In today’s IS news roundup, we will explore the details of the FlightAware and Enzo Biochem cases.
On August 19th, a popular flight tracking platform, FlightAware, disclosed experiencing a data security incident. In this regard, the company asked all potentially impacted users to reset their account login passwords. The shocking part of the story is that the incident was caused by a configuration error that has not been noticed since January 1, 2021. The problem was only discovered on July 25, 2024. According to FlightAware’s notice, exposed data may have included:
Depending on the information users provided, the leaked data may also have included full names, billing and shipping addresses, IP addresses, social media accounts, telephone numbers, birth dates, the last four digits of credit card numbers, Social Security numbers, information about aircraft owned, industry, title, pilot status (yes/no), and account activity.
A similar carelessness led Enzo Biochem, a diagnostic testing provider, to a $4.5 million penalty. This penalty was issued due to a 2023 April ransomware attack that impacted 2.4 million patients.
The investigation revealed that five employees of Enzo were sharing two login credentials, one of which had not been changed for about 10 years. Hackers managed to access the company’s systems and install malicious software using these two staff members’ login credentials.
The information compromised as a result of the breach included:
As you can see, many serious data-related incidents are rooted in internal factors. If you want to mitigate such risks and provide your organization with a quality yet affordable solution, consider SearchInform Managed Security Services. The service allows users to get all the key aspects of internal security under control without creating a financial burden. Click here and get a 30-day free trial.
SearchInform uses four types of cookies as described below. You can decide which categories of cookies you wish to accept to improve your experience on our website. To learn more about the cookies we use on our site, please read our Cookie Policy.
Always active. These cookies are essential to our website working effectively.
Cookies does not collect personal information. You can disable the cookie files
record
on the Internet Settings tab in your browser.
These cookies allow SearchInform to provide enhanced functionality and personalization, such as remembering the language you choose to interact with the website.
These cookies enable SearchInform to understand what information is the most valuable to you, so we can improve our services and website.
These cookies are created by other resources to allow our website to embed content from other websites, for example, images, ads, and text.
Please enable Functional Cookies
You have disabled the Functional Cookies.
To complete the form and get in touch with us, you need to enable Functional Cookies.
Otherwise the form cannot be sent to us.
Subscribe to our newsletter and receive a bright and useful tutorial Explaining Information Security in 4 steps!
Subscribe to our newsletter and receive case studies in comics!