{"id":5450,"date":"2019-12-20T12:38:46","date_gmt":"2019-12-20T12:38:46","guid":{"rendered":"https:\/\/hostnoc-revamp.branex.org\/blog\/?p=5450"},"modified":"2026-07-01T12:09:06","modified_gmt":"2026-07-01T12:09:06","slug":"data-breaches-2019","status":"publish","type":"post","link":"https:\/\/hostnoc-revamp.branex.org\/blog\/data-breaches-2019\/","title":{"rendered":"7 Key Takeaways From 7 Data Breaches In 2019 To Guide Your Cybersecurity Strategy In 2020"},"content":{"rendered":"<h2>7 Takeaways From Data Breaches In 2019<\/h2>\n<p>Here are seven key takeaways from data breaches in 2019.<\/p>\n<p>&nbsp;<\/p>\n<h2>1. Data Aggregators Will Be at Risk<\/h2>\n<p>Verifications.io, an email verification service provider, left its MongoDB database with more than <strong>808 million<\/strong> records exposed. This means that anyone with an internet connection can access their database. The records include personal information such as email addresses, date of birth, phone numbers and physical addresses of employees. Some records even contained information about IP addresses and business leads. This clearly shows that organizations that are storing and using large amounts of user data are a prime target for hackers.<\/p>\n<p>&nbsp;<\/p>\n<h2>2. Cloud Storage Will Be the New Target<\/h2>\n<p>As more and more businesses migrate to the cloud, we will see that the cloud will become the next target for cyber attackers. Add to that the increased risks of insider threat and you will start to think twice before migrating to the cloud. This was evident when sensitive data of more than <strong>100 million<\/strong> US citizens and <strong>6 million<\/strong> Canadian citizens was accessed by an employer of AWS. The data belongs to people who have applied for a Capital One credit card. What\u2019s even worse is the fact that the data also contains Social Security numbers and bank account details of secured credit card customers of Capital One.<\/p>\n<p>A misconfigured firewall might be the main reason behind it as it enabled attackers to execute privileged commands to access the cloud server, which was hosting the data. Although this might not have happened if your data were stored on the <a href=\"https:\/\/hostnoc-revamp.branex.org\/blog\/dedicated-server-hosting\/\">best dedicated servers<\/a> inside your premises, which is why some businesses are still reluctant to migrate all their data to the cloud.<\/p>\n<p>&nbsp;<\/p>\n<h2>3. You Can Pay the Price for Others\u2019 Actions<\/h2>\n<p>Back in June 2019, American Medical Collection fell victim to a massive data breach when they were collecting overdue payments from two of their biggest customers. They realized that some unauthorized users are trying to access sensitive data of millions of patients. More than <strong>20 million<\/strong> records were compromised (<strong>11.9 million <\/strong>belong to Quest Diagnostics and<strong> 7.7 million <\/strong>belong to LabCorp). After the breach, many customers sued the AMCA and they had to file for bankruptcy protection.<\/p>\n<p>This is the best example for companies that are unaware of third-party risks. It brings to light the fact that your business partners, stakeholders, vendors and third parties you are interacting with should all follow cybersecurity best practices; otherwise, you will have to pay the price for someone else&#8217;s mistakes. Irrespective of how good your cybersecurity defenses are, if your third-party vendors don\u2019t have the right security postures, your data is always at risk.<\/p>\n<p>&nbsp;<\/p>\n<h2>4. Insider Threats Are Real<\/h2>\n<p>This one is for those who take internal threats lightly. An insider at the Federal Emergency Management Agency shared personal details of more than <strong>2.3 million<\/strong> survivors of Hurricane Harvey, Irma and Maria and California wildfires with a third-party contractor. FEMA was only required to share the name, date of birth and last four digits of the Social Security number so the contractors can easily verify the eligible candidates for disaster relief, but they ended up sharing physical addresses and even banking details of those survivors. Due to the oversharing of information, the risk of identity theft and fraud increased drastically.<\/p>\n<p>&nbsp;<\/p>\n<h2>5. Compliance is Not Enough<\/h2>\n<p>Earl Enterprises, a parent company of multiple restaurants such as Planet Hollywood,\u00a0Buca di Beppo and Earl of Sandwich was attacked by unknown malware. The hackers were able to steal more than <strong>2 million<\/strong> payment card numbers from customers. The worst part, the data breach was underway for ten months from May 2018 till March 2019 and no one knew about it.<\/p>\n<p>This clearly shows that complying with PCI-DSS is not enough to protect you against data breaches. Such data breaches usually take advantage of back-end systems that are responsible for handling payment processing. This happens when your back-end server responsible for handling credit payments, is used for other unintended purposes.<\/p>\n<p>&nbsp;<\/p>\n<h2>6. Vulnerable Web Apps Are a Soft Target<\/h2>\n<p>Cybercriminals love to target web applications because they are vulnerable and can easily be compromised. The latest victim was Macy\u2019s website which was hacked in October 2019. Data related to people shopping on Macy\u2019s website such as name, address, payment card details, and phone numbers, was compromised. A group of Magecart attackers was successful in injecting malicious card skimming code on the checkout pages and was able to get their hands on the financial and sensitive personal data of users.<\/p>\n<p>Keeping this in view, online retailers should beef up their cybersecurity and fix all the loopholes in web applications. Many hackers implement tactics such as SQL injections, cross-site scripting, session management, and broken authentication and you should protect your web application against these attacks. Research conducted by Positive Technology on web app security paints a gloomy picture. According to the <u><a href=\"https:\/\/www.ptsecurity.com\/ww-en\/analytics\/web-application-vulnerabilities-statistics-2019\/\" target=\"_blank\" rel=\"nofollow noopener\">study<\/a><\/u>, <strong>33%<\/strong> of web applications have extremely poor security and the number of critical flaws in web applications almost <strong>tripled<\/strong> as compared to last year. It also showed that <strong>63%<\/strong> of attacks on E-commerce businesses targeted web services.<\/p>\n<p>&nbsp;<\/p>\n<h2>7. Supply Chain Attacks Will Grow<\/h2>\n<p>Hackers belonging to the Advanced Persistent Threat (APT) group used a combination of techniques such as phishing emails, penetration testing tools and a legitimate red team to compromise more than <strong>100 systems <\/strong>at Wipro. Wipro is one of the largest outsourcing firms in India. Cybercriminals did not stop there. They installed Trojans, which gave them remote access to these systems and used advanced tools to get access to a dozen of Wipro\u2019s customers\u2019 systems.<\/p>\n<p>With several Fortune 500 customers under its belt and the ability to provide access to other companies, it made them a lucrative target. Hackers knew that if they successfully intruded into their systems, they could also access data of other companies without having to target those companies directly with cyber-attacks.<\/p>\n<p>Which cybersecurity lesson did you learn from data breaches in 2019? Let us know in the comments section below.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>7 Takeaways From Data Breaches In 2019 Here are seven key takeaways from data breaches in 2019. &nbsp; 1. Data Aggregators Will Be at Risk Verifications.io,<span class=\"excerpt-hellip\"> [\u2026]<\/span><\/p>\n","protected":false},"author":3,"featured_media":7211,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"content-type":"","footnotes":""},"categories":[25],"tags":[57,93],"class_list":["post-5450","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security-monitoring","tag-cyber-security","tag-data"],"acf":[],"_links":{"self":[{"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/posts\/5450","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/comments?post=5450"}],"version-history":[{"count":3,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/posts\/5450\/revisions"}],"predecessor-version":[{"id":16324,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/posts\/5450\/revisions\/16324"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/media\/7211"}],"wp:attachment":[{"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/media?parent=5450"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/categories?post=5450"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hostnoc-revamp.branex.org\/blog\/wp-json\/wp\/v2\/tags?post=5450"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}