I had to provide some identifying information for a financial service recently and it got me thinking about how numb I've become to the constant stream of massive data breaches. I decided to spend a little time and take a look at how many major breaches have happened this year.
I had plans to include numbers of people affected by each of the breaches, but it turns out that most of the hacks now days don't bother providing a number. The internet is a very connected place and most of these data breaches involve companies who provide services to other companies who provide services to customers and if you dig into them it becomes clear that there isn't anyone doing a full accounting of this.
2024 Data breaches so far
Date | Company | # of victims |
---|---|---|
2024-07-01 | AUTHY | 33mm |
2024-06-26 | EVOLVE | ??? |
2024-05-30 | SNOWFLAKE | 100mm+? |
2024-04-28 | DELL | 49mm |
2024-03-30 | AT&T | 70mm |
2024-02-21 | CHANGE HEALTH | 150mm |
2024-01-16 | TRELLO | 15mm |
KYC is the illicit activity
My takeaway from the depressing list below is that the only tenable path forward is to severely curtail the amount of information any company is allowed to collect. Obviously, this is the exact opposite of pretty much every current trend.
Perhaps the best outcome is that everyone's data is exposed and stolen and misused so often that it becomes useless for any sort of identity verification purpose and businesses and governments are left with no choice but to use public/private keypairs.