Attacks/Breaches
12/15/2011
08:59 AM
50%
50%

5 Big Database Breaches Of Late 2011

Healthcare breaches have dominated the second half of the year. Consider these lessons learned.

Though the second half of the year has been comparably calmer than the first half's database breaches at RSA, Sony, and Epsilon, the breach numbers continued to roll in--especially at healthcare organizations, which made up a disproportionate number of exposed records. Here are some of the biggest breaches that went down in the second half of the year, along with a few database security lessons learned.

1. The Breach Victim: Nemours
Assets Stolen/Affected: Names, addresses, dates of birth, Social Security numbers, insurance data, medical treatment data, and bank account information for 1.6 million patients, vendors, and employees.

Three unencrypted tapes containing a mother lode of personal information on patients, vendors, and employees were lost amid the dust of a facility remodel project when a cabinet that held them since 2004 went missing.

Lessons Learned: Database backups are often the Achilles' heel in enterprise database security. Because of their portability and longevity, database backup tapes are frequently lost in transit or in these types of relocation scenarios. Encryption of data is key to ensuring security even when tapes can't be physically secured.

[ From healthcare to game companies to trusted third-party security companies, a number of significant breaches were reported in 2011. See Slide Show: The Year In Data Theft. ]

2. The Breach Victim: Tricare/SAIC
Assets Stolen/Affected: Protected health information from 5.1 million patients of U.S. military hospitals and clinics.

Another day, another backup tape gone missing. In September, Tricare announced that an employee for one of its contractors, Science Applications International Corp. (SAIC), was driving around with a backup tape containing patient data from 1992 all the way through 2011 for San Antonio-area military treatment facilities. The tapes were stolen from the car, exposing Social Security numbers, addresses, phone numbers, clinical notes, lab test results, prescriptions, and other medical information.

Lessons Learned: In addition to the lessons about backup tape protection, this case shows how important third-party contractor security procedures are to an organization. Enterprises and government agencies alike must be aware of how contractors are touching database information and whether they're employing best practices with regard to how that data is handled.

Read the rest of this article on Dark Reading.

IT's spending as much as ever on disaster recovery, despite advances in virtualization and cloud techniques. It's time to break free. Download our Disaster Recovery Disaster supplement now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Lisa Henderson
50%
50%
Lisa Henderson,
User Rank: Apprentice
12/16/2011 | 2:04:24 AM
re: 5 Big Database Breaches Of Late 2011
Each scenario is perfect in what happens either in a worst case scenario, bad planning, and even not seeing the obvious. The lessons learned are important. I'm amazed we don't see more stories about the negative results of these breaches.

Lisa Henderson, InformationWeek Healthcare, contributing editor
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5314
Published: 2014-11-23
Buffer overflow in Cybozu Office 9 and 10 before 10.1.0, Mailwise 4 and 5 before 5.1.4, and Dezie 8 before 8.1.1 allows remote authenticated users to execute arbitrary code via e-mail messages.

CVE-2014-5325
Published: 2014-11-23
The (1) DOMConverter, (2) JDOMConverter, (3) DOM4JConverter, and (4) XOMConverter functions in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allow remote attackers to read arbitrary files via DOM data containing an XML external entity declaration in conjunction with an entity refe...

CVE-2014-5326
Published: 2014-11-23
Cross-site scripting (XSS) vulnerability in Direct Web Remoting (DWR) through 2.0.10 and 3.x through 3.0.RC2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2014-6477
Published: 2014-11-23
Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4290, CVE-2014-4291, CVE-2014-4292, CVE-2014-4...

CVE-2014-4807
Published: 2014-11-22
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?