It’s every security manager's worst nightmare. A member of the IT department reaches to alert that malicious software has been detected on an internal network, and the hacker potentially has access to layers of sensitive data. In the following days and weeks of remediation, locating an access point, and reinforcing cybersecurity measures, security managers often ask themselves, “could this data leak have been prevented?”
Sensitive information can leak out through any number of channels, for many different purposes, and it can then find its way into the hands of various threat actors worldwide. And just like data leakage can occur in various formats, it can affect nearly any type of company.
The good news? If your data is leaked in a way that could put your company at risk, there’s a good chance that the threat actors behind that risk will communicate in somewhat predictable ways. And, because the dark web is the go-to channel for threat actors worldwide to communicate online, monitoring its underground forums can seriously boost your ability to detect any data leakage that should concern you. As this post will explain, taking full advantage of threat intelligence from the dark web can help companies to detect data leaks promptly.
But first, let’s take a look at what data leakage is and the various forms it can take.
What is Data Leakage?
As open-ended as the term data leakage is, there are some particularly common ways it occurs:
- Phishing attacks: in which a threat actor deliberately uses impersonation to trick a victim into revealing sensitive information.
- Physical exfiltration of data: in which information is released via USB drives, printed pages, or other media (digital or otherwise).
- Insider attacks: an employee, contractor, or another individual with privileged access to a company’s sensitive information is enticed to reveal sensitive information – whether driven by greed, ideology, or simply resentment toward the company.
- Accident: in which an individual fails to take proper precautions and unwittingly leaves sensitive information exposed.
Of course, many data leaks can fit into more than one of these categories – such as in the case of an insider who deliberately exfiltrates sensitive data physically. And even within these categories, data can leak out in various ways. For example, an accident could be quite complex or as simple as leaving a printed page with sensitive information in a publicly visible location.
Still, as varied as data leaks can be, there are certain characteristics they generally have in common – most importantly, the risk they pose to the affected companies and organizations (as well as their customers).
Why is Data Leakage so Dangerous?
Some ways that a data leak could hurt a company are obvious and relatively consistent over time. Any company’s proprietary and sensitive information that is revealed – anything from company credit card numbers to trade secrets and future business plans – could hurt the company’s ability to function and profit.
But where the last several years have really upped the ante is in terms of protecting customers’ personally identifiable information (PII). With privacy regulations like the GDPR and the CCPA dramatically increasing the penalties companies could face for failing to protect their customers’ data adequately, businesses now have a new and major financial incentive to invest in data leakage prevention and detection. Meanwhile, companies that fall victim to high-profile data leaks risk losing their customers’ confidence and business due to the bad press generated by these incidents.
Notable Data Leaks Since 2020
2020 welcomed a lot of chaos in the cybersecurity industry. With the COVID-19 pandemic disrupting the way of normal life, millions of people across the world were moved to remote work environments. Shifting company networks to allow for the remote connection by their entire workforce left organizations scrambling to protect their expanding attack surface.
Bad actors saw 2020 as full of opportunity not just because of remote workforces, but also because of the high-stakes nature of the COVID-19 pandemic. Healthcare organizations and those linked to vaccine creation were hit hard by malicious actors trying to take advantage of their thinned resources and limited time to spend on cybersecurity. And to top it off, 2020 ended with one of the most expansive, organized, and impactful data leaks in third party risk management history with the discovery of SolarWinds. Since then, there have been several prominent data breaches that demonstrate the importance of a having a mature TPRM program.