Five Biggest Data Breaches In History (That We Know About)

Identity theft has clearly become the tactic of choice for hackers and cyber criminals. Here are the Top 5.

According to the data collected by Breach Level Index (BLI) database, there were 974 data breaches worldwide in the first half of 2016, up 15 percent from the 844 breaches during the previous six months (July to December 2015), and up sharply from the 766 data breaches in the first half of 2015.

More than 554 million data records were lost or stolen in the first half of 2016, compared with some 424 million lost or stolen during the previous six months. That represents a dramatic increase of 31 percent

Whereas in previous years’ theft of payment and financial data dominated the headlines, think of the Home Depot and Target attacks, for example, the past six months has seen the continuation of a trend that began in 2015 in which the theft of personal identifiable information has dominated.

Here are the 5 biggest and worst verified data breaches that we know of, so far.

Yahoo breach

In late 2014, hackers stole information associated with at least 500 million Yahoo user accounts. This breach was publicly disclosed by Yahoo two years later on September 22, 2016. This data breach is the largest discovered in the history of the Internet. User names, email addresses, telephone numbers, encrypted or unencrypted security questions and answers, dates of birth, and encrypted passwords were compromised.

Marissa Mayer, the CEO of Yahoo, has known about the data breach since at least July 2016 but withheld the information from people, media, investors, and regulators.

FriendFinder breach

Social adult network service FriendFinder was breached, along with all of its other sites. The FriendFinder Network Inc. (FFN) operates AdultFriendFinder.com, webcam sex-work site cams.com, Penthouse.com and a few others; a total of six databases were reported in the haul.

The hack exposed 412,214,295 accounts, according to breach notification site Leaked Source. The worst part of this leak was that more than 900,000 accounts used the password “123456.”

The website had stored the user data in plain visible format or with the insecure secure hash Algorithm 1 (SHA-1).

Myspace breach

Although Myspace is not that popular anymore, users who had accounts on this social networking site should be aware that their old information could be up for sale online.

Time Inc., which bought the social networking site in February has said that names and passwords from more than 360 million Myspace accounts were compromised.

According to Time, the data was limited to usernames, passwords, and email addresses from the platform prior to June 11, 2013, when the site was relaunched with stronger account security.

Thomas White, a security researcher also known under the pseudonym TheCthulhu, has published the database of 427 million passwords for more than 360 million users of the social network.

LinkedIn breach

The social networking website LinkedIn was hacked on 5 June 2012, and passwords for nearly 6.5 million user accounts were stolen by Russian cybercriminals.

LinkedIn disclosed its 2012 data breach soon after it happened, but password-reset notifications at the time indicated that only 6.5 million user accounts had been affected and the actual number was never disclosed.

We don’t know why LinkedIn did not further investigate the original breach, or to inform more than 100 million affected users, in the intervening four years. According to LeakedSource, just 50 easily guessed passwords (123456) made up more than 2.2 million of the 117 million encrypted passwords exposed in the breach.

According to LeakedSource, just 50 easily guessed passwords (123456) made up more than 2.2 million of the 117 million encrypted passwords exposed in the breach.

Heartland Payment Systems

New Jersey-based payment processor Heartland Payment Systems was breached in 2009. This breach exposed information from approximately 130 million credit and debit cards to cybercriminals.

Malware planted on Heartland’s network recorded card data as it arrived from retailers. Because the company processed payments for more than 250,000 businesses across the country, the impact was huge.

The data stolen included the digital information encoded onto the magnetic stripe built on the backs of credit and debit cards.

An American computer hacker, Albert Gonzalez, was sentenced to 20 years in prison in 2010, the longest sentence ever handed down for computer crime in a US court.

PC Quest:       Review of Organised Cyber Crime:       'Hackers for Hire'- Major Police Effort To Fight Criminal Gangs:     

 

« Snowden Worried That He'll Face Prison Or Execution If Russia Sends Him Home.
Self - Flying Aircraft Take To British Skies »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

Resecurity, Inc.

Resecurity, Inc.

Resecurity is a cybersecurity company that delivers a unified platform for endpoint protection, risk management, and cyber threat intelligence.

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

BackupVault

BackupVault

BackupVault is a leading provider of automatic cloud backup and critical data protection against ransomware, insider attacks and hackers for businesses and organisations worldwide.

XYPRO Technology

XYPRO Technology

XYPRO is the market leader in HPE Non-Stop Security, Risk Management and Compliance.

Cyber Security Supplier Directory

Cyber Security Supplier Directory

Our Supplier Directory lists 6,000+ specialist cyber security service providers in 128 countries worldwide. IS YOUR ORGANISATION LISTED?

Information Risk Management (IRM)

Information Risk Management (IRM)

IRM is an international consultancy dedicated to helping organisations solve key business issues. We provide strategic cyber security advice across a wide range of sectors.

Athena Forensics

Athena Forensics

Athena Forensics is one of the UK's leading providers of Computer Forensics, Mobile Phone Forensics, Cell Site Analysis and Expert Witness Services.

Bulletproof Cyber

Bulletproof Cyber

Bulletproof offer a range of security services, from penetration testing and vulnerability assessments to 24/7 security monitoring, and consultancy.

SERMA Safety & Security (S3)

SERMA Safety & Security (S3)

SERMA Safety & Security provides a comprehensive cybersecurity offering incorporating Expertise, Evaluation, Consultancy and Training, covering hardware, software and information systems.

MadSec Security

MadSec Security

MadSec Security is a leading consulting company whose expertise are information and cyber security.

Blue Lights Digital

Blue Lights Digital

Blue Lights Digital have developed a range of platforms to support digital investigations, as well as providing continued support and education for investigations professionals.

SlashNext

SlashNext

The SlashNext Internet Access Protection System (IAPS) provides Zero-Day protection against all internet access threats including Social Engineering & Phishing, Malware, Exploits and Callback Attacks.

Appvisory

Appvisory

Appvisory by MediaTest Digital is the leading Mobile Application Management-Software in Europe and enables enterprises to work secure on smartphones and tablets.

Bunifu Technologies

Bunifu Technologies

Bunifu Technologies is an Information Security and Custom Software Development Company.

SEON Technologies

SEON Technologies

At SEON we strive to help online businesses reduce the costs, time, and challenges faced due to fraud.

eCosCentric

eCosCentric

eCosCentric provides software development solutions for the IoT, M2M & embedded systems market.

InfoSystems Inc

InfoSystems Inc

InfoSystems provides reliable IT solutions to build and maintain strong and secure systems for both SMB and enterprise organizations.

Vircom

Vircom

With a large majority of cyber attacks starting with email, Vircom provides protection against the worst email security threats to your business.

The Security Bulldog

The Security Bulldog

The Security Bulldog distills and assimilates open source cyber intelligence to enable security teams to understand threats more quickly, make better decisions, and accelerate detection and response.

Insight Enterprises

Insight Enterprises

Insight is a leading solutions integrator, helping you navigate today’s ever-changing business environment with teams of technical experts and decades of industry experience.

Teal Technology Consulting

Teal Technology Consulting

TEAL Technology Consulting is your trusted advisor for all your information security needs.