July 18th, 2024

Why corporations won't spend enough to safeguard your private info

AT&T and UnitedHealth Group faced data breaches compromising customer and patient data, revealing lax cybersecurity practices. Experts stress the need for stricter safeguards and regulatory intervention to address vulnerabilities.

Read original articleLink Icon
Why corporations won't spend enough to safeguard your private info

AT&T, a major telecommunications company, suffered a data breach affecting 110 million customers, exposing sensitive information like call records and locations. This breach, along with a previous incident, highlights the company's lax cybersecurity measures. Similarly, UnitedHealth Group faced a ransomware attack compromising patient data and resulting in a $22 million ransom payment. The breach stemmed from inadequate security practices during a system integration. Both incidents underscore the pervasive issue of data breaches in the corporate world, with companies often failing to prioritize cybersecurity despite the potential risks to consumers. Experts emphasize the need for stricter safeguards and regulatory intervention to address these vulnerabilities. The lack of cybersecurity expertise on corporate boards and the potential financial impacts of breaches further emphasize the urgency for improved data protection measures in the face of evolving cyber threats.

Related

AT&T says criminals stole phone records of 'nearly all' customers in data breach

AT&T says criminals stole phone records of 'nearly all' customers in data breach

AT&T confirms a data breach affecting 110 million customers, involving phone records and location data from 2022-2023. Collaboration with authorities led to one arrest. Snowflake's breach impacted other companies, stressing the need for enhanced security measures.

AT&T says hacker stole some data from 'nearly all' wireless customers

AT&T says hacker stole some data from 'nearly all' wireless customers

AT&T reports a data breach involving call and text records of wireless customers. Stolen data excludes personal details. Additional cybersecurity measures are in place. Collaboration with law enforcement and agencies ongoing.

AT&T says hackers stole records of nearly all cellular customers calls and texts

AT&T says hackers stole records of nearly all cellular customers calls and texts

Hackers accessed AT&T's system, obtaining call and text records from May to Oct. 2022 and Jan. 2023. The breach did not expose content or personal data but included sensitive phone numbers. AT&T is collaborating with law enforcement to investigate and enhance security measures. Senator Wyden highlighted the need for accountability in data breaches.

Hackers Steal Phone, SMS Records for Nearly All AT&T Customers

Hackers Steal Phone, SMS Records for Nearly All AT&T Customers

Hackers accessed AT&T's systems, compromising phone call and text records for 110 million customers. The breach revealed tower locations but not personal data. AT&T delayed disclosure due to security concerns.

The biggest data breaches in 2024: 1B stolen records and rising

The biggest data breaches in 2024: 1B stolen records and rising

In 2024, data breaches exposed over 1 billion records. AT&T, Change Healthcare, and Synnovis faced breaches, impacting customer data security. Snowflake's involvement in multiple breaches raises concerns about data protection.

Link Icon 3 comments
By @pjkundert - 6 months
Because they /can't/ do it. Anyone who claims that legislative or legal peril will accomplish the goal to "safeguard your private info" must be almost impossibly naive. It requires a foundation of /perfect/ cryptographic and operational security, which is ... somewhat unlikely.

The only viable solution is to make it so expensive for them to hold /any/ of your data that they will look for a decentralized solution where you hold your data, and grant authorization for the corporation to use some of it (eg. your name and postal address).

Then, they might be able to fumble that, but the damage is limited to just publicly available data.

Agent-based system that are designed for building large-scale distributed and decentralized systems are the future.

Holochain is one such system. There may be others, but it seems to be the most advanced.

By @miguelazo - 6 months
There’s often no shortage of dollars spent on tools, but efforts to remediate are pretty weak.