
{"id":3290,"date":"2017-12-27T00:00:00","date_gmt":"2017-12-27T00:00:00","guid":{"rendered":"http:\/\/otava.test\/the-biggest-data-breaches-of-2017\/"},"modified":"2017-12-27T00:00:00","modified_gmt":"2017-12-27T00:00:00","slug":"the-biggest-data-breaches-of-2017","status":"publish","type":"post","link":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/","title":{"rendered":"The biggest data breaches of 2017"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-17036\" src=\"https:\/\/otava.test\/wp-content\/uploads\/2019\/04\/top-data-breaches-2016-BLOG-12.23.16-112635440-9.jpg\" alt=\"Data leak\" width=\"350\" height=\"222\" \/>As we did in 2016, we&#8217;re rounding up the biggest data breaches of 2017. What have we learned as a result, and what can companies do better next year?<\/p>\n<p><a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/how-to-protect-yourself-after-the-equifax-data-breach\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Equifax<\/strong><\/a>: The loss of 145 million records may not be the highest in history, but the value of information very well might be. Thanks to an unpatched flaw in an Apache Struts server, names, dates, social security numbers, and more were compromised. Most of the records were American, but about a million people were affected in the UK and Canada as well. To make matters even worse, the credit bureau&#8217;s response to the crisis was less than stellar, with widespread criticism of the company&#8217;s incident response website, officials questioning how much company executives knew before it disclosed the breach, and prompting an investigation by Congress.<\/p>\n<p><strong>Uber<\/strong>: Another breach for the books that falls under &#8220;poorly handled.&#8221; The loss of 57 million records actually happened in October 2016, but Uber didn&#8217;t disclose until November of this year, and it was also discovered the rideshare company had paid the hackers who compromised them $100,000 to stay quiet and delete the data. The result? CSO Joe Sullivan and a deputy were shown the door.<\/p>\n<p><strong>NSA<\/strong>: In April of this year, the NSA lost control of several key hacking tools, when a group known as the Shadow Brokers published stolen code. That lead directly to the <a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/breaking-down-the-wannacry-ransomware-attack\/\" target=\"_blank\" rel=\"noopener noreferrer\">WannaCry ransomware attack<\/a>, thought to be the biggest of its kind and which brought down Britain&#8217;s health system as well as paralyzing companies like Merck, FedEx and more.<\/p>\n<p><strong>Verizon<\/strong>: In July, the phone giant had about 14 million subscribers&#8217; records exposed, thanks to an unprotected Amazon S3 storage server. Anyone who called Verizon customer service during that time could have been affected.<\/p>\n<p><strong>Yahoo<\/strong> (again): After being bought by Verizon, it was revealed that Yahoo&#8217;s massive leak of 1 billion (with a B) records in 2013 actually was 3 billion&#8211;or literally every single account.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Honorable_mention\"><\/span>Honorable mention<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><strong>Amazon S3 storage buckets<\/strong>: While Amazon itself wasn&#8217;t affected, data breaches like Verizon, the U.S. Army and Australian Broadcasting Company were a direct result of unprotected Amazon S3 storage buckets that were misconfigured as public instead of private. A simple common-sense approach to configuring buckets could have protected the integrity of millions of records.<\/p>\n<h2><span class=\"ez-toc-section\" id=\"Lessons_learned\"><\/span>Lessons learned<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>What conclusions can we draw from these breaches? For starters, how a company handles the fallout from a data breach is just as important as its data protection policies. Make sure your incident response plan is timely and properly addresses customer concerns that are bound to rise after a breach.<\/p>\n<p>If you&#8217;re in the public cloud, it&#8217;s also important to make sure that your systems are properly configured to avoid accidental data exposure. Double check your environment when adding or deleting components.<\/p>\n<p>Let us help keep your data safe in one of our <a href=\"https:\/\/otavawebsite.wpengine.com\/operations\/locations\/\" target=\"_blank\" rel=\"noopener noreferrer\">Midwest data centers<\/a>! We offer strong physical, technical and administrative security to maintain the integrity of your data in all manner of incidents, including data breaches. Our experts can also help you develop a robust <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/data-protection\/disaster-recovery-as-a-service\/\" target=\"_blank\" rel=\"noopener noreferrer\">disaster recovery<\/a> plan that addresses policies and procedures before, during and after a cybersecurity incident. <a href=\"https:\/\/otavawebsite.wpengine.com\/contact\/\" target=\"_blank\" rel=\"noopener noreferrer\">Contact us<\/a> to speak to a disaster recovery expert, or download our <a href=\"https:\/\/web.otava.com\/disaster-recovery-answers-all-in-one-place\" target=\"_blank\" rel=\"noopener noreferrer\">free disaster recovery white paper<\/a> to learn more.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>As we did in 2016, we&#8217;re rounding up the biggest data breaches of 2017. What have we learned as a result, and what can companies do better next year? Equifax: The loss of 145 million records may not be the highest in history, but the value of information very well might be. Thanks to an unpatched flaw in an Apache Struts server, names, dates, social security numbers, and more were compromised. Most of the records were American, but about a million people were affected in the UK and Canada as well. To make matters even worse, the credit bureau&#8217;s response to the crisis was less than stellar, with widespread criticism of the company&#8217;s incident response website, officials questioning how much company executives knew before it disclosed the breach, and prompting an investigation by Congress. Uber: Another breach for the books that falls under &#8220;poorly handled.&#8221; The loss of 57 million records actually happened in October 2016, but Uber didn&#8217;t disclose until November of this year, and it was also discovered the rideshare company had paid the hackers who compromised them $100,000 to stay quiet and delete the data. The result? CSO Joe Sullivan and a deputy were shown the door&#8230;.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[48],"tags":[],"other_category":[],"class_list":["post-3290","post","type-post","status-publish","format-standard","hentry","category-cybersecurity"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>The biggest data breaches of 2017 | OTAVA<\/title>\n<meta name=\"description\" content=\"As we did in 2016, we&#039;re rounding up the biggest data breaches of 2017. What have we learned as a result, and what can companies do better next year?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"The biggest data breaches of 2017\" \/>\n<meta property=\"og:description\" content=\"As we did in 2016, we&#039;re rounding up the biggest data breaches of 2017. What have we learned as a result, and what can companies do better next year?\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/\" \/>\n<meta property=\"og:site_name\" content=\"OTAVA\" \/>\n<meta property=\"article:published_time\" content=\"2017-12-27T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/otava.test\/wp-content\/uploads\/2019\/04\/top-data-breaches-2016-BLOG-12.23.16-112635440-9.jpg\" \/>\n<meta name=\"author\" content=\"Irma Brillantes\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Irma Brillantes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/\"},\"author\":{\"name\":\"Irma Brillantes\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\"},\"headline\":\"The biggest data breaches of 2017\",\"datePublished\":\"2017-12-27T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/\"},\"wordCount\":550,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/otava.test\/wp-content\/uploads\/2019\/04\/top-data-breaches-2016-BLOG-12.23.16-112635440-9.jpg\",\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/\",\"url\":\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/\",\"name\":\"The biggest data breaches of 2017 | OTAVA\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/otava.test\/wp-content\/uploads\/2019\/04\/top-data-breaches-2016-BLOG-12.23.16-112635440-9.jpg\",\"datePublished\":\"2017-12-27T00:00:00+00:00\",\"description\":\"As we did in 2016, we're rounding up the biggest data breaches of 2017. What have we learned as a result, and what can companies do better next year?\",\"breadcrumb\":{\"@id\":\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#primaryimage\",\"url\":\"https:\/\/otava.test\/wp-content\/uploads\/2019\/04\/top-data-breaches-2016-BLOG-12.23.16-112635440-9.jpg\",\"contentUrl\":\"https:\/\/otava.test\/wp-content\/uploads\/2019\/04\/top-data-breaches-2016-BLOG-12.23.16-112635440-9.jpg\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.otava.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"The biggest data breaches of 2017\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.otava.com\/#website\",\"url\":\"https:\/\/www.otava.com\/\",\"name\":\"OTAVA\u00ae\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.otava.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.otava.com\/#organization\",\"name\":\"OTAVA\u00ae\",\"url\":\"https:\/\/www.otava.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"contentUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"caption\":\"OTAVA\u00ae\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\",\"name\":\"Irma Brillantes\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"caption\":\"Irma Brillantes\"},\"url\":\"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"The biggest data breaches of 2017 | OTAVA","description":"As we did in 2016, we're rounding up the biggest data breaches of 2017. What have we learned as a result, and what can companies do better next year?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/","og_locale":"en_US","og_type":"article","og_title":"The biggest data breaches of 2017","og_description":"As we did in 2016, we're rounding up the biggest data breaches of 2017. What have we learned as a result, and what can companies do better next year?","og_url":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/","og_site_name":"OTAVA","article_published_time":"2017-12-27T00:00:00+00:00","og_image":[{"url":"https:\/\/otava.test\/wp-content\/uploads\/2019\/04\/top-data-breaches-2016-BLOG-12.23.16-112635440-9.jpg","type":"","width":"","height":""}],"author":"Irma Brillantes","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Irma Brillantes","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#article","isPartOf":{"@id":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/"},"author":{"name":"Irma Brillantes","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263"},"headline":"The biggest data breaches of 2017","datePublished":"2017-12-27T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/"},"wordCount":550,"commentCount":0,"publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"image":{"@id":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#primaryimage"},"thumbnailUrl":"https:\/\/otava.test\/wp-content\/uploads\/2019\/04\/top-data-breaches-2016-BLOG-12.23.16-112635440-9.jpg","articleSection":["Cybersecurity"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/","url":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/","name":"The biggest data breaches of 2017 | OTAVA","isPartOf":{"@id":"https:\/\/www.otava.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#primaryimage"},"image":{"@id":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#primaryimage"},"thumbnailUrl":"https:\/\/otava.test\/wp-content\/uploads\/2019\/04\/top-data-breaches-2016-BLOG-12.23.16-112635440-9.jpg","datePublished":"2017-12-27T00:00:00+00:00","description":"As we did in 2016, we're rounding up the biggest data breaches of 2017. What have we learned as a result, and what can companies do better next year?","breadcrumb":{"@id":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#primaryimage","url":"https:\/\/otava.test\/wp-content\/uploads\/2019\/04\/top-data-breaches-2016-BLOG-12.23.16-112635440-9.jpg","contentUrl":"https:\/\/otava.test\/wp-content\/uploads\/2019\/04\/top-data-breaches-2016-BLOG-12.23.16-112635440-9.jpg"},{"@type":"BreadcrumbList","@id":"https:\/\/www.otava.com\/blog\/the-biggest-data-breaches-of-2017\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.otava.com\/"},{"@type":"ListItem","position":2,"name":"The biggest data breaches of 2017"}]},{"@type":"WebSite","@id":"https:\/\/www.otava.com\/#website","url":"https:\/\/www.otava.com\/","name":"OTAVA\u00ae","description":"","publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.otava.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.otava.com\/#organization","name":"OTAVA\u00ae","url":"https:\/\/www.otava.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","contentUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","caption":"OTAVA\u00ae"},"image":{"@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263","name":"Irma Brillantes","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","caption":"Irma Brillantes"},"url":"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/"}]}},"_links":{"self":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/3290","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/comments?post=3290"}],"version-history":[{"count":0,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/3290\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/media?parent=3290"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/categories?post=3290"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/tags?post=3290"},{"taxonomy":"other_category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/other_category?post=3290"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}