sb-as logo
Story image

Over 2,300 data breaches disclosed so far in 2018 - report

20 Aug 2018

There have been 2,308 publicly disclosed data compromise events through June 30th, according to Risk Based Security's Mid-Year 2018 Data Breach QuickView report.

After a surprising drop in the number of reported data breaches in the first quarter, breach activity appears to be returning to a more “normal” pace.

At the mid-year point, 2018 closely mirrors 2016’s breach experience but still trails the high watermark set in 2017.

Risk Based Security executive vice president Inga Goddijn says, “2018 has been a curious year. After the wild ride of 2017, we became accustomed to seeing a lot of breaches, exposing extraordinary amounts of information.

“2018 is remarkable in that the number of publicly disclosed breaches appears to be levelling off while the number of records exposed remains stubbornly high.”

“It’s not easy to characterise 2.6 billion records exposed as an improvement, even if it is less than the 6 billion exposed at this time last year.”

Phishing for usernames and passwords then using the stolen credentials to access systems or services stands out as a particularly popular attack method utilised by hackers in the first six months of the year.

Additionally, the arrival of the GDPR in late May brought another layer of nuance to the cataloguing and reporting of data breaches.

After the GDPR took effect, data protection authorities across the EU reported sizable spikes in the number of breaches submitted to their offices.

How many will become public - or have already been disclosed and are only now making their way to regulators attention - remains to be seen.

Similar to Q1, fraud continues to hold the top spot for the breach type compromising the most records, accounting for 47.5% of exposed records.

As with prior reports, the number of incidents attributed to hacking remains high, accounting for well over 50% of disclosed breaches.

With the number of vulnerabilities reported this year on pace to exceed 2017 and over 3,000 of those vulnerabilities going uncovered by the CVE and National Vulnerability Database (NVD), it is tempting to attribute the high percentage of breaches from hacking to inferior or incomplete vulnerability intelligence.

Goddijn says, “There are a lot of moving parts to an effective information security program and certainly patch management is one of the trickier components to tackle.

“That said, tried and true social engineering techniques combined with the ability to take advantage of unpatched weaknesses are some of the most effective tools malicious actors can use.

“That means defending against activities like phishing and solid vulnerability management go hand in hand when it comes to stopping hackers,” she says.

“While we expect hacking to remain the leading cause of data loss, we can’t lose sight of the damage that can come from accidental exposure.

“Misconfigured services, exposed S3 buckets and even improper email handling have led to more than their fair share of recent breaches.

Goddijn adds, “This type of data loss is easily prevented and protecting against it is nearly entirely within the organisation’s control. It shouldn’t be overlooked in the quest to prevent external attacks.”

Story image
Almost 10,000 unsecured databases with more than 10 billion credentials exposed
Research has identified a total of 9,517 unsecured databases containing 10,463,315,645 entries with such data as emails, passwords, and phone numbers.More
Story image
Sophos deconstructs Dharma, the 'fast food franchise' ransomware
Dharma is fast-food franchise ransomware: widely and easily available to just about anyone,” says Sophos threat researcher.More
Story image
How business can lift protection against mobile threats
The mobile phone has become ubiquitous both personally and professionally. Many of these devices are able to access corporate networks and sensitive data, yet many may not be as protected or secured as company-owned devices.More
Story image
Fortinet holds position as fastest-growing SD-WAN vendor
According to a new Omida report, the company has seen a 247% revenue growth year-on-year. Plus, Fortinet announces Fortigate 80F.More
Story image
Just 6,000 accounts responsible for over 100,000 email attacks - report
Barracuda has today released a report detailing how 6,170 malicious accounts that use Gmail, AOL, and other email services were responsible for more than 100,000 business email compromise (BEC) attacks on nearly 6,600 organisations. More
Story image
Internet outages drastically increased during COVID-19 lockdowns, report finds
Global internet disruptions increased 63% in March, with internet service providers hit the hardest. This is according to the 2020 Internet Performance Report from ThousandEyes, the internet and cloud intelligence company.More