Data leak

Verizon Enterprise Solutions 1.5 Million Records Exposed on Dark Web

πŸ“… 2016-01-01 🏒 Verizon Enterprise Solutions customer management portal
Primary Source β†—

Incident Details

In early 2016, Verizon Enterprise Solutions β€” the business division of Verizon that provides managed network services to Fortune 500 companies and government agencies β€” suffered a data breach exposing contact information for approximately 1.5 million enterprise business customers. The breach was discovered when the stolen data appeared for sale on a Russian cybercriminal forum for $100,000 for the entire database or $10,000 per 100,000 records. The stolen data included basic customer information such as company names, contact names, addresses, and account details β€” not financial or particularly sensitive personal data. However, the significance was in the victims: Verizon Enterprise Solutions clients include numerous Fortune 500 companies, government agencies, and critical infrastructure operators β€” the contact details could be used for targeted spear-phishing against high-value enterprise clients. KrebsOnSecurity reported the breach on 24 March 2016 after discovering the data for sale. Verizon confirmed the breach and stated it had remediated the vulnerability in its enterprise client portal. The incident was particularly ironic as Verizon’s DBIR (Data Breach Investigations Report) is one of the most respected annual data breach research publications, making Verizon Enterprise Solutions a high-profile breach victim with significant reputational implications.

Technical Details

Initial Attack Vector
Unknown attackers exploited a vulnerability in a Verizon Enterprise Solutions web portal and exfiltrated customer business data; the data was subsequently offered for sale in a Russian cybercriminal forum for $100,000 or $10,000 per portion
Vendor / Product
Verizon Enterprise Solutions customer management portal

Timeline

  1. 2016-01-01 Breach occurred
  2. 2016-03-24 Publicly disclosed
  3. 2016-03-24 Customers notified