What is a Data Breach?
Data Breach is when personal information like names, addresses, credit card numbers, email addresses, phone numbers, Social Security numbers and more is exposed to the wrong people. This can lead to identity theft, fraud, and other forms of distress for affected individuals. Many states have laws that require companies to notify people whose personal information has been compromised in the event of a breach. Some also have laws that require companies to provide remediation services like credit monitoring after a breach.
The causes of a data breach vary, but most often, they stem from identity-based risks. These include compromised credentials (through phishing, password reuse and brute force attacks) and weak authentication controls. In addition, many breaches involve third parties, including partners and vendors. This can be due to misconfigured servers, cloud storage, or shared access to internal systems.
Initial Access–Threat actors perform research and reconnaissance to identify targets and gain entry through compromised credentials or vulnerabilities. Lateral Movement–Threat actors expand their access across systems, targeting privileged accounts when possible. Data Exfiltration–Sensitive data is collected and transferred out of the environment, sometimes in small increments to avoid detection. Monetization or Extortion–The stolen data may be sold, leaked publicly or used in ransomware or extortion schemes.
The first thing to do is work with your forensics experts to determine what information was breached and who it involved. Review backup or preserved data, examine who currently has access to that information, and restrict access if necessary. Consult with your legal counsel about state and federal laws that may be implicated in the data breach.