Implications of this Breach
Unfortunately, the damage is done to this organization Infragard. When security companies are breached, they loose a good deal of credibility. Whether the membership survives this breach remains to be seen. However, what it teaches us is more important.
However, the larger damage may be the industry cybersecurity professionals and C-Suite who’s personal information, however much or little was part of this breach. now puts these individuals and their contacts at increased risk of social engineering and compromise. Hackers parlay this type of information into Spear-phishing attacks. Anyone with an Infragard membership and reasonable amount of information needs to be extra vigilant watching for social engineering and phishing attacks.
Lesson’s Learned
Vetting applications to any organization needs to leverage multi-factor authentication methods. A single phone call to the applicant would have identified this hacker and prevented this breach, at least using this simplistic approach used.
Vet Identities Every Time in Multiple Ways
Every company out there needs a privacy policy on their website. If you collet personal non-public information on your employees or clients, then they are legally allowed to request what data you have about them and many other things (please see this article for data privacy rights). However, hackers are using these data privacy requests to sneak information out of unsuspecting companies that do not properly authenticate the identify of the requestor.
Whether a data privacy request or a membership application, identity verification is critical to avoiding granting an imposter access to critical and sensitive information.
If it can happen with Infragard, it can happen with your company. Beef up your identify and authentication practices across the board and educate your users on the required processes for verification.