
Security through Obscurity: When secrecy alone is not enough (Part 2 of 2)
How can attackers hack you if they don’t know what to look for or how to find it? If you simply make everything in your network opaque, what could ever go wrong?


Healthcare financial services provider Craneware has reported itself to the FBI in the US, and to the Information Commissioner’s Office (ICO) in the UK, over a cyberattack.
Craneware doesn’t directly provide health care such as nursing, doctoring, and actual treatment; instead it offers:
[A]pplications and [an] industry-leading team of experts [that] contextualize operational, financial, and clinical data, providing insights that clearly demonstrate realistic revenue integrity and 340B compliance opportunities for our customers.
In a document submitted to the London Stock Exchange (LSE), the company offers the curious admission that “a significant volume of file names were viewed and exfiltrated,” which at first reading makes it sound as though file contents (the data in the files themselves) were not stolen in the breach.
But the admission continues by saying that “a large element of the data involved is non-sensitive or already public regulatory data.”
This suggests that, in the breach, the attackers not only created a list of available file names, but also stole all the files on that list.
Remember that even non-sensitive data retained by a company for its own commercial benefit or regulatory compliance isn’t supposed to be accessible to outsiders at will.
And the disclosure statement continues by noting that “a percentage of Craneware employee data as well as a subset of customer and partner records have been accessed and exfiltrated.”
Simply put, although some of the stolen data might be considered “harmless” even though it’s now in the hands of cybercriminals, some of it sounds very personal and private indeed.
In this context, the words percentage and subset aren’t helpful, given that the percentage could be 100%, and in mathematical parlance, a set in its entirety is considered to be a subset of itself.
Don’t forget, when talking about cyberattacks, that a breach of N critical records of personal information isn’t somehow mitigated just because 10N or even 100N non-personal and apparently “harmless” records were stolen at the same time.
After all, the cumulative damage caused by a breach can’t get smaller as the breach itself gets bigger!
Why not ask how SolCyber can help you do cybersecurity in the most human-friendly way? Don’t get stuck behind an ever-expanding convoy of security tools that leave you at the whim of policies and procedures that are dictated by the tools, even though they don’t suit your IT team, your colleagues, or your customers!
Paul Ducklin is a respected expert with more than 30 years of experience as a programmer, reverser, researcher and educator in the cybersecurity industry. Duck, as he is known, is also a globally respected writer, presenter and podcaster with an unmatched knack for explaining even the most complex technical issues in plain English. Read, learn, enjoy!

How can attackers hack you if they don’t know what to look for or how to find it? If you simply make everything in your network opaque, what could ever go wrong?

The average cost of a data breach in 2023 was $4.45 million — a 15% increase over three years, marking yet another year in which the average cost has risen significantly. Yet, costs can balloon even higher. Just recently, Change Healthcare had to shell out billions after its breach earlier this year. With the devastatingly high costs of cyberattacks, acting only after you’ve been compromised is a good way to incur some heavy payments or, in some cases, even go […]

According to a study of 35,000 organizations and 12.6 million individuals by KnowBe4, over 33% of users are susceptible to becoming victims of phishing attacks. These attacks often come via phishing emails carrying malicious attachments in the form of .js files, PDFs, excel sheets containing malicious macros, or script files, each of which allows the attacker to execute malicious code. While email security tools often detect these attachments, many still get through, posing a risk to less-trained employees who aren’t […]

By subscribing you agree to our Privacy Policy and provide consent to receive updates from our company.






