Attacks/Breaches

11/15/2016
09:00 AM
Jai Vijayan
Jai Vijayan
Slideshows
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

The 7 Most Significant Government Data Breaches

Mega compromises at federal and state agencies over the past three years has compromised everything from personal data on millions to national security secrets.
Previous
1 of 8
Next

Data maintained by Privacy Rights Clearinghouse shows that federal and state government agencies publicly disclosed a total of 203 data breaches over the past five years.

In all, the breaches resulted in nearly 47 million records being stolen, exposed or otherwise compromised. The number of breached records does not include the numerous cases where agencies either did not disclose the scope of their data breach or the actual number of records that might have been involved.

It also does not include data from incidents like Edward Snowden’s theft of classified documents from the National Security Agency (NSA) or the recently disclosed theft of 50 TB of government data by another former contractor for the NSA and other federal agencies.

In terms of raw numbers, federal and state government agencies suffereda lot fewer breaches and exposed fewer data records than private companies. PRC numbers show that between 2012 and 2016 for instance, financial and insurance companies, retailers, and other businesses disclosed some 950 breaches involving 244.5 million records.

What makes the government breaches more significant though is the kind of information involved. In a majority of cases, government breaches involved personally identifying data, such as names, Social Security numbers, and birthdates, the loss of which have substantially greater consequences for victims than breaches involving loss of credit card data or email account information. In a few cases, the breaches involved loss of top secret and highly confidential data of national security value.

Here, ranked in ascending order of severity, are seven of the most significant government data breaches of the past three years.

 

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio

Previous
1 of 8
Next
Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ClaireEllison
50%
50%
ClaireEllison,
User Rank: Apprentice
11/21/2016 | 4:22:24 PM
Re: amazing
A great post with good questions/ But how to avoid that? I really wanted to send a small word to say thanks to you for the fantastic points you are writing on this site.
ONI SEO
50%
50%
ONI SEO,
User Rank: Apprentice
11/18/2016 | 11:34:05 AM
Mr ROBOT comes soon?
A great post with good questions/ But how to avoid that? What kind of solutions?
kbannan100
50%
50%
kbannan100,
User Rank: Apprentice
11/17/2016 | 10:59:38 PM
It's going to take a village
These breaches are just the tip of the iceberg. We all know that. One of the biggest problems is the amount of unsecured endpoints that are out there. Things like printers that aren't secured and laptops that aren't running antivirus or -- if they are -- have not been patched. It's going to take a lot more work on everyone's behalf before the good guys get ahead of the criminals. 

--Karen Bannan for IDG and HP
Meet 'Bro': The Best-Kept Secret of Network Security
Greg Bell, CEO, Corelight,  6/14/2018
Containerized Apps: An 8-Point Security Checklist
Jai Vijayan, Freelance writer,  6/14/2018
Four Faces of Fraud: Identity, 'Fake' Identity, Ransomware & Digital
David Shefter, Chief Technology Officer at Ziften Technologies,  6/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-0363
PUBLISHED: 2018-06-21
A vulnerability in the web-based management interface of Cisco Unified Communications Manager IM & Presence Service (formerly CUPS) could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulne...
CVE-2018-0364
PUBLISHED: 2018-06-21
A vulnerability in the web-based management interface of Cisco Unified Communications Domain Manager could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSR...
CVE-2018-0365
PUBLISHED: 2018-06-21
A vulnerability in the web-based management interface of Cisco Firepower Management Center could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack and perform arbitrary actions on an affected device. The vulnerability is due to insufficient CSRF protecti...
CVE-2018-0371
PUBLISHED: 2018-06-21
A vulnerability in the Web Admin Interface of Cisco Meeting Server could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to insufficient validation of incoming HTTP requests. An attacker could exploit this vulnerability by sending a craf...
CVE-2018-0373
PUBLISHED: 2018-06-21
A vulnerability in vpnva-6.sys for 32-bit Windows and vpnva64-6.sys for 64-bit Windows of Cisco AnyConnect Secure Mobility Client for Windows Desktop could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. The vulnerability is due to improper ...