165107bfmz4w7so1yhzw75

Just as you were feeling proud of grabbing a train ticket home for the Spring Festival, news broke yesterday that 12306 had suffered a password leak. At the same time, Sony and Microsoft's online gaming networks were also breached by hackers on the same day. A bit earlier, the hackers drawn in by Sony's new film escalated into a political incident that required Obama to step in, and Apple made a public statement because iCloud leaked private photos of Hollywood stars...

In 2014, too many companies were breached by hackers. "Prevent fire, prevent theft, prevent hackers" may be the most fitting phrase for this year. Today, let's review the major hacking incidents of 2014.

12306: Buying a train ticket is really too hard

The password leak was first published on the WooYun security platform after being traced by white-hat hackers. The vulnerability description stated that a large batch of 12306 usernames and plaintext passwords were circulating on the black market, and many accounts were confirmed to be usable. A total of 140,000 accounts were leaked, possibly including yours if you had just grabbed a train ticket.

12306 subsequently issued a statement saying that "all user passwords in the official website database are non-plaintext conversion codes encrypted multiple times, and the user information leaked online flowed out through other websites or channels." It also said that public security authorities had begun investigating. The WooYun security platform later announced that, according to white-hat analysis, the data may have been obtained by hackers using other leaked password databases to try logging into 12306. If users used the same username and password across different websites, they were likely to be caught in this attack.

12306 accounts include sensitive information such as ID card numbers. What you can do is go to TYPCN Tech to check whether your account has been leaked, and as soon as possible change to a secure password, while reducing use of third-party ticket-grabbing tools.

Sony, the year's biggest sufferer: escalated to the level of terrorist attack threats

In terms of breadth and depth of impact, Sony is the company most severely affected by hacker attacks in 2014. Because of a comedy film centered on Kim Jong-un, The Interview (Chinese title: Assassinating Kim Jong-un), Sony suffered the most serious and largest hacking incident of the year, exposing cooperation involving multiple Hollywood stars and even future product plans of companies like Snapchat, and throwing Sony into a crisis of trust and public relations.

The Interview is about (spoilers ahead): the host and producer of the American talk show "Skylark Tonight" learn that Kim Jong-un is their fan and plan to go to North Korea for an interview, only for the CIA to ask them to carry out an assassination mission along the way. This seemingly somewhat satirical movie brought constant trouble to Sony and made the North Korean people feel it was an unforgivable blasphemy against them. Anyway, the consequences were very serious.

A hacker group calling itself "Guardians of Peace" had already entered Sony's network through a backdoor several months earlier. After lurking for months and collecting all kinds of information, it finally posted the information online, including employee information, company plans, product status, and executive emails. This included the Xperia Z4, details of the Spider-Man and Marvel partnership, Men in Black 4, emails between Snapchat and Sony executives, and download packages of several unreleased films.

Sony employees felt like they experienced several Black Mondays, forced to change passwords for 25-30 accounts, and Sony also dismissed several executives.

The "Guardians of Peace" also threatened Sony with terrorist attacks, forcing Sony to abandon large-scale screening plans. The good news is that, despite limited theaters screening the film offline, you can still pay to download or rent it on Xbox Video, YouTube, and Google Play.

Ctrip and Xiaomi: Should you stop buying plane tickets, or stop buying phones?

In March 2014, Ctrip brought the most influential security incident in China that year. According to the vulnerability details described on WooYun, due to technical staff negligence, a massive leak of bank card information used for payments occurred on the server, including users' names, ID card numbers, bank card numbers, and bank card CVV codes.

As one of the largest travel service websites in China, this information leak dealt a heavy blow to Ctrip's reputation.

Just two months after the Ctrip incident, the Xiaomi forum also experienced a user information leak. Unlike some hackers who use existing password databases to try logging into other websites, Xiaomi's leak this time was indeed the entire user password database being attacked. Information published by WooYun showed that the leak may have affected up to 8 million users. Xiaomi officially responded that only users who registered early were affected.

By then it was too late to strengthen defenses; this information had already been circulating underground for a long time. Many Xiaomi users subsequently received scam calls, with the callers providing detailed purchase records and delivery addresses.

Apple: iCloud falls in the "explicit photo scandal"

Even Apple, which had always been very cautious about privacy, made a misstep this year: the iCloud "explicit photo scandal" in August caused a large number of female celebrities' explicit photos to leak on foreign websites, including Jennifer Lawrence, Scarlett Johansson, and Kim Kardashian, among others.

A hacker exploited a vulnerability in the "Find My iPhone" feature to steal user information. Because iCloud allowed users to try passwords multiple times, the hacker repeatedly guessed passwords against certain female celebrities' public email accounts and obtained private photos from their cameras, as well as other celebrities' email addresses. The incident was confirmed to be a targeted hacking attack against specific female celebrities. Subsequently, Apple released a patch and once again promoted two-step verification. The safest method remains to try not to take explicit photos.

South Korea: At least 2/5 of South Koreans lost credit card information

In South Korea, with a population of 50 million, the credit card information of at least 20 million people was stolen. This large-scale leak was not due to any hacker organization's superior skills, but to an employee of a personal credit scoring company stealing from within. The employee of the Korean Credit Bureau was promptly arrested. He or she retrieved the information from the internal servers of three major South Korean banks and sold it to telemarketing companies.

The leaked personal information was all-encompassing: names, ID card numbers, phone numbers, credit card numbers, and credit card expiration dates. This was the most serious information leak in South Korean history.

Negligent JPMorgan Chase: 83 million users' information leaked

This summer, JPMorgan Chase discovered that hackers had controlled more than 90 servers, targeting the banking information of 83 million users.

The cause of the leak was not disclosed until late in the month. According to The New York Times, only one server at JPMorgan Chase did not use two-step verification. It was through an account on that server that hackers entered other servers and stole information. After the intrusion, JPMorgan Chase remained unaware for months.

This time, JPMorgan Chase used facts to show you that two-step verification is indeed much safer, but you must apply it to all servers. If you forget one, it will be bad.

eBay: Lost money, and also lost its CEO

In March this year, eBay asked 128 million users to change their account passwords because its servers had been attacked by hackers. The hackers may have obtained users' personal information, account passwords, and addresses.

However, eBay did not explain in detail how hackers entered the company's servers and obtained the data. The data breach indirectly led to a sharp decline in its profits in the first quarter of 2014, and eBay also fired its then-CEO.

"Innocent" Snapchat: user information leaked, future plans exposed

Snapchat unfortunately experienced two hacking incidents: first, a third-party Snapchat app caused a large number of users' pictures and phone numbers to leak; less than two months after that storm subsided, Snapchat suffered again. Because Sony was hacked, the email communications between Sony executives and Snapchat were also exposed, involving Snapchat's plans for the coming year and collaborations that had not yet been finalized.

In October this year, Snapchat had already experienced a user information leak. Since content on Snapchat is "burn after reading" and deletes itself, a large number of teenagers like sending nude photos or videos. To that end, someone developed a third-party Snapchat platform that logs in with Snapchat account passwords and can then save content on a phone or PC. Hackers attacked one of these third-party platforms, an app called SnapSave, leaking a total of 13 GB of Snapchat images.

This is not to say that Snapchat itself is very secure. Earlier this year, Snapchat was also exposed for leaking the phone numbers of 4.6 million users from its servers; hackers merely exploited two obvious security vulnerabilities in the servers.

After Sony was hacked in December this year, internal emails between Snapchat and Sony executives were also made public, exposing the company's strategy prematurely to public view. These emails showed that Snapchat had acquired Scan.me, a startup focused on QR code scanning and iBeacon technology, as well as Vergence Labs, a manufacturer of glasses cameras. The next steps would be expanding into payments and music, and it was discussing cooperation matters with Sony and Twitter.

There are also some important but lesser-known data breaches in 2014

In addition to the well-known breached companies above, there are some hacker attacks you may not have heard of that also had wide-ranging effects. A vulnerability in the cash register system of home improvement retailer Home Depot leaked credit card information of 56 million customers. The same group of hackers may have orchestrated last year's Target credit card breach, affecting 70 million customers. Hackers took a number of email addresses and contact details from the European Central Bank's website. The attack on Community Health Systems leaked information of 4.5 million American patients, including names, addresses, and Social Security numbers, which could easily be used to forge identities.

a31caab8da7f

The recently launched Norse uses images to show you that hacker attacks are far more frequent than you imagine. Open its real-time map, and you can see ongoing hacker attacks—where they come from, who launched them, and what the targets are.

Remember to change to a secure password and stay calm. In 2015, the number of companies that got hacked will only be more, not fewer.

Original: http://qdaily.com/webapp/articles/4724