Cybersecurity training and certification firm SANS Institute suffers data breach
Thursday, August 13, 2020
Proving that no one is safe from cyberattacks, cybersecurity training and certification services provider SANS Institute has suffered a data breach with the records of some 28,000 customers stolen.
Ilia Kolochenko, founder and chief executive officer of web security company ImmuniWeb, noted that although he didn’t believe that SANS should be held accountable to the same standard of security and data protection as imposed on financial institutions and other highly regulated industries, the amount of information gained is concerning.
“The breach of one single email, however, should not lead to such a significant exposure of personally identifiable information data, even if it’s a drop in the ocean of disclosed data breaches from the last 18 months,” Kolochenko said. “Attackers will now gradually focus their attention on cybersecurity companies and organizations to get their clients’ privileged information or credentials.”
Kolochenko was conciliatory, however, adding that “the rapid and transparent reaction of SANS to this incident is laudable and professional. Moreover, this fairly insignificant incident will now likely boost internal security at SANS and provide additional confidence to its clients and partners.” Read Full Article
teiss: Sans Institute phishing attack: Hackers exfiltrated 28,000 data records
SC Media: Have I Been Pwned code base goes open source as it expands