Watch the video lesson introducing the challenges of digital identity breaches and compromises, and prepare for independent work on studying this topic.
The video lesson also addresses the rise in cyberattacks and the reasons behind them, as well as the most common techniques used by attackers. It describes an example of a well-documented attack on the Australian National University in 2018 and the attack life cycle using a ransomware attack as an example. Finally, it presents what individuals and organisations must do to protect themselves.
Examples of digital identity breaches include unauthorized access to user accounts via stolen passwords, identity misuse on social media, or fraud through fake emails. The effects of such violations can be severe – ranging from financial losses and reputational damage to legal consequences and loss of user trust. The rise in cyber threats is becoming an increasingly serious and global security challenge. The number of attacks grows year by year, with their complexity and destructive potential also increasing. Attacks often target sensitive data, causing operational disruptions, damaging organizational reputations, and resulting in significant financial losses. Personal data of millions of users is routinely compromised, while ransomware attacks are increasingly blocking critical infrastructures such as hospitals and educational institutions. As society becomes more digitally dependent, there is a pronounced need for stronger security measures, user education, and legislative regulation to effectively address these threats. Cyberattacks on individuals and organizations are motivated by various objectives. Financial gain is the most common reason – attackers steal data, extort victims, or execute fraud. Identity theft allows for impersonation and abuse of personal information. Industrial espionage targets confidential business information to gain a competitive advantage. Some attacks have a political or ideological background, such as those carried out by hacktivists. Sabotage is executed to disrupt operations or damage reputations. Attacks are also often used to gain access to resources, for example, to create botnets. When the motive is personal revenge or a challenge, attackers seek to prove their skills. The most common techniques used by attackers today include sending fake emails or messages designed to deceive users into revealing personal information or downloading malicious software. Infecting a computer or network with malware that encrypts data results in attackers demanding a ransom for decryption. A DDoS attack overloads servers and systems, making them unavailable to users. Malware is designed to damage systems, steal data, or take control of computer infrastructure. Exploiting vulnerabilities in web applications allows malicious SQL queries to be executed to access a database. User manipulation is carried out to extract confidential information, often through false or staged scenarios. Stolen user data and passwords are exploited for automated logins across other platforms. An attack in which the attacker intercepts communication between two parties grants them access to sensitive information. A well-known example is the 2018 attack on the Australian National University. According to data published on the university’s website, the attack was attributed to a state-sponsored actor (State Sponsored APT – Advanced Persistent Threat), and was considered a long-term, targeted, and highly sophisticated intrusion. The method of entry was a phishing email with a malicious link or attachment that compromised user credentials. The attackers gained undetected access to various systems for months, using encrypted communication channels and covering their tracks. Access was further expanded by leveraging valid user accounts and administrative privileges. The goal of the attack was to steal sensitive personal, student, and academic data, as well as medical, financial, and employment information, including data going back even 19 years. The attack was only discovered in 2019, highlighting the level of concealment and depth of the breach. The consequences included the exposure of personal data of tens of thousands of current and former students and staff, significant reputational damage, and concerns about potential links to state-sponsored espionage activities. Key lessons learned include the need for continuous monitoring of network traffic, system segmentation, faster incident response, and stronger authentication mechanisms. Another well-known case is the 2017 cyberattack on the supply chain, known as the MERSK case. The attack on one of the world’s largest container operators demonstrated devastating effects within just hours. The type of attack was NotPetya ransomware. MERSK was not the direct target, but rather a local Ukrainian software supplier for accounting and finance – Linkos Group. The breach into MERSK’s system occurred via the compromised accounting software MiDoc, which transmitted the ransomware into the network during an update. The malware spread within MERSK's infrastructure thanks to administrative privileges and vulnerabilities in Windows protocols, such as EternalBlue. The consequences were catastrophic: all data was wiped from 4,000 servers and 45,000 computers, causing global business paralysis, including disruptions to ports, ships, and container tracking systems. The financial loss was estimated at between $250 and $300 million. Recovery was possible because a power outage in the local office in Ghana on the day of the attack left some servers unaffected, allowing for gradual system restoration. Key lessons learned included the need for network segmentation, regular software updates, stronger access controls, and a global incident management security plan. The lifecycle of a cyberattack can be divided into several stages. The first stage is initial infiltration, where attackers enter the system via phishing emails or exploiting vulnerabilities. This is followed by the data exfiltration stage, during which sensitive information is collected. A ransom message then informs the victim of the attack and demands payment. In the lateral movement stage, attackers move within the network to increase damage. After this comes the data encryption stage, which prevents access to information. The final stage involves financial losses, data loss, and a severe impact on the business and reputation of the organisation. To ensure protection, organisations must take various measures. Employees should be regularly educated about threats such as phishing, malware, and social engineering, and awareness of cyber risks should be raised. Access to sensitive data must be secured using complex passwords and multi-factor authentication. It is important to regularly install security updates for software, operating systems, and applications to prevent vulnerabilities, and to use antivirus programs and firewalls to protect against attacks. Regular data backups are essential for recovery in case of an attack, and backups should be physically separated from the main system. Organisations should develop and implement security policies and procedures for managing cybersecurity incidents to ensure consistent and effective data protection.
Background Colour
Font Face
Font Size
Text Colour
Font Kerning
Image Visibility
Letter Spacing
Line Height
Link Highlight