If you didn’t hear it on the news, you probably got an email from Anthem letting you know that your personal information has been exposed in a massive data breach that impacts over 80 million people served by the medical insurer. According to Anthem’s own website established to address this breach, no medical records or credit card information was stolen (that they know of) which is a faint blessing in the face of what was stolen: names, addresses, birthdates, social security numbers, phone numbers, email addresses and employment history. In other words, everything a thief needs to steal your identity.
What this means for you:
As before with other large data breaches, there’s not a darn thing you could have done to protect yourself from the attack. If you just happened to not be a current or former Anthem-covered individual, it’s likely your information was stolen previously in any of the numerous other breaches from last year. Anthem will be offering free credit monitoring to all affected individuals, something that is going to sting their deep pockets signicantly, but will do little good in the long term. Why? Well, unlike credit card numbers, addresses or phone numbers, 80 million people aren’t going to change their names, dates of birth or social security numbers. Identity thefts can outwait the one year of monitoring (still unconfirmed, one year is my guess) that Anthem will provide. You can bet a large number of people won’t continue that service on their own dime, but you might want to consider factoring this type of fee permanently into your annual budgets. Or at least until someone can figure out how to secure our identities and credit better.
From a business standpoint, Anthem’s plight illustrates an important lesson. Though current legislation recommends this sort of data be encrypted, it is not a requirement. Shouldn’t Anthem have taken the extra step to protect your data? Does the government need to mandate common sense and best practice? Will Anthem’s current nightmare convince you to enforce more strict security practices in your own work and personal life? I don’t think you need me to tell you that if you want a prosperous and sustainable business protecting your sensitive data is no longer a recommendation, it’s a requirement.
Unlike previous high-profile security breaches we’ve reported here, the attack on Sony Pictures appears to be more than a “smash-and-grab” attack to steal customer information. In this particular case, the attackers have apparently acquired many sensitive internal documents, including lists of passwords and financial records, and are threatening to release those documents unless their undisclosed demands are met. Known as “doxxing” in the security industry, the threat began to appear on computers throughout the company on November 24, and effectively shut down normal operations. According to internal reports, the hackers gained access to a single internal server within the company, and spread from there.
What this means for you:
The details of how the attackers penetrated Sony security haven’t been released, but I’m willing to bet it was because an employee opened an attachment or clicked a link they shouldn’t have. No matter how competently implemented your security perimeter is, all it takes is a single human error to bring the whole thing tumbling down. In this particular instance, the error was made immeasurably worse by the hackers gaining access to unencrypted documents containing passwords to other internal systems. This lapse in judgement has paralyzed the company and will undoubtedly cost them millions to remediate.
The lesson to be learned from this: sensitive information, especially passwords, should never be stored in the clear on an unsecured spreadsheet or word processing document. At minimum, store those documents in an encrypted partition, or utilize a password manager with two-factor authentication. The other important lesson: don’t assume that just because you have a well-documented security policy that your employees are trained well enough to implement or follow it, even the internal IT staff.
After the massive security breach Target experienced in 2013, Home Depot management had the best intentions in immediately planning for a similar attack being directed at them. Unfortunately, they were about only a quarter of the way through their plans to beef up security at their stores when the big-box DIY chain recently announced that they’ve been hacked, with potentially tens of millions of customers exposed. To add insult to injury, its beginning to look like hackers penetrated Home Depot point-of-sale systems as far back as April.
What this means for you:
By now, you probably realize that there’s not much you can do other than what you’ve already been doing: use credit cards, not debit cards, wherever possible, and always keep an eagle-eye on your purchase history. Credit card companies are already doing a pretty good job with their fraud-detection algorithms – don’t ignore those automated calls when you get them. Given the massive number of breaches happening, it’s very likely that your credit card number has been stolen (or soon will be) if you shop at most large chain-based retailers.
As a business, you can take a lesson from Home Depot’s woes: move quickly. Home Depot’s implementation was likely hampered by both logistical complexity (hardware replacement at thousands of locations scattered across a gigantic area) as well as “traditional” corporate bureaucracy. There’s not much to be done for the first part except to take it into account when combating the second part, which while understandable, will lead to disastrous consequences. Cyber criminals aren’t slowed by corporate chain-of-command – don’t let your decision making process expose you to a damaging security breach.
Despite what US mainstream media might be conveying with their breathless coverage of celebrity accounts being hacked for their lewd selfies, not all hacking activity is for titillation or criminal exploitation. A duo of hackers, self-dubbed LulzSecPeru, have penetrated multiple Peruvian government websites and servers, defacing webpages and stealing confidential data as a demonstration of their hacking abilities and purportedly to shake things up politically. Among the data stolen were several thousand emails from the former Prime Minister, which revealed the presence of possible undue influence by Peruvian industry lobbies. The sudden transparency nearly forced the resignation of the entire cabinet in a Congressional vote of no confidence which only missed passing by one vote.
What this means for you:
Once again, hackers prove that if it touches the internet (and sometimes even when it doesn’t), privacy breaches are just around the corner, especially when what is hidden is likely to be highly valuable to someone. Though this particular feat was slightly less salacious than the celebrity breaches, the only rule of thumb that can be followed is this: if you don’t want your “dirty little secrets” spread all over the internet, don’t put it on an internet-facing computer, cloud server or mobile device. Information, especially confidential data, is the new currency of the world economy, and as with all currencies, most folks will go to great lengths to amass it, especially if it has the potential to undermine authority or generate wealth. Complete isolation from the internet is impossible for most businesses, but you should review very carefully what information is stored where, and the potential damage it can cause your company if it were stolen or exposed in a security breach.
Though no comment has been forthcoming from Apple yet, the mainstream press has been awash in reports that dozens of Hollywood celebrities had their iCloud accounts hacked over the Labor Day holiday weekend and, as you might have guessed, explicit images and videos have surfaced on the internet. News of the breach first surfaced on infamous website 4Chan where an unidentified individual offered to share the explicit material in exchange for bitcoin donations. Representatives for some of the celebrities confirmed the legitimacy of the material, and threatened legal action against both the hackers as well as the various websites where the the photos and videos started appearing. As of now, authorities are still trying to identify the party or parties responsible.
What this means for you:
Despite the numerous, very public incidents of famous people taking explicit photos of themselves and reaping the consequences (good or bad), everyone – famous and not – continues to underestimate the weakness of technology security on mobile devices and cloud platforms, as well as the fact that erasing a file on your smartphone does not necessarily equate to destroying it permanently. Both iOS and Android devices are designed to upload any photos or videos you take with your device to their respective cloud storage platforms, ostensibly to back them up in case of device loss, as well as to facilitate the ability to share them via the internet. What most don’t realize is the default for both platforms is to allow this, and you have to pay attention when setting up your device at the very start to disable this functionality. If you quickly punch “OK” through this process, you can easily miss this very important setting.
As always, if you need to store important information must remain confidential, cloud storage (iCloud, Dropbox, OneDrive, Google Drive, etc.) is a very high-risk option that should only be considered with eyes wide-open to the worst-case scenario. The terms of service/use for most of these platforms indemnify them from these types of breaches, so if even if your information was leaked through no personal fault of your own (as might be the above mentioned hack), it’s highly unlikely you will be able to hold anyone accountable aside from yourself.
Supermarket chains Supervalu, Albertons and Jewel-Osco have joined the illustrious list of large retailers hacked (presumably) for their vast datastores of shopper identities and credit card information. Investigation is still ongoing in both cases as to whether hackers actually managed to retrieve shopper data during the breaches, and whether the data is being used illegally elsewhere. Though the details of the hacks have not been revealed, security analysts are speculating that the hackers probably compromised point-of-sale machines, similar to the attacks that breached Target in 2013.
What this means for you:
As you can imagine, based upon the difficulties of trying to secure your own personal devices, securing a large network of heavily used and highly exposed computers is tricky business. Even the slightest misstep can lead to cybercriminals pouncing on you like a pack of wild hyenas. Large chains like the ones affected above are continuously under attack from multiple vectors primarily because of the type of data hackers absolutely know they have. The best way to descibe the current war between corporate enterprise and cybercriminals would be that of a siege, with the “good guys” turtling up behind walls that being hammered on relentlessly. And as in any siege, even the smallest breach of that wall can lead to a complete razing of the besieged. Unfortunately, the good guys are struggling to innovate as fast as the bad guys who are heavily invested in winning these types of battles, as the stakes can result in huge payoffs in stolen credentials.
As mentioned, none of the supermarket chains have verified that data has been stolen, but if you happen to shop at any of the listed establishments with your credit card, you may want to consider having your credit card company issue you a new number.
Four and a half million patients treated within the hospital network Community Health Systems now have something else to worry about aside from having to see a physician: identity theft. The 28-state network revealed today that its servers had been breached by Chinese hackers who gained access to CHS patients’ names, birthdates, social security numbers, phone numbers and addresses, every bit of data a criminal would need to perpetrate a robust identity takeover. The hackers did not gain access to credit cards or clinical records, which may only serve as a small consolation to this egregious breach of privacy.
What this means for you:
CHS operates primarily in Alabama, Florida, Mississippi, Oklahoma, Pennsylvania, Tennessee and Texas, so if you’ve received medical treatment in one of those states any time since records became computerized, you might be affected by this data breach. As opposed to the widely publicized (but not yet independently verified) Russian hacker haul of 1.2 billion passwords, changing a few passwords isn’t going to help you if you are one of the 4.5 million affected by the CHS data leak. Supposedly, CHS is planning to offer some form of Identity Theft monitoring, which, depending on the level of patience and fortitude you have, may be worth accepting. The alternative – manually monitoring your credit for bogus accounts being opened – can be time-consuming and tedious.
Even if you aren’t impacted by the above – are you keeping a close eye on your credit history? Keep in mind that Credit Monitoring services only do just that – monitor. They can’t prevent criminals from attempting to hijack your credit via bogus credit and loan applications. They will warn you about the attempts, and at best, provide some assistance in working with the 4 credit agencies to rectify the damage. And even unsuccessful attempts ding your credit history, adding injury to insult in this case.
Ahead of a court order that is still pending, Google has blocked delivery of a single email mistakenly sent to a wrong address at the request of the sender’s employer. As most of you can attest, doing something like this, while technically possible within certain parameters, is usually not done for a variety of reasons, not the least of which is opening the Pandora’s box of requests for Google to do the same thing for every email sent to the wrong address or for the wrong reasons. In this particular instance, the sender was a contractor for Goldman Sachs, and the email in question contained significant sensitive customer data sent to the wrong address. Rather than risking a signficant exposure for the customers whose data was contained in the email, on top of saving Goldman Sachs from considerable liability, Google acquiesced to the request, which normally requires a court order.
What this means for you:
The only reason this was even possible in the first place was because the unintended recipient hadn’t actually accessed the account since the email was sent, and therefore Google knew for certain that the email wouldn’t have been read, and there could be “un-sent.” You may have experienced both the relief and disappointment of attempting to “unsend” emails via your own company’s Exchange server, which can call back unread emails, but once the email has been opened by the recipient, intended or not, there’s no way to unsend it. What you should really be taking away from this was why someone was using email to send a report with such sensitive information in the first place. In this case, convenience and ease of use led to a near-catastrophic breach. Do you use email to exchange confidential information with other parties? If you do, you should carefully consider the consequences of a mis-delivered email, and what it might cost your organization.
Telecommunications giant AT&T disclosed on June 13 that three employees of one of its vendors used their privileged access to hack a server containing sensitive customer data, including Social Security Numbers, birth dates and cellular phone numbers. Thus far, AT&T hasn’t revealed how many are affected by this breach, and for the moment it appears that the hackers gained unauthorized access for the purposes of unlocking older generation AT&T phones for use on other carrier networks. The breaches happened in April, but AT&T is only just now notifying affected customers.
What this means for you:
Unlike previous data breaches, the exposed customer data hasn’t appeared for sale (yet!) on the internet black market, but AT&T is offerring a free year of credit monitoring as a mea culpa to its affected customers. If you were affected by this breach, you should have already received a notice from AT&T of the potential exposure. This latest breach demonstrates an important point about security: no matter how much you invest in protecting your perimeter, serious threats may already be behind your “firewall”. As an individual, there is very little you can do to help AT&T be more secure, but you can take your credit history and activity seriously, and always keep your eyes peeled for unusual activity on any online account, regardless of whether they are financial services or not.
In December 2013, French security hacker Eloi Vanderbeken uncovered what appeared to be a backdoor programmed into several models of DSL routers. The affected devices were built around hardware manufactured by Taiwanese company SerComm and the finished products came from several well known brands like NetGear, Linksys and Belkin, to name a few. This backdoor allowed anyone with knowledge of the hole and local access to the router (say through a nearby Wi-fi access point) to gain administrative access to the router and could lead to a complete takeover of the network controlled by the device. Now, several months later, this backdoor is not only NOT fixed, but appears to have been purposefully concealed behind the digital equivalent of a secret knock, which once given, opens the backdoor right up to the same level of exploitation as discovered in December.
What this means for you:
If you own a DSL router, you should check this list to see if your model appears on it. If it does, I recommend replacing it immediately. Even if it does not, you should check to see if your router is among the many models that are compromised in other significant ways. If you happen to be among the fortunate that uses a router not on any of these lists, you should still review the security settings and passwords used by the device, and if you don’t know how to program or even access your router, you need to get someone who does to review the device for you. The router is the front door to your home or business network, and you should not trust your security to something that can be easily broken down or opened with a readily available master key.
Image courtesy of creativedoxfoto / FreeDigitalPhotos.net











