Tuesday, October 1, 2024

The most important knowledge breaches in 2024: 1B stolen data and rising

We’re over midway by 2024, and already this yr we’ve seen among the greatest, most damaging knowledge breaches in latest historical past. And simply whenever you suppose that a few of these hacks can’t get any worse, they do.

From enormous shops of shoppers’ private info getting scraped, stolen and posted on-line, to reams of medical knowledge protecting most individuals in the US getting stolen, the worst knowledge breaches of 2024 thus far have already surpassed at the very least 1 billion stolen data and rising. These breaches not solely have an effect on the people whose knowledge was irretrievably uncovered, but in addition embolden the criminals who revenue from their malicious cyberattacks.

Journey with us to the not-so-distant previous to have a look at how among the greatest safety incidents of 2024 went down, their impression, and in some instances, how they might have been stopped. 

Thriller AT&T knowledge leak uncovered 73 million buyer accounts

Some three years after a hacker teased a printed pattern of allegedly stolen AT&T buyer knowledge, a knowledge breach dealer in March dumped the total cache of 73 million buyer data on-line to a identified cybercrime discussion board for anybody to see. The revealed knowledge included clients’ private info, together with names, telephone numbers and postal addresses, with some clients confirming their knowledge was correct

However it wasn’t till a safety researcher found that the uncovered knowledge contained encrypted passcodes used for accessing a buyer’s AT&T account that the telecoms large took motion. The safety researcher informed TechCrunch on the time that the encrypted passcodes could possibly be simply unscrambled, placing some 7.6 million current AT&T buyer accounts susceptible to hijacks. AT&T force-reset its clients’ account passcodes after TechCrunch alerted the corporate to the researcher’s findings. 

One massive thriller stays: AT&T nonetheless doesn’t know the way the info leaked or the place it got here from

Change Healthcare hackers stole medical knowledge on “substantial proportion” of individuals in America

In 2022, the U.S. Justice Division sued medical health insurance large UnitedHealth Group to dam its tried acquisition of well being tech large Change Healthcare, fearing that the deal would give the healthcare conglomerate broad entry to about “half of all Individuals’ medical health insurance claims” annually. The bid to dam the deal in the end failed. Then, two years later, one thing far worse occurred: Change Healthcare was hacked by a prolific ransomware gang; its almighty banks of delicate well being knowledge have been stolen as a result of one of many firm’s crucial techniques was not protected with multi-factor authentication.

The prolonged downtime attributable to the cyberattack dragged on for weeks, inflicting widespread outages at hospitals, pharmacies and healthcare practices throughout the US. However the aftermath of the info breach has but to be absolutely realized, although the results for these affected are prone to be irreversible. UnitedHealth says the stolen knowledge — which it paid the hackers to acquire a duplicate — consists of the non-public, medical and billing info on a “substantial proportion” of individuals in the US. 

UnitedHealth has but to connect a quantity to what number of people have been affected by the breach. The well being large’s chief government, Andrew Witty, informed lawmakers that the breach could have an effect on round one-third of Individuals, and doubtlessly extra. For now, it’s a query of simply what number of a whole lot of thousands and thousands of individuals within the U.S. are affected. 

Synnovis ransomware assault sparked widespread outages at hospitals throughout London 

A June cyberattack on U.Ok. pathology lab Synnovis — a blood and tissue testing lab for hospitals and well being providers throughout the U.Ok. capital — precipitated ongoing widespread disruption to affected person providers for weeks. The native Nationwide Well being Service trusts that depend on the lab postponed hundreds of operations and procedures following the hack, prompting the declaration of a crucial incident throughout the U.Ok. well being sector.

A Russia-based ransomware gang was blamed for the cyberattack, which noticed the theft of knowledge associated to some 300 million affected person interactions relationship again a “important quantity” of years. Very similar to the info breach at Change Healthcare, the ramifications for these affected are prone to be important and life-lasting. 

A few of the knowledge was already revealed on-line in an effort to extort the lab into paying a ransom. Synnovis reportedly refused to pay the hackers’ $50 million ransom, stopping the gang from taking advantage of the hack however leaving the U.Ok. authorities scrambling for a plan in case the hackers posted thousands and thousands of well being data on-line. 

One of many NHS trusts that runs 5 hospitals throughout London affected by the outages reportedly failed to satisfy the info safety requirements as required by the U.Ok. well being service within the years that ran as much as the June cyberattack on Synnovis.

Ticketmaster had an alleged 560 million data stolen within the Snowflake hack

A collection of knowledge thefts from cloud knowledge large Snowflake rapidly snowballed into one of many greatest breaches of the yr, because of the huge quantities of knowledge stolen from its company clients. 

Cybercriminals swiped a whole lot of thousands and thousands of buyer knowledge from among the world’s greatest corporations — together with an alleged 560 million data from Ticketmaster, 79 million data from Advance Auto Elements and some 30 million data from TEG — by utilizing stolen credentials of knowledge engineers with entry to their employer’s Snowflake environments. For its half, Snowflake doesn’t require (or implement) its clients to make use of the safety characteristic, which protects towards intrusions that depend on stolen or reused passwords. 

Incident response agency Mandiant mentioned round 165 Snowflake clients had knowledge stolen from their accounts, in some instances a “important quantity of buyer knowledge.” Solely a handful of the 165 corporations have up to now confirmed their environments have been compromised, which additionally consists of tens of hundreds of worker data from Neiman Marcus and Santander Financial institution, and thousands and thousands of data of scholars at Los Angeles Unified Faculty District. Anticipate many Snowflake clients to return ahead. 

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles