Internet security researcher Vinny Trola recently made a huge and disturbing discovery. A marketing firm called Exactis had left a massive database unsecured, allowing anyone who stumbled across it to access it.
As a marketing firm, Exactis collects simply mind-boggling amounts of data on consumers all over the globe.
The database in question was a staggering two terabytes in size, and contained more than 150 data fields. Social security numbers were not included in the exposed data.
A variety of personal identification was available, including:
Name
Political affiliation
Bank account details (including balances)
Information on other financial accounts, including stock holdings
Political affiliation
Donations to political causes
The number of children living in the person’s home
The ages of those children
In short, it’s more than enough personally identifiable information to make it a casual exercise for a determined hacker to link it back to a person’s social security number. Even if they didn’t want to jump through the hoops to do that, there’s still enough information in the massive data file that it could open the door to all manners of phishing and other scams.
Trola informed Exactis about the exposed database, and the company immediately took steps to secure it. However, it was sitting there completely unguarded and unsecured for more than two months, and there’s no telling how many people may have accessed the data inappropriately.
Exactis has no formal relationship with any of the people they collect data on, so they’re under no obligation to and are unlikely to inform the people in the database that their personal information was exposed. Given that, your best bet is to assume that you were mentioned in the database, and be on the alert for phishing and other scams in the months ahead.
President & CEO
I hope you enjoyed this article. My mission is to take your stress away from dealing with IT problems. Call (252) 565-1235 or send me a message at our contact us page if you have a question, comment or want help.
While a significant percentage of Americans are suspicious of government spending beyond the essentials, there’s at least one notable exception, according to a recent survey conducted by SecurityFirst.
Another week, another high-profile data breach. This time, Adidas and their online store was the target.
Facebook recently announced a site bug that impacted the privacy settings of more than 800,000 of its users. If you’re one of the unfortunate souls who has been affected, then people you had formerly blocked may have become unblocked, and can now see your posts.
Researchers from Ruhr-Universität Bochum and New York University in Abu Dhabi have discovered serious security flaws in 4G LTE networks that allow hackers to spy on, listen in on, intercept, and disrupt phone calls and text messages.
As most people know, Microsoft Edge was the company’s “reboot.” After trying for years to patch and update their beleaguered Internet Explorer, Microsoft ultimately decided to scrap it and start fresh. Since Edge’s launch, it has struggled to gain traction with users.
There’s some good news from a recent Supreme Court ruling where privacy is concerned, but take it with a grain of salt.
Menlo Security has recently published a new report that will probably dismay you if you’re a business owner.
Good news for the business world in general, and the owners of data centers, in particular.
File this one away under “confirming things we already knew.” A recent study conducted jointly by Blink and Trusona confirmed that people just don’t like passwords very much.