<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:media="http://search.yahoo.com/mrss/" >

<channel>
	<title>it security &#8211; SolvereOne</title>
	<atom:link href="https://www.solvereone.com/tag/it-security/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.solvereone.com</link>
	<description>SolvereOne Site</description>
	<lastBuildDate>Mon, 16 May 2022 21:48:37 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>
	<item>
		<title>Recent Data Breaches USPS and Marriot</title>
		<link>https://www.solvereone.com/recent-data-breaches-usps-and-marriot/</link>
		
		<dc:creator><![CDATA[solvereone]]></dc:creator>
		<pubDate>Fri, 07 Dec 2018 17:22:43 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[IT Security]]></category>
		<category><![CDATA[Managed IT]]></category>
		<category><![CDATA[it security]]></category>
		<category><![CDATA[it support]]></category>
		<category><![CDATA[managed it security]]></category>
		<guid isPermaLink="false">https://www.solvereone.com/pages/?p=5457</guid>

					<description><![CDATA[Recent Data Breaches USPS and Marriot More and more it seems that data breaches are becoming the norm. We recently became aware of two large data breaches and we wanted to share that information with you. USPS Data Breach The first Data breach comes courtesy of the United States Postal Service (USPS). The data breach [&#8230;]]]></description>
										<content:encoded><![CDATA[<h1>Recent Data Breaches USPS and Marriot</h1>
<p>More and more it seems that data breaches are becoming the norm. We recently became aware of <strong>two large data breaches</strong> and we wanted to share that information with you.</p>
<h2 class="mt-20">USPS Data Breach</h2>
<p>The first Data breach comes courtesy of the United States Postal Service (USPS). The data breach was caused by a <strong>broken application programing interface</strong> (API) in the post offices InformedDelivery service. This tool was used to preview incoming mail, track packages, and manage redeliveries.</p>
<p>They were able to pull data on <em>60 million users</em> which included the following:</p>
<ul class="mb-30" style="font-size: 18px; line-height: 27px;">
<li>E-mail addresses</li>
<li>Phone numbers</li>
<li>Mailing campaign data</li>
</ul>
<p>What is worse is that no special hacking tools were needed for this request. The USPS patched the whole this week but it was originally discover in 2017.</p>
<h2 class="mt-20">Marriot Data Breach</h2>
<p>The second data breach comes from Marriot. Marriott’s’ recent data breach of their Starwood reservation <strong>database effected a group of hotels</strong> that were purchased in 2016 by Marriot. The hotels affected by the breach are:</p>
<ul class="mb-30" style="font-size: 18px; line-height: 27px;">
<li>Regis</li>
<li>Westin</li>
<li>Sheraton</li>
<li>W Hotels</li>
</ul>
<p>The information pulled from these breach includes:</p>
<ul class="mb-30" style="font-size: 18px; line-height: 27px;">
<li>Names</li>
<li>Phone numbers</li>
<li>E-mail addresses</li>
<li>Passport numbers</li>
<li>Date of birth</li>
<li>Arrival and departure information</li>
<li>Along with credit card numbers and expiration dates</li>
</ul>
<p>Marriot warns that they <em>cannot confirm if the credit card numbers were decrypted</em> but that have notified compromised guests and their CEO apologized. They have also created an information website located <a href="https://redirect.viglink.com/?format=go&amp;jsonp=vglnk_154360948383812&amp;key=a426d7531bff1ca375d5930dea560b93&amp;libId=jp4gf1n00102i8oq000DAes9iyfm7&amp;loc=https%3A%2F%2Fwww.cnn.com%2F2018%2F11%2F30%2Ftech%2Fmarriott-hotels-hacked%2Findex.html&amp;v=1&amp;out=https%3A%2F%2Fanswers.kroll.com%2F&amp;ref=https%3A%2F%2Fwww.cnn.com%2F2018%2F11%2F30%2Ftech%2Fmarriott-hotels-hacked%2Findex.html&amp;title=Marriott%20says%20500%20million%20Starwood%20accounts%20compromised%20-%20CNN&amp;txt=%20an%20informational%20website." target="_blank" rel="noopener">here</a></p>
<p>With more than 500 million users compromised this marks it as <strong>one of the biggest data breaches in history</strong>. Only Yahoo holds the record for a bigger data breach.</p>
<p>If you participated in either of these companies it is recommended you change your password with them as soon as you can.</p>
<h2 class="mt-20">What can We Do to Mitigate Data Breaches?</h2>
<p><img decoding="async" class="mobile-100 alignright size-full wp-image-5466" style="margin-top: 30px;" src="https://www.solvereone.com/wp-content/uploads/recent-data-breach-img-1.jpg" alt="IT Managed Security" width="40%" height="auto" srcset="https://www.solvereone.com/wp-content/uploads/recent-data-breach-img-1.jpg 768w, https://www.solvereone.com/wp-content/uploads/recent-data-breach-img-1-300x195.jpg 300w" sizes="(max-width: 768px) 100vw, 768px" /><br />
While we normally hear about these large breaches the fact is that smaller businesses are much riper targets for hackers. <em>Small businesses tend to have less or no security policies</em> in place and the growing nature of remote work opens companies up even further to this kind of information.</p>
<p>As a member of the Solvere One Family you are already a step ahead. Our <a href="https://www.solvereone.com/managed-security-northern-virginia.html">managed IT security team monitors your network</a> for any abnormal behavior and with tools like Sophos we are able to prevent possible compromises before they occur, but more can always be done.</p>
<h2 class="clear-float mt-20">Reach out to us about cyber security to enhance your safety</h2>
<p>We have specialists that can help <em>identify vulnerabilities</em> to your network which can then be triaged by our team</p>
<h2 class="mt-20">Keep business and personal accounts separate</h2>
<p><img decoding="async" class="mobile-100 alignleft size-full wp-image-5466 mt-30" src="https://www.solvereone.com/wp-content/uploads/recent-data-breach-img-2.jpg" alt="IT Security Services" width="40%" height="auto" /><br />
It can be difficult to keep track of the various passwords that we use but it is important not to replicate the same password across all devices. We recommend <a href="https://www.dashlane.com/features/password-manager" target="_blank" rel="noopener">Dashlane for password management</a>. Feel free to reach out to your SA for more information</p>
<div class="mb-30 hidden-md hidden-sm hidden-xs clear-float"></div>
<h2 class="mt-30 clear-float">Build Awareness</h2>
<p>Attitude adjusts Latitude as the saying goes. Keep your team engaged and encourage a healthy amount of skepticism when it comes to e-mails from unknown senders, curiosity about your work that goes beyond casual conversation, and more. While movies make hacking look cool the fact is that social engineering is one of the highest forms of hacking; no “hacker skills” needed.</p>
<h2 class="clear-float mt-20">Enforce restrictive data permissions</h2>
<p><img decoding="async" class="mobile-100 alignright size-full wp-image-5466 mt-30" src="https://www.solvereone.com/wp-content/uploads/recent-data-breach-img-3.jpg" alt="Data Security Breach" width="40%" height="auto" /><br />
Most data breaches don’t involve wild card searches, or a high level of sophistication. They often can come from employees either intentionally or unintentionally. The best example of this is using a home device to access work data without a secure VPN system in place. You should be certain that people only have access to the information they need to do their job.</p>
<p>We do our part for this by always reaching out to you, the POC, for approval should anyone request access to data they do not have access to.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
