Image via Complex Original
When you divulge personal information to a company, you do it with the assumption that it's got your best interests at heart; that they're working night and day, and at all times in between, to ensure that your private info is safe from unsavory parties, right? Of course you do. However, the reality is while most companies do intend to keep your data safe, they're at the mercy of their security technology—and of those aforementioned unsavory parties who know very well how to compromise that technology.
Over the past few years we've seen a number of large companies announce major data breaches involving customer's personal data—credit card numbers, addresses, login information, etc.—caused by hackers. Usually, weak firewalls and encryption systems—or lack thereof—have played a vital part in the recent string of cyber attacks. Just recently, Twitter announced that an anonymous party got a hold of nearly 60,000 user names and passwords. The saddest part of all of this is that most of these companies aren’t even on their security A-game. From credit card processors to job websites, take a look at The 11 Worst Online Security Breaches.
11. Twitter
Date: May 7, 2012
Impact: Username and passwords of 58,978 Twitter accounts stolen
On Monday, May 7, 2012, an unidentified person took to Pastebin, a site that allows you to store text files, and dumped a ton of Twitter usernames and passwords. 58,978, to be exact. Twitter immediately downplayed the hack saying that a large majority of the compromised accounts were of spam and duplicate accounts. While that may be true, this the largest breach the young company has experienced.
10. Gawker
Date: December 200
Impact: Email address and passwords of nearly 1.3 million commenters across the Gawker network
Looking to air its frustration over what it called Gawker's "outright arrogance towards the hacker community", a group that flew under the name Gnosis took credit for the massive hack. Gnosis was able to snatch emails and passwords from a large number of members before eventually gaining access to the source code for Gawker's content management system. Thankfully, Gawker didn't hide the hack and immediately let its users know of the breach.
9. AOL
Date: August 6, 2006
Impact: Search, shopping, and banking data stolen from 650,000 users
Sometimes a high-level security breach is not the result of a hack. Sometimes it's just a cause of, as Tech Crunch called it, "utter stupidity". Such was the case when Dr. Arbdur Chowdury, head of AOL's Research department released a text file containing 20 million search query's from 650,000 AOL users. The file somehow became public and spread across the Internet like a new Kate Upton video. AOL swiftly pulled the file down, but it was too late. The damage had been done.
8. Monster.com
Date: August 2007
Impact: 1.3 million users had information stolen
Using high-level credentials allegedly stolen from Monster.com clients, a group of hackers broke into the U.S.'s most popular job recruitment service. According to reports, the hackers had servers set up in Ukraine that they used to infect the computers of some Monster users. The result was the thieving of names, addresses, phone numbers, and email addresses. The hackers then spammed other users in an attempt to glean financial information. The hackers also tried to blackmail users by having them click on a link that would download a virus, and then threaten to delete files from their computer if they did not pay up.
7. CardSystems Solutions
Date: June 17, 2005
Impact: 40 million credit card accounts exposed
As the story goes, hackers broke into CardSystems database by using an SQL Trojan attack, which inserted code into the database via the browser page every four days, placing data into a zip file and sending it back through an FTP. Since the company, for whatever reason, never encrypted users' personal information, hackers gained access to cardholder names, accounts numbers, and verifications codes to over 40 million Mastercard and Visa members. This was an incompetence-fueled fail by the CardSystems tech team.
6. RSA Security
Date: March 17, 2011
Impact: 40 million employee records stolen
You're probably wondering how one of the world's biggest and most reliable tech-security companies could become the victim of an online attack? Peep game. An unknown programmer sent out phishing e-mails to two groups of employees with the subject line "2011 Recruitment Plan," along with an excel spreadsheet that contained malware. The Trojan just so happened to exploit a hole in Adobe's Flash software and installed a remote administration tool called Poison Ivy RAT that gave the hacker remote access to an employee's computer. From there they gained access to over 40 million employee passwords and other RSA systems. Clever.
5. TJX Companies Inc.
Date: December 2006
Impacted: 94 million credit cards exposed
As with every tale, there are two sides to this story. One said a group of hackers took advantage of a weak data encryption system and stole credit card data for over 94 million accounts during a wireless transfer between two Marshalls stores in Miami, Fl. The other story has them breaking into the retail giant's network by toying with its in-store kiosks that allowed people to electronically apply for jobs. How did they manage that? Simple: TJX's network wasn't protected by any firewalls. The latter sounds more believable. Hacking legend and ringleader, Albert Gonzalez, was captured and sentenced to 40 years in prison, while 11 others were arrested.
4. Sony's PlayStation Network
Date: April 20, 2011
Impact: 77 million Playstation Network accounts hacked
Just when you thought the worst thing that ever happened to the PS3 was its horrendous launch, Sony outdoes itself by taking responsibility for what was viewed as the worst gaming community data breach of all-time. On April 26 of last year, Sony claimed its online gaming and movie service had been hacked, with over 77 million accounts being affected, 12 million of which had unencrypted credit card numbers. The electronics giant attributed the problem to the same hack that caused its initial outage on April 20. Hackers gained access to full names, passwords, e-mails, home addresses, purchase history, credit card numbers, and PSN/Qriocity logins and passwords. It took nearly a year for Sony to sort out the entire mess. And that was after a string of hacks targeted at Sony's worldwide music properties. That Xbox Live subscription is looking pretty good right about now, ain't it?
3. Heartland Payment Systems
Date: March 2008
Impact: 134 million credit cards exposed
Cyber criminals apparently used SQL injection techniques to install spyware onto Heartland's data systems and monitor credit card transactions. They obtained cardholder's names and card numbers for over 134 million credit accounts. According to indictment reports, malware might not have always been used, as the SQL injection string was said to have redirected data to an external driver accessed by the hackers. Better late than never, Heartland discovered intruders were scanning its corporate network a few months after the breach started. Two Russians and Albert Gonzalez were held accountable for the attack.
2. Acxiom
Date: Aug. 8, 2003
Impact: 1.6 billion customer records hacked
Hacker Scott Levine broke into Acxiom's, a consumer marketing company, computer database by infiltrating an exchange of data between the company and its other clients on an FTP server that was outside its firewall. The breach was traced to Snipermail.com-a spammer-friendly site run by Levine. Nearly a two-year operation, over 1.6 billion customer records were stolen and 8.2 gigabytes of personal data had been downloaded by the Snipermail capo and his team between April 2002 and August 2003. Levine was convicted on 120 counts of unauthorized access of a protected computer, two counts of access device fraud and one count of obstruction of justice. He also caused $7 million worth of damages and was sentenced to only eight years in prison. You have to love the legal system.
1. Epsilon
Date: March 30, 2011
Impact: TBD
The names and e-mails of customers that were stored in over 108 retail stores, plus several huge financial firms like CitiGroup Inc. and the non-profit educational organization, College Board, were exposed after an unknown assailant hacked into Epsilon's systems. The source of the data breach has yet to be determined, but tech experts say it could lead to numerous phishing scams and countless identity theft claims. At the moment, Epsilon's breach is being estimated as a $4 billion dollar loss. That's the worst-case scenario. Projections have millions, quite possibly billions, being affected once details emerge. So with a client list of over 2,200 global brands and handling over $40 billion e-mails annually, the odds have us looking at the biggest, if not the most expensive, security breach of all-time.