Bitglass Research: Following the Data After a Breach
Have you ever wondered who has access to the data that is freely circulating on the internet after a breach? Data breaches and leaks are no longer rare. It seems like there is a new post every day about a breach, whether it be a retailer, a bank, or a business in general.
Naturally, after any breach, you should take some standard actions: alert the banks you have credit cards with, change your passwords, etc. But is it worth bothering with? Is it worth protecting yourself? What happens to the stolen data? Does anyone know what really happens to it?
Data protection company Bitglass wanted to know and did a little experiment.
They created 1,568 fake employee credentials, using watermarking technologies on files, and left them on the Dark Web to see where they would end up.
The backlash was immediate. Within 12 days, the information had been shared in 22 countries across five continents.
The data had received over 1,100 clicks and was downloaded 47 times. The IP address information crossed cybercrime routes from Nigeria to Russia, with particularly high activity in China and Brazil.
Complicating matters is that most breaches are discovered after an average of 205 days, according to Bitglass, which gives criminals plenty of time to wreak havoc.
Bitglass argues that breaches cannot be prevented, and of course the company encourages businesses to use the security software it developed to monitor their data.
Source:iguru.gr


