SEC536: Adversarial AI - Penetration Testing AI Systems


Experience SANS training through course previews.
Learn MoreLet us help.
Contact usBecome a member for instant access to our free resources.
Sign UpWe're here to help.
Contact Us
Justin had just finished dinner when he noticed an email from the car repair shop he recently visited to fix his car’s engine. The subject line of the email read:
“Important Security Notice About Your Account”
At first, he almost deleted it, assuming it was another scam. But curiosity got the better of him. The email explained that the company had suffered a data breach and that their customer information, including names, email addresses, home addresses, and phone numbers were exposed. The good news was that no credit card information had been compromised. Life was busy, and he decided it was not that big of a deal.
A few days passed. Then Justin started getting strange emails from the car repair company about numerous overdue bills requiring payment. The emails threatened he could go to jail if he did not pay them immediately. The emails looked legitimate, as they not only had the company logo, but they knew his name, phone number and home address. In a panic, Justin clicked on the link and paid the bill. It was several weeks later, while talking to a friend, that he realized the email and the bill were not legitimate — they were phishing emails that cyber criminals had created, using the information they had stolen from the hacked car repair company. By using Justin’s stolen information, the cyber criminals were able to create a more realistic attack. Unfortunately, Justin’s story is becoming increasingly common.
A data breach is a specific term for when personal data held by an organization has been either stolen by cyber attackers or accidentally exposed. In some cases, these organizations are required by law to notify any customers or partners whose data may have been lost or stolen as part of that data breach. The question becomes, what should you do if you are notified?
The good news is that a breach does not automatically mean you will become a victim. What matters most is how you respond.
In some cases, organizations that have experienced a data breach will also offer you some type of identity fraud protection through a third-party service. While these services do little to protect your data, they can help you monitor your financial accounts, set up credit monitoring, and often provide insurance or other protections if you are a victim of identity theft as a result of the breach. Verify the authenticity of the identity monitoring firm, as you’ll be giving them personal information in order to set up your account.
Unfortunately, there is little you can do to protect your data that other organizations collect, as in most cases you have no control over it. But by taking these simple steps, you can go a long way to ensuring you are much more secure when a data breach does happen.


Brandi Narvaez is a Senior Cybersecurity Consultant with over 25 years of experience delivering information security and infrastructure projects.
Learn more