{"id":6580,"date":"2024-12-11T09:50:59","date_gmt":"2024-12-11T15:50:59","guid":{"rendered":"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/cybersecurity-lessons-from-3-public-breaches"},"modified":"2024-12-11T09:50:59","modified_gmt":"2024-12-11T15:50:59","slug":"cybersecurity-lessons-from-3-public-breaches","status":"publish","type":"post","link":"https:\/\/ddi.mohflo.net\/index.php\/2024\/12\/11\/cybersecurity-lessons-from-3-public-breaches\/","title":{"rendered":"Cybersecurity Lessons From 3 Public Breaches"},"content":{"rendered":"<div class=\"media_block\"><a href=\"https:\/\/i0.wp.com\/eu-images.contentstack.com\/v3\/assets\/blt6d90778a997de1cd\/blt0b5bdae5ee8f5433\/6758b8c00203db1c6aca40ec\/sotp-Alfonso_Fabio_Iozzino-alamy.jpg?ssl=1\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/cybersecurity-lessons-from-3-public-breaches.jpg?w=640&#038;ssl=1\" class=\"media_thumbnail\"><\/a><\/div>\n<div><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/cybersecurity-lessons-from-3-public-breaches.jpg?w=640&#038;ssl=1\" class=\"ff-og-image-inserted\"><\/div>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">COMMENTARY<\/span><\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The statistics paint a clear picture \u2014 over 9,000 cyber incidents were <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.itgovernance.co.uk\/blog\/global-data-breaches-and-cyber-attacks-in-2024\">reported<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in just the first half of 2024, translating to nearly one new attack every single hour.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">This escalating risk has pushed cybersecurity to the forefront of business strategy. <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.accenture.com\/content\/dam\/accenture\/final\/accenture-com\/document-2\/Accenture-The-Cyber-Resilient-CEO-Final.pdf\">According to a study by Accenture<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">, 96% of CEOs identified security as essential to their company&#8217;s growth, prompting continuous investment. Yet, despite these efforts, 74% of them expressed concern about their ability to effectively mitigate or withstand cyberattacks due to the increasing complexity of threats. High-profile security incidents provide examples of common vulnerabilities and highlight strategies for businesses to avoid sophisticated attacks.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"1. The Importance of Password Policy\">1. The Importance of Password Policy<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Maintaining a strong password policy is essential for all organizations. A typical policy should mandate a minimum length of eight (better 12) characters, combining letters, numbers, and special symbols. Regularly updating passwords is also a widely accepted practice.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">However, experience has shown us that guideline compliance is only one part of the equation. At Sigma Software Group, we emphasize the importance of thoughtful password creation, encouraging our team to steer clear of easily guessable patterns, like &#8220;Spring2024!&#8221; or &#8220;Summer2024!&#8221; This proactive mindset helps foster a culture of security awareness, which is crucial for preventing password breaches \u2014 an alarming trend that affects individuals and organizations alike.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">The damage:<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> A striking example of this vulnerability occurred in 2020 when Dutch ethical hacker Victor Gevers <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.bbc.com\/news\/technology-55337192\">guessed<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> then-candidate Donald Trump&#8217;s Twitter password on his fifth attempt. The password, &#8220;maga2020!&#8221; \u2014 a nod to Trump&#8217;s campaign slogan &#8220;Make America Great Again&#8221; \u2014 highlighted a significant security gap. Gevers clarified that his intention wasn&#8217;t to steal sensitive information but to raise awareness about online security risks. He advocates for stronger online security measures, including complex password protocols, two-factor authentication, and effective password management.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">The lesson:<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> By adopting a comprehensive approach to password protection, organizations can significantly mitigate risks and bolster their overall cybersecurity posture.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"2. Multifactor Authentication Hits Its Limits\">2. Multifactor Authentication Hits Its Limits<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Multifactor authentication (MFA) was once hailed as a major leap forward in security. By requiring additional layers of verification \u2014 such as passwords, hardware tokens, or biometric scans \u2014 MFA significantly raises the barrier for unauthorized access. However, while MFA adds protection, it is far from infallible.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Consider a scenario where a user loses their phone and laptop simultaneously. Regaining access to critical accounts often involves contacting IT support to verify their identity \u2014 an approach that seems secure but has its flaws, as the gaming giant EA Games found out the hard way.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">The damage:<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> In July 2021, EA Games <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.vice.com\/en\/article\/how-ea-games-was-hacked-slack\/\">suffered<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> a significant breach due to a clever MFA bypass. Hackers used stolen cookies containing an employee&#8217;s login credentials to infiltrate the company&#8217;s Slack channel. Impersonating the employee, they contacted IT support, claiming they had lost their phone at a party and needed a new multifactor authentication token. This <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/application-security\/attacker-social-engineered-backdoor-code-into-xz-utils\">social engineering<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> tactic worked, granting them access to EA&#8217;s corporate network.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The outcome was disastrous. The hackers stole 780GB of sensitive data, including the source code for FIFA 21, the Frostbite engine, and various internal development tools. This data has since been sold on underground forums.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">The lesson:<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> While EA confirmed that no player data was compromised, the incident exposed the vulnerabilities in its security protocols. EA has since acknowledged the gravity of the breach and has been bolstering its defenses to prevent future occurrences.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"3. Humans Are Only Human\">3. Humans Are Only Human<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Even the most advanced security systems are not immune to vulnerabilities. A seemingly minor mistake can introduce significant risks, regardless of the sophistication of tools or protocols in place.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">The damage:<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> A pertinent example comes from Estonia, where engineers implemented best practices while developing national digital identity cards. Unfortunately, errors during this process resulted in <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.darkreading.com\/endpoint-security\/digital-identity-makes-headway-around-the-world\">critical security flaws<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> affecting over 750,000 cardholders.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">These issues primarily stemmed from the card manufacturer, Gemalto. Between 2014 and 2017, Estonian authorities uncovered a major vulnerability in the cryptographic library responsible for private key generation. This flaw created a potential pathway for identity theft, yet Gemalto failed to promptly inform the government. Consequently, Estonian officials had to take emergency measures, suspending the use of digital certificates on the affected cards. This situation led to litigation, resulting in a settlement where Gemalto agreed to pay <\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><a class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_link\" target=\"_blank\" href=\"https:\/\/www.politsei.ee\/en\/news\/a-settlement-agreement-has-been-signed-between-the-police-and-border-guard-board-and-gemalto-ag-tallinn-2021\">\u20ac2.2 million<\/a><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> in compensation.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Additional vulnerabilities arose from ID card management practices. Gemalto generated private keys outside the secure chip and reused the same key across multiple cardholders. This oversight allowed for potential impersonation \u2014 although, fortunately, no actual identity misuse was reported. Estonian experts quickly identified and rectified the issue, ensuring that the threat to digital identities remained theoretical.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"><span class=\"ContentText-BodyTextChunk ContentText-BodyTextChunk_bold\">The lesson:<\/span><\/span><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\"> A robust security framework is insufficient on its own; the human element must also be addressed. To mitigate the potential risks associated with human error, organizations should implement strategies that enhance oversight and resilience. This includes providing comprehensive staff training to elevate security awareness, conducting regular security audits of both internal systems and third-party providers, and establishing clear security protocols that empower employees to recognize and address potential security issues.<\/span><\/p>\n<h2 class=\"ContentText ContentText_variant_h2 ContentText_align_left\" data-testid=\"content-text\" id=\"In a Nutshell\">In a Nutshell<\/h2>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">A recurring theme in these case studies is the impact of human error. As cybersecurity becomes more complex, shortcuts \u2014 such as using simple passwords or bypassing MFA \u2014 often create vulnerabilities that attackers exploit.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">The primary and biggest challenge in cybersecurity lies in striking a balance between implementing robust security controls and maintaining user convenience.<\/span><\/p>\n<p class=\"ContentParagraph ContentParagraph_align_left\" data-testid=\"content-paragraph\"><span class=\"ContentText ContentText_variant_bodyNormal\" data-testid=\"content-text\">Cybersecurity is an ongoing process, not a one-time fix. No single tool can offer complete protection, so a multilayered defense approach, where measures complement each other, is the most effective strategy to mitigate risks and stay ahead of evolving threats.<\/span><\/p>\n<p><a href=\"https:\/\/www.darkreading.com\/cyberattacks-data-breaches\/cybersecurity-lessons-from-3-public-breaches\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>COMMENTARY The statistics paint a clear picture \u2014 over 9,000<\/p>\n","protected":false},"author":12,"featured_media":6581,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[1],"tags":[809],"class_list":["post-6580","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-dark-reading"],"featured_image_urls":{"full":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/cybersecurity-lessons-from-3-public-breaches-scaled.jpg?fit=2560%2C1440&ssl=1",2560,1440,false],"thumbnail":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/cybersecurity-lessons-from-3-public-breaches-scaled.jpg?resize=150%2C150&ssl=1",150,150,true],"medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/cybersecurity-lessons-from-3-public-breaches-scaled.jpg?fit=300%2C169&ssl=1",300,169,true],"medium_large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/cybersecurity-lessons-from-3-public-breaches-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/cybersecurity-lessons-from-3-public-breaches-scaled.jpg?fit=640%2C360&ssl=1",640,360,true],"1536x1536":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/cybersecurity-lessons-from-3-public-breaches-scaled.jpg?fit=1536%2C864&ssl=1",1536,864,true],"2048x2048":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/cybersecurity-lessons-from-3-public-breaches-scaled.jpg?fit=2048%2C1152&ssl=1",2048,1152,true],"chromenews-featured":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/cybersecurity-lessons-from-3-public-breaches-scaled.jpg?fit=1024%2C576&ssl=1",1024,576,true],"chromenews-large":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/cybersecurity-lessons-from-3-public-breaches-scaled.jpg?resize=825%2C575&ssl=1",825,575,true],"chromenews-medium":["https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/cybersecurity-lessons-from-3-public-breaches-scaled.jpg?resize=590%2C410&ssl=1",590,410,true]},"author_info":{"display_name":"Dark Reading","author_link":"https:\/\/ddi.mohflo.net\/index.php\/author\/darkreading\/"},"category_info":"<a href=\"https:\/\/ddi.mohflo.net\/index.php\/category\/uncategorized\/\" rel=\"category tag\">Uncategorized<\/a>","tag_info":"Uncategorized","comment_count":"0","jetpack_featured_media_url":"https:\/\/i0.wp.com\/ddi.mohflo.net\/wp-content\/uploads\/2024\/12\/cybersecurity-lessons-from-3-public-breaches-scaled.jpg?fit=2560%2C1440&ssl=1","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6580","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/comments?post=6580"}],"version-history":[{"count":0,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/posts\/6580\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media\/6581"}],"wp:attachment":[{"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/media?parent=6580"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/categories?post=6580"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ddi.mohflo.net\/index.php\/wp-json\/wp\/v2\/tags?post=6580"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}