News Security

Major Data Breaches That Hit Headlines In 2023

Cyberattacks in India
Cyber threats are omnipresent whether its government or private organisation every organisation feels the threat related to data breaches. Here are notable instances of data breaches and cybersecurity incidents reported in 2023

Despite the progress made in digital infrastructure, the challenge of data breaches persists, presenting significant risks to both government and private entities. Protecting the information of millions of citizens and users is an enormous undertaking. Governments worldwide, in tandem with corporations, face difficulties in ensuring the security of user data. Nevertheless, it’s crucial to acknowledge that no security system is entirely foolproof, as indicated by instances of data leaks reported globally.

MOVEit Cyberattack Rocks 2,000 Organisation Worldwide

In May 2023, a ransomware gang exploited a zero-day vulnerability, compromising the security of over 2,000 organisations globally. Among the victims were notable entities like New York City’s public school system, British Airways, and the BBC. The attackers targeted a weakness in Progress Software’s MOVEit transfer protocol, leading to data theft from government, public, and business organisations. Despite a post-attack patch, legal repercussions ensued, with IBM facing lawsuits related to the breach.

Aadhaar Data Breach Shakes India’s Cybersecurity Landscape

In October, Resecurity, a cybersecurity company, reported a massive data breach affecting 815 million Indian citizens. Personal information, including Aadhaar numbers and passport details, surfaced on the dark web. While the source of the leak remained unclear, threat actors claimed access to a 1.8 terabyte data leak related to an undisclosed Indian law enforcement agency.

WordPress Sites Targeted 

Over 17,000 WordPress websites fell victim to a relentless campaign exploiting known flaws in premium theme plugins. The attackers inserted Linux backdoors, redirecting users to fake tech support pages and scams. The campaign, active since 2017, operated in six waves, using unique tactics to tackle detection. Popular themes like Newspaper and Newsmag were targeted, putting a vast number of websites at risk.

Boeing Faces Data Leak After Ransomware Attack

One of the world’s largest defence and space contractors, Boeing, experienced a cybersecurity incident resulting in the release of internal data by cybercriminals. A group threatened to publish sensitive information unless a ransom was paid, leading to the exposure of Boeing’s parts and distribution business data. While Boeing assured the public of no threat to flight safety, questions lingered about the compromise of defence information.

23andMe Acknowledges “DNA Relatives” Feature Breach

In October, genetics testing company 23andMe disclosed a breach in its “DNA Relatives” feature, enabling users to compare ancestry information. The breach, attributed to a credential stuffing attack, prompted the company to notify affected customers. Hackers advertised stolen data from the company’s online forum, leading to concerns about the compromise of sensitive genetic information.

Data Security Concerns India

In 2023, India faced significant challenges in data security. At the beginning of the year, RailYatri, a train ticketing platform, confirmed a data breach in December 2022. Despite the Railway Ministry’s denial that user data sold on the dark web originated from the Railways, RailYatri acknowledged the breach.

Another incident involved an alleged leak in the CoWIN portal, where a bot on Telegram shared personal data of Indian citizens. This included names, Aadhaar, and passport numbers of those registered on the COVID-19 vaccine network. Despite the Health Ministry dismissing the reports as “mischievous,” it acknowledged that the Indian Computer Emergency Response Team (CERT-In) was assessing the portal’s security. Subsequently, authorities in Bihar apprehended a man and a juvenile in connection with the alleged data leak.

Despite official denials and scrutiny by relevant authorities, these occurrences highlight the persistent difficulties in ensuring the security of sensitive information.

Leave a Reply

Your email address will not be published. Required fields are marked *