Versuchen GOLD - Frei

Native Data Breach: Anatomy Of A Cloud

Enterprise IT World

|

June 2019

Case study of a real-life example of a cloud-native data breach, how it evolved and how it possibly could have been avoided.

- Sanjay

Native Data Breach: Anatomy Of A Cloud

The company is a photo-sharing social media application, with over 20 million users. It stores over 1PB of user data within Amazon Web Services (AWS), and in 2018, it was the victim of a massive data breach that exposed nearly 20 million user records. This is how it happened.

Step 1: Compromising a legitimate user. Frequently, the first step in a data breach is that an attacker compromises the credentials of a legitimate user. In this incident, an attacker used a spear-phishing attack to obtain an administrative user’s credentials to the company’s environment.

Step 2: Fortifying access. After compromising a legitimate user, a hacker frequently takes steps to fortify access to the environment, independent of the compromised user. In this case, the attacker connected to the company’s cloud environment through an IP address registered in a foreign country and created API access keys with full administrative access.

Step 3: Reconnaissance. Once inside, an attacker then needs to map out what permissions are granted and what actions this role allows.

WEITERE GESCHICHTEN VON Enterprise IT World

Enterprise IT World

Enterprise IT World

SecurityScorecard Exposes Global ASUS Router Hijack "WrtHug" With Suspected China Links

SecurityScorecard's STRIKE threat intelligence team, working with ASUS, has uncovered Operation WrtHug- a sophisticated global espionage campaign hijacking thousands of ASUS home and SOHO routers to create covert relay nodes across Asia, the US, and Europe.

time to read

1 min

November 2025

Enterprise IT World

Armis Raises $435 Million Pre-IPO Funding, Valued at $6.1 Billion

Armis, the global leader in cyber exposure management, has secured US$435 million in pre-IPO funding, boosting its valuation to US$6.1 billion.

time to read

1 min

November 2025

Enterprise IT World

Enterprise IT World

Paytm Bets on AI in Travel with Launch of 'Paytm Checkin'

Paytm (One 97 Communications Limited), India's leading digital payments and financial services company, has unveiled Paytm Checkin, an Al-powered travel app designed to transform trip planning and booking through conversational intelligence and personalization.

time to read

1 min

November 2025

Enterprise IT World

Enterprise IT World

FROM AGENTIC AI TO INCLUSIVE GROWTH: IFTA UNVEILS FINTECH TRENDS 2026 AHEAD OF 10TH ANNUAL INDIA FINTECH FORUM

The 10th edition of the India FinTech Forum (IFTA) spotlights Agentic AI, embedded finance, democratization of wealth, cyber resilience, and fintech for Bharat as the key trends shaping India's financial future. The event, to be held on December 10, 2025, in Mumbai, will also honour disruptive fintech startups transforming the BFSI landscape.

time to read

4 mins

November 2025

Enterprise IT World

Enterprise IT World

INDIA'S DPDP ACT: A NEW ERA FOR DATA PRIVACY AND DIGITAL TRUST

The Digital Personal Data Protection Act, 2025 sets a clear framework for consent, accountability, and governance-reshaping how businesses handle personal data in an Al-driven economy.

time to read

3 mins

November 2025

Enterprise IT World

Enterprise IT World

TIRED OF SPAM CALLS? HOW THE DPDP RULES, 2025 PUT YOU BACK IN CONTROL. THE DAILY NUISANCE WE ALL KNOW

The Digital Personal Data Protection Act, 2025 sets a clear framework for consent, accountability, and governance-reshaping how businesses handle personal data in an Al-driven economy.

time to read

4 mins

November 2025

Enterprise IT World

Enterprise IT World

CyberArk Launches Free TLS Certificate Scan Tools to Help Businesses Prevent Outages and Rising Labor Costs

CyberArk has unveiled two free tools -the TLS Certificate Renewal Impact Calculator and TLS Certificate Discovery Scan to help organizations prepare for a seismic shift in certificate management.

time to read

1 min

November 2025

Enterprise IT World

Enterprise IT World

Consistent Infosystems to Showcase Advanced Surveillance Technologies at IFSEC India 2025

Consistent Infosystems, one of India's fastest-growing IT hardware and security technology brands, is gearing up for a strong presence at IFSEC India 2025, scheduled from 11-13 December at Pragati Maidan, New Delhi.

time to read

1 min

November 2025

Enterprise IT World

Enterprise IT World

Lenovo India Surges to USD 1.2 Billion Quarterly Revenue, Fueled by Al and Digita Infrastructure Demand

Lenovo India has delivered a landmark performance in Q2 FY25/26, posting USD 1.2 billion in revenue-an impressive 23% year-on-year growth-marking one of its strongest quarters to date.

time to read

1 min

November 2025

Enterprise IT World

CyberArk's New TLS Tools Signal a Turning Point in Automation and Risk Management

As TLS certificate lifespans shrink dramatically-from 398 days today to just 47 days by 2029-automation is no longer optional; it's mission-critical for business continuity.

time to read

1 min

November 2025

Translate

Share

-
+

Change font size