The only good news in regard to 2015 U.S. data breaches was that fewer took place than the year before – by a hair. The bad news was the number of exposed records doubled compared to 2014 figures.

There were 781 data breaches in 2015, which exposed 169,068,506 records containing personally identifiable information, according to the San Diego-based Identity Theft Resource Center. That is just shy of the record-setting 783 incidents, which revealed 85,611,528 records, in 2014.

The ITRC defines a data breach as an incident that puts personal information (such as an individual name plus a Social Security number, driver's license number, or medical or financial record information) at risk because of exposure. For some breaches, statistics were not yet reported or were unconfirmed.

According to the ITRC, the five breached industry sectors in 2015 were: Medical/Healthcare (66.7%), Government/Military (20.2%), Business (9.6%), Banking/Credit/Financial (3%) and Educational (.4%). The number of confirmed records exposed, by industry, was: Medical/Healthcare (112,832,082), Government/Military (34,222,763), Business (16,191,017), Banking/Credit/Financial (5,063,044) and Educational (759,600).

The biggest credit union breach took place at the $308 million, Winston-Salem, N.C.-based Piedmont Advantage Credit Union, which notified its 46,000 members in early March that a laptop containing PII was missing.

Two data breaches were highly talked up in the media, but did not make the 10 biggest list. First, a misconfigured database exposed the information of 191 million registered U.S. voters for more than a week. Independent security researcher Chris Vickery discovered the 300GB database on Dec. 20 and reported it to DataBreaches.net, which keeps track of online security blunders.

Second, a breach of the online affair website Ashley Madison lit up 37 million usernames, passwords, addresses, phone numbers and credit card transactions on the Dark Web. Four NCUA work email addresses were among those compromised.

Following are the biggest 2015 U.S data breaches, based on confirmed, exposed PII records.

1. Anthem Inc.: 78.8 Million Records

In February at the Indianapolis-based health insurer Anthem Inc., hackers accessed a corporate database. It included a list of current and former U.S. customers and employees, and personal information such as birthdays, medical IDs, Social Security numbers, street and email addresses and employment information, including income data.

2. OPM: 21.5 Million Records

In June and July, the U.S. Office of Personnel Management discovered two separate but related cybersecurity breach incidents, which exposed the personal data of current and former Federal government employees, contractors and others. The OPM blamed the attack on Chinese hackers. Hackers acquired forms submitted by applicants seeking security clearances with the federal government. These 127-page forms contained, among other things, the names of friends, relatives and associates of the applicants as well as financial information.

3. T-Mobile: 15 Million Records

In September, Experian North America discovered an unauthorized party accessed certain servers, exposing Social Security numbers, and other data on people who applied for financing from wireless provider T-Mobile USA. Information included names, addresses, Social Security numbers, birthdates, identification numbers (such as driver's license, military ID or passport numbers) and additional information used in TMobile's own credit assessment.

4. Premera Blue Cross: 11 Million Records

The Mountlake Terrace, Wash.-based Premera Blue Cross disclosed an intrusion into its network might have resulted in a breach of financial and medical records. It indicated that state-sponsored espionage groups based in China might have been the culprits. The company said it learned about the attack on Jan. 29, 2015. However, its investigation revealed that the initial attack occurred on May 5, 2014.

5. Excellus Blue Cross Blue Shield: 10 Million Records

In September, the Rochester, N.Y.-based Excellus Blue Cross Blue Shield and a partner company revealed a breach, which stole Social Security numbers and other identifying information, as well as information related to claims members made to pay for medical care.

6. Georgia Secretary of State: Six Million Records

In November, two women filed a class action lawsuit alleging a massive data breach took place within Georgia Secretary of State Brian Kemp's office involving the Social Security numbers and other private information belonging to voters statewide. The suit alleged the unauthorized information, released in October, contained birthdates and driver's license numbers. In response, Kemp's office blamed a “clerical error” and said it did not consider it a breach of its system. It said 12 organizations, including statewide political parties, news media organizations and Georgia GunOwner Magazine received the file.

7. Scottrade: 4.6 Million Records

In October, the St. Louis-based Scottrade said federal law enforcement officials notified the company about crimes involving the theft of information from Scottrade and other financial services companies. It said all client passwords remained encrypted at all times and did not see any indication of fraudulent activity due to the incident. The company said the unauthorized access appeared to have occurred from late 2013 to early 2014.

8. UCLA Health System: 4.5 Million Records

A July cyberattack on UCLA Health System's computer network exposed data containing personal and medical information, including names, addresses, Social Security numbers and medical data, including information related to conditions, medications, procedures and test results.

9. Medical Informatics Engineering: 3.9 Million Records

In May, the technical team at the Fort Wayne, Ind.-based Medical Informatics Engineering discovered suspicious activity on one of its servers. It determined some protected health information had been exposed, including patient names, home and email addresses, birthdates and some Social Security numbers.

10. Amazon Web Services: 1.5 Million Records

A contractor for the Larkspur, Calif.-based Systema Software inadvertently posted insurance claim data and other highly sensitive information on Amazon Web Services. Data exposed included Social Security numbers, insurance claim information, claimant ID numbers, drug test results, details and dates of medical services provided, billing amounts and payment information.

Complete your profile to continue reading and get FREE access to CUTimes.com, part of your ALM digital membership.

Your access to unlimited CUTimes.com content isn’t changing.
Once you are an ALM digital member, you’ll receive:

  • Breaking credit union news and analysis, on-site and via our newsletters and custom alerts
  • Weekly Shared Accounts podcast featuring exclusive interviews with industry leaders
  • Educational webcasts, white papers, and ebooks from industry thought leaders
  • Critical coverage of the commercial real estate and financial advisory markets on our other ALM sites, GlobeSt.com and ThinkAdvisor.com
NOT FOR REPRINT

© 2024 ALM Global, LLC, All Rights Reserved. Request academic re-use from www.copyright.com. All other uses, submit a request to [email protected]. For more information visit Asset & Logo Licensing.

Roy Urrico

Roy W. Urrico specializes in articles about financial technology and services for Credit Union Times, as well as ghostwriting, copywriting, and case studies. Also: writer/editor of a semi-annual newsletter for Association for Financial Technology since 1997 and history projects funded by the U.S Interior Department, National Park Service and Warren County (N.Y.).