- 11 months ago
On this episode of Incognito Mode, join WIRED Senior Editor Andrew Couts for a deep dive into the six worst data breaches of the past 10 years.
Category
🤖
TechTranscript
00:00Data breaches happen literally all the time.
00:04Something is probably getting hacked right now.
00:06Today, we'll do a deep dive into the six worst data breaches of the past 10 years.
00:10This is incognito mode.
00:19In July 2015, a person or group calling themselves the Impact Team
00:23announced that they had hacked AshleyMadison.com,
00:26a website used for people who want to cheat on their spouses.
00:28A website that I definitely only heard about for the first time this morning.
00:34Impact Team threatened to release the data on all of AshleyMadison's users
00:37unless its parent company, Avid Life Media,
00:39deleted AshleyMadison.com as well as its sister site, EstablishedMen.
00:43Instead of deleting the websites, Avid Life Media released several statements
00:46basically saying that they were dealing with a breach.
00:49In response, Impact Team released the details of 2,500 accounts to prove that they had the data.
00:54A month later, after Avid Life Media failed to delete the websites,
00:57Impact Team released the account details of all of AshleyMadison's 36 million users.
01:01Unlike some criminal hackers, which wage attacks simply to get money,
01:05or state-sponsored hackers, which do it for other purposes like espionage,
01:08hacktivists generally wage attacks simply to make a moral point,
01:11such as getting a website for cheaters off the internet.
01:14You have a lot of people that are freaking out right now that are very concerned that this
01:18information would never get out and back to their spouses. These email addresses can be
01:22used for other things. They can be used for identity theft. They can be used for blackmail
01:26and extortion.
01:27The data Impact Team released included phone numbers, email addresses, including thousands
01:31linked to U.S. military and government accounts, as well as other details. It also revealed that,
01:36while Avid Life Media charged people $19 to have their accounts deleted,
01:39it didn't actually delete that data. It was just removing profiles. The company is said to have
01:43made $1.7 million a year just from people having their data deleted. The leak also exposed some 1200
01:49Saudi Arabian email addresses, which is particularly dangerous because adultery is punishable by death
01:55in Saudi Arabia. Also exposed was Josh Duggar, a member of the reality TV show 19 Kids and Counting,
02:00a family-focused show that promoted Christian values. Duggar was later convicted as a sex offender
02:05on unrelated charges. Reporting found that some 70% of Ashley Madison's users were men,
02:10and of the few women that were on the site, many of them only logged in once or were just bots.
02:14Impact Team's leak led to widespread harassment and shaming of Ashley Madison users, and reportedly
02:19led to at least two deaths by suicide. Avid Life Media ultimately faced a major class action lawsuit
02:24and was forced to settle. But the data that Impact Team released is still online. So is
02:28AshleyMadison.com, and the perpetrators remain unknown. In October 2020, a popular chain of
02:36mental health clinics in Finland called Vastamo announced that it had been breached. The attacker
02:40said that they had stolen patient records and was extorting the company for 40 Bitcoin, or roughly 400,000
02:45Euros at the time. The hacker had the records of roughly 36,000 patients. For a country with just 5.5
02:51million people, this breach made it one of the worst crimes impacting the most people in Finnish history.
02:55Not only that, but this breach was extremely cruel, impacting some of the most sensitive
02:59information about a person, including notes with their therapist and other health information.
03:03The hacker, using the name Ransom Man, first tried extorting the company directly. When that failed,
03:08he began trying to blackmail patients individually, sending out tens of thousands of ransom notes,
03:13threatening to reveal patient information. Records show that the hacker accessed the company's
03:17systems not once, but twice. A flaw in the company's IT system exposed the entire patient
03:21database to the internet. This gave the hacker access to unencrypted records that were
03:25not anonymized. As part of the extortion scheme, the hacker was posting patient records daily,
03:30in an attempt to pressure Vossamo to pay the ransom. The hacker was later revealed to be
03:33Julius Kivamaki, a member of the infamous hacker group Lizard Squad, which was responsible for the
03:382014 Christmas hacks of Xbox Live and the PlayStation Network. Why did you do this? It affected so many
03:44people. Why we did it? Mostly to raise awareness, to amaze ourselves. In February 2023, Kivamaki was
03:50arrested in France and was ultimately convicted of the Vossamo hack and sentenced to six years and
03:54three months in Finnish prison. Recently, Kivamaki was released from custody as he appeals his case.
03:59Vossamo has since gone bankrupt.
04:04In 2015, a security engineer was doing a routine checkup on the network of the Office of Personnel
04:09Management, a U.S. government agency that handles employment for most of the federal government.
04:13That routine checkup ultimately led to the discovery of one of the biggest hacks of a U.S.
04:17government agency in history. More than 21 million Americans had personal information
04:22stolen from government files in a data breach that was six times as large as originally disclosed.
04:28OPM is basically like the HR department for the U.S. federal government. That means they have a
04:32mountain of information about everyone who works for the federal government or applies for a job
04:36there or has ever worked there in the past. Around the time of the breach, OPM was spending off more
04:41than 10 million attempted digital intrusions a month. In this case, hackers were able to exploit a
04:45vulnerability in OPM systems and install malware on fewer than 10 servers, one of which is known as
04:50the jump box, which gave them access to OPM's entire system. Now, you might think a hack of this scale
04:55would be really obvious and easy to detect. But in this case, security personnel had to follow small
05:00digital breadcrumbs, which ultimately led them to a website called opmsecurity.org. This third-party
05:06website was registered by somebody under the name Steve Rogers or Captain America. That Captain America
05:12reference ultimately led investigators to a Chinese military hacking group, which often referenced
05:17Captain America in their breaches. At this point, OPM knew that it had been hit by an advanced persistent
05:22threat or APT, which is typically a state-sponsored group of hackers. Now, when we're talking about APTs,
05:28we're not talking about some kids causing havoc or even cyber criminals trying to make money. We're
05:33talking about the world's most advanced hackers, which are often steal this data and use it for espionage
05:37purposes, blackmail, or national security reasons. Among the most sensitive data stolen in the OPM
05:43breach was its trove of what's known as Standard Form 86. The SF-86 questionnaire can include all
05:48types of sensitive questions, including those about personal finances, past drug use, and psychiatric care.
05:54Word coming down late this afternoon of what sources are telling us is a massive Chinese hack of U.S.
06:00government computers, perhaps on a scale never seen in this country before.
06:04So how big is this breach? Well, to give you some figures, at the time, OPM was processing more
06:09than 2 million background checks a year. That includes everyone from federal contractors to
06:14federal judges. OPM's database included more than 18 million archived copies of Standard Form 86. It
06:20also gathered data on applicants for some of the government's most secretive jobs. That data can
06:25include everything from the results of lie detector tests to notes on people's sexual behavior. The
06:30hackers also grabbed personnel files on 4.2 million past and present government employees. And finally,
06:36just before the breach was revealed, the hackers grabbed 5.6 million images of fingerprints. The
06:41hack of OPM ultimately exposed 22.1 million records on U.S. government employees, people who had undergone
06:47background checks, and their families. At the time, there was a lot of speculation about what the Chinese
06:52military hackers would do with the data they had stolen. Some of these included recruiting spies or even
06:57creating fake fingerprints for bypassing biometric security. But it's still a mystery why the hackers
07:02wanted the data and what they might have done with it. Massive personal data breach. Equifax,
07:11the credit monitoring company, says the social security numbers of 143 million Americans may have
07:17been exposed. One of the most infamous hacks of all time is the 2017 breach of Equifax, a major credit
07:23reporting agency. Attackers had gained unauthorized access to certain Equifax data files. The hack exposed
07:30personal records of nearly 148 million Americans, along with roughly 14 million UK citizens and 19,000
07:36Canadian citizens. This makes it one of the largest exposures of personal data in history. This was a
07:42massive breach affecting most adult consumers in this country. But what was also exposed was Equifax's really
07:49poor security practices. Just to give you a sense of what Equifax is, it's one of the top three major
07:54credit reporting bureaus. It operates in 24 countries, and it has an annual revenue of around $5 billion.
08:00Given that the company handles extremely sensitive data like your social security number and even
08:04issues credit scores, you would think that security would be their utmost priority. A scathing new report
08:10finds one of the largest data breaches in the US history was entirely preventable. The Equifax breach
08:15began in May of 2017, but the company didn't learn about it until July, and it didn't tell the public
08:20about it until September. To make matters worse, there was a patch available to the vulnerable
08:24software the hackers exploited all the way back in March, which means Equifax had two months to fix
08:29its systems, which would have prevented the hack. Investigators found that Equifax failed to use
08:33multi-factor authentication and even used the username and password admin for one of their portals. Maybe they
08:38should have been reading Wired to find out why they should not do that. Equifax's poor security practices
08:43was already known to the company years before. An audit in 2015 found that Equifax's IT team wasn't
08:49following the company's own patching schedules. The data stolen from Equifax included people's names,
08:53social security numbers, date of birth, addresses, and driver's license numbers. And some people even
08:58had their credit card numbers stolen. There are strangers out there that know who I am,
09:02they know my birth date, they know my social security number, and they know specifically where I live.
09:07That scares me. In 2019, Equifax agreed to pay the US federal government and all 50 states
09:12between $575 million and up to $700 million as a result of the breach. As part of the settlement,
09:18Equifax agreed to pay $300 million to affected customers and also provide them with free credit
09:23monitoring services. In 2020, the US Department of Justice charged four members of the Chinese
09:28People's Liberation Army with crimes related to the Equifax breach. China's government denies
09:32their involvement and this data has never been posted online. If you were anywhere near the internet or
09:39our television during the contentious 2016 presidential election in the United States,
09:43all you heard about was Russia, Russia, Russia. There was Russian bots in our comments,
09:47there was fake news, there was Russian meddling all over the place, or so some said. No matter
09:52what anyone says about Russia's involvement in that hectic 2016 election, one thing we do know is
09:57that Russia's military hacked the Democrats and we have the emails to prove it. The 2016 hacks against
10:02the Democrats wasn't just one hack and it wasn't even just one group. It's been reported that it was
10:06two separate Russian military hacking groups known as Cozy Bear and Fancy Bear. In summer of 2015,
10:11Cozy Bear, a hacker group tied to the Russian military, gained access to the servers of the
10:16Democratic National Committee. Separately, in March 2016, Fancy Bear hackers gained access to the personal
10:21email of John Podesta, Hillary Clinton's presidential campaign chair. Then in April of that year,
10:26Fancy Bear also gained access to the DNC servers. When the breaches of the DNC were first revealed,
10:30experts believe that Cozy Bear and Fancy Bear were operating independently and had no knowledge of each
10:35other's activities, which is common among Russian military hackers. The U.S. intelligence community
10:40even concluded that Russia hacked the Democrats in order to help the election of Donald Trump.
10:44WikiLeaks! I love WikiLeaks! In June of 2016, someone operating under the name Guccifer 2.0 started
10:51pinging reporters with offers of leaked emails from the DNC and the Clinton campaign. Ultimately,
10:55some 44,000 emails would be released online either by a website called DCLeaks or by WikiLeaks,
11:00the radical transparency organization run by Julian Assange. One of the biggest scandals to come out of the
11:05email leaks was evidence that the Democratic Party clearly favored Hillary Clinton over Senator
11:10Bernie Sanders in the 2016 primary. So this is another set of email problems for the Democrats
11:15and Hillary Clinton. Bernie Sanders supporters are very upset by these revelations that shown in
11:19these emails. However, the ultimate result was just pure chaos, and it's led to a lot of weird
11:24things in American politics, from the mainstreaming of conspiracy theories to the ultimate distrust of
11:29pretty much everyone in the political sphere. Another lasting consequence was the rise of Pizzagate and
11:34other conspiracy theories, which stemmed from the Podesta email leaks. Pizzagate, if you don't
11:38remember, is the completely unfounded conspiracy theory that Democrats are a pedophilic cabal that
11:43included raping children in the basement of a pizza shop in Washington, DC. A pizza shop,
11:47it should be noted, that does not have a basement. The rise of Pizzagate ultimately led to the rise of
11:51QAnon, which ultimately led to the weird, polarized, fractious political environment we're in today.
11:56This is a good example of state-sponsored hackers stealing data, not for the data itself, but for what
12:01releasing that data could do. In late 2024, U.S. officials revealed that roughly 10 U.S.
12:08telecommunication companies had been infiltrated by Salt Typhoon, a hacker group tied to China's
12:13government. The hacked telecom companies include AT&T, Verizon, and T-Mobile, and several others.
12:19The Salt Typhoon hackers were found to have been spying on the phone calls and text messages of
12:22both the Harris and Trump campaigns, as well as the office of then-Senate Majority Leader Chuck Schumer.
12:27It was later revealed that Salt Typhoon successfully hacked the U.S. National Guard. In August, the FBI
12:32said that Salt Typhoon hackers had targeted 600 organizations in 80 countries, including 200
12:38American companies. Salt Typhoon's breach of U.S. telecommunications networks is seen as the worst
12:42telecom hack in U.S. history. The Chinese hackers were in the American telecom system for probably a
12:49year before they were detected. It's so bad that even the FBI recommended that people use encrypted
12:54messaging systems like Signal to protect their communications. While companies and government
12:58officials say they've taken steps to mitigate Salt Typhoon's attacks, they've stopped short of saying
13:02they've completely eliminated the threat, knowing that Salt Typhoon hackers are difficult to root out.
13:07Because Salt Typhoon's hacking campaign is still ongoing, the impacts of these breaches are unknown.
13:12This has been Incognito Mode. Until next time.
Comments