Antivirus, Crypto Currency, Enterprise, GDPR, Internet Security, Social Media

9 Biggest Hacks/Leaks of 2017

2017 was a year where nothing seemed safe. Bombshell hacks and serious security breaches were experienced both in the Government…

2017 was a year where nothing seemed safe. Bombshell hacks and serious security breaches were experienced both in the Government and private sector.

2017 was hit with a high number of cybersecurity meltdowns ranging from stolen credit card numbers to global ransom campaigns that cost private companies millions of dollars. As we do more and more of our businesses online, hackers too are developing sophisticated ways of either spreading ransomware or stealing crucial data that is vital for our businesses and government operations.

In a report released by Bitdefender, it was found that ransomware payments doubled in 2017 hitting a record $2 billion as compared to 2016. According to Trend Micro, if the trend continues, there’s a high possibility that ransomware will most likely hit $9 billion by the end of 2018. With that being said, this article will outline and explain 9 of the biggest hacks and data breaches of 2017.

 

Equifax

Credit reference agency Equifax revealed that approximately 143 MILLION of its US customers information was breached in May of 2017. This most vital information exposed by this leak was the social security numbers of its 143 million American users. Other information revealed included names, birth dates, addresses, and drivers license numbers. As many as 209,000 users had their credit card numbers exposed also.

Due to the nature of the information revealed, all of its users are now potential targets for identity theft. It was recommended that any affected by the breach put a freeze on their credit report to prevent further damage.

The hack didn’t only include American users. It was revealed that limited information was also leaked regarding British and Canadian users. Four main groups of UK users were identified, this included almost 640,000 phone numbers and 30,000 driving license numbers. 12,000 users email addresses and 15,000 Equifax membership details were also exposed.

This massive data hack led to the resignation of the company’s chairman and CEO, Richard Smith.

There was also some controversy regarding the timing of the company’s statement about the hack. Several high ranking members of the firm exercised their right to sell off stock options worth millions of dollars between the time the breach was discovered and it was revealed to the press.

 

NSA

Although this story started as early as August 2016, the majority of the damage caused was revealed over the course of 2017. The Shadow Broker hacking group had been releasing classified information believed to be from the NSA via Twitter and Pastebin. The information contained within asked for criminals to send bitcoin bids in return for hacking tools used by the NSA.

On April 8 2017, the group released the hacking tools they claim to have stolen from the NSA’s own Equation hacking Group. In total, they released more than one gigabyte of software used to exploit Microsoft products. By the time that the group released the NSA’s leaked hacking tools, Microsoft had already patched all of the 0-day exploits they utilized.

The hacking tools weren’t the only thing that the notorious hacking group appears to have stolen from the NSA. They have revealed other information such as the 2017 Shayrat Missile Strike, President Trump’s attack against a Syrian Airfield.

 

NHS

ransomwareFollowing on from the release of the NSA’s hacking tools, we have the 12 May 2017 ransomware attack on the UK’s National Health Service. The NHS became the target of a fast-spreading ransomware called WannaCry. This ransomware encrypted the computer’s data and demanded a payment in the untraceable cryptocurrency, bitcoin. The WannaCry attack was created off the back of the exploits released by the Shadow Brokers previously.

Even though Microsoft had patched all of the 0-day exploits used in the NSA’s tools, the NHS still had thousands of computers not updated. This led to over one-third of NHS organizations being disrupted, with thousands of NHS computers infected by the ransomware. Eventually, a kill switch was found for the ransomware which meant that devices were no longer locked.

Due to the scale of the attack, thousands of appointments and operations were canceled. The effect of the attack was still being felt weeks later as a huge backlog had been created.

 

US Voter database

In June 2017 more than 198 Million US voters personal information was leaked. This information wasn’t hacked but instead was available to browse due to a security misconfiguration. The database was stored on Amazon S3 servers by data firm Deep Root Analytics. Although the information revealed by this leak isn’t much more than what is publicly available already, the sheer volume of aggregated data makes it valuable to would be cybercriminals.

The leak was discovered by Chris Vickery of security analyst firm UpGuard. A large part of the company’s research involves scanning the internet for any publicly accessible information. This led to the firm not only finding the US voter database but also databases relating to Mexican and Philippine voters.

Macron Campaign

Another political entry into our list is the “massive and coordinated” hacking attack on now French President, Emmanuel Macron. In the last few days run-up to election day May 2017, several gigabytes of information was uploaded to document sharing site Pastebin by an anonymous poster. The Macron campaign team revealed that tens of thousands of internal emails, along with other documents had been breached. The files were initially spread on 4chan, a site which is popular with far-right leaning posters.

The En Marche! campaign team claimed that this was no the first time that they had come under attack. A statement claimed they had “consistently been targeted by such initiatives” during the entire presidential campaign of 2017. They also claim that many false documents had been added to the leak in an attempt to spread disinformation.

Due to the timing of the hack, neither presidential candidate could comment on the subject. This was due to Frances laws on presidential campaigning, which ban communications before the polling stations opened.

Cloudflare

February 2017 saw a security bug in the popular content delivery network, Cloudflare, expose millions of users data. The leak, named Cloudbleed after the infamous Heartbleed bug discovered in 2014, exposed data such as passwords and security tokens.

The cloudbleed bug was discovered by Google Project Zero research, Tavis Ormandy. He discovered a buffer overflow issue in Cloudflare’ servers that meant that sensitive data could be returned by the proxy servers accidentally. This data was then being cached by search engines such as google.

In response to the bug, Cloudflare disabled several of its features – Email obfuscation, server-side Excludes and HTTPS rewrites to stop the leak. The company didn’t notify its users by itself, Ormandy followed policy and waited seven days before releasing his findings publicly. Following this public release Cloudflare confirmed the security flaw whilst also reassuring customers any information would now have been flushed from search engine caches.

Verizon

Chris Vickery of UpGuard pops up again after discovering a Verizon customer database unprotected from public access. This database was stored on Amazons S3 cloud servers by a third party vendor used by Verizon, NICE systems. The database contained sensitive information for up to 6 Million Verizon customers. Information such as PIN codes to verify customers were listed, alongside the customers’ phone numbers. This information is enough for anyone to access any of the Verizon customers accounts, even with two-factor authentication enabled.

With access to a customers account, cybercriminals could potentially add extra lines to a Verizon account leading to extra unwanted charges. The database was created from information gleaned when people contacted customer service over a 6 month period. Both business and residential customers data was exposed in the leak.

It turned out that the leak by NICE System had occurred when they uploaded the database to the S3 service and marked it as public. Verizon did not offer a way to check if a users PIN was exposed, although it did recommend that all users change their PIN as a precautionary measure.

Uber

One of the biggest hacks of 2017 technically took place in 2016. Ridesharing app Uber concealed the breach of 57 million customers personal data in October 2016 by failing to notify both its users and also regulators.

Like other hacks we saw in 2017, the information taken was stored on a third-party cloud service. This information was reportedly accessed by two hackers and in a surprising move, Uber decided to pay the hackers a ransom of $100,000 (£75,000 at the time) to delete the data and keep quiet about the information.

The information stolen included users names, phone numbers, and email addresses. Drivers for the firm had more sensitive information taken including their driving license numbers. Uber confirmed that highly sensitive information such as date of birth and social security numbers were not revealed during the hack.

Ubers chief executive Dara Khosrowshahi stated, “None of this should have happened, and I will not make excuses for it”. Uber stated at the time that it was actively monitoring the situation and Uber’s then chief security officer Joe Sullivan was forced to resign.

Yahoo

2017 saw the acquisition of internet giant Yahoo by Verizon Communications. Unfortunately, it also saw Yahoo release information about the biggest data breach in history.

Yahoo had revealed information about a data breach before it’s acquisition which lead to a drop in the acquisition price of over $300m. Verizon then went on to hire external forensic investigators and new information came to light.

Verizon revealed in October 2017 that information from over 3 billion Yahoo accounts had been stolen in August 2013. Data taken included names, email addresses, and hashed passwords but no financial information of its users. Unencrypted user security questions were also breached. Yahoo sent emails to affected accounts and prompted all users to update their passwords at the time.

Experts have stated that it is common for data security breach estimates to be initially on the lower end, but I do not believe anyone would have guessed that 3 billion accounts could be breached at one time.

To conclude…

Apart from the 9 biggest hacks of 2017 listed in this article, there were many other major security breaches that took place in the past year. Among these we didn’t mention include the HBO data leak, the Kaspersky controversy, the River City Media leak, the LastPass hack and finally, the Sony Pictures hack.

Looking at a majority of these security breaches, you’ll discover that data was lost through rather straight forward exploits. Unfortunately it doesn’t matter how vigilant you are with your data, until big business takes security seriously then we are all at risk. Lets hope for a safer 2018.

Be the first to write a comment.

Leave a Reply

Your email address will not be published. Required fields are marked *

Crypto Currency

What’s next for SEI after reclaiming $0.30? Check forecast

Key takeaways SEI has reclaimed the $0.30 psychological level, paving the way for further rally. The positive performance comes despite Bitcoin and other major cryptocurrencies recording losses. SEI rallies as BTC and others falter SEI, the 47th-largest cryptocurrency by market cap, is one of the best performers in the top 100 over the last 24

Key takeaways SEI has reclaimed the $0.30 psychological level, paving the way for further rally. The positive performance comes despite Bitcoin and other major cryptocurrencies recording losses. SEI rallies as BTC and others falter SEI, the 47th-largest cryptocurrency by market cap, is one of the best performers in the top 100 over the last 24 […]
The post What’s next for SEI after reclaiming $0.30…
Read More

Continue Reading
Crypto Currency

Bitcoin slides, Ether, XRP, Dogecoin move lower ahead of Fed Chair’s final Jackson Hole speech

Key Takeaways Bitcoin and altcoins fell in a broad crypto market decline ahead of the Fed Chair’s Jackson Hole speech. Market volatility increased as investors anticipated possible Fed rate changes and reacted to ongoing inflation concerns. Share this article Bitcoin slipped under $113,000 on Tuesday, triggering a market-wide downturn that sent Ethereum, XRP, and Solana

Key Takeaways

  • Bitcoin and altcoins fell in a broad crypto market decline ahead of the Fed Chair’s Jackson Hole speech.
  • Market volatility increased as investors anticipated possible Fed rate changes and reacted to ongoing inflation concerns.

Share this article

Bitcoin slipped under $113,000 on Tuesday, triggering a market-wide downturn that sent Ethereum, XRP, and Solana lower. The total crypto sector fell to $3.8 trillion, down 3.5% on the day.

The price of Bitcoin dropped nearly 3% in the last day to $112,696, marking a return to levels not seen since the beginning of the month, CoinGecko data shows.

Ether dropped more than 4% to $4,100 after flirting with record highs in the past few days. Losses are spread across major altcoins, with XRP down nearly 6%, Dogecoin and Chainlink off over 5%, and Sei and Cardano plunging 8%.

The pullback comes ahead of the Fed’s Jackson Hole symposium on Friday, where Chair Jerome Powell is scheduled to deliver his keynote address. Markets are bracing for whether he signals a September rate cut or doubles down on inflation concerns, especially after US inflation data offered mixed signals in July.

The headline CPI slowed to 2.7% but core inflation edged up to 3.1% and PPI climbed 3.3%. The combination of weakening job growth and persistent price pressures has raised stagflation fears, which could complicate the Fed’s decision-making.

“Higher‑than‑expected PPI numbers (producer prices jumped 0.9% month‑on‑month against a 0.2% forecast) have complicated the Fed’s policy framework, so the market will be looking for hints on the Fed’s thinking ahead of its September policy meeting,” said QCP Capital analysts in a statement. “Last year, Powell used Jackson Hole to telegraph an easing bias; this year, Trump’s tariffs and political pressure create a much more contentious backdrop.”

Traders are still pricing in a 25-basis-point cut at the September 17 FOMC meeting, though odds have eased following hotter-than-expected inflation readings.

Analysts predict Powell will be cautious during his final Jackson Hole speech. The Fed Chair may acknowledge that risks to employment and inflation are balancing, suggesting a cut could be appropriate if trends continue, but he is unlikely to commit to a specific policy action.

Since expectations for a September cut are already priced in, any hint that action might be delayed could feel like a tightening of policy for investors.

However, signals that quantitative tightening may end or that regulatory shifts are coming could boost liquidity and potentially reignite Bitcoin’s rally toward year-end, analysts suggest.

Elsewhere, US stocks also reflected uncertainty at Tuesday’s market close.

The S&P 500 fell nearly 0.6% and the Nasdaq Composite dropped around 1.5%, while the Dow Jones Industrial Average edged up.

Tech and chipmakers led losses, with Nvidia down 3.5%, AMD off 5.4%, and Broadcom lower by 3.6%. Palantir sank 9%, the worst S&P 500 performer, while Tesla, Meta, and Netflix also slipped.

Share this article

?xml>?xml>?xml>
Read More

Continue Reading
Crypto Currency

David Bailey’s Bitcoin treasury KindlyMD acquires $679 million in BTC

Key Takeaways KindlyMD acquired 5,744 Bitcoin worth approximately $679 million through its subsidiary Nakamoto Holdings. The purchase is part of KindlyMD’s strategy to accumulate one million Bitcoin as a corporate reserve asset. Share this article KindlyMD, led by President Donald Trump’s Bitcoin advisor David Bailey, announced Tuesday it had spent approximately $679 million to accumulate

Key Takeaways

  • KindlyMD acquired 5,744 Bitcoin worth approximately $679 million through its subsidiary Nakamoto Holdings.
  • The purchase is part of KindlyMD’s strategy to accumulate one million Bitcoin as a corporate reserve asset.

Share this article

KindlyMD, led by President Donald Trump’s Bitcoin advisor David Bailey, announced Tuesday it had spent approximately $679 million to accumulate around 5,744 Bitcoin.

With the latest acquisition, KindlyMD’s Bitcoin stash surpasses 5,764 units, equating to over $655 million at current prices of about $113,840. The company used PIPE proceeds for the purchase as part of its strategy to acquire one million Bitcoin under the Nakamoto Bitcoin Treasury.

Commenting on KindlyMD’s BTC purchase, the first since it completed its merger with Nakamoto Holdings, CEO Bailey reiterated that his team is doubling down on Bitcoin as a cornerstone asset for the future.

“Our long-term mission of accumulating one million Bitcoin reflects our belief that Bitcoin will anchor the next era of global finance, and we are committed to building the most trusted and transparent vehicle to achieve that future,” he added.

KindlyMD now ranks sixteenth among corporate Bitcoin holders, ahead of firms like Semler Scientific and GameStop.

Shares of the company (NAKA) fell 14% at Tuesday’s open as Bitcoin slipped from above $115,800 to $113,846 amid a market-wide pullback.

Share this article

?xml>?xml>?xml>
Read More

Continue Reading
Crypto Currency

Halving Tailwind or Liquidity Trap? Analysts Weigh In on Bitcoin’s Path Ahead

With Bitcoin hovering near record levels, analysts are split on what comes next. Swyftx Lead Market Analyst Pav Hundal warns the charts hint at trouble ahead, urging caution across altcoins. Crypto Analyst Chiefy, however, sees the latest volatility as part of the halving cycle’s natural rhythm…

With Bitcoin hovering near record levels, analysts are split on what comes next. Swyftx Lead Market Analyst Pav Hundal warns the charts hint at trouble ahead, urging caution across altcoins. Crypto Analyst Chiefy, however, sees the latest volatility as part of the halving cycle’s natural rhythm…
Read More

Continue Reading