HomeAll Articles10 cybersecurity fails that should never have happened
August 11, 2022

10 cybersecurity fails that should never have happened

Some of the biggest cybersecurity failures were not sophisticated attacks. They were preventable mistakes, missed updates, and basic controls left unchecked. The damage came later.

None of these incidents required sophisticated attacks. In most cases, the weakness was already there, sitting in plain sight: a missed update, a forgotten account, a poorly configured system.

The cost of that kind of oversight is not theoretical, with breaches averaging around $4.4 million globally, and far higher in the US. Beyond the financial hit, the damage to brand reputation can last far longer.

1. First American Financial Corporation data breach (2019)

With an estimated 885 million records affected, the First American Financial Corp data breach was an enormous 2019 hack that led to widespread losses. Bank account numbers, bank statements, mortgage and tax records, wire transfer receipts, driver’s license photos, and even Social Security numbers were all shared publicly as a result of this First American breach. This hack was particularly noteworthy because it was a true accident. The New York Department of Financial Services found, upon investigation, that the leak occurred solely because First American failed to follow its own internal security procedures. The web design of its data storage structure contained a simple authentication error. This web design flaw, called an “Insecure Direct Object Reference” (IDOR), allows anyone who searches for a direct link to access it. First American failed to check on its web structure, allowing all of these secure documents to be accessed by anyone who searched. This cybersecurity fail went undetected for years. 

2. CSDN Leak (2022)

Human error tops the list in this recent 2022 breach. According to reports, a leak of 23 terabytes of personal data was traced back to a developer working for the Chinese government. The government developer apparently accidentally included access credentials for a Shanghai police database in a tech blog post on the China Software Developer Network (CSDN). Up to 1 billion Chinese resident records were then found listed for sale on the dark web, thought to be the biggest leak of all time. 

3. Equifax data breach (2017)

Almost everyone has heard of the Equifax data breach, which cost not only $700 million in payments to those affected but also lasting professional damage. An application vulnerability on one of Equifax’s websites was eventually found to be the source of the enormous breach, prompting congressional inquiries into Equifax’s lax cybersecurity policies. According to the findings, inadequate system segmentation led to lateral contamination across multiple sites and data storage systems. 

4. Marriott International data breach (2018)

Taking a trip is supposed to be relaxing, but the 2018 Marriott International data breach cost many vacationers their peace of mind. In this hack, 500 million records were compromised, including passport information, travel dates, credit card numbers and expiration dates, as well as Marriott-specific details such as Starwood Preferred Guest numbers. The hack was traced back to a failure to update and integrate systems when Marriott purchased Starwood back in 2016. By 2018, they still had yet to update the old Starwood IT infrastructure, which had been hacked back in 2014. When Starwood was incorporated into the Marriott system, the damage only spread. 

5. Ellsworth, Kansas water hack (2021)

In one of the most dangerous hacks on the list, a disgruntled former employee used their login credentials to shut down the town’s sanitation services, affecting its drinking water. The Ellsworth, Kansas hack was a simple case in which the former employee’s login information had not been deactivated after he resigned. The remote login jeopardized the entire town’s health and safety, but was luckily discovered before harm could spread. 

6. Facebook Cambridge Analytica Scandal (2018)

Because of the amount of personal information stored on its platform, Facebook has been the target of a barrage of hacks throughout the years, the most damning of which was the Cambridge Analytica scandal. The social network has been criticized for not addressing key weaknesses in its cybersecurity infrastructure that allowed the marketing firm Cambridge Analytica to collect data on up to 87 million users worldwide. 

7. Target credit card leak (2013)

How secure is your supply chain? In some cases, your business is only as secure as the vendors who service it. A 2013 hack revealed that up to 60 million Target customers had their personal and financial information stolen when the HVAC company that serviced certain Target locations was hacked. The lateral attack cost Target an $18.5 million settlement spread across multiple state lawsuits and a $10 million class-action settlement, as well as individual direct payments to consumers who showed they had suffered losses. 

8. SEPA Christmas hack (2020)

An enormous cyberhack devastated the Scottish Environmental Protection Agency on Christmas Eve 2020. The incident is believed to have cost the Agency around $1.2 million, as well as around $2 million in uncollected fees and penalties due to the lost or stolen records. Around 1.2 GB of data, including backup copies of records, was stolen. The breach was believed to have been caused by an employee clicking a link in a phishing email. 

9. Yahoo database breaches (2013 & 2014)

The once-great email and search giant Yahoo was crippled by back-to-back cyber breaches that cost the company millions, leaked private customer information, and ultimately lost the brand its good name. The 2014 hack was particularly egregious, given that a similar 2013 effort succeeded in affecting over 3 million accounts. 

10. SolarWinds (2019)

The SolarWinds breach showed how trusted software can become an attack vector. By compromising a routine update, attackers were able to move through networks that had already approved the software as safe. The impact extended across governments and enterprises, and investigations continued long after the initial discovery. The lesson is not tied to one incident. It is that once broken, supply chain trust is extremely difficult to contain.

Small failures, large consequences

None of these incidents required breakthrough techniques. They relied on gaps that were already understood but not addressed. The lesson is not that systems fail. It is that failures are often allowed to develop. Prevention is rarely about doing more. It is about not ignoring what is already known. 

Gabrielle West
Gabrielle West
Gabrielle West is an experienced tech and travel writer currently based in New York City. Her work has appeared on Ladders, Ultrahuman, and more.

What do you think?

Popular Articles