“Verizon responded to a recent data breach that affected millions of customer accounts. Data on "as many as 14 million" Verizon customers was readily available to download after an employee at Nice Systems left them on an unsecured Amazon server, ZDNet reported on Wednesday.” - http://www.cnbc.com
“The security vulnerability comes just one month after the company officially acquired Yahoo, which suffered the world’s largest hacks in 2014 and 2016.” - https://thinkprogress.org
“..a Verizon spokesperson told CNBC on Wednesday. "We have been able to confirm that the only access to the cloud storage area by a person other than Verizon or its vendor was a researcher who brought this issue to our attention. In other words, there has been no loss or theft of Verizon or Verizon customer information."” - http://www.cnbc.com
“Verizon told ZDNet that it believes no one actually accessed the data, and the data didn’t contain truly sensitive information like social security numbers or bank accounts, but it’s a wake-up call to anyone using cloud storage.” - https://www.geekwire.com
“The data repository, an Amazon Web Services S3 bucket administered by a NICE Systems engineer based at their Ra’anana, Israel headquarters, appears to have been created to log customer call data for unknown purposes; Verizon, the nation’s largest wireless carrier, uses NICE Systems technology in its back-office and call center operations.” - https://www.upguard.com
“Verizon confirmed on Wednesday the personal data of 6 million customers has leaked online. The security issue, uncovered by research from cybersecurity firm UpGuard, was caused by a misconfigured security setting on a cloud server due to "human error."” - http://money.cnn.com
“The incident stemmed from NICE security measures that were not set up properly. The company made a security setting public, instead of private, on an Amazon S3 storage server -- a common technology used by businesses to keep data in the cloud. This means Verizon data stored in the cloud was temporarily visible to anyone who had the public link.” - http://money.cnn.com
“The critical data repository in question was exposed not by the enterprise holding primary responsibility for the information, but by a third-party vendor to the enterprise. It was a publicly accessible AWS S3 bucket owned by third-party vendor NICE Systems that revealed the sensitive personal details of Verizon customers.” - https://www.upguard.com
”In short, NICE Systems is a trusted Verizon partner, but one that few Americans may realize has any access to their data. Such third-party vendors are entrusted every day with the sensitive personal information of consumers unaware of these arrangements. There is no difference between cyber risk for an enterprise and cyber risk for a third-party vendor of that enterprise.” - https://www.upguard.com
“The National Security Agency is currently collecting the telephone records of millions of US customers of Verizon, one of America's largest telecoms providers, under a top secret court order issued in April. The order, a copy of which has been obtained by the Guardian, requires Verizon on an "ongoing, daily basis" to give the NSA information on all telephone calls in its systems, both within the US and between the US and other countries. The document shows for the first time that under the Obama administration the communication records of millions of US citizens are being collected indiscriminately and in bulk – regardless of whether they are suspected of any wrongdoing.” - https://www.theguardian.com
1. What ISP do you have?
2. Do you know how much power ISPs have?
3. What is the answer to these non-secure ISPs?
Protect your data,
- Citizen
(Image Source)