Save StorySave this storySave StorySave this storyIt was a strange year in cyberspace, as US president Donald Trump and his administration launched foreign policy initiatives and massive changes to the federal government that have had significant geopolitical ramifications. Through it all, the steady drumbeat kept pounding of data breaches, leaks, ransomware attacks, digital extortion cases, and state-sponsored attacks that have unfortunately become a backdrop of daily life.Here's WIRED's look back on this year's most significant breaches, hacking sprees, and digital attacks.
Stay alert, and stay safe out there.Salesforce IntegrationsAttackers grabbed data from the sales management giant Salesforce in at least two breaches this yearbut they didn't compromise Salesforce directly. Instead, the group breached third-party Salesforce contractor integrations, including those of Gainsight and Salesloft.Google's Threat Intelligence Group published about the spree in August, saying that some Google Workspace data had been compromised as part of the breach of the sales and marketing platform Salesloft Drift.
Though the incident was not a direct hack of Google Workspace, it represented a rare instance in recent years of Alphabet customer data being exposed.Other impacted companies include Cloudflare, Docusign, Verizon, Workday, Cisco, LinkedIn, Bugcrowd, Proofpoint, GitLab, SonicWall, Adidas, Louis Vuitton, and Chanel. The credit bureau TransUnion also had a breach apparently tied to the situation that exposed the information of 4.4 million people, including names and Social Security numbers.The spree was perpetrated by a group known as Scattered Lapsus Huntersa potential amalgam of actors and tooling from the hacking and data theft groups Scattered Spider, Lapsus, and ShinyHunters.
Researchers note, though, that the group isn't actually a one-to-one evolution of the three namesakes. Regardless, Scattered Lapsus Hunters have a data leak site where they've been previewing troves of stolen data from the campaign and conducting digital extortion attacks on victims.Clops Oracle E-Business Hacking SpreeThe ransomware group Clop is known for carrying out mass exploitation of vulnerabilities for data breaches and extortion attacks.
Discussion
Join the conversation
Be the first to comment