Privacy Please

S6, E244 - They didn't hack in, they just logged in: The LexisNexis Security Incident


Listen Later

Send us a text

We explore the recent LexisNexus data breach that exposed sensitive personal information of over 364,000 individuals through a third-party platform accessing their GitHub account. This incident highlights critical vulnerabilities in how data brokers handle our most sensitive information and raises questions about regulatory oversight.

• Data exposed included names, date of birth, phone numbers, social security numbers, and driver's license numbers
• The breach occurred when someone accessed the company's GitHub account through a third-party platform
• Attackers likely found hard-coded credentials that allowed them to move laterally through systems 

• Data brokers operate with minimal regulation despite handling massive amounts of sensitive information
• Better governance policies and automated privacy operations could significantly reduce these risks
• Both technical solutions and regulatory approaches are needed to protect consumer data

  • Breach Occurred: December 25, 2024.
  • Discovery: April 1, 2025.
  • Public Notification: May 27, 2025.
  • Notice Letters Sent: May 24, 2025.

Shameless plus: Check out tools like Transcend's autonomous privacy operations to help prevent similar incidents and continue to monitor your privacy activities.


Support the show

...more
View all episodesView all episodes
Download on the App Store

Privacy PleaseBy Cameron Ivey

  • 4.7
  • 4.7
  • 4.7
  • 4.7
  • 4.7

4.7

29 ratings


More shows like Privacy Please

View all
Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

369 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,016 Listeners

The Privacy Advisor Podcast by Jedidiah Bracy, IAPP Editorial Director

The Privacy Advisor Podcast

66 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

175 Listeners

Hacking Humans by N2K Networks

Hacking Humans

314 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

188 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

73 Listeners

Your Undivided Attention by The Center for Humane Technology, Tristan Harris, Daniel Barcay and Aza Raskin

Your Undivided Attention

1,556 Listeners

Serious Privacy by Dr. K Royal, Paul Breitbarth & Ralph O'Brien

Serious Privacy

22 Listeners

Dwarkesh Podcast by Dwarkesh Patel

Dwarkesh Podcast

489 Listeners

Big Technology Podcast by Alex Kantrowitz

Big Technology Podcast

475 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

134 Listeners

She Said Privacy/He Said Security by Jodi and Justin Daniels

She Said Privacy/He Said Security

12 Listeners

Masters of Privacy by Sergio Maldonado

Masters of Privacy

6 Listeners

The AI Policy Podcast by Center for Strategic and International Studies

The AI Policy Podcast

43 Listeners