With the advancements in technological approach, the information security level of organizations and businesses should reach a particular standard. Instead of this present year, there have been more security and data breaches than one would care to admit. From the start of 2019, many notable organizations have sustained major cyber-leaks, data breaches, and information theft including the financial and operational details of their businesses.
It seems like cybercriminals and illicit hackers are playing the game at the highest possible level, where the information security firms and organizations are not even cutting it close.
Some organizations proved to be dafter than the others, while some became aware of the attack at an early stage and were able to do something about it, the others didn’t even know about the intrusion in their security systems until after the damage was done.
Now, we will be discussing some of the most technical cyber-hacks of 2019 and try to find the reason that led to these attacks in the first place;
- Toyota
The biggest automobile giant in the world sustained a heavy blow in terms of data breach over a total of 8 of their subsidiaries. February and March were the months where two separate data breaches set in and affected the automobile giant in a targeted data breach. According to a Toyota company representative, some facts about the breach came into light, such as only the customer's personal information was affected by the breach leaving the employee's data and the credit card information of the customers intact.
A total of 3.1 million customers of Toyota and Lexus were affected by the data breach, Toyota announced in a press release that they are willing to implement the necessary security changes to make sure that something like this never happens again, however, the exact timeline of the implementation was not revealed.
- Evite
Evite a social media platform was hacked in February 2019 of a series of attacks now confirmed as unauthorized access to an inactive data storage facility. Multiple items were hacked and taken completely off of their mainframe systems such as the customer's username, passwords, date of birth mailing address, and others, etc. However, no customers were targeted in terms of their financial information but only their data. A total of 10 million users were affected in this security breach.
- Canva
Canva is an Australian company that offers online graphics services to the customers, in the February of 2019, the company sustained a major data breach affecting nearly 139 million users. The company first detected a data breach onto their networks and was abruptly aware of the situation, the company started to practice several security measures to nullify the attack, but by the time they could do something the hackers had already done what they came to do.
Hackers stole valuable user data, including names, passwords, usernames, country names, User data about their cities, and dedicated URL's as well. For those users who didn't use the social login, their passwords were encrypted by bcrypt and stored in the form of the hashes. Even such security measures were disarmed by the attackers, and they held these passwords hostage for a good amount of time before reaching media and claiming responsibility for the attack.
Although later on, Canva helped the users reclaim their accounts through new passwords generated by a more secure encryption entity, the original motive of the current cyber-attack could not be determined. The attack is believed to be targeted and a potential try of the attackers to stole valuable data so they could sell it over illegal forums.
- American Medical Collection Agency (AMCA).
Between February 2018 and March 2019, the AMCA sustained a heavy blow in terms of important user data being take away. The data stolen included the names, mailing addresses, stoical security number, bank details, and other essentials as well. Many organizations were infected, given the ramifications of the recent data breach, including the LabCorp and the Optium360.
It was too late before the initiation of breach could be discovered; it first became observable when almost the credit card details of 200,000 patients were made available for sale over the darknet. The data that was stolen and was made available for sale could be traced back to Optium360 and the LabCorp.
The details of the breach could still not be properly worked out, but it was found that over 20 million patients sustained a severe blow to their personal and financial data security. LabCorp has initiated a free two-year credit card monitoring and identity protection services to the users whose social security details were leaked during the severe data breach. Now it can be made evident that how severe the impact of unattended data and security breaches can be for the society and how long an organization can sustain the cyber attacks or continue to work while not doing anything to fight against them.
- Capital One
At the very beginning of March 2019, Capital One sustained a severe data breach among its security networks. The personal information and sensitive user data were made the target. The illicit hackers stole multiple assets such as the names, addresses, date of births, credit information and other crucial details including the social security variances.
A through the speculation of the attack was conducted, and the findings were not as near amusing, a server misconfiguration was held accountable for the daunting series of attacks where crucial user data was stolen. Nearly 106 million users were severely affected by the breach, and important data was either lost or held captive by the hackers.
2019 has been a tough year, fairly considering the number of cyber-attacks sustained by verily profound and intricate organizations. A common denominator in all the attacks that occurred was a general lack of system monitoring and consistently upgrading the security measures to the latest standards. If correct procedures are not adopted by the organizations to protect their resources, then more attacks are imminent in the future.
But if a strong strategy to overcome the attacks and point them out even before they happen, then there is a chance that these attacks can be stopped effectively and important resources saved from the cybercriminals.
