Data leak
Verizon Enterprise Solutions 1.5 Million Records Exposed on Dark Web
Primary Source βIncident Details
In early 2016, Verizon Enterprise Solutions β the business division of Verizon that provides managed network services to Fortune 500 companies and government agencies β suffered a data breach exposing contact information for approximately 1.5 million enterprise business customers. The breach was discovered when the stolen data appeared for sale on a Russian cybercriminal forum for $100,000 for the entire database or $10,000 per 100,000 records. The stolen data included basic customer information such as company names, contact names, addresses, and account details β not financial or particularly sensitive personal data. However, the significance was in the victims: Verizon Enterprise Solutions clients include numerous Fortune 500 companies, government agencies, and critical infrastructure operators β the contact details could be used for targeted spear-phishing against high-value enterprise clients. KrebsOnSecurity reported the breach on 24 March 2016 after discovering the data for sale. Verizon confirmed the breach and stated it had remediated the vulnerability in its enterprise client portal. The incident was particularly ironic as Verizon’s DBIR (Data Breach Investigations Report) is one of the most respected annual data breach research publications, making Verizon Enterprise Solutions a high-profile breach victim with significant reputational implications.
Technical Details
- Initial Attack Vector
- Unknown attackers exploited a vulnerability in a Verizon Enterprise Solutions web portal and exfiltrated customer business data; the data was subsequently offered for sale in a Russian cybercriminal forum for $100,000 or $10,000 per portion
- Vendor / Product
- Verizon Enterprise Solutions customer management portal
Timeline
- 2016-01-01 Breach occurred
- 2016-03-24 Publicly disclosed
- 2016-03-24 Customers notified