Personal details of up to 50,000 Australians posted on line in one of Australia’s largest data breach

November 2, 2017

Contractors and third party providers are notorious for being weak points in data security.  Some of the largest data breaches have occurred through poor data security of contractors.  The Sony and Target breaches were caused by hackers accessing sites through a contractors access point. It happens in Australia on a more regular basis than people appreciate. And it has now happened in Australia on a very significant scale.  Itnews reports that files, which included full names, passwords, IDs, phone numbers, and email addresses as well as some credit card numbers and details on staff salaries and expenses was made available on line by a contractor.  In all personal information of 50,000 Australians were compromised.  Of that 50,000 Read the rest of this entry »

Deloite data breach in September has ongoing consequences in a month where an estimated 55 million records were compromised in data breaches

In late September this year Deloitte was the target of a successful sophisticated cyber attack which involved compromising client emails and confidential data of its clients, many of which are significant organisations. As is commonly the case with major data breaches the impact of the breach is not immediately known.  Often it requires a review to determine the extent of the breach.  It is not uncommon for hackers to remain undetected for weeks and sometimes months as they access data and decide what to steal or leak.  In the case of Deloitte’s breach was much larger than originally thought affecting the emails of 350 clients among which were US Government agencies including a server hosting emails for the US departments of state, energy, homeland security, and defense, the United States Postal Service, the National Institute of Health and the Federally guaranteed mortgage companies Fannie Mae and Freddie Mac.  The reputational damage to Deloittes has been immense, not least because it and the other big 3 accounting firms market themselves as experts in consulting in data storage, data security and compliance with privacy laws.

According to itgovernance in List of data breaches and cyber attacks in October 2017 – 55 million records leaked October was a bad but not untypical month in terms of data breaches which affected a broad range of companies.  There were financially inspired attacks such as Read the rest of this entry »