Data breaches: Often, this is just the first step in an attack

Datenleck - oft nur der erste Schritt eines AngriffsDatenleck - oft nur der erste Schritt eines Angriffs
Datenleck - oft nur der erste Schritt eines Angriffs

A data breach can have far more serious consequences than the simple theft of information. Even if no sensitive data—such as passwords—is compromised, cybercriminals can exploit the stolen information to carry out targeted phishing attacks. This recent case shows that stolen customer data can provide a credible context for fraud attempts. Companies must therefore not only protect their own infrastructure but also that of their partners. Data minimization and clear security requirements are essential.

In the event of a data breach, the first concern is the information that has been stolen

If no passwords, credit card information, or other particularly sensitive data are involved, the damage quickly seems manageable. However, the current case involving buyers of Steam products illustrates why this assessment may prove insufficient. According to the information available to date, it was not Valve that was attacked, but a logistics provider. Names, contact information, shipping addresses, and details about the ordered merchandise are reported to have been compromised. This data does not grant direct access to Steam accounts. However, it can provide cybercriminals with something else: a credible context for their next attack.

When a phishing email suddenly matches the situation

A generic message about a supposedly undelivered package is likely to make many recipients suspicious. The reaction may be different, however, if an order is actually in transit and the message contains corresponding details. If a hacker knows, for example, the customer’s name, address, and the Steam hardware ordered, they can tailor their scam attempt accordingly. A purported message reporting delivery issues then seems plausible, since several pieces of information it contains are actually accurate. This is precisely what makes stolen customer data so valuable to criminals. It doesn’t necessarily have to grant them direct access to an account. Instead, it can be used to gain the victim’s trust. Anyone who believes the message is genuine risks clicking on a link and entering a password or payment information on a fake website. In this scenario, highly sensitive information is not actually stolen during the initial attack. The criminals obtain it only later, using the data they stole earlier.

AI Facilitates Attacks Targeting Individual Recipients

Personalized fraud attempts are not a new phenomenon. However, generative AI makes it possible to create a large number of them with significantly less effort. Stolen datasets can be automatically analyzed and tailored to different recipients. Depending on the recipient’s location, for example, the message can use the appropriate language and mention a delivery service commonly used in that region. The wording can also be modeled after genuine delivery notifications. This means cybercriminals no longer need to manually customize thousands of messages. At the same time, the clues that used to often indicate a phishing attempt are becoming less reliable. There is no longer a need to use incorrect language or obviously inappropriate boilerplate text when individual messages can be generated automatically. A single stolen data record can thus lead to a chain of targeted attacks, which are much more difficult for the affected recipient to identify as fraud attempts.

The Steam incident is also a supply chain issue

There is a second aspect to this: companies can lose customer data even if their own systems have not been compromised. This is because many business processes only function if information is transmitted to external service providers. This does not apply solely to logistics companies. Cloud services, payment providers, CRM systems, support providers, and payroll providers also process data on behalf of other companies. If one of these partners falls victim to a successful attack, the information of numerous customers or employees could be compromised. When it comes to information security, the question is therefore not limited to how well the company’s own infrastructure is protected. It is just as important to determine which external organizations receive data and what risk this poses.

Less stored data means a smaller attack surface

Companies must therefore precisely identify which service providers process which information. It is important to verify whether all transmitted data is necessary for the intended purpose and how long it is retained. In addition, security requirements and the procedures to be followed in the event of an incident must be clearly defined. Data minimization plays a central role here. Data that a service provider does not need—and therefore does not receive—cannot be stolen in the event of an attack on its systems. The same applies to information that has been deleted upon expiration of the required retention period. The Steam case thus highlights a danger that is often underestimated when assessing data breaches. What matters is not only what criminals can do immediately with the stolen information. One must also consider the next attack that this data could enable. A seemingly limited security incident can thus become the first link in a much longer chain of attacks.

More articles