Worst Data Breaches of 2018

It seemed like data breaches were everywhere in 2018, affecting everyone from a Canadian cannabis store to Chili's to the U.S. Postal Service. Here are a few of the biggest data breaches of the year.

It seemed like data breaches were everywhere in 2018, affecting everyone from a Canadian cannabis store to Chili’s restaurants. Yale even discovered and disclosed a 2008 data breach this year. The amount and types of data accessed varied, but each incident was another reminder of the importance of data security.

We’ve rounded up a few of the biggest data breaches from 2018 below.

Marriott

One of the biggest data breaches of the year—and potentially of all time—was disclosed earlier this month. Marriott International, the world’s largest hotel chain, announced a breach of its Starwood guest reservation database and said that as many as 500 million guests could be affected. Upon investigation, Marriott found that there had been unauthorized access since 2014 and that an “unauthorized party” had copied and encrypted some information and “took steps toward removing it,” but the company did not specify how much data was removed.

Marriott said that for about 327 million of affected guests, accessed information included some combination of a name, address, phone number, email, passport number, Starwood Preferred Guest account information, date of birth, gender, arrival and departure information, reservation data and communication preferences.

My Fitness Pal

Under Armor said about 150 million users were affected by a data leak in the company’s MyFitnessPal app that occurred in February. Under Armor said notified users via email and in-app messages, and it was “working with leading data security firms to assist in its investigation.”

The company said “an unauthorized party acquired data associated with MyFitnessPal user accounts,” such as usernames, passwords and email addresses.

Quora

About 100 million Quora users were affected by authorized access to one of its systems by a “malicious third party,” according to the site. Quora said it was logging out all users who might have been affected in order to prevent further damage and notifying users whose data had been compromised.

Compromised information may include names, emails, encrypted password and data imported from linked networks.

USPS

A security vulnerability in the U.S. Postal Service’s “Informed Visibility” mail tracking and reporting service potentially exposed the data of more than 60 million customers. The postal service said it is not aware of anyone’s records being accessed, but the security hole has been fixed.

The service’s API could have allowed almost anyone with a USPS account to view other users’ account details and even access information such as when critical documents and checks were scheduled to be delivered to their mailboxes.

Facebook

Among the many unfortunate headlines for Facebook this year was a massive data breach that exposed the account details and personal information of almost 50 million users. Facebook said they have fixed the security vulnerability and alerted authorities of the breach.

The hack was possible due to Facebook’s “View As” feature, which lets users view their own account as if they were a stranger in order to check post privacy settings, etc. The feature gives the user an “access token,” which allows them to log back into their account without resubmitting information, and hackers exploited this to harvest other users’ access tokens.

 

 

If you use the same login information and password for accounts across many different websites, hackers could potentially find your login in a data breach of a lower-stakes app and use it to access your account on something more important and private, like a bank account. Read more about protecting yourself from hackers here.

If you’ve been hacked, here are some steps you can take to protect yourself after the fact.

Featured

  • 2025 Security LeadHER Conference Program Announced

    ASIS International and the Security Industry Association (SIA) – the leading membership associations for the security industry – have announced details for the 2025 Security LeadHER conference, a special event dedicated to advancing, connecting and empowering women in the security profession. The third annual Security LeadHER conference will be held Monday, June 9 – Tuesday, June 10, 2025, at the Detroit Marriott Renaissance Center in Detroit, Michigan. This carefully crafted program represents a comprehensive professional development opportunity for women in security this year. To view the full lineup at this year’s event, please visit securityleadher.org. Read Now

    • Industry Events
  • Report: 82 Percent of Phishing Emails Used AI

    KnowBe4, the world-renowned cybersecurity platform that comprehensively addresses human risk management, today launched its Phishing Threat Trend Report, detailing key trends, new data, and threat intelligence insights surrounding phishing threats targeting organizations at the start of 2025. Read Now

  • NRF Supports Federal Bill to Thwart Retail Crime

    The National Retail Federation recently announced its support for the Combating Organized Retail Crime Act of 2025. The act was introduced by Chairman Chuck Grassley, R-Iowa, Senator Catherine Cortez Masto, D-Nev., and Representative Dave Joyce, R-Ohio. Read Now

  • ISC West 2025 Brings Almost 29,000 Industry Professionals to Las Vegas

    ISC West 2025, organized by RX and in collaboration with the Security Industry Association, concluded at the Venetian Expo in Las Vegas last week. The nation’s leading comprehensive and converged security event attracted nearly 29,000 industry professionals and left a lasting impression on the global security community. Over five action-packed days, ISC West welcomed more than 19,000 attendees and featured 750 exhibiting brands. Read Now

    • Industry Events
    • ISC West
  • Tradeshow Work Can Be Fun

    While at ISC West last week, I ran into numerous friends and associates all of which was a pleasant experience. The first question always seemed to be, “How many does this make for you?” Read Now

    • Industry Events
    • ISC West

New Products

  • Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

    Connect ONE®

    Connect ONE’s powerful cloud-hosted management platform provides the means to tailor lockdowns and emergency mass notifications throughout a facility – while simultaneously alerting occupants to hazards or next steps, like evacuation.

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.

  • ComNet CNGE6FX2TX4PoE

    The ComNet cost-efficient CNGE6FX2TX4PoE is a six-port switch that offers four Gbps TX ports that support the IEEE802.3at standard and provide up to 30 watts of PoE to PDs. It also has a dedicated FX/TX combination port as well as a single FX SFP to act as an additional port or an uplink port, giving the user additional options in managing network traffic. The CNGE6FX2TX4PoE is designed for use in unconditioned environments and typically used in perimeter surveillance.