CyberElements
Back

Can data breaches be avoided?

CyberElements,

Share via

The most dangerous kind of data breach is the one you don’t know about.

Frank Abagnale

According to the Ponemon Institute’s Cost of a Data Breach Report 2023, it takes nine months on average to identify and contain a data breach. Cybercriminals are using sophisticated techniques that make it difficult even to detect one.

First, what are the main causes of data breaches?

Obviously the attacker is to blame. But it is essential that companies take the required measures to avoid such attacks. Here are a few causes.

  • Weak credentials. Are you still using the same password for all your accounts? Written on a sticky note? Passwords are the key to protecting your data, and criminals rely on software to crack even difficult ones.
  • Security vulnerabilities. To perform an attack, hackers look for a vulnerability to exploit.
  • Internal error. A simple human error can lead to a data breach costing a company its security — losing a device, communicating confidential data to a third party believed to be trustworthy, sending a contaminated document.
  • Internal malice. Beyond human error, an employee sometimes carries out data theft for different reasons: sent by competitors, acting out, and so on.

What are the consequences of data breaches?

When a data leak happens, whether through an innocent error or a malicious act, companies must deal with the consequences.

  • Reputational damage.
  • Legal action. Companies are supposed to protect their customers’ data, and legal action can be taken where that protection is not offered. British Airways had to pay a £20M fine after experiencing a data breach, accused of not putting adequate security measures in place when managing its customers’ personal information.
  • Financial losses. In 2023 the estimated cost of a data breach was $4.45M, according to the Ponemon Institute.

The 3CX attack: a double supply chain attack in one

The 3CX data breach is a rare — if not the first — incident in which hackers used a supply chain attack to initiate another one successfully. How did it happen?

3CX announced that various versions of the VoIP application were compromised on 30 March. After investigation, it was discovered that the attack began in 2021, when hackers infected a Trading Technologies software package with malicious code. In 2022 a 3CX employee downloaded the infected software onto their personal computer, allowing hackers to get access to that employee’s work credentials. From there the 3CX network was accessed via VPN, allowing lateral movement and slipping infectious code into the VoIP application and the 3CX website.

Users who downloaded the infected application may have given the hackers access to sensitive information such as phone number, email address and credit card details.

The Google Fi and T-Mobile data breach

Google Fi is a mobile virtual network that operates on its partners’ physical network infrastructure, such as T-Mobile and U.S. Cellular.

In January 2023, T-Mobile suffered a data breach affecting 37M customers and resulting in the theft of their account information. The attackers were also able to access Google Fi customers’ data: phone number, SIM card number, activation date, account status and chosen service plan. The attack is suspected to have been running since at least November 2022. Google Fi has not communicated the number of affected customers.

Having this information, hackers proceeded with SIM swapping attacks targeting Google Fi customers. A rise in phishing attempts is expected to follow.

How can we prevent a data breach?

The two data breaches above illustrate the importance of securing critical data. That data will often need to be regularly accessed by both a company’s internal employees and third parties for business operations — which leads to the security paradox.

How can we create an invincible barrier while allowing access for both internal employees and third parties? In other words, how can we give access to certain users and not others? This can be done only by applying a Zero Trust approach, and here is how.

  • Protocol break technology. A Zero Trust architecture equipped with protocol break technology allows protocol rewriting and control of flows. It acts as the auditor at the port who discharges a ship and makes sure all goods are safe and secure before putting them in a truck.
  • Clientless web access. Unlike client-based access, clientless access allows users to reach their resources without installing any client on their devices. Control can then be centralised, forcing regular updates and allowing better patch management.
  • The use of virtualisation. A virtualised application is displayed on the user’s device while being executed on a remote device — in a data centre, for example.

HTML5 delivery

This is where HTML5 delivery becomes interesting. It regroups the technologies listed above while giving access to a resource via any browser. Only images are communicated to the user, and only keyboard and mouse flows are allowed to be transmitted from the user. So you make sure that no infection can be transmitted to the organisation’s network, and you limit the interactions with the user’s workstation.

You can add a further security layer by integrating UBA (User Behaviour Analytics) to continuously verify the identity of the user. As seen in the Google Fi breach, hackers were able to access SIM serial numbers and initiate SIM swapping attacks; UBA matters a great deal in stopping those. In the 3CX incident, the hacker was able to use the credentials of one employee to move laterally within the network and carry out another attack — which could have been avoided with UBA and privileged management features such as just-in-time workflows.

With the rise of data breaches there are no heroes, only victims

In the aftermath, the cost of a data breach can be tremendous, especially as hackers use new and sophisticated techniques. As we have seen, double attacks have started to be used, and more of them are expected in the months to come.

Add the fact that a data breach is rarely discovered before it is too late, and starting a Zero Trust journey matters more than ever.

Tags

  • Articles
  • ZTNA
  • MSPs
  • Third-Party & Vendor Access

Let’s secure your access together