Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Oklahoma Securities Commission Data Breach
News & Analysis

Oklahoma Securities Commission Data Breach

ISBuzz TeamBy ISBuzz TeamJanuary 17, 2019Updated:July 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

Another huge leak of government information – a huge amount, 3 terabytes, of unprotected data from theOklahomaSecurities Commission wasuncoveredby Greg Pollock, a researcher with cybersecurity firm UpGuard. It amounted to millions of files, many on sensitive FBI investigations, all of which were left wide open on a server with no password, accessible to anyone with an internet connection.

Expert Comments below:

Kevin Bocek, Vice President, Security Strategy & Threat Intelligence at Venafi:

“Sensitive data is often shared in vulnerable places, soOklahoma’s potential breach of 3TB of FBI data isn’t especially shocking.

However, if we examinesecurities.ok.gov, it appears that the state is not using trusted machine identities, like TLS keys and certificates. Today, browsers are marking this site as ‘not secure,’because it is not using HTTPS encryption. Thismeansthatbrowsers do not trust the machineidentities used to identifyOklahoma’s servers.

In 2015, the Obama administration required all US federal agencies to use machine identities and HTTPS. But studies have shown that26% of public US federal government serversarestillnot using TLS keys and certificates or HTTPS. Unfortunately,using machine identities effectivelyis often so challenging that many organizations just don’t take the steps neededto keep their data and private communications safe.

Ultimately, until organizations automate the useand protectionof machine identities, we’ll continue to see exampleslike thisof machine identity failuresthat weakensecurity.”

Pravin Kothari, CEO atCipherCloud:

Pravin Kothari

“The trend is not our friend in 2019. Cyberattacks and data breaches continue to be announced at record rates. Administrative and management errors at theOklahomaSecurities Commission exposed 3 terabytes of data on their servers going back to 2012. To make it worse, most of the data across these many millions of files were not encrypted.

The moral of the story is the same. Automation is required to manage and check configurations and administration, both on-premise and in the cloud. Even if exposed accidentally if the data is encrypted, it is not by definition breached. Encryption must be used from the enterprise “edge.” All data available to online access should be encrypted, not only in the database but during transmission, middleware, API transit and in use. Tools like data loss prevention (DLP) can make sure sensitive data is *always* encrypted. Finally, identity access management (IAM) technologies such as 2-factor authentication (2FA) and single single-on (SSO) further harden your infrastructure and protect access to your systems and networks.

Yes, there are sophisticated advanced threats that are sometimes impossible to stop. But most of these victims like theOklahomaSecurities Commission are falling prey to attackers that are exploiting very basic weaknesses in their cyber defense.”

Matan Or-El, Co-Founder and CEO at Panorays:

“Data security is not necessarily always about protecting from attackers; quite often it’s about protecting against mistakes. The Oklahoma data leak is the latest in a long series of incidents in which sensitive data was exposed to the internet by mistake, where anyone could access it. By continuously monitoring the attack surface of an organization, one can learn a lot about the security and data hygiene practices of an organization. This is what is needed to detect mistakes and assess the overall cyber posture of enterprise data and third-party data protection practices.”

Sam Curry, CSO atCybereason:

“The agency needs a high level set of answers and updates. They can appear to be heroes or villains in this, but they don’t have the luxury of being victims. We the people need to know the root cause, how it won’t happen again and the contamination: who used the data, what they did with it and the implications on cases affected. The process of discovery isn’t comfortable for anyone, but the FBI and DOJ need to take the same medicine they frequently dispense in the name of justice. The rule of law requires or and we the people require it. Quis custodiet ipsos custodes: who watches the watchmen. Now is the chance to be a hero by being open and honest and organized and clear.”

Anurag Kahol, CTO atBitglass:

“What is especially troubling about this data leak is the seemingly blasé response from theOklahomaSecurities Commission. Leaving a database containing highly sensitive information unprotected and publicly accessible is careless and irresponsible; additionally, the agency is worsening the situation by failing to address the issue directly with the public. While all organizations need to defend their data, government agencies, in particular, must adhere to the highest of security standards – the type of information that they collect, store, and share demands it.

These kinds of leaks can have lasting consequences for all parties involved. To prevent such breaches, all organizations, including government agencies, must adopt modern security technologies. Dynamic identity and access management solutions, for instance, can verify users’ identities, detect potential intrusions, and enforce multi-factor authentication in a real-time, step-up fashion.”

Carl Wright, CCO atAttackIQ:

“Data leaks are often caused by gaps in security programs that can be easily prevented. TheOklahomaSecurities Commission’s leak of three terabytes of FBI data could have been avoided if they had visibility into the state of their defenses.

All organizations, including government agencies, must take a proactive approach to protecting sensitive data through continuous evaluation of their security controls, processes and people to uncover and remediate gaps that could be compromised by threat actors.”

Jonathan Bensen, Interim CISO and Senior Director of Product Management atBalbix:

“Leaking three terabytes of the FBI’s data due to leaving a server unsecured without a password is a critical error and indicates the need for theOklahomaSecurities Commission, as well as other government agencies, to strengthen their current security measures to ensure future breaches can be avoided in the first place.

Leaving a database containing such critical information unsecured is an elementary mistake for which there is no excuse. That said, organizations are increasingly struggling to maintain continuous visibility of all of their assets and successfully monitor the growing number of potential threats. Monitoring and analyzing the attack surface Analyzing and improving enterprise security posture is simply no longer a human scale problem. To best combat these threats, agencies must implement security tools that use machine learning and automation to monitor their enormous attack surfaces and vast IT asset landscape to proactively identify and address security vulnerabilities to mitigate the risk of future breaches.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}