9.5M Exposed in Healthcare Breach, Hackers Hunt AWS Root Logins 🔐
Two stories from today's threat landscape show how much damage a single exposed dataset or a stolen login can cause — one to your customers, one to your cloud.
A Healthcare Breach Just Exposed 9.5 Million People's Most Sensitive Data
Healthcare company Aesto disclosed that hackers broke into part of its Amazon cloud infrastructure and accessed records on 9,540,683 people — nearly the population of New York City. The stolen data reportedly includes medical records, insurance details, financial information, and government ID numbers: the kind of information that's hard to change once it's out. The intrusion ran for about two weeks last December, but Aesto didn't confirm the exposure until May and didn't notify affected people until June, months after the fact. If you or someone you know gets a notice from Aesto, don't ignore it — this is exactly the kind of leak that fuels identity theft and targeted phishing scams for years to come.
Hackers Are Trying to Break Into 150+ Companies' AWS Accounts — Starting at the Top
Security researchers at Datadog uncovered a coordinated campaign hammering the "root" accounts — the master keys — of more than 150 organizations' Amazon Web Services setups with stolen or guessed passwords. No successful break-ins have been confirmed yet, but the fact that attackers have a working list of root account emails to target is alarming on its own, since that access controls everything in a company's cloud environment. For any business running on AWS, this is a reminder that root accounts need multi-factor authentication and should almost never be used for day-to-day logins. A single compromised root account can mean a company's entire cloud infrastructure — and every customer's data in it — is up for grabs.
Stay ahead of threats with GOCO Security at gocosecurity.com.
.jpg)
Comments
Post a Comment