Free Phishing Test
CYBER THREATS

Data Breach at a Company

22-jul-2022 6 minutes read

The data leak problem affects everyone. It can happen to both corporations and smaller enterprises, as well as private individuals. This phenomenon is growing due to the increasing amount of data processed in IT systems. Preventing leaks requires greater awareness of cyber threats, employee education and compliance with security procedures.   

How does company data leak?

Data leaks are not necessarily related to hacker interference, as we write about below.

Lack of awareness and inattentiveness

Very often, the source of the leak is the unconscious action of the person who processes it. For example, company employees who send information electronically to many recipients at the same time usually use the “for information” (CC) function. This is not a good practice because each recipient of the email then obtains information about the addresses of the other correspondents. The recommended solution is to use the “blind carbon copy” (BCC) option. 

Can your team recognize dangerous messages?

Incorrectly configured systems

It is also not uncommon to have incorrectly configured systems (FTP, databases, code and document repositories) that allow employees access without knowing the password. Employees gain a bit of convenience at the expense of data security. An additional error by the administrator in the infrastructure configuration may result in the exposure of such a system to the public network and from there it is a direct path to leakage. If no criminal personally targets the company’s infrastructure, bots scanning the network for such tasty morsels will do so.  

Lost or abandoned data media

Data leakage may also occur in the event of loss or theft of an unencrypted laptop, smartphone, hard drive or pendrive. On the secondary market, however, you can often come across sales of post-lease or obsolete equipment that is no longer used. It often contains data that has not been properly disposed of and the reading of which is not a challenge for the buyer. 

Abandoned or unsecured documents

Data leaks do not always involve electronic media or networks. In times of general digitalization, the importance of proper management and disposal of documents is rarely mentioned. It is also worth mentioning the “clean desk” principle. Documents left on the desk are a serious breach of security because unauthorized persons may gain access to it during our absence from the office.

Of course, access to data does not always result in a leak and not all unsecured data or abandoned documents will end up in the wrong hands. Nevertheless, the problem should not be underestimated and the company should not be exposed to losses. 

Data leakage and hackers’ activity

The actions of criminals pose a serious threat to the security of company data. Stolen information is a valuable commodity on the black market. The hacker can therefore sell them or use them to carry out further, sophisticated attacks. 

Cybercriminals often target websites that allow users to register. Why? Because the target of their attack is login data, usually the email address and password. Unfortunately, many people, including company employees, use one password for many websites. As you can easily guess, there is a high probability that a cybercriminal who obtains such data will also gain access to the protected information of a specific company.

To illustrate the situation, we will give an example. The hacker stole a person’s password from a discussion forum and then logged in to the email box using the same password. After gaining access to the email, he reset and changed the password to the employee’s work account, which gave him access to the company’s data. 

Although passwords in databases are increasingly stored in an implicit form (cryptographic hash function), there are effective methods of recovering their explicit form. You should be aware that even a set of personal data without passwords is a valuable commodity that gives hackers the opportunity to launch targeted attacks. It also happens that PESEL is used as part of the authentication process, which is subject to special protection in accordance with Art. 87 GDPR and should be processed in accordance with the principle of data minimization. 

ransomware is also a huge threat, especially to enterprises. The victim is usually presented with a ransom demand in exchange for a key to decrypt the files. Data leaked from the company concerns not only the company directly, but also external entities, e.g. contractors. We wrote extensively about this type of malware in other articles:

How to ensure your organization’s cybersecurity?

Even the most secured IT system will be susceptible to human errors, which is why employee awareness is so important. To minimize the negative effects of data leakage, it is worth following several rules:

The less personal data, the better

Provide the minimum required personal data. The less personal data about you is processed, the less attractive it will be to hackers or the more difficult it will be to use it to carry out an attack or identity theft.  

Separate work and private space

This is a good practice that will help you increase your privacy. It is best to have more than one email box – separate for official matters, shopping and entertainment services. This practice increases privacy and, in the event of a leak, significantly reduces the actions that need to be performed (e.g. changing email addresses, phone numbers).  

Enable multi-factor authentication

Multi-factor authentication gives you an additional layer of security that will protect you from losing access to your account even if someone intercepts your password. That is why it is so important to use this mechanism wherever possible. As an employer, you should ensure that your employees use multi-factor authentication when logging in to company systems such as email or VPN

Use a password manager

This allows your passwords to be unique and strong, making attacks much more difficult. An additional benefit is that you do not have to remember your passwords – the manager will not only generate them, but will also remember them and store them in a safe safe.

React to incident alerts

The provisions of the Personal Data Protection Act impose an obligation on the personal data administrator to notify users if a data leak has been detected. Such information must primarily include the scope of the data that was leaked. Do not ignore this type of information and in the event of a leak, follow the administrator’s recommendations. However, before you do this, make sure the message is not a phishing attempt. We recommend that you contact your administrator in advance to confirm that a leak has indeed occurred. 

Gain specialised knowledge about cybersecurity

Build a resilient cybersecurity culture with our support

Let's discuss your organization's cyber needs

Fill in the form

Would you like to test the resilience of your systems?

Fill in the form to schedule a free, no-obligation consultation. We will discuss the scope of the penetration tests and prepare a proposed approach tailored to your organization and infrastructure.
Would you prefer to speak to us directly?
+48 732 123 579