Back in 2023 of September Johnson Controls experienced a huge ransomed attack Over 27 TB of data was stolen, and the ransom was set at $51 million. The breach is believed to have originated within Johnson Controls offices in Asia, where attackers exploited weaknesses in regional systems. The ransomware deployed in the attack was developed using leaked source code from the Babuk and Ragnar Locker ransomware families. Babuk and Ragnar are both hacker groups this led to Johnson Controls loss of 27 million dollars it took 23 million to solve the problem and they had a 4 million loss in revenue. The Ransome attack warned other companies on how serious cyber-attacks can be and should be taken more seriously especially companies that manufacturing and infrastructure, which should strengthen their defenses against cyber threats. Luckily Johnson Controls used backups and other tools available to recover systems and applications. Customer platforms, like their Simplex Customer Portal, faced some delays, however most operations resumed quickly.
.
The data breach was discovered in 2016 but was happening during 2013 and 2014 these attacks exposed the names, email addresses, phone numbers, dates of birth, hashed passwords, and security questions of users. The hackers were affiliated with Russia exploited their access to steal and monetize user credentials. The breach in 2013, however, remains officially unresolved. In total, all 3 billion Yahoo accounts were affected, making it the biggest data breach ever recorded. The stolen data was later sold and used for scams, identity theft, and unauthorized account access. Yahoo fixed this by Improved security systems, including better encryption and monitoring they were also working with law enforcement to find the hackers. Yahoo could have prevented this attack by Better encryption. Some data like security questions was not properly protected Faster detection. The attack went unnoticed for years Regular security audits to find weaknesses early could have also prevented this.
I never understood how common cyber attacks are and how they accrue cause of a company poor protection of their websites not only that but the amount of money lose along with personal information we lose with each attack.