Forms of Data Breaches
A data breach occurs when a cybercriminal infiltrates a data source and extracts confidential information. This can be done by physically accessing a computer or network to steal local files or by bypassing network security remotely. While most data breaches are attributed to hacking or malware attacks, other breach methods include insider leaks, payment card fraud, loss or theft of a physical hard drive of files and human error. One Verizon study tells us that 71% of breaches are financially motivated and that ransomware accounts for nearly 24% of incidents where malware is used. This is of major concern since, at least, 36% of external data breach actors in 2019 were involved in organized crime. The most common cyber-attacks used in data breaches are:
Ransomware
Ransomware is software that gains access to and locks down access to vital data. Files and systems are thereby locked down and a fee is then demanded, commonly in the form of cryptocurrency. The most common targets in such attacks are enterprise companies and businesses.
Malware
Malware, also commonly referred to as “malicious software,” is a term that describes any program or code that harmfully probes systems. The malware is designed to harm your computer or software and commonly masquerades as a warning against harmful software. The “warning” attempts to convince users to download varying types of software and, while it does not damage the physical hardware of systems, it can steal, encrypt or hijack computer functions. Malware can penetrate your computer when you are navigating hacked websites, downloading infected files or opening emails from a device that lacks anti-malware security. Common targets in such attacks are individuals and businesses.
Phishing
Phishing scams are some of the most common ways hackers gain access to sensitive or confidential information. Phishing involves sending fraudulent emails that appear to be from reputable companies, with the goal of deceiving recipients into either clicking on malicious links or downloading infected attachments, usually to steal financial or other confidential information. The most common targets in such attacks are individuals and businesses.
Denial of Service (DoS)
A Denial of Service is a cyber-attack in which the perpetrator seeks to make a machine or network resource unavailable to its intended users by temporarily or indefinitely disrupting services of a host connected to the Internet. It is typically accomplished by flooding the targeted machine or resource with superfluous requests in an attempt to overload systems and prevent some or all legitimate requests from being fulfilled. The most common targets in such attacks are sites or services hosted on high-profile web servers such as banks.