Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Endpoint

1/19/2017
03:15 PM
Connect Directly
Twitter
LinkedIn
RSS
E-Mail
50%
50%

Number Of Data Breach Disclosures Jumped 40% in 2016

Though there were no mega breaches, 2016 had more breaches on record than any previous year, according to a new report.

Last year witnessed few data breaches of the kind that rocked 2015 when organizations like Anthem, the Office of Personnel Management and Ashley Madison reported security incidents involving tens of millions of personal records. Still, 2016 was a pretty bad year for data breaches.

New data from the Identity Theft Resource Center (ITRC) and CyberScout show that 2016, in fact, had more reported breaches than any previous year.

A total of 1,093 security incidents involving loss of sensitive data were disclosed last year. The number represented a 40 percent jump compared to the 780 breaches reported in 2015. In all, about 36.7 million records were exposed in the breaches, which the two organizations described as any incident where an individual’s name along with their driver’s license number, Social Security Number, bank or financial account data, medical records and credit or debit card data is exposed.

In keeping with recent trends, the business sector including retail organizations, suffered the most number of breaches and accounted for 495 or 45.2% of all reported incidents. Healthcare organizations, with 377 breaches or 34.5% of the reported total, ranked second in the list of most breached organizations, followed by educational institutions with 98, and then government and military entities with 72 reported incidents.

In terms of raw numbers, banks and credit card companies had fewer breaches (52) than organizations in any of the other sectors included in the data breach report. However, that number does not tell the full story of the extensive financial damage caused to several banks in 2016 by attackers who exploited the SWIFT messaging network to illegally transfer huge sums of money to offshore accounts.

Hacking, payment card skimming, and phishing attacks represented the leading cause for data loss for the eighth year in a row, according to CyberScout and the ITRC. Combined, the three attack methods accounted for 55.5% of all reported security breaches last year, or nearly 18% higher than in 2015.

Many of the phishing attacks — the report does not specify an exact number — involved CEO business email compromise schemes, and resulted in the exposure of highly sensitive corporate data including those related to state and federal tax filings.

Non-malicious slip-ups, like accidentally sending out an email with sensitive customer data or employees negligently posting confidential data on a public facing website, accounted for a surprisingly high 9.2% — or nearly 1,000 — of the reported incidents last year.

Eva Velasquez, president and CEO of ITRC says it is not entirely clear if the higher number of data breaches in 2016 occurred because there were more actual breaches, or simply because more of them are being reported under new disclosure requirements.

“It is our opinion that both are factors here, but that it is more likely that breaches are actually being discovered due to more robust security measures being in place,” she says.

While the business sector was most impacted last year, it is important keep in mind that over time other sectors have been impacted more heavily for different reasons, Velasquez points out. At one time, for instance, financial companies were big targets since attackers perceived them as having a lot of valuable information. In recent years, the medical and business sectors have gone back and forth as favorite targets.

A study released in December by TrapX showed that attacks on healthcare organizations for instance, grew 63% in 2016 and included some major incidents such as a breach at Banner Health that exposed 3.6 million records, and another at Newkirk Products which compromised 3.4 million records.

 “As the thieves come up with more creative ways to monetize our data, different data becomes more valuable, hence the thieves change their targets,” Velasquez says.

Data breaches have become more or less the third certainty in life, adds Adam Levin, chairman and founder of CyberScout. “Businesses of every size and stripe are under assault practically every minute of every day,” Levin says.

“As defenders, they must get everything right while an attacker need find only one point of vulnerability … and make no mistake, foreign and domestic attackers are well armed, fully weaponized and in war mode.”

Related Content:

 

Jai Vijayan is a seasoned technology reporter with over 20 years of experience in IT trade journalism. He was most recently a Senior Editor at Computerworld, where he covered information security and data privacy issues for the publication. Over the course of his 20-year ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Shantaram
50%
50%
Shantaram,
User Rank: Ninja
1/20/2017 | 12:26:42 PM
Re: 192.168.0.1
Thanks, nice thoughts!
kbannan100
50%
50%
kbannan100,
User Rank: Moderator
1/19/2017 | 11:30:13 PM
Data loss
There's a Ponemon study that finds 62 percent of respondents said they are "pessimistic about their ability to prevent the loss of data contained in printer mass storage and/or printed hard copy documents." I wonder how many breaches came from something simple yet underprotected such as printers? Also from the study: "56 percent of respondents believe employees in their organizations don't see printers and hard copy documents as an area of high security risk." 

Add people who don't see printers as a risk to the fact that there are still printers that are unsecured or unpatched and you've got a problem. 

--Karen Bannan for IDG and HP
COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/9/2020
Introducing 'Secure Access Service Edge'
Rik Turner, Principal Analyst, Infrastructure Solutions, Omdia,  7/3/2020
Russian Cyber Gang 'Cosmic Lynx' Focuses on Email Fraud
Kelly Sheridan, Staff Editor, Dark Reading,  7/7/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal, a Dark Reading Perspective
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5607
PUBLISHED: 2020-07-10
Open redirect vulnerability in SHIRASAGI v1.13.1 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
CVE-2020-15001
PUBLISHED: 2020-07-09
An information leak was discovered on Yubico YubiKey 5 NFC devices 5.0.0 to 5.2.6 and 5.3.0 to 5.3.1. The OTP application allows a user to set optional access codes on OTP slots. This access code is intended to prevent unauthorized changes to OTP configurations. The access code is not checked when u...
CVE-2020-15092
PUBLISHED: 2020-07-09
In TimelineJS before version 3.7.0, some user data renders as HTML. An attacker could implement an XSS exploit with maliciously crafted content in a number of data fields. This risk is present whether the source data for the timeline is stored on Google Sheets or in a JSON configuration file. Most T...
CVE-2020-15093
PUBLISHED: 2020-07-09
The tough library (Rust/crates.io) prior to version 0.7.1 does not properly verify the threshold of cryptographic signatures. It allows an attacker to duplicate a valid signature in order to circumvent TUF requiring a minimum threshold of unique signatures before the metadata is considered valid. A ...
CVE-2020-15299
PUBLISHED: 2020-07-09
A reflected Cross-Site Scripting (XSS) Vulnerability in the KingComposer plugin through 2.9.4 for WordPress allows remote attackers to trick a victim into submitting an install_online_preset AJAX request containing base64-encoded JavaScript (in the kc-online-preset-data POST parameter) that is execu...