computer keyboard

With 4.1 Billion Records Exposed in Six Months, 2019 Is On Course To Be Record Year For Data Breaches

Only eight breaches were responsible for the exposure of 3.2 billion records in the first half of the year, according to new research.

In the first six months of 2019, 4.1 billion compromised records were exposed in more than 3,800 publicly disclosed breaches, according to a new study published by Risk Based Security, a security research firm.

While security breaches have been in the headlines all year long, a large majority of the records ⁠— 3.2 billion ⁠— were revealed in just eight breaches. The largest of those breaches involved Verifications.io, a company that approves email addresses for third-party customers. That breach of nearly a billion names, email addresses and other personal information was due to an unsecured database that was openly accessible online, 24/7 Wall Street reported.

The second largest breach also involved a massive 885 million real estate transaction records, which were maintained by First American Financial. Cultura Colectiva, a Mexico-based digital media company, exposed 540 million Facebook users’ data through a misconfigured database in the third-largest leak.

Based on the number of records leaked, all three were among the top 10 breaches of all time, 24/7 Wall Street reported.

But while Risk Based Security analyzed the largest breaches, it also found that a large majority of breaches reported in early 2019 had a “moderate to low severity score,” meaning they exposed 10,000 or fewer records. As Forbes notes, this is because small businesses are often easy targets for hackers due to their lack of cybersecurity protections for their data.

“Quarter after quarter the pattern has repeated itself,” said Inga Goddijn, executive vice president at Risk Based Security. “The vast majority of incidents are attributable to malicious actors outside an organization. Unauthorized access of systems or services, skimmers and exposure of sensitive data on the Internet have been the top three breach types since January of 2018.”

The business sector was responsible for 67 percent of the reported breaches and nearly 85 percent of the exposed records, the firm found. And while only 149 of the 3,813 incidents involved misconfigured databases and services, those breaches exposed over 3.2 billion records. Indeed, just this week, a security researcher discovered that MoviePass, the movie ticket subscription service, exposed customer credit card numbers by not protecting a crucial database with a password.

About the Author

Haley Samsel is an Associate Content Editor for the Infrastructure Solutions Group at 1105 Media.

Featured

  • 5 Tips to Improve Your Password Security

    Change Your Password Day is right around the corner. Observed every year on February 1, the day aims to raise awareness about cybersecurity and underscores the importance of keeping passwords strong and up to date. Read Now

  • Enhancing Port Security

    DP World Yarimca, one of the largest container terminals of the Gulf of İzmit and Turkey, is a strong proponent of using industry-leading technology to deliver unrivaled value to its customers and partners. As the port is growing, DP World Yarimca needs to continue to provide uninterrupted operations and a high level of security.To address these challenges, DP World Yarimca has embraced innovative technological products, including FLIR's comprehensive portfolio of security monitoring solutions. Read Now

  • Hot AI Chatbot DeepSeek Comes Loaded With Privacy, Data Security Concerns

    In the artificial intelligence race powered by American companies like OpenAI and Google, a new Chinese rival is upending the market—even with the possible privacy and data security issues. Read Now

  • Survey: CISOs Increasing Budgets for Crisis Simulations in 2025

    Today, Cyber Performance Center, Hack The Box, released new data showcasing the perspectives of Chief Information Security Officers (CISOs) towards cyber preparedness in 2025. In the aftermath of 2024’s high-profile cybersecurity incidents, including NHS, CrowdStrike, TfL, 23andMe, and Cencora, CISOs are reassessing their organization’s readiness to manage a potential “chaos” of a full-scale cyber crisis. Read Now

New Products

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles.

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.