While only 14,500 accounts were compromised in the relatively small credential stuffing attack that successfully hit the Canadian government, highly sensitive financial and personal information were exposed.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Hackers compromised more than 300,000 Spotify accounts in a credential stuffing attack exploiting a third-party database containing 380 million credentials stolen from other breaches.
Daily fantasy sports and gambling platform DraftKings has confirmed that numerous user accounts were compromised following a series of credential stuffing attacks.
Credentials are everywhere, they are a demonstrated weak link in organizational security, and malicious actors have demonstrated that they prefer using them over approaches. As a result, credentials are both the best and the last chance to catch adversaries.
Costco sent a data breach notification to its customers after discovering a credit card skimmer at one of its stores. Several customers complained of unauthorized transactions.
A suspected fraudster accessed credit data of 24 million South Africans and 800,000 businesses in a massive Experian data breach.
Credit monitoring giant TransUnion has suffered an apparent Salesforce data breach, affecting over 4.4 million people, with ShinyHunters claiming responsibility.
The CRI guidance does not really focus on whether or not to make ransomware payments, instead stressing that victims should make early contact with law enforcement (regardless of their ultimate decision) and that they have many options to explore.
As cyber crime groups grow and "corporatize," they find themselves under pressure to keep up with wages. Operating expenses are largely devoted to paying employees and contractors for their work, with 80% a typical number.
The cyberattack on Colonial Pipeline was a big lesson. It is imperative that critical infrastructure companies uplevel their protection against modern security risks by using modern techniques and automation to comply with new cybersecurity regulations.










