Another year, another collection of security disasters. Here are my picks for the top 10 security stories of 2007, in no particular order because they are all depressing.
1. TJX / TJ Maxx Breach
Over 45 million credit card numbers stolen because someone thought WEP encryption on their wireless network was good enough. In 2007. WEP. I do not even know where to begin.
2. The Storm Worm
A botnet so large and sophisticated that it probably had more computing power than most Fortune 500 companies. Storm proved that malware authors are better at distributed systems than most enterprise architects.
3. UK Government Loses 25 Million Records
Two unencrypted CDs containing personal data on 25 million people. Sent through the mail. Lost. The fact that this data was on CDs in the first place tells you everything about government data handling practices.
4. Estonian Cyber Attacks
An entire country taken offline by DDoS attacks during a political dispute with Russia. The first real example of cyber warfare against a nation state, and a preview of things to come.
5. iPhone Security Concerns
Apple released the iPhone and immediately the security community started finding problems. No encryption on the filesystem, no enterprise management, and a browser that inherits all of Safari security issues.
6. Hannaford Brothers Breach
4.2 million credit card numbers stolen through malware on point-of-sale systems. The company was PCI compliant at the time of the breach. Let that sink in.
7. Monster.com Breach
1.3 million records stolen and used for targeted phishing campaigns. Attackers used the stolen data to send convincing job-related phishing emails. Social engineering at scale.
8. The Death of the Perimeter
2007 was the year it became impossible to pretend that firewalls alone could protect an organization. Between mobile devices, remote workers, SaaS applications, and partner connections, the perimeter effectively ceased to exist.
9. Organized Cybercrime Goes Mainstream
The Russian Business Network made headlines, MPack became the malware toolkit of choice, and it became clear that cybercrime was a business, not a hobby.
10. PCI DSS Gets Real
Payment card industry compliance went from nice to have to do it or lose your ability to process cards. Many organizations discovered they had been ignoring requirements they did not understand.
Here is to 2008. I am sure it will be even worse.