The biggest data breaches of 2023
Read the original in Spanish →
As we begin the new year, once again, we summarize the security breaches that have exposed the greatest number of personal data.
The year 2023 saw a total of 2,800 incidents and more than 8 billion records were compromised based on reported attacks. A figure much higher than last year with just over 1,000 incidents and 480 million compromised data.
These numbers show that good data governance is increasingly necessary within organizations and, ultimately, the importance of encrypting personal data.
The buying and selling of personal data in “dark-web” forums is not something new, but it is becoming a very lucrative business, with a business figure that reached $3 billion in 2021.
Main gaps in 2023
DarkBeam (UK)
Sector: Cybersecurity
Compromised records: 3.8 billion
DarkBeam, a cybersecurity risk management company, left an interface of Elasticsearch and Kibana unprotected, exposing 3.8 billion records with emails and passwords. The leak was discovered on September 18 by the CEO of cybersecurity news site SecurityDiscovery.
Real Estate Wealth Network (US)
Sector: Construction/Real Estate
Compromised records: 1.5 billion
Cybersecurity researcher, Jeremiah Fowler, discovered a passwordless database with 1.5 billion records containing real estate data for millions of people, including name, address, and phone number.
Indian Council of Medical Research (ICMR)
Sector: Medical care
Compromised records: 815 million
The personal data of more than 815 million Indians was compromised and found for sale on the dark web. The violation is due to a vulnerability of the database that stored COVID-19 test records. It was discovered due to an advertisement on the dark web by a user named ‘pwn0001’ that offered a database with Aadhaar numbers, passport details, names and contact information.
Kid Security (Kazakhstan)
Sector: IT Services/Software
Compromised records: 300 million
KidSecurity is a parental control app used to track children, it has over a million downloads on Google Play. Elasticsearch and Logstash instances with more than 300 million records containing private user data remained public for more than a month. The data included 21,000 phone numbers and 31,000 email addresses, as well as users’ payment information, exposing the first six and last four digits of credit cards, the month and year of expiration, and the issuing bank.
Twitter (X) (USA)
Sector: IT Services/Software
Compromised records: 220 million
In December 2023, private data of 200 million Twitter users, including their email addresses, was put up for sale. This data is believed to come from a bug in the Twitter API between June 2021 and January 2022, which allowed attackers to send contact information such as email addresses and receive the associated Twitter account in return.
TuneFab (Hong Kong)
Sector: IT Services/Software
Compromised records: 150 million
This tool for downloading music from Spotify and other services suffered a leak of more than 150 million records with IP addresses, user area, user ID, emails and device information due to a misconfiguration of a MongoDB database.
SAP SE Bulgaria (Bulgaria)
Sector: IT Services/Software
Compromised records: 95 million
Researchers at Aqua Nautilus have discovered Kubernetes Secrets - objects containing small amounts of sensitive data, such as passwords, tokens or keys - related to hundreds of Internet-exposed organizations in public GitHub repositories.
Among them was SAP SE Bulgaria, credentials were discovered that provided access to 95 million artifacts, which are used to deploy manifests, as well as download permissions.
Luxottica Group (Italy)
Sector: Manufacturing
Compromised records: 74 million
Last year Luxottica, a company that produces eyeglass frames, reported that a company employee suffered a data breach in 2021 that exposed the personal information of 70 million customers after a database was published for free on hacking forums in May 2023. The data contains more than 74 million email addresses, they also have names, addresses, phone numbers and dates of birth.
Conclusions
Databases with personal information exposed by misconfigurations or unknown vulnerabilities are a serious security problem. Even if nothing more than the email account is stored, this information is useful to make Phishing attacks larger and, by simple probability, more successful.
The purpose of this post is to raise awareness about the progress of personal data breaches and the importance of taking security measures such as encrypting this critical data.
Credits: Image by Kerfin7 on Freepik