TwitterDeutsche Version
GDPR
Data Breaches

A Look Back at Data Breaches and Security Incidents in 2019

Telescope
Datum22. January 2020

2019 was an eventful year marked by numerous data breaches, cyberattacks, and security incidents. Facebook alone, together with Instagram and WhatsApp, has been linked to eight data breaches. When it comes to voice assistants, all the tech giants are making headlines. We’ve summarized theand most sensational cases in a two-part overview:

 

Part 1: January through June 2019

January

Mass doxing: personal data of politicians and other celebrities published

The year got off to a spectacular start: A 20-year-old from Hessepublished personal data and internal party documents belonging to approximately 1,000 German politicians and other public figures via the Twitter account @_0rbit. The suspect had already been under investigation in 2016, but detectives were stymied by encrypted data storage devices. It was only after a tip from a security expert that the investigation was linked to the new case. The CDU/CSU is calling for tougher penalties for hackers and an expansion of the investigative authorities’ powers&authorities. [1] [2] [3] [4] [5]

Collection #1: 21 Million Passwords for Onlineaccounts have surfaced on underground forums

Security blogger Troy Hunt discovered a massive collection of login credentials for online services on the internet, dubbed “Collection #1.” It includes 773 million email addresses and 21 million passwordsin plain text, as well as over 1.16 billion combinations of these credentials. [1]

Collections #2 through #5: Another 1.3 billion login credentials

Shortly after Collection #1, employees at the Hasso Plattner Institute discovered Collections #2 through #5 in a hacker forum. The institute sets up a platform where users can enter their email address to find out whether it is present in the datasets. [1]

Exposed Elasticsearch Server with 108 Million Records&records

Security researcher Justin Paine discovered an Elasticsearch server belonging to an online casino group on the Internet. The operators failed to set up access protection. [1]

Unprotected MongoDB database containing 208 million resumes

Bob Diachenko of Hacken.io discovered an exposed MongoDB instance by analyzing a search engine’s data stream. Without password protection, resumes of Chinese job seekers could be accessed. [1]

ExploitsMicrosoft Cloud

Between January 29 and February 1, 2019, the clouds for Office 365 and some Azure services experienced widespread outages. The outages were caused by network components and DNS disruptions. [1]

24 million mortgage and bank loan documents exposed online

Similarly, security researcher Bob Diachenko discovered an unprotected Elasticsearch database on the Internet that can be traced back to the data and analytics company Ascension in the U.S. state of Texas. The database contains 51 gigabytes of reports captured via optical character recognition (OCR). [1] [2]

February

617 million login credentials surfaced on the dark web

On the black market website Dream Market, a database containing stolen data from 16 different websites is being offered for $20,000. [1] [2] Shortly thereafter, the hacker offered 127 million login credentials for eight additional websites at a price of $14,500. [1] [2]

March

Hackers Remain Undetected in Citrix’s Network for Five Months

Unknown hackers infiltrated Citrix’s internal network and copied business documents and employees’ personal data. [1]

BitLocker keys can be read from the TPM chip

Using hardware costing the equivalent of 25 euros security expert Denis Andzakovic demonstrates how to read the key for the BitLocker encryptionencryption from the TPM chip. The only protection is a PIN used for pre-boot authentication.

Exposed MongoDB database from verifications.io containing over 763 million email addresses

Security expert Bob Diachenko has once again discovered an unprotected MongoDB database. The 150-gigabyte data trove from the email verification service contains email addresses, phone numbers, and lead information. [1]

More than 20,000 Facebook employees have access to plaintext passwords

Citing an unnamed insider, IT security expert Brian Krebs reports in his blog that Facebook employees were able to access the unencrypted passwordsof up to 600,000 million Facebook and Instagram users. [1] [2]

95,000 images and 25,000 audio recordings from Stalkerware available online

Motherboard reports on a public database belonging to a stalkerware provider. Users of this software use it to monitor children and spouses. The database contains more than 95,000 images and over 25,000 audio recordings. This discovery joins 12 other cases involving stalkerware providers, such as FlexiSpy, which made headlines due to un&hacked databases. [1]

Implantable defibrillators with security issues

Medtronic already caused a stir in 2018 at the hacker conference Black Hat with vulnerabilities in pacemakers and insulin pumps&f. In 2019, critical vulnerabilities in its implantable defibrillators came to light. The devices can be remotely manipulated by hackers in such a way that they fail in an emergency. [1] [2] [3]

Ransomware Paralyzes Norsk Hydro

Norsk Hydro, one of the largest aluminum producers based in Norway, is being held hostage by the LockerGoga ransomware. Both the office and production networks are affected. As a result, some of its 50 plants worldwide are being switched to manual operation. [1]

$400,000 in ransom paid following a ransomware attack

An attack involving a ransomware Trojan has largely paralyzed the administration of Jackson County in the U.S. state of Georgia. Faced with the threat of a total IT shutdown lasting several months, the administration pays the ransom of $400,000. [1] [2]

April

Medical Practice Closes After Ransomware Attack

In the U.S. state of Michigan, the Brookside ENT & Hearing Services is closing in the U.S. state of Michigan following a ransomware attack. [1]

Hackers Gain Access to Private Outlook.com Mailboxes

&Through a vulnerability in the Microsoft customer support portal, hackers managed to gain access to non-business Outlook.com accounts over a period of six months. [1] [2]

Citycomp Blackmailed Over Publication of Major Customer Data

Citycomp, a globally operating IT service provider headquartered in Ostfildern-Scharnhausen near Stuttgart, has been hacked and is being blackmailed with thepublished the stolen customer data. The dataset is reported to total 516 gigabytes, comprising 312,570 files in 51,025 folders. Citycomp’s customers include Ericsson, Leica, Toshiba, UniCredit, British Telecom, Hugo Boss, NH Hotel Group, Oracle, Airbus, Porsche, and Volkswagen. [1] [2] [3]

Hacker group Winnti breaches chemical company Bayer

The IT systems of the DAX-listed company Bayer AG have been infected with malware by the hacker group Winnti . According to security experts, the group is acting on behalf of the Chinese government. According to Bayer, the first Winnti infections occurred as early as the beginning of 2018. In July 2019, investigations by Bayerischer Rundfunk (BR) and Norddeutscher Rundfunk (NDR) revealed that at least eight German companies had been attacked by the Winnti group. Among the attackers’ targets were Siemens, BASF, and Henkel. [1] [2] [3] [4]

Hacker Compromises Tens of Thousands of User Accounts for GPS Tracker Apps

By reverse-engineering the GPS tracker apps iTrack and ProTrack, a hacker discovered the password and the addresses for the tracking servers. He could have almost saved himself the trouble, since the default password is 123456, which regularly appears in the top 10 of password lists. Some of the trackers can shut off a vehicle’s engine when it is stationary. [1] [2]

4,000 records of FBI agents posted online

A hacker group that claims to have hacked more than 1,000 websites has published the records of 4,000 FBI investigators online as proof. The records contain real names, personal and work email addresses, job titles, phone numbers, and mailing addresses. [1] [2]

Unsecured GPS trackers from Vidimensio

GPS-tracking smartwatches from the Austrian company Vidimensio allowed anyone to locate their wearers with meter-level precision and eavesdrop on their conversations. [1] [2]

Open database containing Wi-Fi access credentials for more than two million hotspots

The popular Android app WiFi Finder is designed to help users connect to hotspots. Security experts from TechCrunch have discovered that the login credentials for the database are unsecured. In addition to public hotspots, the database also stored the Wi-Fi names (SSID), geocoordinates, BSSIDs (unique IDs of the access points), and plaintext passwords for numerous private Wi-Fi access points. The app’s developer did not respond to TechCrunch’s report. The security experts were ultimately able to get the database taken offline through the hosting provider Digital Ocean. [1]

Data breach at e-learning platform Oncampus

According to a report by Golem users of the German e-learning provider Oncampus are receiving fraudulent emails ®arding email addresses used exclusively by Oncampus. Through its own research, Golem discovered PHP vulnerabilities on the web servers that may have served as a gateway for hackers.

Unprotected backup file containing 120,000 profiles from the dating site Web-Amor

This is not the first time that backup files containing personal data have been left unprotected on web servers. For example, in 2017, an unprotected backup file of the MySQL database containing 200,000 customer records was available for anyone to download at Deutsche Post under the address https://www.umziehen.de/dump.sqlA similar incident occurred at the dating site Web-Amor, whose operator was contacted by Golem regarding the discovery. However, the operator is not showing any understanding: “Don’t you busybodies have anything better to do?” was the response Golem received. The responsible Thuringian State Commissioner for Data Protection has been informed.

Unsecured database containing 12.5 million records on pregnant women found online

And once again, it is Bob Diachenko who has tracked down yet another unsecunprotected database on the Internet. This time, he stumbled upon an Indian government database that allows access—without password protection—to data on 12.5 million pregnant women. [1]

540 million records from Facebook apps left unprotected on AWS servers

The Mexican media company Cultura Colectiva stores data from its Facebook apps in unsecured areas of Amazon's cloud service, AWS. [1] [2 [3]

"Alexa": Amazon Employees Are Listening

A report from the financial news service Bloomberg , the AI (Artificial Intelligence) behind the "Alexa" infrastructure does not yet appear to be very advanced. Some of the commands directed at "Alexa" are listened to, transcribed, and reviewed by Amazon employees to improve speech recognition , transcribed, and reviewed. In the process, recordings containing television noise or unidentifiable sounds are also sent to employees without the users’ knowledge. Amazon allowsallows users to opt out of having their recordings used to improve the service in the settings. Google and Apple also stated, in response to a request from Bloomberg, that they subject recordings to human review. [1]

May

Emotet Infection at Heise Zeitschriften Verlag

An employee of the Heise Group opens an email referring to a genuine business transaction. However, the attached Word document is infected with the Emotet ransomware Trojan. When the employee activates the editing function of the Word file, Emotet spreads throughout the Heise Group’s network and that of the Heinz Heise publishing house. Although numerous computers are infected with Emotet and the malware Trickbot, which usually accompanies it, the encryption of data can be prevented. [1]

11 million photos left unprotected on Ricoh’s photo portal Theta360

Staff at vpnMentor have discovered an unprotected Elasticsearch database belonging to Ricoh’s photo portal Theta360

According to the security researchers, the 11 million photos include very private images. In some c&, the usernames for social media platforms are also listed. [1]

Misuse of the Federal Employment Agency’s job board by data brokers

SWR reporters have discovered that thousands of fake job postings are being published on the Federal Employment Agency’s job board by data brokers. The goal is not to fill a specific position, but to collect and resell applicant data. One data broker reports publishing up to 3,000 job listings per day. This results in between 3,000 and 5,000 data records per month. Cost: 3 euros per data record. [1]

TeamViewer Hacked by Winnti Group

Compared to news magazine Spiegel TeamViewer, a company based in Göppingen and provider of the remote maintenance software of the same name, confirms that it was attacked in 2016 by the hacker group Winnti in 2016. The entire infrastructure was replaced. The incident was not made public because, reportedly, no evidence was found of customer systems being infected or customer data being stolen. [1]

Election Campaigning Targeting Infants

When obtaining information from the voter registration database for campaign purposes, data is transmitted that includes individuals who are not eligible to vote and those for whom data transmission restrictions have been filed. As a result, even infants and toddlers receive personalized campaign mailings. [1]

Hackers breach pharmaceutical company Charles River Laboratories

All major pharmaceutical and biotech companies, as well as every major academic and government research institution, are among Charles River Laboratories’ clients. According to customer notice unknown attackers have breached the company’s internal network and copied confidential customer data. [1] [2]

Trojan Infection When Using Asus' Cloud Storage Service

Inadequate security measures have allowed attackers to compromise Asus's WebStorage cloud storage service. Users of the service may currently be targeted with Trojans. [1]

139 million user records stolen from online design app Canva

The hacker group GnosticPlayers is said to have copied all data stored on Canva. 139 million users are affected. [1]

IT systems in the U.S. city of Baltimore infected with ransomware for the third time

About the exploit that became known from an NSA leak "Eternal Blue" , 10,000 administrative systems in the U.S. city of Baltimore are infected with the "RobbinHood" ransomware and locked&. At times, the email and billing systems are out of service. The extortionists demand a ransom of 13 bitcoins; however, after consulting with the FBI, the city refuses to pay. The estimated damage amounts to the equivalent of 16.1 million euros. [1] [2] [3] [4]

Security Vulnerability in WhatsApp

Facebook issues a security warning regarding a vulnerability in WhatsApp’s VoIP stack. Unauthorized users can use WhatsApp’s call feature to gain remote access to the affected device. [1]

885 million documents belonging to real estate buyers left unprotected online

The U.S. real estate service provider First American Financial Corp. stores confidential documents related to mortgage transactions unprotected on its web server. All it takes is knowledge of the exact address, which customers receive via email. By changing the contract number, unauthorized access to a total of 885 million documents is possible. [1] [2]

June

WeTransfer Sends Emails with Download Links to the Wrong Users

WeTransfer is a service for sharing files. For unknown reasons, however, between June 16 and 17, emails containing download links were sent not only to the intended recipients but, unrelated third parties also received emails containing the corresponding download links. Since no authentication is required for the download, third parties can access the data. [1]

Debt collection agency AMCA loses 17.7 million patient records in a hack

The two pharmaceutical companies Quest Diagnostics and LabCorp must admit&admit to the U.S. Securities and Exchange Commission (SEC) that their debt collection service provider, AMCA, lost data due to a cyberattack. The data includes payment information, medical records, and patients’ Social Security numbers. [1] [2]

Riviera Beach City Government Hit by Ransomware

The IT systems of the Riviera Beach city government in Florida have been encrypted by a ransomware attack. After three weeks, the city council decides to pay the ransom of $600,000. [1] [2]

Three Leading Antivirus Manufacturers Hacked

Russian hackers claim to have infiltrated the networks of three of theleading anti-virus software manufacturers. Security experts suspect the Russian hacker group Fxmsp is responsible. The three companies are reportedly McAfee, Symantec, and TrendMicro. [1] [2]

Codename Soft Cell: Global Operation Against Telecommunications Providers

More than ten telecommunications companies, primarily mobile network operators, have been under attack by a hacker group since at least 2017. The perpetrators primarily exploit vulnerabilities in IIS web servers to plant webshells. This allows them to intercept login credentials and deploy additional attack tools. According to analyses, the hackers are believed to be targeting customers’ metadata and location information. The intrusion tools used were typical of the Chinese hacker group APT10, which is said to have state support. [1] [2] [3]

Unprotected lists of supporters on Campact’s petition platform

Campact’s WeAct petition platform allows unauthorized access to lists of campaign supporters. A total of 1.8 million supporters are reportedly affected. [1]

Photos of travelers at U.S. Customs and Border Protection (CBP) were copied by hackers

Approximately 100,000 travelers have been affected by a data breach at U.S. Customs and Border Protection. Photos and videos of license plates are being offered for free download on the dark web. [1] [2]

 

Part 2 of the Review (July through December)