{"id":4153,"date":"2019-07-17T01:39:31","date_gmt":"2019-07-16T15:39:31","guid":{"rendered":"https:\/\/flippa.com\/blog\/data-breaches-big-and-small-what-can-we-learn\/"},"modified":"2024-03-26T20:06:28","modified_gmt":"2024-03-26T10:06:28","slug":"data-breaches-big-and-small-what-can-we-learn","status":"publish","type":"post","link":"https:\/\/flippa.com\/blog\/data-breaches-big-and-small-what-can-we-learn\/","title":{"rendered":"Data Breaches Big and Small: What Can We Learn?"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">If you own an online business or website, you need to actively take meaures to prevent a data breach. If you are considering <\/span><a href=\"https:\/\/www.flippa.com\/sell\"><span style=\"font-weight: 400;\">selling your online business<\/span><\/a><span style=\"font-weight: 400;\">, you should make sure your across the <\/span><a href=\"https:\/\/flippa.com\/blog\/category\/cybersecurity\/\"><span style=\"font-weight: 400;\">best security practices<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><span style=\"font-weight: 400;\">You&#8217;ve probably heard that those who don&#8217;t learn the lessons from history will repeat its mistakes. In the world of cyber-security, failing to heed that advice could have devastating effects <a href=\"https:\/\/www.getweave.com\/reputation-management\/\" target=\"_blank\" rel=\"noopener\">on your reputation and bottom line<\/a>.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That&#8217;s exactly what seems to have happened in 2018, which smashed all records <\/span><a href=\"https:\/\/www.darkreading.com\/attacks-breaches\/2017-smashed-worlds-records-for-most-data-breaches-exposed-information\/d\/d-id\/1330987\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">set in 2017<\/span><\/a><span style=\"font-weight: 400;\">, itself a jaw-dropping year for data breaches. Not only was there major chaos in terms of financial loss and damaged reputations for corporate giants, about 60% of reported breaches <\/span><a href=\"https:\/\/smallbiztrends.com\/2017\/01\/cyber-security-statistics-small-business.html\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">targeted small businesses<\/span><\/a><span style=\"font-weight: 400;\">. Those are the ones that rarely make the news.<\/span><\/p>\n<p><i><span style=\"font-weight: 400;\">Only 10 percent of cybercrimes are even reported, so imagine how the actual numbers add up.<\/span><\/i><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<h2><b>Digging into Breaches<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">What kind of malfeasance are we talking about? More than half of the leaks exposed customer information, and a whopping 46% or more leaked credit card and other financial records, including account numbers.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">One of the most dangerous times for small companies is during a merger. With so many larger companies buying up smaller businesses and online properties changing hands like it was a poker game, all parties involved need to take care they don\u2019t inadvertently <\/span><a href=\"https:\/\/flippa.com\/blog\/6-security-best-practices-leading-up-to-a-sale\/\"><span style=\"font-weight: 400;\">release privileged data in the process<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">What can you learn from big and small data breaches in order to prevent future grief?\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Without further ado, and in no particular order, here are a few of our \u201cfavorite\u201d breaches of 2018 and a handful of case studies to provide context and additional insight.<\/span><\/p>\n<h4><b>1. British Airways<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">From August 21 &#8211; September 5, hackers were able to access credit card payments of 380,000 travelers on both the airline website and mobile app.\u00a0<\/span><\/p>\n<h4><b>2. Orbitz<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">The travel aggregation portal experienced a database hack that exposed the credit card information of 880,000 travelers who booked through their website between January 1, 2016 and December 22, 2017. The hack wasn&#8217;t discovered until a year later.<\/span><\/p>\n<h4><b>3. SingHealth<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Singapore&#8217;s health care information system was hacked in an attempt to gain information about the Prime Minister&#8217;s health. In the process, the hackers exposed the patient histories, names, and addresses of 1.5 million other citizens.<\/span><\/p>\n<h4><b>4. T-Mobile<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">On August 20, 2018, the telecommunications giant was hacked via an API interface. Encrypted passwords and billing information of two million customers was exposed.\u00a0<\/span><\/p>\n<h4><b>5. Saks\/Lord and Taylor<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">On an undisclosed date (because no one is sure when) the credit card information of five million customers was accessed. The hacking group JokerStash claimed responsibility.<\/span><\/p>\n<h4><b>6. Timehop<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">From December 2017 to July 2018, names, addresses, and some phone numbers of 21 million Timehop members were left vulnerable due to insufficient authentication in their cloud computing environment.<\/span><\/p>\n<h4><b>7. Ticketfly<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">The online ticket seller was hacked by someone calling themselves &#8220;IsHaKdZ&#8221;. Personal information of 27 million customers was exposed.\u00a0<\/span><\/p>\n<h4><b>8. Facebook<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">It was a banner year for the social media giant. In addition to their problems with third-party data sales and congressional hearings, the accounts of 29 million users were exposed when hackers gained access tokens to their accounts. This occurred from July 2017 to September 2018.<\/span><\/p>\n<h4><b>9. Chegg<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Personal information, shipping addresses, user names, and passwords of 40 million customers were accessed by an &#8220;unauthorized person&#8221; between April 29, 2018 and September 19, 2018. The eCommerce website is an online retailer selling such brands as EasyBib.<\/span><\/p>\n<h4><b>10. Google+<\/b><\/h4>\n<p><span style=\"font-weight: 400;\">Personal information of 52.5 million account holders, including employers and job titles, was exposed due to a software glitch. This happened from March 2015 to 2018, and again from November 7 to November 13, 2018. Google has since shut down this platform for good.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">One of the most dangerous times for small companies is during a merger. With so many larger companies buying up smaller businesses and online properties changing hands like it was a poker game, all parties involved need to take care they don\u2019t inadvertently <\/span><a href=\"https:\/\/flippa.com\/blog\/6-security-best-practices-leading-up-to-a-sale\/\"><span style=\"font-weight: 400;\">release privileged data in the process<\/span><\/a><span style=\"font-weight: 400;\">. <\/span><\/p>\n<h2><b>Data Breach Case Studies<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">Behind each data breach or leak lies a personal story of a company that didn\u2019t pay attention to details. Taking a deeper dive into a few of them might more seriously demonstrate the gravity of what can happen when security isn\u2019t emphasized. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Does your business have the resources to withstand a million-dollar leak? How about $100,000? Most companies don&#8217;t. In fact, most small companies will go out of business within six months of a data breach, even without the negative publicity. Almost as bad as the difficulty you\u2019ll likely encounter trying to <\/span><a href=\"https:\/\/flippa.com\/blog\/preparing-to-plan-an-exit\/\"><span style=\"font-weight: 400;\">sell a website<\/span><\/a><span style=\"font-weight: 400;\"> with a data breach history.<\/span><\/p>\n<h3><b>Case Study: <\/b><a href=\"https:\/\/www.zdnet.com\/article\/another-data-leak-hits-india-aadhaar-biometric-database\/\" target=\"_blank\" rel=\"noopener\"><b>Aadhaar<\/b><\/a><\/h3>\n<p><b>Customers affected:<\/b><span style=\"font-weight: 400;\"> 1.1 billion<\/span><\/p>\n<p><b>What Happened?<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Aadhaar is the national database that contains all Indian government identification cards. The database not only holds names and ID numbers but also biometric information like iris scans and fingerprints. Although registration in this database isn&#8217;t mandatory, some 1.1 billion Indian residents are enrolled.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The system is used for everything from registering a sim card to obtaining government benefits. It was accessed via a leak from the state-owned utility company, Indane, allowing anyone with access to their website to download customer ID numbers. It was due to a vulnerable endpoint, something that is easily patched.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This isn&#8217;t the first time the Aadhaar system has had security issues. The company has suffered numerous breaches, and the government did nothing about this latest leak for weeks, calling it fake news when the public learned of the breach.\u00a0<\/span><\/p>\n<p><b>Key takeaway:<\/b><span style=\"font-weight: 400;\"> Digging deeper into the breach, we find that the problem can actually be traced to Indane, an Indian LPG gas company with vendor access to Aardhaar but which was leaking data through unsecured website endpoints. Whether Indane specialized in incompetence or simply tried to cut <\/span><a href=\"https:\/\/www.webhostingsecretrevealed.net\/website-hosting-cost\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">website hosting costs<\/span><\/a><span style=\"font-weight: 400;\"> related to development is unclear, but the bottom line lesson remains that a government database is only as secure as the vendors allowed to access it.\u00a0\u00a0<\/span><\/p>\n<h3><b>Case Study: <\/b><a href=\"https:\/\/techcrunch.com\/2018\/11\/30\/starwood-hotels-says-500-million-guest-records-stolen-in-massive-data-breach\/?guccounter=1\" target=\"_blank\" rel=\"noopener\"><b>Starwood Hotels<\/b><\/a><\/h3>\n<p><b>Customers affected:<\/b><span style=\"font-weight: 400;\"> 500 million records<\/span><\/p>\n<p><b>What happened?<\/b><\/p>\n<p><span style=\"font-weight: 400;\">As we can see from <\/span><a href=\"https:\/\/www.calyptix.com\/top-threats\/small-business-cyber-attacks-that-stole-thousands\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">numerous cases<\/span><\/a><span style=\"font-weight: 400;\">, hotels are a prime target for hackers and breaches. They hold credit card information for reservations and the dates that people will be away from their homes. This is an open invitation to various means of theft.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">In the case of Starwood, parent company of the Marriott chain, the guest database experienced &#8220;unauthorized access&#8221; that was only discovered on September 10, 2018, but the leaks may have been ongoing as far back as 2014. The database contained not only guest names, addresses, and phone numbers, but credit card information, reservation dates, and passport numbers. What a treasure trove for thieves!<\/span><\/p>\n<p><b>Key takeaway:<\/b><span style=\"font-weight: 400;\"> Starwood failed to implement even basic security strategies. Though the company has been short on details, it seems hackers were basically living on their servers. One method of entry was infiltration of a POS system. For a nominal fee, the <\/span><a href=\"https:\/\/privacycanada.net\/best-vpn-canada\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">best VPNs available today<\/span><\/a><span style=\"font-weight: 400;\"> would have encrypted their POS network, ensuring that any leaked customer data stayed private. Nota bene: avoid using free VPNs\u00a0<em>at all costs<\/em> <a href=\"https:\/\/www.techulator.com\/resources\/18785-dangers-and-security-risks-of-using-a-free-vpn\" target=\"_blank\" rel=\"noopener\">as they are fraught with security holes<\/a>.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Additionally, in the case of Starwood, the guest database was not protected until November 2018, two months after the breach was discovered. Security suite software and a robust firewall might have prevented THIS unauthorized ingress. Since the company has hotels all over Europe, it&#8217;s also left itself open to potential fines of up to 4% of gross revenues <\/span><a href=\"https:\/\/www.tripwire.com\/state-of-security\/security-data-protection\/data-breach-fine\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">under the new GDPR regulations<\/span><\/a><span style=\"font-weight: 400;\">.\u00a0<\/span><\/p>\n<h3><b>Case Study: PATCO Construction\u00a0<\/b><\/h3>\n<p><b>Customers affected:<\/b><span style=\"font-weight: 400;\"> The company<\/span><\/p>\n<p><b>What happened?<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Trojan Horse virus was slipped into the company&#8217;s system, allowing thieves to access their corporate account and drain it to the tune of just over half a million dollars in less than a week. The company was able to recoup just under $200,000 of the money, though they initially failed in a lawsuit against the bank that handles ACH transfers, which they believe didn&#8217;t use reasonable security during wire transfers. They won on appeal, but still had to pay interest on hundreds of thousands in overdraft fees.<\/span><\/p>\n<p><b>Key takeaway:<\/b><span style=\"font-weight: 400;\"> Before you conduct any business electronically, make sure that the bank and any third-parties involved in conducting transfers and other financial business use adequate security. You should also ask how they handle data breaches in the case that any occur.<\/span><\/p>\n<h2><b>How to Protect Yourself and Customers<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">What happened to Volunteer Voyages demonstrates that small business owners don&#8217;t have much recourse after the fact. If the banks won&#8217;t reimburse you and police have <\/span><a href=\"https:\/\/metro.co.uk\/2018\/04\/11\/cyber-criminals-earn-1-4-million-year-rarely-caught-7457312\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">trouble catching cyber criminals<\/span><\/a><span style=\"font-weight: 400;\">, what&#8217;s left?<\/span><\/p>\n<p><span style=\"font-weight: 400;\">We\u2019ve touched on the idea that a data breach can make it hard to <\/span><a href=\"https:\/\/www.flippa.com\/sell\"><span style=\"font-weight: 400;\">sell an online business<\/span><\/a><span style=\"font-weight: 400;\">. At the very least, expect it to drive <\/span><a href=\"https:\/\/flippa.com\/blog\/what-sellers-need-to-know-about-buyers-valuations\/\"><span style=\"font-weight: 400;\">down the valuation<\/span><\/a><span style=\"font-weight: 400;\"> to the point that your profit potential is downright depressing. Consider the following steps to boost site security for a reasonable expense. The money spent will likely be far less than the financial hit you\u2019ll take in the event of a data leak or breach.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The most important thing you can do is learn about data protection, and make sure that all of your employees and subcontractors understand the process and necessity. The second step is to perform a thorough assessment of where your network stands on cybersecurity. If you don&#8217;t have qualified personnel on-staff, outsource an audit to a reputable security consulting firm. However, the knowledge you gain is meaningless unless you use it, which is step three.\u00a0<\/span><\/p>\n<h4><span style=\"font-weight: 400;\">The most relevant <\/span><a href=\"https:\/\/www.dataversity.net\/how-ai-helps-organizational-cybersecurity-in-2019\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">data security measures<\/span><\/a><span style=\"font-weight: 400;\"> you can employ are:<\/span><\/h4>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Install a firewall<\/span><\/li>\n<\/ul>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Buy security tools like an anti-virus software that are made especially for small businesses.<\/span><\/li>\n<\/ul>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Evaluate and redesign security protocols to meet today&#8217;s threats.<\/span><\/li>\n<\/ul>\n<ul>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Use a VPN with high-grade encryption and privacy protection on every network and connected device used by you, your employees, and vendors.<\/span><\/li>\n<li style=\"font-weight: 400;\"><span style=\"font-weight: 400;\">Educate staff about passwords.\u00a0<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">With a full <\/span><a href=\"https:\/\/www.tracesecurity.com\/blog\/articles\/81-of-company-data-breaches-due-to-poor-passwords\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">81% of breaches<\/span><\/a><span style=\"font-weight: 400;\"> traced to weak or repetitive passwords, simply tending to this one area could greatly reduce your exposure to hacker mischief. Today\u2019s acceptable passwords should be long and convoluted to evade ever-stronger cracking techniques. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Rather than try to manage passwords with faulty human brainpower, organizations should use password management software and <\/span><a href=\"https:\/\/www.interserver.net\/blog\/two-factor-authentication-a-security-must-have\/\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">two-factor authentication<\/span><\/a><span style=\"font-weight: 400;\"> (2FA). This puts your computer to work creating and managing company passwords and forces a two-step login process that requires a second key generated to a different device (like your smartphone) in addition to the one you\u2019re trying to log into.\u00a0\u00a0\u00a0<\/span><\/p>\n<h2><b>Final Thoughts<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">With a full <\/span><a href=\"https:\/\/www.tracesecurity.com\/blog\/articles\/81-of-company-data-breaches-due-to-poor-passwords\" target=\"_blank\" rel=\"noopener\"><span style=\"font-weight: 400;\">81% of breaches<\/span><\/a><span style=\"font-weight: 400;\"> traced to weak or repetitive passwords, simply tending to this one area could greatly reduce your exposure to hacker mischief. Today\u2019s acceptable passwords should be long and convoluted to evade ever-stronger cracking techniques.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Don&#8217;t allow your company to become another statistic. You can avoid being the next hard-luck tech story by taking the offensive when it comes to data protection.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Effective, enterprise-wide employee training, comprehensive security solutions, and automation are all best practices to incorporate without breaking your budget. Start today because tomorrow might be the day you get hacked.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>You&#8217;ve probably heard that those who don&#8217;t learn the lessons from history will repeat its mistakes. In the world of cyber-security, failing to heed that advice could have devastating effects on your reputation and bottom line.<br \/>\nThat&#8217;s exactly what seems to have happened in 2018, which smashed all records set in 2017, itself a jaw-dropping year for data breaches.<\/p>\n","protected":false},"author":37,"featured_media":1535,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_et_pb_use_builder":"","_et_pb_old_content":"","_et_gb_content_width":"","content-type":"","inline_featured_image":false,"footnotes":""},"categories":[34,297],"tags":[],"dipi_cpt_category":[],"acf":[],"_links":{"self":[{"href":"https:\/\/flippa.com\/blog\/wp-json\/wp\/v2\/posts\/4153"}],"collection":[{"href":"https:\/\/flippa.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/flippa.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/flippa.com\/blog\/wp-json\/wp\/v2\/users\/37"}],"replies":[{"embeddable":true,"href":"https:\/\/flippa.com\/blog\/wp-json\/wp\/v2\/comments?post=4153"}],"version-history":[{"count":1,"href":"https:\/\/flippa.com\/blog\/wp-json\/wp\/v2\/posts\/4153\/revisions"}],"predecessor-version":[{"id":26183,"href":"https:\/\/flippa.com\/blog\/wp-json\/wp\/v2\/posts\/4153\/revisions\/26183"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/flippa.com\/blog\/wp-json\/wp\/v2\/media\/1535"}],"wp:attachment":[{"href":"https:\/\/flippa.com\/blog\/wp-json\/wp\/v2\/media?parent=4153"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/flippa.com\/blog\/wp-json\/wp\/v2\/categories?post=4153"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/flippa.com\/blog\/wp-json\/wp\/v2\/tags?post=4153"},{"taxonomy":"dipi_cpt_category","embeddable":true,"href":"https:\/\/flippa.com\/blog\/wp-json\/wp\/v2\/dipi_cpt_category?post=4153"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}