📢 Data Breach at Optus: A Lesson in API Security and Oversight In a recent court filing, Australia's Communications and Media Authority (ACMA) detailed the significant data breach at Optus, which exposed the personal information of over nine million customers. This breach, traced back to a coding error that broke API access controls, highlights critical gaps in security practices and oversight. 🔍 The Incident: --Cause: The API had two entry points, each secured in 2017. In 2021, a coding error broke one of the access control lists (ACLs). Unfortunately, the defect was only detected in one of the entry points, despite both being impacted by the same flaw. --Detection: Optus identified and fixed the issue on the Main domain in 2021, but the Target domain remained vulnerable. --Impact: In September 2022, an attacker exploited this vulnerability, accessing customer information via Target APIs. The attack was not sophisticated, relying on simple trial and error. 💡 Key Takeaways: --Single Entry Point Strategy: While the obvious move was to ensure that the same fixes were applied to all entry points, the better move for future security is to have only one entry point, one set of security controls, and one instance to support, secure, document, and implement. --Segregation and Security: Ensuring that API traffic is segregated and properly secured is crucial. --Regular Audits: Continuous monitoring and auditing of all domains and access points can prevent prolonged vulnerabilities. --Timely Response: Rapid identification and rectification of security issues are essential to protect customer data. 🔍 Broader Implications: --API Vulnerabilities: APIs remain a common source of security flaws, reminiscent of web hacking from the early 2000s. It's critical to delve into API security and recognize their susceptibility to traditional attacks. --Reasonable Cybersecurity: This incident is the second recent determination by an Australian authority that a commercial business failed in implementing reasonable cybersecurity measures. While guides like the CIS framework are very specific and useful, defining and achieving reasonable cybersecurity is a global imperative. This incident serves as a stark reminder of the importance of robust security protocols and vigilant oversight in safeguarding sensitive customer information. 🔗 Stay informed and vigilant! #CyberSecurity #DataBreach #API #TechNews #ACMA #InfoSec #DataProtection #ReasonableCybersecurity
Bryan Beekhof 🚀’s Post
More Relevant Posts
-
🚨 Optus data breach exposes 9.5M customers! A coding error in a forgotten API left personal data vulnerable since 2018. #Cybersecurity leaders, ensure your APIs are secure and regularly audited to avoid similar incidents. #DataBreach #APISecurity Read more: [The Register](https://lnkd.in/dAE3TyzT)
Coding error in forgotten API blamed for massive data breach
theregister.com
To view or add a comment, sign in
-
🚨 Breaking News for IT Warriors and Cybersecurity Guardians! 🚨 Optus, the Aussie telco giant, left a redundant website unprotected for YEARS, risking the data of over 9 million customers! 😱🔓 🔍 Here's the scoop: - Blame it on a coding oopsie that shattered API access controls! - Let's face it: A coding error hanging out for ages is like leaving your front door wide open with a neon sign saying, Hackers Welcome! 🚪🔓 💭 My Tech Crystal Ball Predictions: - **Lesson Learned**: Time to dust off those access control policies, folks! Security is like flossing — you gotta do it every day, not just before the dentist! - **History Repeats**: Remember Equifax, Marriott? Neglected security always comes back to bite! It's the Oops, we did it again of the tech world! 🔄 🔒 Cybersecurity Crusaders, unite! Let's discuss: - How can we prevent these ghost town websites from haunting us with data breaches? #TechSavvySolutions 💡🔒 - Share your thoughts — What would YOU do to ensure your API access controls are tighter than a jar of pickles? #GuardiansOfCyber 🛡️ Stay vigilant, stay secure! Let's fortify our digital fortresses, one API at a time. ⚔️💻 #ainews #automatorsolutions *Drop your wisdom below, and let's armor up against the dark forces of cyber threats!* 💬💪 #CyberSecurityAINews ----- Original Publish Date: 2024-06-20 22:44
Coding error in forgotten API blamed for massive data breach
theregister.com
To view or add a comment, sign in
-
Don't let a simple coding error become a costly cyber nightmare! This data breach shows why robust cyber insurance and vigilant security practices are essential. #CyberSecurity #DataBreach #CyberInsurance https://lnkd.in/dYZuReQN Get in touch [email protected]
Coding error in forgotten API blamed for massive data breach
theregister.com
To view or add a comment, sign in
-
If you want better security, think like a hacker! Hackers always target low hanging fruits first before moving to sophisticated hacks. Plug the easy loopholes first! And it isn't always about getting someone to run vulnerability assessments and pentests. Looking at access controls, managing changes to code and systems configs, and regularly managing patches, are ever important! The Optus breach was more a case of improper change management processes. A VAPT exercise which is a point in time assessment, may or may not have captured this gap. Security management is a collective responsibility that cuts across departments and roles. The sooner a company's management realizes this, the better prepared they would be for threats! #securityassurance https://lnkd.in/dAMePGy2
Coding error in forgotten API blamed for massive data breach
theregister.com
To view or add a comment, sign in
-
This is why #APISecurity today is a must for every #organization and in particular for #Telcos to avoid service disruption and most of all compromise your #brandreputation #security #cybersecurity #akamai https://lnkd.in/dNYz4Ydz
Coding error in forgotten API blamed for massive data breach
theregister.com
To view or add a comment, sign in
-
🚨 #CybersecurityUpdate: Fortinet has reported a security incident where an unauthorized individual accessed less than 0.3% of customer files on a third-party cloud-based drive. No customer impact or service disruption has been detected, and Fortinet's operations remain unaffected. 🔒 Immediate actions included terminating access, notifying law enforcement, and enhancing monitoring and detection systems. Fortinet reassures that financials or operations are not materially impacted. 🛡️ As transparency is key, Fortinet has communicated with affected customers and is committed to preventing future incidents. Stay informed and vigilant! #Fortinet #DataSecurity #InfoSec #CyberAttack #RiskManagement https://lnkd.in/gvrHBP9w
Notice of Recent Security Incident | Fortinet Blog
fortinet.com
To view or add a comment, sign in
-
New research from Tenable®, Inc., an exposure management firm, has unveiled over 26,500 potential internet-facing assets among Southeast Asia’s leading banking, financial services, and insurance (BFSI) companies. The study highlighted significant cybersecurity vulnerabilities in the region’s top financial institutions. The study also exposed significant cyber hygiene issues within the BFSI sector, including outdated software, weak encryption, and misconfigurations. Notably, nearly 2,500 assets still support TLS 1.0, a deprecated security protocol that was disabled by Microsoft in September 2022. Misconfigurations were also concerning, with over 4,000 assets originally intended for internal use being exposed externally. #stayvigilant #VigilantAsia #cybersecurity #cybersecuritymalaysia #cybersecuritysingapore
Financial Sector’s In Malaysia And Region Vulnerable To Cyberattacks
https://www.businesstoday.com.my
To view or add a comment, sign in
-
Securing data: EFDPO Congress in Berlin Data theft, data leaks and data security: this was the topic of the first day of the EFDPO Congress, which is currently taking place alongside the BvD Association Days in Berlin. Dr Christoph Bausewein from the international company Crowdstrike spoke about the resilience that companies need to develop in order to survive cyberattacks. According to him, data attacks have increased exponentially since the 1990s. Making systems secure against attacks and data theft ‘is the reality of the future,’ said Bausewein. In order to achieve cyber resilience, he explained the NIS 2 directive for network and information security, the update of the NIS 1 directive and the EU's DORA regulation for more resilience against cyber security in the financial sector. Christian Dürschmied used the most recent decisions of the European Court of Justice to show how complex the question of concrete material damage is for those affected whose data was disseminated without their consent. He looked at various decisions in which companies did not comply with the provisions of the GDPR, including the Deutsche Wohnen ruling of 5 December 2023 and against Media Markt of 25 January 2024. Dr Gwendal Le Grand from the European Data Protection Board (EDPB) had previously presented the Coordinated Enforcement Frameworks (CEF) and explained the EDPB's services, particularly for small and medium-sized enterprises. The EDPB website offers its own ‘Data Protection Guide’. According to Secretary General Pierre-Yves Lastic, 17 European countries currently belong to the European Federation of Data Protection Officers (EFDPO).
To view or add a comment, sign in
-
SUMMARY: CSC ServiceWorks reported a data breach affecting confidential information following a cyberattack in early 2023. MAIN POINTS: - CSC ServiceWorks experienced a cyberattack resulting in a data breach in 2023. - The breach exposed sensitive information including names, addresses, and social security numbers. - The company has notified affected individuals and taken steps to improve security measures. TAKEAWAYS: - Data breaches can compromise highly sensitive personal information. - Organizations must enhance security protocols to prevent future cyberattacks. - Prompt notification and response are crucial after a data breach. #databreach #infosec #cybersecuritynews
CSC ServiceWorks discloses data breach after 2023 cyberattack
bleepingcomputer.com
To view or add a comment, sign in
-
We're sharing an important update regarding the recent National Public Data breach. This breach affects a significant number of individuals, potentially including some of our customers/employees/partners. National Public Data (NPD), a data aggregation service, reported a substantial data breach affecting approximately 2.9 billion records. This breach includes sensitive information such as Social Security numbers, names, addresses, email addresses, and phone numbers. ** Details to Note:** Timeline of the Incident: The breach is believed to have occurred around late December 2023, with potential data leaks continuing into April and the summer of 2024. Compromised Data: The exposed data includes personal information from the past three decades, including Social Security numbers. Current Measures: NPD is actively working with authorities and has implemented additional security protocols to prevent similar incidents in the future. ** Steps to Take:** Verify Your Data: Several online tools can help you verify if your information has been compromised. Monitor Your Accounts: Regularly review your financial accounts for any signs of unauthorized activity. Consider a Credit Freeze: To guard against identity theft, freezing your credit report is a recommended measure. You can find more information on the process at the National Institute of Standards and Technology (NIST): https://lnkd.in/dTmH5TW. Stay informed and safeguard your personal information! #DataBreach #CyberSecurity #IdentityTheft #SocialSecurity #DataProtection #CyberThreats #CreditFreeze #SecurityMeasures #InfoSec #DataPrivacy #FraudProtection #SecurityBreach #PersonalData #DataLeak #RiskManagement #ThreatIntelligence #CyberAttack #DataSecurity #TechNews #ITSecurity #SecurityUpdate #DataBreachAlert #CyberAwareness #FraudDetection #TechAlert #IdentityProtection #DataSafeguard #PrivacyConcerns #CyberRisk #NetworkSecurity #IncidentResponse #DataCompromise #SecuritySolutions #DigitalSecurity #CyberDefense #OnlineSafety #FraudPrevention
NIST Special Publication 800-63B
pages.nist.gov
To view or add a comment, sign in