{"id":2169,"date":"2023-12-08T22:27:00","date_gmt":"2023-12-08T22:27:00","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/apple-25b-records-exposed-surge-data-breaches"},"modified":"2023-12-08T22:27:00","modified_gmt":"2023-12-08T22:27:00","slug":"apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2023\/12\/08\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches\/","title":{"rendered":"Apple: 2.5B Records Exposed, Marking Staggering Surge in Data Breaches"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt8b08ca011a9050e7\/657385b4a8411404074a53db\/compromise_YuRi_Photolife_shutterstock.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">An Apple-commissioned report this week has highlighted once again why analysts have long recommended the use of end-to-end encryption to protect sensitive data against theft and misuse.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The report is based on an independent study of publicly reported breach data that a professor at the Massachusetts Institute of Technology conducted for the tech giant. It showed that ransomware campaigns and attacks on trusted technology vendors contributed to a sharp increase in data breaches and the number of records compromised in these breaches over the past two years.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Billions of Compromised Records<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">In 2021 and 2022, data breaches exposed a staggering 2.6 billion personal records \u2014 some 1.5 billion of them last year alone. That number will likely be even higher in 2023 if trends so far this year are any indication.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The total number of data breaches in the first nine months of 2023 alone is already 20% higher than the total for all of 2022. Corporate and institutional breaches exposed sensitive records belonging to some 360 million people through the end of August 2023.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Data from IBM&#8217;s 2023 Cost of a Data Breach and a separate Forrester research study, quoted in the <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.apple.com\/newsroom\/2023\/12\/report-2-point-6-billion-records-compromised-by-data-breaches-in-past-two-years\/\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Apple report<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, showed that 95% of organizations that experienced a recent breach had experienced at least one other previous breach. Seventy-five percent had experienced at least one data compromise incident in the previous 12 months.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Ransomware and vendor attacks contributed in a major way to the sharp increase in data breaches and resulting compromise of sensitive records. The number of ransomware attacks in the first nine months of 2023, for instance, was 70% higher than the same period in 2022. Some 50% more organizations reported experiencing a ransomware attack in the first half of 2023 compared to 2022, and the number appears to be trending even higher in the back half of the year.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The study also found that 98% of organizations currently have a relationship with a technology vendor that has experienced at least one recent data breach. Examples in the report of breaches involving vendors and vendor technologies that had an impact on a broad number of organizations and individuals include ones at <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/massive-goanywhere-rce-exploit\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Fortra<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/3cx-breach-cyberattackers-second-stage-backdoor\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">3CX<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/software-vendors-may-face-greater-liability-in-wake-of-moveit-lawsuit\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Progress Software<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, and <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/endpoint-security\/chinese-apt-cracks-microsoft-outlook-emails-government-agencies\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">Microsoft<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;This rising threat to consumer data is a consequence of the growing amount of unencrypted personal data that corporations and other organizations collect and store, particularly in the cloud,&#8221; Apple said in its report. &#8220;Organizations can reduce the likelihood of hackers using or selling their consumer data by encrypting data stored in their networks, making it only readable by those who have the key to decrypt it.&#8221;<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">Breaches Heighten Need for Encryption<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The need for organizations to encrypt data \u2014 while it is in use, in transit, and at rest \u2014 is a long recognized issue. Few dispute the effectiveness of data encryption in protecting stolen data against misuse and in rendering stolen data useless to those who steal it. Several regulations and industry mandates \u2014 such as PCI DSS, HIPAA, GLBA, and the EU&#8217;s GDPR \u2014 require or recommend encryption, especially for stored data and for data in transit.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Encryption stands as a formidable defense against unauthorized access to sensitive information,&#8221; says Demi Ben-Ari, CTO and co-founder of Panorays. Encryption makes data unreadable to unauthorized parties, greatly reducing the risk of data exposure even in the event of a data breach, he says. &#8220;The strength of encryption in making stolen data useless highlights its crucial role as a basic protective measure.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Even so, many organizations \u2014 as Apple&#8217;s study and that from others suggest \u2014 have continued to drag their feet on <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/technology-firms-delivering-much-sought-encryption-in-use\" target=\"_blank\" class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" rel=\"noopener\">data encryption<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> for a medley of reasons. These include the perceived complexity of encryption systems, the potential cost involved, concerns over performance impacts, and a lack of in-house expertise to manage encrypted systems effectively, says Craig Jones, vice president of security operations at Ontinue.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\">A Moderate-to-Difficult Challenge<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">&#8220;Implementing end-to-end encryption can range from moderately difficult to very challenging, depending on the organization&#8217;s size, existing infrastructure, and the types of data being encrypted,&#8221; Jones says. &#8220;It requires careful planning, investment in the right tools and technologies, and often a cultural shift in how data security is perceived and managed.&#8221; Often organization can run into problems related to key management, which is a major issue because losing keys can mean losing access to data permanently. Organizations also need to consider potential performance impacts related to encryption and ensure compatibility with existing systems and formats, Jones says.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The rapid and growing adoption of cloud computing is another factor that organizations need to factor in when considering encryption plans. Data that Apple&#8217;s study reviewed showed that 80% of breaches involved data stored in the cloud. Encrypting such data can be more challenging than encrypting data on premises.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Organizations that have good security practices usually have full visibility over their legacy networks, says Ken Dunham, director of cyber threats at Qualys. &#8220;But when they migrate to cloud, they often lose the ability to have similar controls, visibility, management, and operations to address the pros and cons of encryption in action.&#8221; The need for organizations to maintain a hybrid network of legacy and modern technologies while they complete digital transformation initiatives adds another layer of complexity, he adds.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">One mistake organizations can make is relying solely on cloud providers for data encryption, Ben-Ari says: &#8220;While cloud providers offer valuable security measures, organizations must assume direct responsibility for encrypting their data.&#8221;<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">He recommends that organizations prioritize technologies that are user-friendly to facilitate smooth integration; phased implementations can further minimize disruption to daily operations.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">And finally, he recommends that organizations take advantage of the shared responsibility model that many cloud providers and leading SaaS vendors offer that allow organizations to give users many advanced encryption features at the click of a button.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/apple-25b-records-exposed-surge-data-breaches\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An Apple-commissioned report this week has highlighted once again why<\/p>\n","protected":false},"author":12,"featured_media":2170,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-2169","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches.jpg?fit=1000%2C587&ssl=1",1000,587,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches.jpg?fit=300%2C176&ssl=1",300,176,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches.jpg?fit=640%2C376&ssl=1",640,376,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches.jpg?fit=640%2C376&ssl=1",640,376,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches.jpg?fit=1000%2C587&ssl=1",1000,587,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches.jpg?fit=1000%2C587&ssl=1",1000,587,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches.jpg?fit=1000%2C587&ssl=1",1000,587,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2023\/12\/apple-2-5b-records-exposed-marking-staggering-surge-in-data-breaches.jpg?fit=1000%2C587&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2169","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=2169"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/2169\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/2170"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=2169"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=2169"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=2169"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}