Security News > 2020 > August > SANS cybersecurity training firm suffers data breach due to phishing attack
The breach compromised 28,000 records, exposing such data as names, phone numbers, physical addresses, and email addresses.
On Aug. 6, security training firm SANS Institute discovered a data breach of approximately 28,000 records as the result of one successful phishing attack against a single employee.
There is a certain alarm that a cybersecurity training firm should itself be caught in a security incident, even if due to the actions of a single employee.
"We don't know if SANS had two-factor authentication enforced, or if the attacker was able to bypass those controls if in place. It is surprising that an organization like SANS would suffer such a large breach and that the compromise was not detected until a supposedly unrelated review of email configurations was taken."
In the case of phishing attacks, training should include phishing simulations where employees are taught how to respond to suspicious emails.
News URL
Related news
- Tech giant Nidec confirms data breach following ransomware attack (source)
- Henry Schein discloses data breach a year after ransomware attack (source)
- Australian Organisations Targeted by Phishing Attacks Disguised as Atlassian (source)
- Free Sniper Dz Phishing Tools Fuel 140,000+ Cyber Attacks Targeting User Credentials (source)
- One-Third of UK Teachers Lack Cybersecurity Training, While 34% Experience Security Incidents (source)
- DOJ, Microsoft seize 107 domains used in Russia's Star Blizzard phishing attacks (source)
- Dutch Police: ‘State actor’ likely behind recent data breach (source)
- Comcast and Truist Bank customers caught up in FBCS data breach (source)
- Internet Archive hacked, data breach impacts 31 million users (source)
- Internet Archive data breach, defacement, and DDoS: Users’ data compromised (source)