Skip to main content
banner image
venafi logo

The Major Data Breaches of 2017: Did Machine Identities Play a Factor?

The Major Data Breaches of 2017: Did Machine Identities Play a Factor?

Major breaches of 2017
December 19, 2017 | Eva Hanscom

Simply put: this was a banner year for mega data breaches; according to Gemalto’s Breach Level Index, over 900 data breaches occurred during the first half of 2017, which compromised 1.9 billion records. More data was stolen in the first six months of 2017 than the entirety of 2016. Unfortunately, the massive exfiltration of data is a critical symptom of weak machine identity protection.

In the aftermath of major security incidents, experts often wonder how cybercriminals were able to exfiltrate large amounts of data while remaining undetected. Compromised machine identities allow attackers to use encrypted tunnels where traffic is only sporadically inspected - an approach that permits them to evade security controls. In fact, a recent study from A10 Networks found that 41 percent of cyberattacks use encryption to evade detection.

“Organizations increasingly rely on encrypted communication between rapidly changing networks of machines that are used for a wide range of critical-business functions,” said Nick Hunter, senior technical manager for Venafi. “To secure encrypted communications between machines, it’s vital that we protect each machine’s unique identity with at least the same rigor and precision we use to protect the online identities of humans. Unfortunately, most organizations don’t have the technology or intelligence necessary to do this, and because the number of machines on enterprise networks is exploding, this problem is rapidly getting worse.”

To highlight the role that compromised machine identities played in the data breaches revealed in 2017, we examined security incidents where large amounts of data were extracted without detection. Due to the massive scope and duration of these breaches, it’s likely machine identities played a pivotal role in these breaches.

“Effective machine identity protection requires complete visibility and continuous assessment of all identities across the extended enterprise,” concluded Hunter. “Only comprehensive intelligence can drive the automated, coordinated actions that are necessary to proactively remediate machine identity weaknesses. Until more organizations have these capabilities, we will continue to see massive breaches, even among large organizations with major investments in security. The only way organizations can stem the rising tide of data loss is to automate machine identity protection.”

Will we continue to see breaches that manipulate weak machine identities in 2018?

Subscribe to our Weekly Blog Updates!

Join thousands of other security professionals

Get top blogs delivered to your inbox every week

See Popular Tags

You might also like

hands reaching out of laptop screen holding ballot box, another person's hand casting a vote
Encryption

Will Encryption Backdoors Hurt Election Infrastructure? Security Professionals Say Yes.

Man standing in front of a cyber-secured world.

What If You Could Guarantee Eliminating Outages in Your Organization?

Next Gen Code Signing Venafi digital thumbprint

Next Gen Code Signing Takes Machine Identity Protection to the Next Level

About the author

Eva Hanscom
Eva Hanscom

Eva is Public Relations Manager at Venafi. She is passionate about educating the global marketplace about infosec and machine-identity issues, and in 2018 grew Venafi's global coverage by 45%.

Read Posts by Author
get-started-overlay close-overlay cross icon
get-started-overlay close-overlay cross icon
Venafi Risk assessment Form Image

Sign up for Venafi Cloud


Venafi Cloud manages and protects certificates



* Please fill in this field Please enter valid email address
* Please fill in this field Password must be
At least 8 characters long
At least one digit
At last one lowercase letter
At least one uppercase letter
At least one special character
(@%+^!#$?:,(){}[]~`-_)
* Please fill in this field
* Please fill in this field
* Please fill in this field
*

End User License Agreement needs to be viewed and accepted



Already have an account? Login Here

×
get-started-overlay close-overlay cross icon

How can we help you?

Thank you!

Venafi will reach out to you within 24 hours. If you need an immediate answer please use our chat to get a live person.

In the meantime, please explore more of our solutions

Explore Solutions

learn more

Email Us a Question

learn more

Chat With Us

learn more
Chat