Irony, thy name is SANS: 28k records nicked from infosec training org after staffer's email account phished
- Reference: 1597241590
- News link: https://www.theregister.co.uk/2020/08/12/sans_institute_data_breach/
- Source link:
SANS published some details of the breach on its [1]website . One person was phished, leading to the compromise of their email account.
Data taken included names, email addresses, phone numbers, job titles, company names, postal addresses and country of residence. Around 28,000 items of data were taken.
In a statement on its website, SANS said: "Aside from the affected user, we currently believe that no other accounts or systems at SANS were compromised."
SANS digital forensics instructors are heading up the investigation into what went wrong, with the organisation adding: "We are working to ensure that no other information was compromised and to identify opportunities to harden our systems and improve our response. When the investigation is complete, we will run a webcast to outline our learnings if there is information that we think would be useful to the community."
People whose data was nicked will be notified by email, said the organisation, which also invited people with questions to send them to info@sans.org to find out more.
A SANS staffer confirmed to The Register that the hackers harvested the data they accessed from attachments sent to the affected account and did not harvest information from its address book. We will update this article if we hear more.
Although the incident is embarrassing, and does heighten the risk of identity theft or fraud in the manner of any data breach, it goes to show that even security organisations are not immune from the common threats facing us all. ®
Updated to add
SANS got in touch to tell The Reg : "The compromised PII consisted of information of individuals who had recently registered for our virtual DFIR Summit and was intended for community outreach purposes. So this meant the data consisted of First name, Last name, Email, Work phone, company name, work address and country of residence – information that is largely available in publicly available databases. No customer records, no instructor records or other parties were impacted."
Get our [2]Tech Resources
[1] https://www.sans.org/dataincident2020
[2] https://whitepapers.theregister.com/
Re: Eh, what?
Only discovered on 6th August 2020...
I'll need to look back through my mail archive as it was some months ago (pre-UK lockdown) that I received a scam email that disclosed the password I only used for SANS...
Can't remember if I sent an email/complete a contact us webform notifying SANS of a potential breech...
Re: Eh, what?
It's not very reassuring that they don't know the difference.
Since when have people's emails been "largely available in public databases"?
I think they meant spam lists.
Information in public database
So glad to see the info was in a public database. That makes it all better then!
Publicly Available Already, That's Alright Then
Whatever happened to the organization's duty of care to protect PII in it's own database(s) whether it is available in some other organzation's data assets or not? Whatever happened to the notion of a zero trust network? After all, SANS was promoting those principals as recently as April 21 of this year ...https://www.sans.org/webcasts/zero-trust-to-secure-data-networks-113050
Eh, what?
"We are working to ensure that no other information was compromised"
"Ensure" is a very reassuring word. But how, exactly, can that be done? How are they going to unleak any other information that they find was leaked? Did they, by any chance, mean, "We are working hard to figure out whether any other information was compromised"? That is a necessary, and more achievable, but ultimately much less reassuring aspiration.