Worst Data Breaches of 2018

It seemed like data breaches were everywhere in 2018, affecting everyone from a Canadian cannabis store to Chili's to the U.S. Postal Service. Here are a few of the biggest data breaches of the year.

It seemed like data breaches were everywhere in 2018, affecting everyone from a Canadian cannabis store to Chili’s restaurants. Yale even discovered and disclosed a 2008 data breach this year. The amount and types of data accessed varied, but each incident was another reminder of the importance of data security.

We’ve rounded up a few of the biggest data breaches from 2018 below.

Marriott

One of the biggest data breaches of the year—and potentially of all time—was disclosed earlier this month. Marriott International, the world’s largest hotel chain, announced a breach of its Starwood guest reservation database and said that as many as 500 million guests could be affected. Upon investigation, Marriott found that there had been unauthorized access since 2014 and that an “unauthorized party” had copied and encrypted some information and “took steps toward removing it,” but the company did not specify how much data was removed.

Marriott said that for about 327 million of affected guests, accessed information included some combination of a name, address, phone number, email, passport number, Starwood Preferred Guest account information, date of birth, gender, arrival and departure information, reservation data and communication preferences.

My Fitness Pal

Under Armor said about 150 million users were affected by a data leak in the company’s MyFitnessPal app that occurred in February. Under Armor said notified users via email and in-app messages, and it was “working with leading data security firms to assist in its investigation.”

The company said “an unauthorized party acquired data associated with MyFitnessPal user accounts,” such as usernames, passwords and email addresses.

Quora

About 100 million Quora users were affected by authorized access to one of its systems by a “malicious third party,” according to the site. Quora said it was logging out all users who might have been affected in order to prevent further damage and notifying users whose data had been compromised.

Compromised information may include names, emails, encrypted password and data imported from linked networks.

USPS

A security vulnerability in the U.S. Postal Service’s “Informed Visibility” mail tracking and reporting service potentially exposed the data of more than 60 million customers. The postal service said it is not aware of anyone’s records being accessed, but the security hole has been fixed.

The service’s API could have allowed almost anyone with a USPS account to view other users’ account details and even access information such as when critical documents and checks were scheduled to be delivered to their mailboxes.

Facebook

Among the many unfortunate headlines for Facebook this year was a massive data breach that exposed the account details and personal information of almost 50 million users. Facebook said they have fixed the security vulnerability and alerted authorities of the breach.

The hack was possible due to Facebook’s “View As” feature, which lets users view their own account as if they were a stranger in order to check post privacy settings, etc. The feature gives the user an “access token,” which allows them to log back into their account without resubmitting information, and hackers exploited this to harvest other users’ access tokens.

 

 

If you use the same login information and password for accounts across many different websites, hackers could potentially find your login in a data breach of a lower-stakes app and use it to access your account on something more important and private, like a bank account. Read more about protecting yourself from hackers here.

If you’ve been hacked, here are some steps you can take to protect yourself after the fact.

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West
  • Live From ISC West 2024: Post-Show Recap

    ISC West 2024 is complete. And from start to finish, the entire conference was a huge success with almost 30,000 people in attendance. Read Now

    • Industry Events
    • ISC West
  • ISC West 2024 is a Rousing Success

    The 2024 ISC West security tradeshow marked a pivotal moment in the industry, showcasing cutting-edge technology and innovative solutions to address evolving security challenges. Exhibitors left the event with a profound sense of satisfaction, as they witnessed a high level of engagement from attendees and forged valuable connections with potential clients and partners. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • Camden CV-7600 High Security Card Readers

    Camden CV-7600 High Security Card Readers

    Camden Door Controls has relaunched its CV-7600 card readers in response to growing market demand for a more secure alternative to standard proximity credentials that can be easily cloned. CV-7600 readers support MIFARE DESFire EV1 & EV2 encryption technology credentials, making them virtually clone-proof and highly secure. 3

  • Mobile Safe Shield

    Mobile Safe Shield

    SafeWood Designs, Inc., a manufacturer of patented bullet resistant products, is excited to announce the launch of the Mobile Safe Shield. The Mobile Safe Shield is a moveable bullet resistant shield that provides protection in the event of an assailant and supplies cover in the event of an active shooter. With a heavy-duty steel frame, quality castor wheels, and bullet resistant core, the Mobile Safe Shield is a perfect addition to any guard station, security desks, courthouses, police stations, schools, office spaces and more. The Mobile Safe Shield is incredibly customizable. Bullet resistant materials are available in UL 752 Levels 1 through 8 and include glass, white board, tack board, veneer, and plastic laminate. Flexibility in bullet resistant materials allows for the Mobile Safe Shield to blend more with current interior décor for a seamless design aesthetic. Optional custom paint colors are also available for the steel frame. 3

  • HD2055 Modular Barricade

    Delta Scientific’s electric HD2055 modular shallow foundation barricade is tested to ASTM M50/P1 with negative penetration from the vehicle upon impact. With a shallow foundation of only 24 inches, the HD2055 can be installed without worrying about buried power lines and other below grade obstructions. The modular make-up of the barrier also allows you to cover wider roadways by adding additional modules to the system. The HD2055 boasts an Emergency Fast Operation of 1.5 seconds giving the guard ample time to deploy under a high threat situation. 3