Category: Notice

  • 4 Common Causes of Data Breaches (and Real Cases That Show Them)

    4 Common Causes of Data Breaches (and Real Cases That Show Them)

    By J. Mesa

    Most data breaches trace back to a short list of causes. April 2023 delivered a clear example of four of them in a single month. I covered those incidents in our May 2023 Cyber Bytes, and the lessons still apply.

    This post walks through each cause, the real case behind it, and what your business can do.

    What is a data breach?

    A data breach is any incident where someone gains access to information they have no right to see. It can result from an attack, a configuration mistake, a lost device, or an insider. The data may be customer records, employee files, login credentials, or business documents.

    Cause 1: How do attackers steal data from healthcare providers?

    The case. Shields Health Care Group, a medical imaging provider, reported the largest breach of the month. An intruder accessed its systems and exposed the personal data of about 2.3 million people.

    Why it happens. Healthcare records hold names, birth dates, insurance details, and medical history in one place. That makes them valuable for fraud. Providers also run many connected systems, which gives an intruder room to move.

    How to prevent it.

    • Limit each account to the records its user needs
    • Require multi-factor authentication
    • Monitor for unusual access to patient or customer files
    • Encrypt sensitive data

    Any business that holds health information for a provider falls under HIPAA as well, so the same rules reach billing companies and IT vendors.

    Cause 2: What is a cloud misconfiguration?

    The case. ICICI Bank, a major Indian financial institution, faced a data leak tied to misconfigured cloud storage. Researchers reported that sensitive files, including bank statements and card details, sat open to the internet.

    Why it happens. Cloud storage is secure when its settings are right. A storage folder set to public, a sharing link open to anyone, or an account without multi-factor authentication exposes everything inside. No attacker has to break in, because the data is already out.

    How to prevent it.

    • Review who can see each cloud folder and remove public access
    • Turn off “anyone with the link” sharing for sensitive files
    • Require multi-factor authentication on every cloud account
    • Check settings again after any change in staff or vendors

    Cause 3: How does ransomware lead to a data breach?

    The case. Capita, a business services company in the United Kingdom, suffered a ransomware attack. Staff lost access to Microsoft Office applications, and the attackers also stole data.

    Why it happens. Modern ransomware groups copy your files before they lock them. The outage is the visible damage. The stolen data causes the longer problem, because it leads to notifications, legal exposure, and extortion.

    How to prevent it.

    • Train staff to spot phishing, the most common way in
    • Patch systems, with internet-facing ones first
    • Keep an offline backup and test it
    • Limit how far one compromised account can reach

    Cause 4: Why are old systems a security risk?

    The case. The American Bar Association disclosed a breach that exposed the login credentials of about 1.4 million members. The data came from a legacy system the organization had decommissioned in 2018.

    Why it happens. Retired systems still hold data. Nobody patches them, nobody watches them, and the credentials inside often still work elsewhere because people reuse passwords.

    How to prevent it.

    • Keep an inventory of every system, including the ones you no longer use
    • Delete or archive the data when you retire a system
    • Shut old systems down for good and remove them from the network
    • Require password changes when old credentials may be exposed

    What do these four breaches have in common?

    None of them needed an exotic technique. Each came from a basic gap:

    • Too much access
    • A wrong setting
    • A successful phishing email or an unpatched system
    • A forgotten server

    Attackers look for the easy way in. Closing the basic gaps removes most of their options.

    How do I know if my business has been breached?

    • Customers or staff receive phishing emails that use real details about them
    • Accounts show logins from unfamiliar places
    • You find new user accounts or mail forwarding rules nobody created
    • A vendor, a bank, or law enforcement contacts you
    • Your data or credentials appear in a breach lookup such as haveibeenpwned.com

    Many organizations learn about a breach from an outside party, months after it began. Monitoring shortens that gap.

    What should I do after a breach?

    1. Contain it. Disconnect affected systems and reset passwords from a clean device.
    2. Call your IT provider, your cyber insurer, and your attorney.
    3. Find out what data was involved and whose it was.
    4. Notify affected people and regulators as the law requires.
    5. Fix the cause before you bring systems back.

    What are the takeaways for everyone?

    • Be careful with online interactions. Treat unexpected emails and links with suspicion, at work and at home.
    • Use strong, unique passwords. A different password for every account means one breach does not open the others. Add multi-factor authentication.
    • Stay current. Keep systems updated with security patches, and stay informed about new threats.

    How can a small business lower its breach risk this month?

    1. List every system and cloud account you own, including old ones.
    2. Remove access for former staff and vendors.
    3. Check cloud sharing settings.
    4. Turn on multi-factor authentication everywhere it is offered.
    5. Run a phishing awareness session.

    Who is responsible when a vendor causes the breach?

    You are, in the eyes of your customers. If a payroll company, an IT provider, or a cloud service loses data you gave it, the people affected still gave that data to you. Most breach notification laws put the duty to notify on the business that collected the information.

    Lower that risk before it arrives. Ask each vendor how it protects your data, write security and notification terms into the contract, and share only what the vendor needs to do its job.

    Your next step

    Staying informed and practicing the basics lets us all reduce the impact of cyberattacks. If you want to know which of these four gaps exist in your business, Cerberus Cybersecurity can show you with a risk and compliance assessment. Reach out to us to see how we can help you defend against cyberattacks.

  • 4 Major Data Breaches of 2023 and What Small Businesses Can Learn

    4 Major Data Breaches of 2023 and What Small Businesses Can Learn

    By J. Mesa

    March 2023 was a rough month for cybersecurity. A financial company, a pharmacy services provider, a phone carrier, and a school district all disclosed breaches within weeks of each other. I covered them in our April 2023 Cyber Bytes.

    The details differ. The lessons repeat, and they apply to a business of any size.

    What happened at Latitude Financial?

    Latitude Financial, an Australian consumer lender, disclosed a breach that reached about 14 million customer records. The stolen data included driver’s license numbers, passport numbers, and financial statements.

    The lesson: keep less data. Many of the records belonged to past customers and applicants. Data you no longer need is risk with no benefit.

    • Set a retention period for each type of record
    • Delete or destroy records when the period ends
    • Collect ID documents only when the law requires it

    What happened at PharMerica?

    PharMerica, a large US pharmacy services provider, suffered a ransomware attack. The attackers took personal information on nearly 6 million people, including names, addresses, Social Security numbers, and health data.

    The lesson: ransomware is also data theft. Attackers steal first and encrypt second. Healthcare organizations of every size, including small clinics, hold the kind of data they want.

    • Patch systems, and start with those that face the internet
    • Keep an offline backup and test it
    • Encrypt sensitive records
    • Limit each account to the data its user needs

    What happened at T-Mobile?

    T-Mobile started 2023 by disclosing a breach that affected about 37 million customer accounts. In the spring it disclosed a second, smaller incident that affected 836 customers and exposed account PINs and personal details.

    The lesson: one fix is not the end. A company that has been breached once stays a target. Security needs steady attention, with regular reviews and monitoring.

    • Review access and security settings on a schedule
    • Monitor for unusual activity on customer accounts
    • Treat every incident as a reason to look for related gaps

    What happened at Minneapolis Public Schools?

    A cyberattack disrupted the district’s computer systems for days. The attackers later published student and employee data online.

    The lesson: attackers go where defenses are thin. Schools, local governments, and nonprofits hold sensitive records and run on tight budgets. The same is true of many small businesses.

    • Know what sensitive data you hold and where
    • Have a response plan before you need one
    • Decide in advance how you will communicate with the people affected

    Were small businesses hit too?

    Yes. Small business breaches seldom make national news, and reports from the same period describe many of them. Most involved phishing or ransomware, and they exposed financial data, customer information, and internal documents.

    A small company faces the same attackers with fewer resources. It also has one advantage: fewer systems and fewer people make the basics easier to get right.

    What do these breaches have in common?

    • Valuable data in one place. Each victim held large volumes of personal information.
    • A gap in the basics. Access controls, patching, and monitoring matter more than advanced tools.
    • Costs beyond the attack. Notification, legal work, and lost trust followed each one.

    How do breaches like these affect me as a customer?

    If your data was in one of these breaches:

    1. Read the notice the company sent and accept any free credit monitoring.
    2. Place a free credit freeze with Equifax, Experian, and TransUnion.
    3. Change your password and PIN on the affected account, and anywhere you reused them.
    4. Watch for phishing that mentions the breach. Criminals use stolen details to look legitimate.

    What should a small business do now?

    1. Invest in employee training. Teach staff to recognize and avoid phishing.
    2. Use strong passwords and multi-factor authentication. Make it harder for attackers to log in.
    3. Back up your data on a schedule. Have a tested plan to restore it after an attack.
    4. Reduce what you store. Delete records you no longer need.
    5. Consider outside help. A security firm can find gaps you don’t see.

    How much does a breach cost a small business?

    The bill has several parts: recovery work, legal advice, notification, lost sales during downtime, and customers who leave. Businesses that hold regulated data can also face fines. For many small companies, the downtime alone threatens the business.

    Does cyber insurance help?

    It can. A policy can pay for forensic investigation, legal help, notification, and business interruption. Insurers expect controls such as multi-factor authentication and backups, and they ask about them on the application. Insurance works alongside good security. It does not replace it.

    How do I prepare before a breach happens?

    • Write a one-page incident response plan with names and phone numbers
    • Keep a printed copy
    • Know your notification duties under state law and any industry rules
    • Run a short tabletop exercise once a year: walk through a pretend breach and see where the plan falls short

    How can I tell if a breach notice is real?

    Scammers send fake breach notices to steal more information. A real notice does not ask you to click a link and enter your password or Social Security number. If you receive one, go to the company’s website by typing its address yourself, or call a number you already have, and confirm the notice there.

    Which industries do attackers target most?

    Any industry that holds personal or financial data draws attention. Healthcare, finance, education, retail, and professional services such as law and accounting appear in breach reports year after year. Attackers follow two things: data they can sell and organizations that can’t afford downtime. If your business fits either description, plan as though you are on the list.

    How long do I have to notify people after a breach?

    It depends on the law that applies. US state laws set their own deadlines, and many call for notice without unreasonable delay. Rules for health and financial data add their own timelines. Learn your deadlines now, and keep your attorney’s number in your response plan.

    Your next step

    Organizations must keep adapting their defenses to protect their money, their reputation, and the people who trust them. If you want to know how your business would hold up, Cerberus Cybersecurity can help with training, policy, and risk assessments. Visit our contact page to get in touch.