Industry News: Cyber

Know Your Breach: 20/20 Hearing Care Network

Written by Cybersecurity | Jun 4, 2021 3:36:36 PM

The target: 20/20 Hearing Care Network, a vision and hearing benefits administrator.

The take: 3.3 million records of Personally Identifiable Information including: names, addresses, member numbers, date of birth, and health insurance information.

The attack vector: An unsecured Amazon Web Services cloud storage database server was left online with no password protection. This meant anyone with an internet connection was able to connect and download the data. In addition, after the data was removed by the attackers, it was then deleted.

This breach highlights the critical importance of firm’s data backups, and if there should be an incident where information is deleted, it’s essential to be able to restore data to fully ascertain the scope of the breach. Proper credential management to ensure accounts and permissions are appropriately deployed and used, is an integral part of maintaining a robust cybersecurity posture.

Read more...