DEV Community

Serguey Shinder
Serguey Shinder

Posted on

Our Most Common Data Breach Began With the First Three Letters of a Name

Last year we logged thirty four personal data incidents. Two came from outside the company: a phishing message that reached one mailbox, and a stolen laptop that was encrypted. The other thirty two were emails sent to the wrong person, and in twenty seven of those the sender had typed the first few letters of a name and accepted what the mail client suggested.

The examples are ordinary and a little painful. A disciplinary outcome letter meant for a warehouse operative called Kerri went to a haulier's dispatcher called Kerry. A customer's statement of account went to a competitor who had once emailed our credit controller about something unrelated. A spreadsheet of agency workers and their home addresses went to an external distribution list whose name began with the same word as the internal one. Three of the incidents were reportable and we reported them.

For years my security programme had nothing to say about any of this. It was built around attackers, and by any honest count attackers caused a small fraction of our harm. The mail client, meanwhile, remembers every address anybody has ever written to, and places an outside stranger beside a colleague in a list that appears after three keystrokes. We send around forty thousand external emails a week. At that volume, an error rate too small for anyone to notice in themselves becomes a steady supply of incidents.

The people involved were quick, and the tool had been designed to make them quicker.

So we changed the tool instead of running another training module. The remembered address lists were cleared and no longer offer external suggestions. Any message with an external recipient and an attachment raises a confirmation that names the organisations it is going to. Outgoing mail is held for sixty seconds. Letters from human resources and statements from credit control now go out through a portal where the recipient has to sign in, so a wrong address produces a notification rather than the document. And misdirected mail is its own category in our incident reporting, counted beside phishing.

Misaddressed messages are down by about two thirds in six months.

I spent most of my career preparing for a breach in which somebody tries to get in. The ones we actually had were one of us, in a busy afternoon, sending something out.

– Serguey Shinder

Top comments (0)