes=\"auto, (max-width: 138px) 100vw, 138px\" \/><\/a>2019 is on pace to be the <strong>worst year ever for data breaches<\/strong>. If things continue at the same pace <strong>8.2 billion records<\/strong> will be exposed by the end of 2019. The threat intelligence firm <a href=\"https:\/\/www.riskbasedsecurity.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Risk Based Security<\/a> <a href=\"https:\/\/pages.riskbasedsecurity.com\/2019-midyear-data-breach-quickview-report\" target=\"_blank\" rel=\"noopener noreferrer\">reports<\/a> that during the <strong>first half of 2019<\/strong> over <strong>4.19 billion records<\/strong> were exposed in 3,813 reported breaches between January and July 2019.<\/p>\n<p><a href=\"https:\/\/www.riskbasedsecurity.com\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101589 size-thumbnail\" title=\"Risk Based Security logo\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/rbs_logo.png?resize=75%2C75&#038;ssl=1\" alt=\"Risk Based Security logo\" width=\"75\" height=\"75\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/rbs_logo.png?resize=75%2C75&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/rbs_logo.png?resize=150%2C150&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/rbs_logo.png?w=200&amp;ssl=1 200w\" sizes=\"auto, (max-width: 75px) 100vw, 75px\" \/><\/a>Those numbers work out to more than <strong>20 data breaches a day<\/strong>. <strong>Eight mega-breaches<\/strong> that exposed more than 100 million records were reported. These web-based breaches were primarily the result of <strong>leaving databases accessible<\/strong> to third parties and <strong>failing to protect<\/strong> them. <em><a href=\"https:\/\/www.forbes.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Forbes<\/a><\/em> <a href=\"https:\/\/www.forbes.com\/sites\/daveywinder\/2019\/08\/20\/data-breaches-expose-41-billion-records-in-first-six-months-of-2019\/#34d8f082bd54\" target=\"_blank\" rel=\"noopener noreferrer\">reports<\/a> that these <strong>misconfigured databases<\/strong> and services accounted for 149 of the 3,813 incidents reported this year. According to <em>Forbes<\/em>, the mega-breaches exposed over <strong>3.2 billion records<\/strong> and accounting for 78.6% of the total records exposed in the first half of 2019.<\/p>\n<h3>Largest data breaches<\/h3>\n<p>The 10 largest data breaches for the first half of 2019 are:<\/p>\n<ol>\n<li><a href=\"https:\/\/www.mediapost.com\/publications\/article\/333276\/email-vendor-verificationsio-seems-to-be-out-of-b.html\" target=\"_blank\" rel=\"noopener noreferrer\">Verifications.io<\/a> (<a href=\"https:\/\/www.bankinfosecurity.com\/breach-verificationsio-exposes-763-million-records-a-12158\" target=\"_blank\" rel=\"noopener noreferrer\">982 million<\/a>),<\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20231215034350\/https:\/\/www.firstam.com\/index.html\" target=\"_blank\" rel=\"noopener noreferrer\">First American Financial<\/a> (<a href=\"https:\/\/krebsonsecurity.com\/2019\/05\/first-american-financial-corp-leaked-hundreds-of-millions-of-title-insurance-records\/\" target=\"_blank\" rel=\"noopener noreferrer\">885 million<\/a>),<\/li>\n<li><a href=\"https:\/\/culturacolectiva.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Cultura Colectiva<\/a> <a href=\"https:\/\/www.theverge.com\/2019\/4\/3\/18293978\/facebook-app-developers-leak-user-records-data-cloud-servers\" target=\"_blank\" rel=\"noopener noreferrer\">(540 million<\/a>),<\/li>\n<li>unknown organization in India\u00a0 (275 million),<\/li>\n<li>unknown organization in China (202 million),<\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20220216012244\/https:\/\/dubsmash.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Dubsmash<\/a> (<a href=\"https:\/\/web.archive.org\/web\/20210228132343\/https:\/\/in.pcmag.com\/security\/128637\/massive-breach-exposes-617-million-accounts-from-dubsmash-500px-and-more\" target=\"_blank\" rel=\"noopener noreferrer\">161 million<\/a>),<\/li>\n<li><a href=\"https:\/\/www.canva.com\" target=\"_blank\" rel=\"noopener noreferrer\">Canva<\/a> (<a href=\"https:\/\/nakedsecurity.sophos.com\/2019\/05\/28\/millions-of-canva-users-data-stolen-as-gnosticplayers-strikes-again\/\" target=\"_blank\" rel=\"noopener noreferrer\">138 million<\/a>),<\/li>\n<li>Justdial (<a href=\"https:\/\/www.bankinfosecurity.asia\/researcher-justdial-leaks-information-on-100-million-users-a-12385\" target=\"_blank\" rel=\"noopener noreferrer\">100 million<\/a>),<\/li>\n<li><a href=\"https:\/\/web.archive.org\/web\/20211218043836\/http:\/\/mobiledrip.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Mobile Drip<\/a> (<a href=\"https:\/\/securitydiscovery.com\/massive-sms-bombing-operation\/\" target=\"_blank\" rel=\"noopener noreferrer\">80 million<\/a>), and<\/li>\n<li>Unknown U.S. firm (80 million).<\/li>\n<\/ol>\n<p>The Verifications.io, First American Financial, and Cultura Colectiva breaches are ranked among the top 10 breaches of all time based on the number of records exposed.<\/p>\n<p><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101590\" title=\"Database security\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/database_security.jpg?resize=147%2C110&#038;ssl=1\" alt=\"Database security\" width=\"147\" height=\"110\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/database_security.jpg?resize=150%2C113&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/database_security.jpg?resize=75%2C56&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/database_security.jpg?w=300&amp;ssl=1 300w\" sizes=\"auto, (max-width: 147px) 100vw, 147px\" \/><a href=\"https:\/\/www.consumeraffairs.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Consumer Affairs<\/em><\/a> <a href=\"https:\/\/www.consumeraffairs.com\/news\/nearly-4000-data-breaches-have-exposed-41-billion-consumer-records-so-far-in-2019-082119.html\" target=\"_blank\" rel=\"noopener noreferrer\">says<\/a> the <strong>Verifications.io<\/strong>, an email marketing company whose <strong>misconfigured database<\/strong> exposed 982,864,972 names, addresses, and Facebook, LinkedIn, and Instagram accounts. The information associated with the breach includes email addresses, dates of birth, phone numbers, fax numbers, genders, IP addresses, and personal mortgage amounts. As a result of the incident, Verifications.io has ceased operations.<\/p>\n<p dir=\"ltr\">If you\u2019ve bought a house, particularly in California, another breach may impact you. <strong>First American Financial Corporation<\/strong> exposed 885,000,000 records. <em>Consumer Affairs<\/em> writes that <strong>exposed data<\/strong> included real estate closing transaction records that contained names, <strong>Social Security numbers<\/strong>, phone numbers, email and physical addresses, driver\u2019s license images, <strong>banking details<\/strong>, and mortgage lender names and loan numbers.<\/p>\n<h3>Other interesting data breach infobits<\/h3>\n<ul>\n<li>The <strong>number of breaches<\/strong> also reached a <strong>new high<\/strong> during the first half of 2019.<\/li>\n<li>The average number of records lost per leak was just 230.<\/li>\n<li>The majority of breaches had a moderate to low severity score and exposed 10,000 records or less.<\/li>\n<\/ul>\n<p>Thankfully RBS says more critical data was less commonly stolen during attacks.<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/web.archive.org\/web\/20190413083113\/https:\/\/www.serasrecords.com\/document-scanning\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101591\" title=\"Electronic records\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_records.png?resize=103%2C100&#038;ssl=1\" alt=\"Electronic records\" width=\"103\" height=\"100\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_records.png?resize=150%2C145&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_records.png?resize=75%2C73&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/data_records.png?w=357&amp;ssl=1 357w\" sizes=\"auto, (max-width: 103px) 100vw, 103px\" \/><\/a>Social Security numbers<\/strong> were stolen in 11% of attacks,<\/li>\n<li><strong>Addresses<\/strong> were stolen in 11% of attacks,<\/li>\n<li><strong>Account numbers<\/strong> were stolen in 10% of attacks,<\/li>\n<li><strong>Birth dates<\/strong> were stolen in 6% of attacks,<\/li>\n<\/ul>\n<p>The sectors impacted<\/p>\n<ul>\n<li>Healthcare 224 breaches,<\/li>\n<li>Retail 199\u00a0breaches,<\/li>\n<li>Finance and insurance 183 breaches,<\/li>\n<li>Government and information 160 breaches each, and<\/li>\n<li>Education 99 breaches..<\/li>\n<\/ul>\n<p>Inga Goddijn, executive vice-president at Risk Based Security <a href=\"https:\/\/www.computerweekly.com\/news\/252468677\/2019-set-to-be-another-record-year-for-data-breaches\" target=\"_blank\" rel=\"noopener noreferrer\">told<\/a> <a href=\"https:\/\/www.computerweekly.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>ComputerWeekly.com<\/em><\/a>,<\/p>\n<p style=\"text-align: justify; padding-left: 30px;\"><em>It is hard to be optimistic about the outlook for the year \u2026 The number of breaches is up and the number of records exposed remains stubbornly high. Despite best efforts and awareness among business leaders and defenders, data breaches continue to take place at an alarming rate.<\/em><\/p>\n<p><strong><a href=\"https:\/\/blogs.elon.edu\/technology\/phishing-scams\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101597 size-medium\" title=\"Phishing\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/phishing_goldfish.jpg?resize=150%2C138&#038;ssl=1\" alt=\"Phishing\" width=\"150\" height=\"138\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/phishing_goldfish.jpg?resize=150%2C138&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/phishing_goldfish.jpg?resize=75%2C69&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/phishing_goldfish.jpg?w=250&amp;ssl=1 250w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a><\/strong><\/p>\n<h3>Phishing<\/h3>\n<p><strong>Phishing<\/strong> is a tried and tested first step for gaining access to systems and services, the report said. The phished data can be used to perpetuate attach. The most frequently stolen data are email addresses and passwords. These credentials are valuable to attackers because they can be used across multiple domains (<em>because we know users don&#8217;t use unique IDs for each account<\/em>) for credential stuffing. These credentials can also be changed by the attacker (<em>or the Owner<\/em>). The report points out that 70% of the known breaches included email addresses and 65% included passwords.<\/p>\n<p>Phishing can also lead to other critical but less monetized data. The report said phishing can lead to the exposure of unusual or unexpected types of data, including electronic signatures, calendars, marriage certificates, and company-issued employee ID numbers, all valuable for social engineering or spear-phishing attacks.<\/p>\n<p><strong><em>rb-<\/em><\/strong><\/p>\n<p><em><a href=\"https:\/\/www.digitaltrends.com\/computing\/study-children-spending-more-time-with-screen-media-than-books\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-101601 size-medium\" title=\"Script baby\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/script_kiddie-e1566658765891-150x84.jpg?resize=150%2C84&#038;ssl=1\" alt=\"Script baby\" width=\"150\" height=\"84\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/script_kiddie-e1566658765891.jpg?resize=150%2C84&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/script_kiddie-e1566658765891.jpg?resize=75%2C42&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/script_kiddie-e1566658765891.jpg?w=542&amp;ssl=1 542w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>Businesses need to get their security act together &#8211; they were responsible for over 2\/3&#8217;s of the breaches by RBS. The garden variety cyber-criminal is a script-kiddie who will run automated scripts looking for unsecured databases in order to scrape up any data they can. The big breaches make the headlines, but the everyday incidents make the money for most attackers.<\/em><\/p>\n<h6>Related Posts<\/h6>\n<ul>\n<li><a href=\"https:\/\/www.computerweekly.com\/news\/252455311\/Data-breaches-affected-more-than-a-billion-people-in-2018\" target=\"_blank\" rel=\"noopener noreferrer\">Data breaches affected more than a billion people in 2018<\/a> (<a href=\"https:\/\/www.computerweekly.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Computer Weekly<\/a>)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>2019 is on pace to be the worst year ever for data breaches if things continue on pace 8.2 billion records will be exposed by 2020<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3161,125,2825,612,951,4],"class_list":["post-100639","post","type-post","status-publish","format-standard","hentry","category-security","tag-3161","tag-data-breach","tag-database","tag-phishing","tag-pii","tag-security"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/100639","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=100639"}],"version-history":[{"count":10,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/100639\/revisions"}],"predecessor-version":[{"id":131078,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/100639\/revisions\/131078"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=100639"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=100639"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=100639"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}