Attacks/Breaches
1/12/2012
11:42 AM
50%
50%

Hack Attacks Now Leading Cause Of Data Breaches

Exclusive: Identity Theft Resource Center identifies hacking, followed by data lost in transit and insider attacks, as the leading data breach culprits in 2011.

10 Companies Driving Mobile Security
10 Companies Driving Mobile Security
(click image for larger view and for slideshow)
The majority of data breaches stem from hack attacks, followed by data that's lost while physically in transit. That's according to a forthcoming study from the Identity Theft Resource Center (ITRC), which assessed all known information relating to the 419 breaches that were publicly disclosed in the United States in 2011. A copy of the report was provided to InformationWeek in advance of its release.

Last year, data breaches triggered by hacking--defined by the ITRC as "a targeted intrusion into a data network," including card-skimming attacks--were at an all-time high, and responsible for 26% of all known data breach incidents. The next leading cause of breaches was data on the move (18%)--meaning electronic storage devices, laptops, or paper reports that were lost in transit--followed by insider theft (13%).

Overall, malicious attacks--counting not just hack attacks but also insider attacks--accounted for 40% of publicly disclosed breaches, while 20% of breaches were the result of accidental data exposure.

All told, the ITRC counted 22.9 million records as being exposed in 2011, of which 81% included social security numbers. Of all known breaches, 62% involved the exposure of social security numbers and 27% involved credit or debit card data.

[ Want to know more about hack attacks? Read 6 Worst Data Breaches Of 2011. ]

Online attacks aren't the only data breach threat vector. Notably, 16% of known breaches in 2011 involved paper-based breaches, although only 1.4% of the total quantity of breached records were paper-based. Paper-based breach refers to paper reports or printouts that get lost or stolen. But the ITRC said that one challenge with counting such breaches is that they typically don't get noticed until they're spotted by outsiders and reported to local media. Furthermore, many states' data breach notification laws don't require companies to report paper-based breaches.

Data breach incidence varies sharply by industry, which may be a sign of each one's overall information security program effectiveness. In 2011, the government and armed services saw the greatest volume of records exposed (comprising 44% of all exposed records), followed by non-financial businesses (33%), medical and healthcare groups (16%), educational institutions (4%), and banking, credit and financial firms (3%).

Meanwhile, non-financial businesses, as well as medical and healthcare groups, saw the largest incidence of insider theft, while non-financial businesses were hacked far more often than other industries. Notably, 17% of all breaches involved hack attacks against businesses, compared with hack attacks against banking, credit and finance (3%), education (2%), medical and healthcare (2%), and government and military (1%).

In the wake of ITRC's study of 2011 data breaches, however, a large question remains: How accurate is the underlying data? "Breaches have long been unreported, or underreported," Karen Barney, ITRC's program director, said in an email interview. "Any efforts to accurately quantify the actual number of breaches, and resulting number of compromised records, are stymied in the absence of mandatory reporting on a national level."

Indeed, in 2011, only 52% of publicly disclosed breaches actually detailed the number of sensitive records that had been exposed. Furthermore, what counts as sensitive?

"Another challenge is to clearly define how to identify the threat to consumers when the compromised information is not 'sensitive' personal information but 'non-personal' in nature," said Barney. "It is well-known that this type of information still poses a threat to consumers through spear-phishing and social engineering."

For its 2011 data breach report, the ITRC counted as sensitive only credit card or financial account numbers, as well as social security numbers, medical insurance numbers or driver's license numbers. It didn't count email addresses, passwords, or other supposedly less-sensitive pieces of data. In other words, the nearly 23 million records known to have been exposed last year doesn't count many more millions of records that were exposed, and which criminals could employ to scam people via spear-phishing and other types of social engineering attacks.

InformationWeek is conducting our third annual State of Enterprise Storage survey on data management technologies and strategies. Upon completion, you will be eligible to enter a drawing to receive an Apple 32-GB iPod Touch. Take our Enterprise Storage Survey now. Survey ends Jan. 13.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-6477
Published: 2014-11-23
Unspecified vulnerability in the JPublisher component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality via unknown vectors, a different vulnerability than CVE-2014-4290, CVE-2014-4291, CVE-2014-4292, CVE-2014-4...

CVE-2014-4807
Published: 2014-11-22
Sterling Order Management in IBM Sterling Selling and Fulfillment Suite 9.3.0 before FP8 allows remote authenticated users to cause a denial of service (CPU consumption) via a '\0' character.

CVE-2014-6183
Published: 2014-11-22
IBM Security Network Protection 5.1 before 5.1.0.0 FP13, 5.1.1 before 5.1.1.0 FP8, 5.1.2 before 5.1.2.0 FP9, 5.1.2.1 before FP5, 5.2 before 5.2.0.0 FP5, and 5.3 before 5.3.0.0 FP1 on XGS devices allows remote authenticated users to execute arbitrary commands via unspecified vectors.

CVE-2014-8626
Published: 2014-11-22
Stack-based buffer overflow in the date_from_ISO8601 function in ext/xmlrpc/libxmlrpc/xmlrpc.c in PHP before 5.2.7 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code by including a timezone field in a date, leading to improper XML-RPC encoding...

CVE-2014-8710
Published: 2014-11-22
The decompress_sigcomp_message function in epan/sigcomp-udvm.c in the SigComp UDVM dissector in Wireshark 1.10.x before 1.10.11 allows remote attackers to cause a denial of service (buffer over-read and application crash) via a crafted packet.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?