The biggest data breaches of 2023

Jan 24, 2024 | Trends

Read the original in Spanish →

The biggest data breaches of 2023

As we begin the new year, once again, we summarize the security breaches that have exposed the greatest number of personal data.

The year 2023 saw a total of 2,800 incidents and more than 8 billion records were compromised based on reported attacks. A figure much higher than last year with just over 1,000 incidents and 480 million compromised data.

These numbers show that good data governance is increasingly necessary within organizations and, ultimately, the importance of encrypting personal data.

The buying and selling of personal data in “dark-web” forums is not something new, but it is becoming a very lucrative business, with a business figure that reached $3 billion in 2021.

Main gaps in 2023

DarkBeam (UK)

Sector: Cybersecurity

Compromised records: 3.8 billion

DarkBeam, a cybersecurity risk management company, left an interface of Elasticsearch and Kibana unprotected, exposing 3.8 billion records with emails and passwords. The leak was discovered on September 18 by the CEO of cybersecurity news site SecurityDiscovery.

Real Estate Wealth Network (US)

Sector: Construction/Real Estate

Compromised records: 1.5 billion

Cybersecurity researcher, Jeremiah Fowler, discovered a passwordless database with 1.5 billion records containing real estate data for millions of people, including name, address, and phone number.

Indian Council of Medical Research (ICMR)

Sector: Medical care

Compromised records: 815 million

The personal data of more than 815 million Indians was compromised and found for sale on the dark web. The violation is due to a vulnerability of the database that stored COVID-19 test records. It was discovered due to an advertisement on the dark web by a user named ‘pwn0001’ that offered a database with Aadhaar numbers, passport details, names and contact information.

Kid Security (Kazakhstan)

Sector: IT Services/Software

Compromised records: 300 million

KidSecurity is a parental control app used to track children, it has over a million downloads on Google Play. Elasticsearch and Logstash instances with more than 300 million records containing private user data remained public for more than a month. The data included 21,000 phone numbers and 31,000 email addresses, as well as users’ payment information, exposing the first six and last four digits of credit cards, the month and year of expiration, and the issuing bank.

Twitter (X) (USA)

Sector: IT Services/Software

Compromised records: 220 million

In December 2023, private data of 200 million Twitter users, including their email addresses, was put up for sale. This data is believed to come from a bug in the Twitter API between June 2021 and January 2022, which allowed attackers to send contact information such as email addresses and receive the associated Twitter account in return.

TuneFab (Hong Kong)

Sector: IT Services/Software

Compromised records: 150 million

This tool for downloading music from Spotify and other services suffered a leak of more than 150 million records with IP addresses, user area, user ID, emails and device information due to a misconfiguration of a MongoDB database.

SAP SE Bulgaria (Bulgaria)

Sector: IT Services/Software

Compromised records: 95 million

Researchers at Aqua Nautilus have discovered Kubernetes Secrets - objects containing small amounts of sensitive data, such as passwords, tokens or keys - related to hundreds of Internet-exposed organizations in public GitHub repositories.

Among them was SAP SE Bulgaria, credentials were discovered that provided access to 95 million artifacts, which are used to deploy manifests, as well as download permissions.

Luxottica Group (Italy)

Sector: Manufacturing

Compromised records: 74 million

Last year Luxottica, a company that produces eyeglass frames, reported that a company employee suffered a data breach in 2021 that exposed the personal information of 70 million customers after a database was published for free on hacking forums in May 2023. The data contains more than 74 million email addresses, they also have names, addresses, phone numbers and dates of birth.

Conclusions

Databases with personal information exposed by misconfigurations or unknown vulnerabilities are a serious security problem. Even if nothing more than the email account is stored, this information is useful to make Phishing attacks larger and, by simple probability, more successful.

The purpose of this post is to raise awareness about the progress of personal data breaches and the importance of taking security measures such as encrypting this critical data.


Credits: Image by Kerfin7 on Freepik

← Previous Password reset risks: exposing phone numbers Next → Protecting your brand: DMARC
← Return to blog Back to top ↑