Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - News & Analysis - Swedentransport Agency Data Leak
News & Analysis

Swedentransport Agency Data Leak

ISBuzz TeamBy ISBuzz TeamJuly 25, 2017Updated:December 4, 20246 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

News broke yesterday that the Swedish transport agency suffered a major data breach, and then subsequently attempted to cover it up. Following the outsourcing of its databases and networks to, every conceivable top secret database was leaked: fighter pilots, SEAL team operators, police suspects, people under witness relocation. IT security experts commented below.

 Ken Spinner, VP of Global Field Engineering at Varonis:

“IT outsourcing and lax data security practice strike again: this time in Sweden, compromising government documents, sensitive personally identifiable information on citizen and military data, criminal records – even details on confidential witness protection programs.
We see this time and time again, and what have we learned?  Nobody can be exempt from data privacy laws and security policies that are put in place to protect citizen information.

Exposing this type of data – and this much of it – is a huge red flag: not only can critical data and research be compromised, but personal data can be leveraged to breach more secure systems.  Not to mention the potential fallout from witness protection information being publicly available, details on secret military units, and other data that can be damaging to a government and its citizens.

The best way to reduce the risk of deliberate or accidental data exposure is to limit access to those who need it the most – keeping sensitive data locked down – and to monitor data access so that when something suspicious happens, you can catch it before it turns into global headlines.

It’s often the act of cutting corners on data privacy policy enforcement, simple mistakes, or generally bad security habits that end up causing breaches – rather than a nefarious attack.  Limiting data access and taking a privacy-by-design approach goes a long way in proactively protecting critical data.  Perhaps most importantly, government agencies – and any organisation that processes and stores sensitive data – need to establish and uphold strong cybersecurity and data protection practices: not only for internal use, but for all third party contractors as well.

By strengthening data protection practices — adopting a least privilege approach and monitoring user behaviour — organisations (and indeed, governments) will not only bolster their cybersecurity defenses, but they’ll be more protected against data leaks, insider threats and sophisticated cyberattacks as well.”

Itsik Mantin, Director of Research at Imperva: 

“With the flourish in AI technologies that rely heavily on enormous volumes of data for making better decisions, securing it becomes a huge challenge for security officers. More users rely in their work on access to more data, and they need this access most of the time. With dynamic data access needs of users that are hard to predict, an attempt to harness the traditional approach of building least-privilege access control system that grants each user with access to the data he really needs, is as futile as herding cats.

Like many of the breaches, this data breach is not the result of hackers penetrating the organisation and stealing data from it, but involves according to what was published, third-parties having access to highly sensitive database that could steal it, and an employee that accidentally sent this database to long list of unauthorized recipients.

The fact that the database had left the transport agency and reached uncontrolled devices, leaves only little optimism for who can have a copy now. The ability to contain such breach depends heavily on the time it takes the organisation to detect the breach and reach the uncontrolled devices to which the data arrived. However, the problem with these breaches involving insiders and third-parties is that no malware is involved and no penetration to the organisation happens, and leaving security mechanisms like firewalls and anti-viruses totally blind to them. In order to obtain quick detection that may facilitate containment of such breaches, security controls should focus on access to business critical data and users private data, monitor access, comparing access patterns to the “regular” activity, and detect anomalous data access.”

Kyle Wilhoit, Senior Cybersecurity Threat Researcher at DomainTools: 

“Until organizations learn basic compensating security controls, this will continue, and likely get even worse. Things as simple as two factor authentication, and not sharing the same password across multiple accounts could be instrumental in stopping this kind of breach. Cybercriminals will use a data breach of this size to create a healthy pipeline of future cybercrimes, beginning after the records have been sold on the dark web; This could be used to facilitate identity or banking fraud, as well as to send targeted phishing emails, leading to malware. To try and cover this up is totally unacceptable, and represents yet another example of both nation-states organizations not taking cybercrime-the key word being ‘crime’ – seriously.”

Marco Cova, Senior Security Eesearcher at Lastline: 

“This attack, and the subsequent cover-up attempt by the Swedish transport authorities shows the importance of both protection from data breaches, and transparency in the event when they occur. Episodes like this show that data leaks may occur because of ‘simple’ screw-ups rather than because of attacks. Organizations should limit the amount of data they collect and store to the minimum required to carry out their mission; they should further identify the pieces of data that have different security or privacy levels, and ensure that they are shared, both internally and with authorized third-parties, on a strict need basis. The fact that these details have been carelessly shared puts the individuals concerned at particular risk of falling victim to further cybercrime, making the attempted cover-up particularly disturbing. Governments and the organizations of all kinds need to develop a more ethical response to data breaches, which does not include attempts to save their own skin and instead focuses on damage control for the victims.”

Javvad Malik, Security Advocate at AlienVault:

Javvad Malik“The leak itself is indicative of poor security practises, with the entire database being emailed in clear text. It also highlights challenges in securing third party supply chains. Furthermore, the issue was compounded by an apparent lack of security controls that should have been in place to detect such a leak.

It also gives privacy advocates more reason to be concerned where governments are seeking to expand surveillance powers, as this breach shows, governments are incapable of keeping their biggest of secrets secure.”

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Visual data is the blind spot in enterprise security: that’s about to change

May 4, 20267 Mins Read

Making stolen data worthless: why security must start with the data

March 30, 20265 Mins Read

Meta’s Smart Glasses Privacy Scandal Expands After Sama Credentials Found on the Dark Web

March 10, 20264 Mins Read
ISB-Bora-Side-Bar

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}