Here comes our report on recent data leakages. Today, let's examine the incidents those resulted in the disclosure of customer information at two large companies.
Casio Computer Co. Ltd, an electronics manufacturer based in Japan, reported a leak of customer personal information.
The incident came to light after an employee discovered a database failure. Upon investigation, Casio determined that an unauthorized party had gained access to web application "ClassPad.net" database within its development environment.
It is alleged that approximately 92,000 records, containing details of Japanese customers and more than 35,000 records, containing details of customers in other countries were accessed. The affected clients included both private individuals and educational institution customers.
Leaked data included:
Casio officials claimed that "some of the network security settings in the development environment were disabled due to an operational error of the system by the responsible department and insufficient operational management".
After discovering the incident, the company notified law enforcement and Japan's data watchdog. At this time, the vulnerability has been fixed and the ClassPad.ne application is working correctly.
The second incident we examine also involves exposure of personal information, kept in an unprotected database.
Indian medical diagnostics company Redcliffe Labs left its database unprotected, exposing the personal information of more than 12 million patients. The vulnerability in the database was discovered by cybersecurity researcher Jeremiah Fowler. He claimed that the total size of the disclosed data was 7TB.
The data involved a large number of medical records containing personal information about customers, including
It is further alleged that, in addition to the listed information, the database contained development files, related to the company’s mobile application.
According to Jeremiah, as soon as the company became aware of the incident, it immediately blocked access to the database. However, it is currently unknown how long the documents had been in the public domain.
Keeping business data organized and managing its flow can be a challenge. Classify valuable data, audit access rights, archive critical documents and monitor user’s operations on data with SearchInform FileAuditor and be confident that your corporate data is safe.
SearchInform uses four types of cookies as described below. You can decide which categories of cookies you wish to accept to improve your experience on our website. To learn more about the cookies we use on our site, please read our Cookie Policy.
Always active. These cookies are essential to our website working effectively.
Cookies does not collect personal information. You can disable the cookie files
record
on the Internet Settings tab in your browser.
These cookies allow SearchInform to provide enhanced functionality and personalization, such as remembering the language you choose to interact with the website.
These cookies enable SearchInform to understand what information is the most valuable to you, so we can improve our services and website.
These cookies are created by other resources to allow our website to embed content from other websites, for example, images, ads, and text.
Please enable Functional Cookies
You have disabled the Functional Cookies.
To complete the form and get in touch with us, you need to enable Functional Cookies.
Otherwise the form cannot be sent to us.
Subscribe to our newsletter and receive a bright and useful tutorial Explaining Information Security in 4 steps!
Subscribe to our newsletter and receive case studies in comics!