Data Breaches as a Top Cyber Security Threat

 

 Today, we live in a world of technology. Science has evolved very rapidly in the past few decades which has allowed us to make our lives easier and more entertaining. The internet could be considered as one of the ground-breaking inventions of human history. Almost everyone in this world relates to this large network. Social media, Electronic mails, Instant messaging, Video streaming came with the internet and now it has become a part of human life.

With great potentials comes grave dangers. Some people use their knowledge to perform criminal activities via the internet. These personals are called Black Hat Hackers. The Black Hats work in the shadow and couldn’t easily be caught. These people are equipped with programming and social engineering skills which make them more dangerous than common criminals.              

Why do hackers target private data?

 

To understand this, we need to understand what kind of private data is associated with the cyberspace that could be vulnerable. Normally, larges companies like Amazon does their marketing according to statistics because it’s vital for the company to provide the right products and services needed. But statistics is impossible without data. The more the data they have, the more accurate the predictions will be. You might be familiar with this if you have used any social media accounts. The ads they show are more likely to be relevant to your recent online activity. For example, Google AdSense works just like this. So, as we can see, your private data can have a high monetary value.

Although even companies like Google has their limits. Privacy is a human right and can’t be accessed by others as they will. The Data Protection Act clearly states what are the legal boundaries when accessing other private data. However, the Black Hats are criminals who are not abided by the law. They constantly struggle to snitch users’ social media accounts, credit card numbers, phone numbers, and other valuable data. They either keep those data for themselves or sell them in the black market for really high prices.

What is a data breach?

A data breach can be defined like this according to an employ of Symantec Securities.


A data breach is a security incident in which information is accessed without authorization. Data breaches can hurt businesses and consumers in a variety of ways. They are a costly expense that can damage lives and reputations and take time to repair

Normally data breaches happen when you don’t take proper security precautions when browsing the web. For example, weak passwords could be a reason for a data breach.

The following are considered as the main reasons for data breaches.

System vulnerabilities

Nothing in this world is perfect. This is even true for software systems as well. The attackers will scan for vulnerabilities and exploit them and hack into the system to steal the data. The main reason for theses kind of breaches could be out-dated software. So, keep in mind to keep all the software updated. And it’s the programmer’s responsibility as well to overlook these security threats and prepare for them.

Hackers normally use software like Metasploit and Beef to exploit certain systems. But advanced black hats use custom build programs to exploit systems.

Figure 1: Exploitation tools provided in Kali Linux by Offensive Security

Weak passwords

This can be considered as the major reason for security breaches. Normally security specialist recommends using long and complex strings as passwords. But humans are unable to remember such complex strings and tend to use simple phrases that hackers can easily guess. However, most of the systems encrypt the password to storage purposes. Even these hashed passwords can be breakable via a simple dictionary attack if the password is easily guessable.

Figure 2: Password descriptors provided in Kali Linux

Decryption software like the hash cat and john the ripper are extremely popular among penetration testers. However, this software will never 100% decryption guarantee because it depends upon the dictionary page used, password complexity, and type of encryption used.

Figure 3:A week password in MD5 encryption is cracked easily with John the Ripper

Specialized malware raids

These types of malware are engineered to attack specific components of the system. Usually, hackers inject malware using social engineering techniques such as phishing, spamming, etc. to trick the users to steal their credentials. These types of attacks are highly efficient and impactful. Hackers use rouge URLs, vulnerable websites, and spam emails as a medium to carry on with these types of attacks. Clicking these types of URLs or emails would infect your computer. But modern-day web browsers and email services are capable of detecting these kinds of threats and takes necessary actions to keep the user safe.

For example, we can take Stuxnet, a specialized worm type virus that hit Iran in 2010. It mainly targeted Siemens industrial systems and spread through Windows operating systems. At the time, Iran nuclear energy project was using Siemens's industrial systems and had a major drawback in the project after the attack occurred.

Figure 4: The mechanism of the Stuxnet virus (Source: Pinterest)

How to prevent data breaches?

So, the next question that comes to mind is how can we protect our data from hackers? Securing yourself from these kinds of threats is now easier than before because cybersecurity specialists constantly research about threats and educate the software developers on how to make their application more secure. But still, the user has a major role to play if they want to make sure that their private data is safe. Now let us see how we can protect ourselves from these threats.

Keep systems well maintained and updated

This means that you should be updated about any recent security concerns. Normally software developers such as Google or Facebook issue mobile app updates very frequently to ensure their applications are well fortified against the latest security threats. So, it’s up to the users to maintain their applications properly. Keep in mind that you must at least update your software once a month if your application provider issues new patches.

And most importantly, it is recommended to use antivirus software to protect yourself. There is a higher chance of data breach if there is any malware on any computing device. It's recommended scanning your computing device with antivirus software once a week. And most of the antivirus software provides extra cybersecurity features such as firewalls, VPN for secure browsing, etc.

Figure 5: The top 10 antivirus software in 2019

Fortifying your credentials

This could be the best way in preventing data breaches. Most of the data breaches happen if login credentials such as password leaks. To make your password more secure you can,

1.      Chose a password that is longer than 8 characters.

2.      Use alphanumeric letters and symbols to the password.

3.      Don’t use the same password for different login platforms.

4.      Avoid using personal information in passwords (i.e.: birthdays, names, etc.)

Or you can always refer to the rockyou text file. This file contains the most common passwords used by users. Better check this file out and cross-refer with the passwords that you use. If you find one of your passwords in this text file, you better change them because even the novice hackers use this rockyou text file as a dictionary page to crack passwords.

Avoid using sensitive information such as credit card numbers in untrusted web pages and applications. Try to use safe and secure payment portals as much as you can and usage of antivirus software is recommended if you are frequently doing online transactions.

Conclusion

The cyber-world is filled with miracles and threats as well. Beware, threats are lurking in the depths of the web waiting to strike and better be prepared for it. Stay safe and happy surfing 😉.

Comments

Post a Comment

Popular posts from this blog

How to install Parrot OS in Oracle VM VirtualBox

Track social media accounts using the Sherlock Project