The 18 biggest data breaches of the 21st century

The 18 biggest data breaches of the 21st century

Current Article Review         

  1. Locate a current article about how an organization was breached/hacked and customer data was stolen. The article can be published within the last 4 years.
  2. Provide a Link to the article or attach a copy of the article.
  3. Complete the Summary information below and post this to the discussion board to share your research with your peers.
  4. Post the title of your article and the link to our class discussion Page. Once an article is listed on the discussion page it cannot be submitted again by another student.
Title of the article The 18 biggest data breaches of the 21st century
Topic Uber
Author Taylor Armerding
Publisher CSO Online
Date of publication 20 December 2018
Link to Article https://www.csoonline.com/article/2130877/the-biggest-data-breaches-of-the-21st-century.html

 

 

The main idea of the article:

Uber global transport firm experiences a major breach in late 2016. However, the violation not revealed to the public until late 2017. The incident has handled the management haphazardly as they negotiated with hackers to destroy stolen data and they paid them a colossal amount of money. The breach potentially affected Uber stake when it transacted with Softbank.

 

Information presented: List at least five points made by the author

 

1. Uber system hacked and 57 personal identification information of 57 million users stolen and 600,000 drivers.

2. The hackers too accessed Uber GitHub account and stole password credential, information that should be stored there.

3. Uber did not notify the relevant authorities of the incident nor the customers.

4. A revelation of the event caused Uber valuation to drop from $68 billion to $48 billion.

5. Uber management negotiated with hackers to destroy stolen data.

Response to the article:

The article shows blatant negligence and carelessness of the Uber management in protecting private and confidential data. The company did not invest in cybersecurity of organizational data. Multiple security measures would have been done to secure data. Organizations should have data policy to define procedures followed in case of incidents.