Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Learning Lessons From The Biggest Data Breaches Of 2017
Articles

Learning Lessons From The Biggest Data Breaches Of 2017

ISBuzz TeamBy ISBuzz TeamJanuary 31, 2018Updated:July 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

With the threat landscape constantly evolving and cyber-criminals looking for new ways to breach organisations’ defences, maintaining the integrity of the business network and the data that resides there is a growing challenge. By and large, organisations are just about coping with the array of potential threats they are facing, but the growing number of threats can be overwhelming.

In 2017, we witnessed some of the most high-profile and effective breaches ever seen, highlighting that significant breaches have equally significant consequences, ranging from reputational damage to legal investigation. Perhaps this is why more organisations than ever before have a clear understanding of the potential impacts of a data breach.

So, with organisations becoming increasingly cyber-security aware, what can we learn from the top five breaches of 2017 as businesses look to enhance their security posture for 2018 and beyond?

NHS

2017 was a turbulent year in cybersecurity for the NHS, not only was it hit by the WannaCry ransomware, but it was also revealed that 26 million patients’ medical records had been breached.

Based on knowledge in the public domain, we believe the root cause of the vulnerability relates to an ‘enhanced data sharing’ option. If enabled, that data can be accessed by hundreds of thousands of other users of the same system. This is a common oversight, as organisations tend to focus on their web application testing and security, but fail to extend this security to their desktop applications.

We regularly find vulnerabilities like this when we’re auditing desktop applications and the communication mechanisms that support them. By extending the same care to both web and desktop applications, these vulnerabilities can be minimised.

Equifax

In September 2017, Credit Reference Agency Equifax revealed it had suffered a massive global data breach that affected 143 million consumers in the USA and up to 400,000 in the UK. Hackers accessed sensitive information including names, addresses, dates of birth and credit card numbers.

While all the details of the breach have not been disclosed, based on public information it appears that the initial point of compromise came from an affected web server. The critical vulnerability in question had been publicly disclosed, and a patch released, months before the breach occurred.

This breach highlights how critically important it is for all organisations to be on top of their vulnerability management processes, ensuring that critical patches for software and systems are applied as soon as possible.

Regular penetration testing and vulnerability scanning feed into a central vulnerability management system within the wider Governance, Risk and Compliance (GRC) processes. They’re fundamental to help mitigate the risk of these kinds of breaches occurring. After all, if you’re not aware of your vulnerabilities and risks, you can’t treat them.

 Yahoo

Shortly after the Equifax breach was announced, Yahoo revealed that in 2013, every Yahoo account that existed had been hacked. In total, three billion accounts for Yahoo’s email, Tumblr, Fantasy and Flickr services had been compromised, and the exfiltrated data was made available for sale on the dark web.

Yahoo has never confirmed or released details about how the information was compromised. However, these types of breaches usually originate from an exploited website vulnerability. Preventing such a hack starts with using controls that identify vulnerabilities. However, it’s also critical that incident response processes are in place to identify attacks in progress.

Uber

In November 2017, ride hailing service Uber revealed that the personal information of 57 million Uber customers and drivers worldwide had been stolen. According to The Guardian, Uber had previously concealed the breach and paid hackers $100,000 to delete the data and keep quiet.

We believe the breach resulted from credentials left in a Git repository, which the attackers accessed by compromising a developer’s account. Code repositories should be adequately protected. Ensure credentials are never left in code or in repositories, and make sure that all users are taking advantage of multi-factor authentication and are using unique passwords for every system and service.

In addition, it’s vital that those repositories are audited before being made public. Any sensitive information, such as passwords and SSH private keys, must be cleaned from the code. Too often, comments are left in the code that reveal sensitive information. Permissions should also be checked frequently and audited to ensure security – including private repositories.

Beyond securing vulnerable information, communication is key. Uber tried to brush the breach under the carpet, but making your customers aware of a breach as soon as possible is the best response. This will be critical when the General Data Protection Regulation becomes enforceable. Under the regulation, organisations must notify of the breach to the relevant supervisory authorities and affected parties within 72 hours of it discovery, as failure to do so could result in fines up to €20m or 4% of world-wide revenue, whichever is greater.

Alteryx

In the last major breach of the year, a cyber risk researcher revealed that data analytics software company Alteryx, had left a 36-gigabyte database exposed in an Amazon Web Services storage bucket. Alteryx’s unsecured database was discovered during a routine search of Amazon Web Services storage buckets, with the breach affecting 123 million households in the USA.

Configuration related vulnerabilities like this are common, and AWS storage buckets that have not been protected correctly with the right controls are frequently discovered. According to The Register, information from Accenture, Verizon, Viacom, and the US military had been inadvertently left online due to incorrect configuration.

When storing sensitive information in the public cloud, it’s vital to implement best practice security measures. All storage buckets must be configured correctly, with procedures, checks and balances in place to make sure that systems can’t go live without being properly audited. Each configuration must be checked against potential vulnerabilities, and it is best practice to ensure that the configuration is peer reviewed before the system goes live.

With 2017 now in the rear-view mirror, organisations are focused on ensuring that they’re well protected against the threats that 2018 will undoubtedly have to offer. But looking back at the lessons of 2017 will help to avoid repeating the mistakes of the past.

[su_box title=”About Luke Potter” style=”noise” box_color=”#336588″][short_info id=’102737′ desc=”true” all=”false”][/su_box]

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Foxconn confirms cyberattack following Nitrogen ransomware claims

May 14, 20263 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}