TwitterDeutsche Version
GDPR
Data Breaches

A Look Back at Data Breaches and Security Incidents in 2019

Telescope
Datum22. January 2020

Part 2: July through December 2019

July

13 German Red Cross hospitals hit by ransomware

According to authorities, a service account created ten years ago was the vulnerability that attackers exploited to infiltrate the networks of a total of 13 German Red Cross clinics. The attackers encrypted servers and databases. Details regarding ransom demands and the type of malware have not been disclosed. [1] [2]

How Google Handles Voice Recordings

In April, Google stated upon inquiry that it also relies on human analysis for its voice assistant. Belgian public broadcasting investigated the matter and, with the help of a whistleblower, analyzed over 1,000 recordings. Contrary to what Google claimed as recently as April, the recordings allow for the identification of individuals in numerous cases. [1]

Apple contractors listen to confidential recordings via Siri

The Guardian reveals that Apple contractors regularlyregularly listen to confidential recordings as part of quality assurance efforts. This includes confidential medical information, drug deals, and how couples have sex. As with Alexa and other voice assistant providers, accidental activations of voice assistants occur time and again. [1] [2]

17,000 Websites Infected Due to Misconfiguration of S3 Buckets

Criminals Infect 17,000 Websites with Spyware tocredit card data. A common pattern is misconfigured Amazon S3 buckets, which allow attackers to inject the malicious JavaScript code designed to harvest the data. [1]

7.5 terabytes of data on Russian intelligence projects copied

Sytech, a service provider for the Russian intelligence agency FSB, was hacked by the hacker group 0v1ru$. BBC Russia calls it what is likely the largest data leak in the history of Russian intelligence agencies. [1]

Online banking outage at Commerzbank and DKB

Online access to Commerzbank and DKB’s internet banking services has been unavailable for several hours. At Commerzbank, withdrawals from ATMs are temporarily unavailable, and purchases using the Girocard (EC card) are also not working. [1]

Palo Alto Admits to Critical Vulnerability One Year After Fix

In 2018, firewall manufacturer Palo Alto quietly fixed a vulnerability in its GlobalProtect VPN module with a new firmware update. GlobalProtect is used to connect to corporate networks via SSL-VPN. The vulnerability allows the execution of arbitrary malicious code, enabling attackers to completely take over the firewall. Hackers can thus completely bypass the firewall’s protection mechanisms and eavesdrop on data traffic passing through the device. The online ride-sharing service Uber was attacked via this vulnerability. Only after the publication of a guide on how to hack GlobalProtect —more than a year later—a security advisory regarding the vulnerability.

Smart home manufacturer ORVIBO’s database exposed online

A report by vpnMentor, the database for customers of the smart home manufacturer ORVIBO was accessible without protection. It contained email addresses, last names, and exact location data for the respective smart home devices. Passwords stored as MD5 hashes without salt—a method that has not been considered state-of-the-art for many years— as well as reset codes, were found in the dataset at the time. According to vpnMentor’s analysis, the devices—which include video cameras—are used not only in private homes but also in business settings. One of the devices is labeled “massage room.” These smart home devices are sold in Germany through Amazon, among other retailers. [1]

Hackers Breach Bulgarian Tax Authority

Unknown individuals gained access to the systems of the Bulgarian tax authority NAP and copied data belonging to millions of people. In addition to personal information, the attackers also obtained tax and pension information belonging to the affected individuals. [1]

Capital One Hacked – 100 Million Customers Affected

The U.S. bank Capital One was hacked via a misconfigured web application firewall at a cloud provider. The perpetrator is believed to be a 33-year-old former employee of Amazon Web Services (AWS). The stolen data consists of credit card applications from the past ten years. Social Security numbers are also said to have been included for over one million customers. [1] [2]

Logitech Unifying wireless technology vulnerable tohacker attacks

Security expert Marcus Mengs has discovered several vulnerabilities in Logitech’s Unifying wireless technology that allow keystrokes to be intercepted and PCs to be controlled remotely. Using a known-plaintext attack, attackers can extract the key for AES encryption. The attack requires only a 12-euro wireless module from Nordic Semiconductor (nRF52840), which can be used to eavesdrop on the pairing process between the receiver and the device. Anyone who cannot ensure adequate physical protectionmust expect successful attack attempts. [1] [2] [3]

Hacker Breach at Freenet Subsidiary Vitrado

According to Vitrado, data from approximately 67,000 affiliate partners was copied from an SQL database. The data records contain names, addresses, email addresses, and bank account information. [1]

August

State Farm Online Accounts Compromised

State Farm, the largest provider of property and casualty insurance in the United States, has been hacked via a credential stuffing attack. This attack involves targeting new victims with combinations of email addresses and passwords obtained from numerous data breaches. Since State Farm customers often use the same password for other services, the hackers have an easy time of it. [1] [2]

T-Mobile Customer Data Stolen by Hackers

The U.S. subsidiary of T-Mobile announced in a press release that it had detected unauthorized access to customer data. Approximately two million customers are reportedly affected. The data includes customer names, phone numbers, email addresses, and customer numbers. [1]

AWS Virtual Hard Drive Left Unprotected Online

A security researcher discovered unprotected Elastic Block Store volumes on Amazon Web Services (AWS). On the storage devices, he found login credentials for databases, VPN networks, and other sensitivematerial. The operators of the volumes had set the access mode from “Private” to “Public.” [1]

Hackers Steal 14 Million Customer Records from Hostinger

Unknown individuals gained access to a database belonging to the web hosting company Hostinger and obtained login credentials for 14 million customers. Although the passwords are stored as SHA-1 hashes, this hash algorithm has been considered insecure for several years. [1]

More than 130,000 tenant records at LEG accessible to unauthorized parties

Customers of the Düsseldorf housing association LEG canaccess other tenants’ data after logging into the tenant portal by changing the contract number in the URL. A student discovered this trivial security vulnerability and reported it to the State Data Protection Commissioner of North Rhine-Westphalia as well as to the press. [1] [2]

Data from 1.2 million users of the porn portal Luscious left unprotected

vpnMentor reports &about a porn portal where users can upload their own content. The portal’s Elasticsearch database is accessible via the Internet using a web browser without a password. Among the 1.195 million users, 50,000 are reportedly from Germany. [1] [2]

90,000 People Affected by Data Breach in Mastercard’s “Priceless Specials” Rewards Program

An Excel list containing 90,000 entries was discovered on the website of Mastercard’s rewards program. It contains first and last names, dates of birth, email addresses, and, in many cases, mailing addresses and cell phone numbers. Shortly thereafter, a second list appeared that also included full credit card numbers. [1] [2]

700,000 guest records at Choice Hotels publicly accessible

Choice Hotels, which includes chains such as Clarion, EconoLodge, Comfort Inn, and Quality Inn, left its customer database openly accessible on the Internet for four days. Despite the short timeframe, hackers found the unsecureddatabase and demanded a ransom of 0.4 Bitcoin. [1]

Unsecured Biostar2 biometric database found online

Once again, employees at vpnMentor an unprotected database containing 27.8 million entries&on the Internet. Fingerprints, photos, and passwords belonging to millions of people are stored in unencrypted form in the Biostar2 database of the South Korean company Suprema. The data from Biostar2 is to be integrated into the AEOS access control system—used by 5,700 companies and government agencies worldwide—as part of a partnership with Nedap. [1]

MoviePass database with 161 million entries found online without password protection

A security researcher discovered an unprotected database containing customer information and, in some cases, credit card data from the movie ticket service MoviePass. However, the company did not respond to the security expert’s notification. It was only after TechCrunch contacted MoviePass that the database was taken offline. During the investigation, it emerges that MoviePass had already been informed of the data breach by another security researcher months earlier. [1]

Tracking by Kaspersky Antivirus

Editors at Heise Publishing discovered during a test of antivirus software that Kaspersky’s antivirus program injects a unique ID directly into the HTMLcode. This allows any website to read this ID and misuse it for tracking. [1]

iPhone’s Face ID feature tricked

At the BlackHat 2019 hacker conference, a security researcher demonstrated how the sensors can becan be tricked by voice, fingerprint, or facial recognition used in iPhones. One of the hacks presented requires nothing more than a pair of DIY glasses costing just a few euros and some tape. [1]

BRK Leaks Sensitive Health Data to Facebook

Confidential data from blood donors registered with the Bavarian Red Cross Blood Donation Service is being sent to Facebook via a tracking pixel. Donors are asked to provide information regarding HIV infections, pregnancy, drug use, or diabetes. The Bavarian State Office for Data Protection Supervision is launching an investigation. [1] [2]

September

Cortana and Skype Eavesdropped On

Given that Amazon, Apple, and Google have people review recordings from their voice assistants, it comes as little surprise that Microsoft also hires service providers to analyze Cortana commands and Skype conversations—and in the process, learns intimate details about the users involved. [1] [2]

Food delivery service DoorDash loses data on 4.9 million individuals

For five months, hackers had access to the data of customers, employees, and merchants. The attackers were able to access customer data, usernames, password hashes, as well as copies ofand parts of credit card data. [1]

Billions of patient records openly accessible

Employees of Bayerischer Rundfunk (BR) and the U.S. investigative platform ProPublica have discovered insecurely configured PACS (Picture Archiving and Communication System) servers worldwide. Through these servers, unauthorized access to X-ray images and other patient data is possible via the Internet for anyone using the viewing program "Radiant DICOM Viewer." Unprotected servers can be found via open databases such as Shodan or Censys. The root cause is the DICOM communication standard used by the PACS servers, which dates back to the 1980s. In many cases, access to the datais not protected by a password. In Germany alone, at the time of discovery, approximately 15,000 data records belonging to German citizens—containing approximately 2.85 million images—were openly accessible. Oleg Pianykh, a professor of radiology at Harvard Medical School, published a study on unprotected PACS servers as early as 2016. [1] [2] [3]

Data Breach at Haufe Zeugnis Manager

On September 20, 2019, Haufe-Lexware informed its customers that on October 13, 2017, an employee of the Haufe Group had stored a list of Haufe Zeugnis Manager Premium users unencryptedon the web server. Users who used the Zeugnis Manager between December 2016 and September 2017 were affected. The file was discovered by the company’s own employees and removed on August 20, 2019. Haufe-Lexware has found no evidence of unauthorized access to the list but acknowledges that not all access logs are available to rule out such access.

Customer Information: Haufe Zeugnis Manager Data Breach

Ransomware Attackers Came Away Empty-Handed

The IT systems of the New Bedford city government in the U.S. state of Massachusetts have been infected by the “Ryuk” ransomware. IT experts were able to contain the spread early on, so that only four percent of the city’s government computers were affected by the infection. Nevertheless, the city administration offered the extortionists approximately $400,000 as a ransom tothe files. The insurance company would have covered this amount. However, the extortionists demanded bitcoins worth 5.3 million US dollars. Ultimately, the extortionists came away empty-handed. [1] [2]

Ransomware Paralyzes Berlin Court of Appeal

The Emotet encryption Trojan has infected the IT systems of the Berlin Higher Regional Court. Court President Bernd Pickel does not expect operations to resume before 2020. With 30 emergency PCs, initial specialized proceedings can be resumed and invoices paid. An audit conducted in 2017 had already revealed, among other things, that Microsoft Word 95—software that had not been supported since January 1, 2002Microsoft Word 95—which had not been supported since January 1, 2002—was still in use. [1] [2]

Unsecured Elasticsearch Server Containing Data on Ecuadorian Residents Discovered

Two Israeli security researchers discovered a publicly accessible server containing 20.8 million records on nearly all residents of Ecuador. The data records also include information on bank account balances, credit information, and employment details. Among those affected are records on the President of Ecuador and WikiLeaks founder Julian Assange. [1] [2]

CEO Fraud with an Artificial Voice

Criminals are using artificial intelligence-based software to imitate the voice of a CEO at the German parent company. At first, the CEO of the branch had no reason to suspect anything and transferred 220,000 euros to an account held by the perpetrators. It is only when he is asked to make a second transfer that he becomes suspicious. [1] [2]

Neustadt City Administration Hit by Emotet

An infection with the Emotet ransomware has crippled the IT systems of the Neustadt am Rübenberge city administration. [1]

419 million Facebook users’ phone numbers freely accessible

Security researcher Sanyam Jain finds a file on a server containing 419 million Facebookusers. Criminals can use the phone numbers for so-called SIM swapping. In this process, the victim’s cell phone number is transferred to a SIM card in the perpetrator’s possession &. This allows SMS messages—such as a TAN for online banking—or calls to be redirected. [1]

1,300 credit card details memorized using photographic memory

A salesperson at a shopping center in Tokyo is alleged to have, during 1,300 payment transactions,memorized the 16-digit credit card numbers, security codes, and expiration dates and misused them to make purchases at the victims’ expense. The perpetrator had the purchased goods shipped to his home address. This allowed criminal investigators to easily solve the case. [1] [2]

October

Phishing with Alexa

Researchers at SRLabs demonstrate how trojanized apps can be used to remotely control and instruct Alexa and Google Home to ask their users for a password. [1] [2] [3]

22 City and Municipal Governments Affected by Ransomware Attack

The wave of ransomware infections shows no signs of abating. The IT systems of 22 municipalities in the U.S. state of Texas have been crippled by ransomware. [1]

Another Security Vulnerability in WhatsApp

Back in May, WhatsApp made headlines with a security v. A new vulnerability has come to light that allows attackers to gain access to chat histories and photos. Malware can also be installed through this vulnerability. For the attack to succeed, the victim must receive an infected file via WhatsApp. Exploits to take advantage of this vulnerability are quickly becoming available online. [1]

330,000 login credentials from a sex portal have surfaced on the dark web

A Dutch and an Italian sex portal were hacked via a vulnerability in outdated vBulletinforum software. The attacker stole email addresses and password hashes in the MD5 format—which is considered insecure—as well as other data from people seeking contact with prostitutes and escorts. The hacker is offering the data for sale on the dark web for just 300 euros. [1] [2]

Health app Ada shares sensitive data with Facebook and other analytics companies

The health app from Berlin-based Ada Health GmbH is alleged to have shared sensitive user data with Facebook and the analytics service providers Amplitude and Adjust. The Techniker Krankenkasse health insurance provider uses the app for its members. [1] [2]

Security Vulnerability in Millions of Unitymedia Routers

The Connect Box, which provides internet connectivity via Unitymedia to 2.2 million households, allows full control through an injection vulnerability. This is particularly problematic for customers who have enabled the remote maintenance feature. As a result, the devices are also vulnerable to attacks from the Internet. [1]

Forum hack at security software manufacturer Comodo

A hacker exploited a security vulnerability in Comodo’s vBulletin forum software and stole data from 170,000 forum users. [1]

Attackers intercept private keys from VPN provider NordVPN

&Through an insecure remote management system, unknown attackers managed to steal private keys used to generate X.509 certificates. These certificates are used in SSL/TLS connections to websites or VPN nodes. With these private keys, criminals can intercept data traffic from such secure connections. [1] [2]

Antivirus software maker Avast hacked

Hackers can gain access to temporary VPNaccounts, hackers were able to infiltrate the Czech software company Avast. The attackers appear to have targeted the security software CCleaner, which they intended to infect with malicious code. This would have allowed the attackers to achieve a wide-distribution of backdoors. [1]

Data Breach at UniCredit

The financial institution UniCredit reports that a data breach has been detected. Three million records containing email addresses, phone numbers, and addresses of Italian customers are affected. [1]

7-Eleven Fuel App with Data Breach

A 7-Eleven app for paying for fuel allows access to other users’ data. The app has been downloaded two million times. [1]

Database containing data from 7.5 million Adobe customers exposed on the internet

Bob Diachenko has once again discovered an unprotected database. This time, it affects customers of Adobe’s Creative Cloud subscription. The data records contain email addresses and subscription details. [1]

November

Google Receives Millions of Patient Records

To develop new services and features in the healthcare sector, Google is receiving millions of health records from U.S. citizens. This sensitive data includes complete medical histories, lab results, hospital stays, and diagnoses—all linked to patients’ names and dates of birth. However, those affected are unaware of this; according to Google, their consent is not required. [1]

Emotet paralyzes the IT systems at Fürstenfeldbruck Hospital

Following an attack by the Emotet ransomware, Fürstenfeldbruck Hospital is facing a week-long IT outage. 450 computers have been affected by the infection. The hospital can now only treat emergencies. Other patients are being transferred to nearby hospitals. [1]

1 terabyte data breach at Gekko Group

Security researchers discovered more than one terabyte of unsecured customer data online at business travel provider Gekko Group, a subsidiary of AccorHotels. This includes login credentials, booking information, and credit card details from direct customers, as well as those of some subcontractors. However, experts at vpnMentor also found data from other travel providers and booking portals, such as booking.com and hotelbeds.com. The affected server was subsequently secured. [1] [2]

Security vulnerability in Alexa and similar devices caused by laser-based remote control

Security researchers from the U.S. and Japan demonstrate how easily smart home systems such as Alexa and Amazon Echo can be remotely controlled—and completely unnoticed. From a distance of 75 meters, the researchers were able to “inject” commands into the device using a laser beam aimed at the assistant system’s microphone. This could be done, for example, from the window of the house across the street. From turning off the power to opening smart-home-controlled doors andorder groceries—everything is possible. Although widespread abuse is unlikely. [1]

Hacker attack on Adobe’s Magento Marketplace

Unknown attackers hacked Magento’s server and gained access to email addresses, MageIDs, names, billing, and shipping addresses. Credit card information and passwords are reportedly not affected. The servers were temporarily taken offline, and affected customers were notified. No details were provided of the attack. [1] [2]

Data breach involves 4 terabytes of data

Bob Diachenko and Vinny Troia discover an unprotected Elasticsearch server containing 4 billion user accounts. The data includes private and social information such as names, email addresses, phone numbers, and LinkedIn and Facebook profile information. This makes it one of the largest single-source data breaches in history. The data appears to be associated with two different data enrichment companies: “People Data Labs” and “OxyData.Io." [1]

Trend Micro Customer Data Sold to Scammers

Threat from Within: An employee of Trend Micro, an IT and server security company, steals customer data—including names, email addresses, and support ticket numbers to sell them to fraudsters. These are then used fraudulently for purported technical support cases. Credit card information is reportedly not affected. Customers who are allegedly contacted by Trend Micro under the pretext of a technical issue should end the call and report it. The company itself does not contact its customers by phone in this manner. [1]

Database containing approximately 500,000 user records from an online game is freely available on the web

A freely accessible backup database containing 452,634 users of the online version of the game “Magic: The Gathering“ has been discovered by a British security firm. It contains the names, usernames, and email addresses of the users. Passwords were also found on the database, but they were protected by a hashing algorithm and a salt and therefore could not be easily viewed. [1]

Hackers Gain Access to Customer Data from Smartphone Manufacturer OnePlus

This is not the first incident to affect OnePlus. This time, hackers were able to infiltrate the customer area of the online store and extract data to use in personalized phishing emails. The data includes email addresses, contact numbers, names, and mailing addresses. Passwords and payment information are not believed to have been copied. [1]

Router vulnerability allows unprotected access to patient data

An IT expert discovers a publicly accessible Windows server belonging to a medical practice in Celle on the Internet. In addition to data on approximately 30,000 patients, the server also contained employment contracts, termination notices, donation records, lists of debtors, and business performance reports (BWA). The cause was a faulty port forwarding configuration on port 443 of a web server within the practice’s network. This port is typically used for secure SSL/TLS connections on web servers. However, the Telekom router does not just open port 443, but all ports from 440 to 449. By default, Windows server shares are accessible on port 445. Further research by Heise Publishing reveals that a faulty firmware version of the Telekom routers is responsible for the unintended opening of additional ports. [1]

Data breach at Conrad Electronic

Unknown individuals gained access to 14 million customer records from an Elasticsearch instance belonging to the Conrad Electronic Group. The records include mailing addresses, in some cases email addresses, fax numbers, and phone numbers, and—in just under 20% of the affected records—IBANs as well. [1]

Politically Motivated Hack Targets Offshore Bank

A dataset containing over 600,000 internal emails and documents from the servers of a subsidiary of Cayman National Bank and Trust has been made publicly available online. The hacker-activist “Phineas Fisher” claims responsibility for the attack, through which he claims to have stolen a six-figure sum in dollars. Access was gained through vulnerabilities in the bank’s own VPN and firewall systems. [1]

Update Causes Data Breach at Berlin Criminal Investigation Department

An IT employee performed an update from Windows 7 to Windows 10 without first backing up the local hard drives. The result: Case-related data, analyses, and investigative notes pertaining to robbery, fraud, and repeat offenders were deleted without the possibility of recovery. [1]

December

University of Giessen Hit by Ransomware

The University of Giessen has been offline for about two weeks. The cause is an infection with the “Ryuk” ransomware, as confirmed by the public prosecutor’s office. Once again, the Emotet malware is believed to have served as the entry point; it turns infected email attachments—most often even Office documents from recently contacted recipients with plausible-sounding content—into easy traps. No ransom note was sent. The university presumably reacted quickly enough. The identity of those behind the attack remains unknown. [1]

Tens of Thousands of Citizens’ Data on eBay

In Coburg, a dealer is selling returned SSD storage devices on eBay. These were previously in use at the vehicle registration office and the youth welfare office of the Coburg District Administration. The drives contained unencrypted personal data of citizens and internal emails from the agency. Since the data cleansing process apparently failed to achieve its purpose, buyers of these second-hand items now receive the agency’s data as a bonus. [1]

Data breach at Lufthansa Miles & More

For about 40 minutes, customers who were logged into Lufthansa’s Miles & More website were able to view other customers’ data. The information displayed included, among other things, name, loyalty card number, date of birth, address, email, phone number, mileage balance, transaction data, and travel preferences. It is also temporarily possible to redeem other customers’ miles. According to a statement from Lufthansa, this appears to be due to a technical error, not a hacker attack. [1]

Fürth Hospital Hacked with Emotet

For several days, the Fürth Hospital will be unable to admit new patients. Surgeries must be postponed, and the entire IT system must be taken offline. The reason for this is a hacker attack using Emotet. [1]

BMW Network Affected by Industrial Espionage

Since spring 2019, the Vietnamese hacker group “OceanLotus” has been snooping around in BMW’s network. They gained access via a fake website and the Cobalt Strike attack framework. The goal of the operation is presumably industrial espionage, a threat that is increasingly affecting the automotive industry. In this case, no sensitive data was compromised, as BMW’s IT security experts first monitored the intruders and then took the affected computers offline. It is suspected that OceanLotus is spying on behalf of the Vietnamese government. [1]

604-gigabyte data breach at TrueDialog

A 604 GB database belonging to the American SMS provider TrueDialog is accessible online, unencrypted and unprotected. Security researchers at vpnMentor discovered it using web mapping. Nearly one billion pieces of highly sensitive data, passwords, and private information from text messages can be easily accessed. The consequences of the data breach are still incalculable for the 5 billion customers as well as the company itself. [1]

Music streaming service Mixcloud hacked, and database listed for sale

Mixcloud itself only learned of the hack when the database containing over 20 million user accounts was offered for sale on the dark web for around $4,000. The unknown hackers obtained users’ IP addresses, email addresses, and passwords. However, most users are not affected, as they log in to the streaming service via Facebook. In these cases, Mixcloud states that it does not store passwords. Users are nevertheless advised to set a new password. [1]

Cyberattack on Maastricht University

For over a week, a hacker attack using ransomware has paralyzed all of the university’s Windows systems. The IT experts on the case cannot yet confirm whether research data was also copied. The Russian organization TA505 is behind the attack. Whether a ransom demand—common in ransomware attacks—was made to the university is not being disclosed for tactical reasons related to the investigation. [1]

Data from 267 million Facebook users online

Security researchers led by Bob Diachenko discovered a database on an unsecured server on the Internet. It contains over 267 million records of Facebook users, primarily from the U.S. It is believed that the collection was created with criminal intent and originated from Facebook’s developer API. The database was taken offline after it was discovered. [1]

Theft of hard drives containing data on 29,000 Facebook employees

Unknown individuals stole several hard drives from a Facebook employee’s car. These drives contained salary information, Social Security numbers, and other data belonging to 29,000 employees of the company. [1]

CCC Finds Vulnerabilities in the German Healthcare Network

At the Chaos Computer Congress 36C3, hackers from the Chaos Computer Club (CCC) demonstrate how they manage to gain access to the telematics network. 115,000 medical practices are connected to this network. The system is intended to be used for the mandatory transfer of digital patient data and electronic prescriptions. Due to a lack of identity verification, hackers can obtain valid healthcare professional IDs, practice IDs, connector cards, and health cards under the identities of third parties and thereby gain access to applications on the telematics network and health data. [1] [2]

 

Part 1 of the Review (January through June)