wasc-whid@lists.webappsec.org

WASC Web Hacking Incidents Database

View all threads

WHID 2011-66: Epsilon Data Breach

WW
WASC Web Hacking Incidents Database
Mon, Apr 25, 2011 1:15 PM

*Entry Title: *WHID 2011-66: Epsilon Data Breach
*WHID ID: *2011-66
*Date Occurred: *April 4, 2011
*Attack Method: *SQL Injection
*Application Weakness: *Improper Input Handling
*Outcome: *Leakage of Information
*Attacked Entity Field: *Marketing
*Attacked Entity Geography: *
*Incident Description: *Epsilon--the largest distributor of permission-based
email in the world--revealed that millions of individual email addresses
were exposed in an attack on its servers. While no other information was
apparently compromised, security experts are warning users to brace for a
tidal wave of more precise spear phishing attacks.
*Mass Attack: *No
Reference:
http://www.pcworld.com/businesscenter/article/224192/epsilon_data_breach_expect_a_surge_in_spear_phishing_attacks.html
Attack Source Geography:

*Entry Title: *WHID 2011-66: Epsilon Data Breach *WHID ID: *2011-66 *Date Occurred: *April 4, 2011 *Attack Method: *SQL Injection *Application Weakness: *Improper Input Handling *Outcome: *Leakage of Information *Attacked Entity Field: *Marketing *Attacked Entity Geography: * *Incident Description: *Epsilon--the largest distributor of permission-based email in the world--revealed that millions of individual email addresses were exposed in an attack on its servers. While no other information was apparently compromised, security experts are warning users to brace for a tidal wave of more precise spear phishing attacks. *Mass Attack: *No *Reference:* http://www.pcworld.com/businesscenter/article/224192/epsilon_data_breach_expect_a_surge_in_spear_phishing_attacks.html *Attack Source Geography:*