What You Should Know About the Mother of All Breaches, 2024

What You Should Know About the Mother of All Breaches, 2024

The world of cybersecurity is always changing; new vulnerabilities and threat actors seem to pop up overnight — well-armed and motivated. If you've been reading the headlines about the recent mother of all breaches (MOAB) release on the dark web, it's a stark reminder that we must always remain vigilant. 

In this blog, I’ll break down the situation and offer some tips for businesses looking to better protect themselves and their customers. 

So What Exactly Happened?

In late January of 2024, it was announced that a massive data leak was discovered on the dark web, which included over 26 billion records and took up over 12 terabytes of data. It was almost instantly referred to as “the mother of all breaches” because of the staggering size of the data.

240209_MARCO_MOAB_1

Why You Shouldn't Panic

Much of the discovered data was already known to have been compromised from previous incidents, including major platforms such as LinkedIn, Tencent, and Twitter, amongst others. 

Why You Should Be Cautious

SpyCloud, a cybercrime analytics and prevention company, recently announced that roughly 1.6 billion records “appeared distinct.” This means that in addition to data being previously available through past data breaches, some new data was included as well. 

How To Protect Yourself and Your Business 

The average cost of a data breach was $4.45 million in 2023, the highest average on record. Yes, it’s that bad. But the vast majority of data breaches are entirely preventable. So don’t use this data breach as an excuse to throw up your hands. Use it as a reminder to get smart about cybersecurity. 

240209_MARCO_MOAB_2

Review Cybersecurity Best Practices

If you haven’t upped your cybersecurity posture in the past few years, now’s your wake-up call. Make the time to review your basic cybersecurity posture and ensure that common controls are in place. With all this data being compiled in one place, it makes it even easier for even the most basic malicious hackers to attack your accounts with any credentials available from previous breaches.

Follow basic cybersecurity hygiene. For starters, make sure your staff isn’t guilty of any of these: 

  • Using passwords that have been involved in past breaches
  • Not using MFA on all accounts, including VPN, cloud accounts, and admin accounts
  • Re-using passwords 

Watch for Phishing Attempts

Be on high alert for phishing emails that may be tailored to their target — you! 

240209_MARCO_MOAB_3

With this compromised data out there, attackers will have more accurate information about individual accounts that were involved in these breaches. Attackers can and often do use templates to trick you into thinking it is from the actual vendor, so make sure you click on known secure links and bookmarks, search results, or go directly to a company's homepage.  

Don’t assume that you’re too smart to fall for a phishing scam. Hackers have been upping their game to use your brain’s cognitive biases against you — including overconfidence. 

Monitor for Compromises

There are many tools out there to monitor to see if your data has been included in data breaches. Perhaps the easiest place to start monitoring this is to go to www.haveibeenpwned.com, enter your email address, and review your results.

Getting Up To Speed on Cybersecurity

Cybersecurity evolves quickly, and it’s becoming a specialized field. Many internal IT teams simply don’t have the time or the resources to keep on top of this. So we’ve put together a cybersecurity checklist to help simplify the recommendations of the National Institute of Standards and Technology’s Cybersecurity Framework (NIST CSF)

240209_MARCO_MOAB_4

Pro tip: You can also use this checklist to make sure your current IT provider is taking good care of you. Just like in every business, not all providers are the same, and some have been known to cut corners. 

But if you can check off all of the boxes, congratulations! You’re in good shape, and you should have some peace of mind right now! If you can’t, then at least you’ll know exactly where your vulnerabilities are and how to address them. 

Get Our Cybersecurity Checklist  Download Now

Related Posts

NIST Cybersecurity Framework: Full Overview & Guide
NIST Cybersecurity Framework: Full Overview & Guide

Back in 2013, the federal government directed NIST (National Institute of Standards and Technology) to work with industry leaders to build a common framework for cybersecurity risk...

Urgent PaperCut NG/MF Vulnerability: What You Need to Know
Urgent PaperCut NG/MF Vulnerability: What You Need to Know

If you run PaperCut NG or PaperCut MF, this is the one advisory to stop and read today. In short: PaperCut has confirmed active, real-world exploitation of a vulnerability affectin...

How To Measure Your Cybersecurity Posture Against the NIST Framework
How To Measure Your Cybersecurity Posture Against the NIST Framework

A lot of businesses aren’t sure whether they actually have cybersecurity best practices in place. To be fair, cybersecurity is a moving target, and what was considered sufficient p...

The AI Governance Framework Every Org Needs Before Scaling AI
The AI Governance Framework Every Org Needs Before Scaling AI

AI is showing up in the enterprise faster than most governance programs can keep pace with: forecasting models, customer service bots, code generation tools, decision-support syste...

What Is Vishing?
What Is Vishing?

Vishing is short for “voice phishing.” Like other forms of phishing attacks — including email and text-based scams — the goal is to trick someone into handing over credentials, fin...

Cybersecurity Tips for Small Business Owners
Cybersecurity Tips for Small Business Owners

Too many small business owners still think they’re “too small” to be targeted by a cybercriminal. Unfortunately, 43% of cyberattacks each year are aimed at small businesses.

5 Common Healthcare Cybersecurity Challenges (and How MDR/SOC Can Help)
5 Common Healthcare Cybersecurity Challenges (and How MDR/SOC Can Help)

In our conversations with healthcare clients, we hear the same five security challenges come up again and again. If you're reading this, you're probably dealing with some version o...

Why Is MFA Important — and Is Your Business Using It Correctly?
Why Is MFA Important — and Is Your Business Using It Correctly?

Passwords alone haven't been enough to protect business accounts for years. Most IT professionals know this. Most business owners have heard it. And yet credential theft remains on...

What Is Cloud-Native Security?
What Is Cloud-Native Security?

Most businesses didn't set out to build a cloud-native environment. They started using Microsoft 365, added a cloud-based phone system, migrated a few workloads to Azure or AWS, an...

The Security Strategy AI-Powered Attacks Demand
The Security Strategy AI-Powered Attacks Demand

The threat environment changed. Not gradually. Abruptly. Tools like Anthropic’s Claude Mythos and the latest generation of AI-assisted exploitation capabilities have fundamentally ...