Michael Meixner

Geht nicht, gibts nicht

Data Breach Investigations Report 2009

Anbei ein paar Highlights aus den Data Breach Report 2009

285 MILLION RECORDS WERE COMPROMISED IN 2008. 

How do breaches occur?

 

 

 

 

 

In the more successful breaches, the attacker exploited some mistake committed by the victim, hacked into the network,
and installed malware on a system to collect data. 98 percent of all records breached included at least one of these
attributes. Unauthorized access via default credentials (usually third-party remote access) and SQL injection (against web
applications) were the top types of hacking. The percentage of customized malware used in these attacks more than
doubled in 2008. Privilege misuse was fairly common, but not many breaches from physical attacks were observed in 2008.

 

67

% were aided by significant errors (<>).

 

64

% resulted from hacking (+5%).

 

38

% utilized malware (+7%).

 

22

% involved privilege misuse (+7%).

9 % occurred via physical attacks (+7%).
————————————————————–
 

81

% of victims were not Payment Card Industry

 

83

% of attacks were not highly difficult (<>).

 

87% w

ere considered avoidable through simple or

 

99.9

% of records were compromised from servers

69 % were discovered by a third party (-6%).————————————————————————–
Quelle: verizonbusiness

Add a comment

UA-12689907-1