Personal Data Leak Affects 33 Million US Employees
Information exposed in the leak includes personal details of employees from the Department of Defense and US Postal Service.
The personal data of more than 33 million employees from US-based organizations was found lying unprotected on the web, reports Help Net Security. The leaked information, available on Troy Hunt's Have I Been Pwned service, had been compiled by US business service firm Dun & Bradstreet (D&B), which sells commercial data to businesses.
Security researcher Hunt got the data from a reportedly reliable source, and it is believed that it may have been stolen from the unprotected database of a D&B customer. The information includes personal details such as email addresses and company information. Affected employees include those of the Department of Defense, US Postal Service, AT&T, FedEx, Citigroup and others.
"In terms of where this data specifically came from, D&B don't believe it was directly from one of their systems and with thousands of customers purchasing this information, we may well never know who lost it," says Hunt.
Although the leaked data was not classified, it carries the risk of misuse by cybercriminals who aim to impersonate employees and get their hands on more sensitive information.
Read more on Help Net Security.
About the Author
You May Also Like
Unleashing AI to Assess Cyber Security Risk
Nov 12, 2024Securing Tomorrow, Today: How to Navigate Zero Trust
Nov 13, 2024The State of Attack Surface Management (ASM), Featuring Forrester
Nov 15, 2024Applying the Principle of Least Privilege to the Cloud
Nov 18, 2024The Right Way to Use Artificial Intelligence and Machine Learning in Incident Response
Nov 20, 2024