YEAR OF THE

BREACH
@appnetsecurity

linkedin.com/in/mprerad

mprerad@gmail.com
1993.
1993.

2013.
2164

Data breach
incidents
2164

Data breach
incidents

60% HACKING
2164

Data breach
incidents

60% HACKING

71.2% EXTERNAL
2164

Data breach
incidents

60% HACKING

71.2% EXTERNAL

822 MILLION
DATA RECORDS STOLEN IN 2013
THAT‘S ABOUT

1/9
OF WORLD
POPULATION
IN 2013 ONLY
96.8%
of all exposed records involved
outside the organization activity
540+ MILLION
OF RECORDS EXPOSED

NEARLY

1/2

OF INCIDENTS

66.5%
of ALL exposed records
369 million
exposed records
TOP 5 BREACHES OF 2013
“ There are only two types of companies:

those that have

been hacked

and those that will

be hacked.”
Robert S. Mueller, III
Director, FBI
LARGEST
DATA BREACHES

OF 2013
Biggest breach in history

152+ MILLION
username + hash password combo

2.8+ MILLION
credit card information
+ source code leak
110+ MILLION
RECORDS EXPOSED

70+ MILLION
NAMES, EMAILS, PHONES

40+ MILLION
CREDIT/DEBIT CARDS
58+ MILLION
names, encrypted passwords, emails
54 MILLION
ID‘s, addresses, names

“in two hours hackers downloaded all the information.”

70%

of whole Turkish

population

Hacked system (for Database and
website Management) didn’t have
ANY security product installed.
50+ MILLION
names, encrypted passwords, emails
50+ MILLION

names, encrypted passwords, emails, date of birth
Good Job: credit card info stored on separate system
Bad Job: SHA1 hashing algorithm used – low protection
42 MILLION
name, encrypted password, emails, birthday

* 56 Homeland Security Dept. employees
22 MILLION
user ID‘s (login), no passwords stolen

No real big value, except possible SPAM
or selling database of emails
20+ MILLION
emails, physical address, phones

* data stolen from hotel reservations
6 MILLION
email and/or phone number

Bug in DYI (Download Your Information) feature
Allowed downloading contacts from friends

Facebook keeping it as small story as
possible outcome is companies
blocking access to FB from work again
4.6 MILLION
Usernames and phone numbers

Announced on 31st December, soon after
declining Facebook offer. Coincidence?
4+ MILLION
username and password combo

No credit card data stolen, stated by Groupon Taiwan
2nd largest HIPAA
breach ever reported to HHS

4+ MILLION

names, addresses, social security number, date of birth

How? 4 unencrypted computers were stolen from HQ
2.4 MILLION
social security numbers, bank accounts, drivers licenses.

Waited 7 months to notify affected persons!
2.4 MILLION
full credit card details

Started by infecting PC‘s with Malware!
It will cost Schnucks several millions of $$$
2 MILLION

names, addresses, ID‘s, bank details, phone numbers

INSIDER INTRUSION!
„PONY“ BOTNET ATTACK
2+ MILLION
username, passwords

318.121
70.532
59.549
21.708
Keystroke logging used
1.82 MILLION
username, password, email
by exploiting Adobe’s ColdFusion app server

1 MILLION
drivers license numbers, names

160.000
social security numbers
1+ MILLION
usernames, emails, hashed passwords

Infected through 3rd party software
860.000+
usernames, emails, hashed passwords

Zero Day Remote Code Execution
“We found a critical vulnerability in
all vBulletin versions 4.x.x and 5.х.x. and
have successfully uploaded our shell on
the official vBulletin server and dumped
their database after getting root access. ”
Critical breach!

850.000

credit card numbers, expiry dates and
associated names and addresses

241.000

high or no-limit American Express
including Fortune 500 CEOs and A-list celebrities
465.000
unknown portion of data

Data of card holders leaked through
temporay unencrypted log file
300.000

names, email addresses, passwords, phone numbers
Hackers tried to BLACKMAIL company

asking for $50.000 for stolen data
250.000
usernames, emails, passwords
100.000+
usernames, emails, addresses

Researcher hack, not real threat
BUT...
1 EVENT
BECAME
HISTORY
...AND 1 BECAME FUNNIEST 

* Anonymous hacked North Korean websites, twitter, flickr...
1 HACKER GROUP
WAS VERY ACTIVE
Hacked by Syrian Electronic Army
Let me remind you of...
Biggest incidents in 2011/2012
2.5 BILLION
TOTAL NUMBER OF
STOLEN RECORDS

* in history
THAT‘S ABOUT POPULATION OF

+
India

China
SEE WORLD‘S BIGGEST DATA BREACHES

VISUALIZED

http://www.informationisbeautiful.net/visualizations/worlds-biggest-data-breaches-hacks/
HAVE YOU
BEEN HACKED

???
Mihajlo Prerad
slideshare.net/mprerad
@appnetsecurity
linkedin.com/in/mprerad

mprerad@gmail.com
Thank You!

Biggest Data Breaches of 2013