Seattle PC Consulting Blog
Checking In on Some More Data Breaches
Threats to data security are seemingly everywhere. Some companies spend millions of dollars a year on data security, but it only takes one unwitting user to tear down their huge investment. In fact, 2018 saw over 446.5 million records compromised, even if the number of data breaches dropped by almost 25 percent. Today, we will look at the biggest breaches that have happened from the beginning of May.
May 2, 2019 - Citrix
Conferencing and digital workplace software company, Citrix, revealed that hackers gained access to the company’s network between October 2018 and March 2019. Data stolen included Social Security numbers, financial information, and data of current and former employees.
May 3, 2019 - AMC Networks
1.6 million users of AMC Network’s Sundance Now and Shudder streaming services had their data left exposed through a database that was left unsecured. Names, email addresses, subscription details were compromised.
May 9, 2019 - Freedom Mobile
Freedom Mobile, a Canadian mobile provider had an estimated 1.5 million customers’ personal and financial information left exposed on a third-party server. The types of data left exposed included names, email addresses, mailing addresses, dates of birth, and credit card information.
May 13, 2019 - Indiana Pacers
The legal team behind the National Basketball Association’s Indiana Pacers was the victim of a major phishing attack. Employee and customer names, addresses, dates of birth, Social Security numbers, passport numbers, driver’s license numbers, medical insurance information, card numbers, digital signatures and login information. No number of affected individuals has been given by the team.
May 14, 2019 - WhatsApp
WhatsApp has experienced a security flaw that provided access to an Israeli government surveillance agency, NSO Group. NSO Group had limited access to the microphone, camera, and WhatsApp message text of the app’s 1.5 billion users.
May 20, 2019 - Instagram
Facebook-owned Instagram, fell victim to a data breach that exposed more than 49 million Instagram influencers, celebrities, and brands’ Instagram information when an Indian-based social media marketing company left it exposed.
May 24, 2019 - Canva
The 139 million users of Canva, a cloud-based graphic design tool, had their names, usernames, and email addresses exposed when hackers infiltrated their server.
May 24, 2019 - First American Financial Corporation
First American Financial Corp., a leading title insurer for the U.S. real estate market, had 885 million customers’ Social Security numbers, bank account numbers, mortgage and tax records, wire transaction receipts, and driver’s license images compromised for all customers as far as back as 2003.
Other May breaches: Inmediata Health Group, Uniqlo, Wyzant, Flipboard, Checkers (the fast food chain).
June 3, 2019 - Quest Diagnostics
Almost 12 million patient records have been compromised when hackers took control of the payments page of AMCA, a major payment vendor for Quest Diagnostics. Data such as financial account data, Social Security numbers, and health information (ePHI) were left exposed.
June 4, 2019 - LabCorp
In the same hack, LabCorp announced that 7.7 million of its customers were impacted.
June 6, 2019 - Opko Health
In the same attack, Opko Health had 422.600 customer and patient records compromised.
June 10, 2019 - Emuparadise
The gaming website Emuparadise had their users’ IP addresses, usernames, and passwords exposed in a data breach.
June 11, 2019 - Evite
More than 100 million users of the Evite event planning app have had their information put up for sale on the dark web. Information that was stolen included names, email addresses, IP addresses, and cleartext passwords. Some even had their dates of birth, phone number, or postal address exposed.
June 11, 2019 - Total Registration
Kentucky-based Total Registration, a facilitator of scholastic test registrations had their entire service compromised. Victims, who were mainly students who had registered for PSAT and Advanced Placement tests, had their names, dates of birth, grade level, gender, and Social Security number exposed.
June 12, 2019 - Evernote
A security vulnerability in Evernote’s Web Clipper Chrome extension gave hackers access to the online data of over 4.5 million users. Exposed data includes authentication, financial, all private communications, and more.
June 20, 2019 - Desjardins
Over 2.7 million individuals and 173,000 businesses had their data stolen by a single Desjardins employee. Canada’s largest credit union, the hack resulted in the exposure of names, dates of birth, social insurance numbers, addresses, phone numbers, and email addresses of customers
Other June breaches: Oregon Department of Human Services, U.S. Customs and Border Protection, EatStreet, Dominion National
July 17, 2019 - Clinical Pathology Laboratories
Due to the AMCA breach that affected Quest Diagnostics, Opko Health, and Labcorp, Clinical Pathology Laboratories had 2.2 million patients’ personal and medical information exposed with an additional 34,500 patients’ credit card or banking information breached.
July 18, 2019 - Sprint
A still unknown number of Sprint customer accounts were hacked through Samsung.com’s “add a line” website. Some exposed information includes names, billing addresses, phone numbers, device types, device IDs, monthly recurring charges, account numbers, and more.
Other July breaches: Maryland Department of Labor, Los Angeles County Department of Health Service, Essentia Health, Fieldwork Software, Los Angeles Personnel Department
August 5, 2019 - Poshmark
The online marketplace, Poshmark, has announced that they’ve been hacked. Usernames and email addresses of an unreported amount of clients have been exposed in the breach. Poshmark has nearly 50 million users.
August 5, 2019 - Stock X
The online fashion-trading platform had its over 6.8 million user accounts exposed. Data that was out there included customer names, email addresses, usernames and passwords, shipping addresses, and purchase histories.
August 9, 2019 - CafePress
A data breach at CafePress, a custom t-shirt and merchandise company, exposed the names, email addresses, physical addresses, phone numbers, and passwords of over 23.2 million customers.
August 15, 2019 - Choice Hotels
Hackers left over 700,000 guest records exposed in a coordinated extortion attempt on the Choice Hotel chain. Stolen information included names, addresses, and phone numbers.
August 16, 2019 - Biostar 2
VPNMentor and independent security researchers uncovered a data breach containing over a million individuals’ facial recognition information as well as the unencrypted passwords and usernames of 27.8 million individuals exposed from Biostar 2, a biometric security platform.
Other August breaches: Presbyterian Healthcare Services, State Farm
Millions of people from all around the world are victims of corporate data breaches each week. If you would like to keep your business safe and secure, contact the IT security professionals at Seattle PC Consulting today at (206) 512-8045.