"The most flourishing empires began with usurpation."

The mathematician Jean Sylvain Bailly had no idea how relevant this phrase would still be today. Cybercriminals, for their part, seem to have taken it to heart.

The "data breaches" are among the most significant activities on certain Dark web forums, and identity theft is undoubtedly one of the most lucrative.

Whether as part of an organized group or in a highly opportunistic manner, cybercriminals are ramping up their activities by diversifying their targets and using increasingly devious methods to get their hands on one of the holy grails of data: personal information.

Femme avec une identité inconnue : usurpation d'identité
What if you could no longer prove your identity?
  1. Defining the concept of identity theft
    1. Integrity breach
    2. Confidentiality breach
    3. Loss of availability
  2. Is there a real awareness of the risks associated with identity theft?
  3. What are the causes of data loss or theft?
  4. The consequences of identity theft
    1. Personal consequences
    2. Sociological, psychological, and physical impacts

Defining identity theft

To fully understand the consequences of personal data theft, we must first define its scope.

According to theICO (Information Commissioner's Office in the UK), a personal data breach is defined as "a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed." This is both very broad and very precise. However, we can derive a classification from it, the 3 main categories of which are:

Integrity breach

It concerns unauthorised or accidental alteration of personal data. This is often the case in the fraudulent use of official documents such as identity papers.

Confidentiality breach

It primarily concerns cases of unauthorised or accidental disclosure of, or access to, personal data. The recent case of millions of AP-HP patient records, who were tested for COVID-19, being published on the Dark Web is a glaring example.

Loss of availability

It generally follows a loss of access to or the destruction of personal dataEvery ransomware attack against public, financial, or healthcare organizations is a tragic example. These cyberattacks have prevented these entities from accessing their patients' or users' data, and have sometimes led to catastrophic outcomes.

It is understood that a data breach is not limited to just one of these categories, and that it can involve all three categories simultaneously. This is the case with high-level ransomware attacks, which involve double, triple, or quadruple extortion mechanisms.

Once this framework is established, the question remains as to what is meant by "personal data." According to the CNIL, "personal data is any information relating to an identified or identifiable natural person."[1]

Here is what can currently be easily found for sale on the Dark web:

  • Date of birth
  • Passport
  • Credit card number
  • Biometric data
  • Social security number
  • Address
  • Financial documents
  • Photographs
  • Driver's license number
  • Phone number
ce qu'on peut acheter sur le dark web pour faciliter l'usurpation d'identité d'un individu
A great deal of personal information can be easily purchased on the Dark web

All this data, which is likely to allow for the direct or indirect identification of a natural person, are personal data. They are more important to cybercriminals than most people realize.

Are people truly aware of the risks associated with identity theft?

Here are some statistics that provide food for thought regarding how people perceive risk and how readily the majority "give away" their personal information.

According to a study by Le Figaro [2] :

  • 65% of French people do not feel they are targets for personal data theft
  • 60% believe they are well protected against such incidents

However, according to The Trade Desk 2021:

  • 3 out of 4 French people say they do not feel they have enough control over their data online.[4]

Finally, a 2020 study by the marketing firm IntoTheMinds estimates that nearly 60% of internet users accept website terms of service without reading a single line [5]. However, for some, these terms are simply unacceptable: overly broad data collection (first name, last name, location, email address, etc.), abusive usage... The means to protect this collected data are almost non-existent. Fortunately, since 2018, the GDPR (General Data Protection Regulation) has been in place to protect us in Europe. Sadly, this is not enough, as zero risk does not exist.

" By 2025, it is estimated that 75 billion devices will be connected to the Internet, up from 25 billion in 2019. "[6] This explosion in the number of exposed devices will inevitably lead to more and more personal data being connected, available, and therefore stealable. It now seems accepted and normal for our refrigerator to be able to read our emails and notify us via our Twitter account that the butter is about to expire...

The personal data market is booming on the Dark web. Very specific areas are even being created to allow cybercriminals to conduct their business. Here are some examples of what is being traded:

prix d'éléments importants pour l'usurpation d'identité sur le Dark Web
Price indices on the Dark web

What are the causes of data loss or theft?

Statistics show that: the main causes of loss or theft are a lack of user attention and the overexposure of personal data. Unfortunately, people often forget their intrinsic value.

There are also other reasons, sometimes more technical, that can lead to these data breaches.

Examples include:

  • the weaknesses in application development using this data, which allow cybercriminals to bypass security mechanisms
  • the proliferation of hosting locations for this data, resulting in a loss of control over protection measures
  • the corporate test environments, abandoned after deployment but still accessible to cybercriminals
  • the desire to constantly simplify the user experience, at the expense of basic security protocols (unsecured Wi-Fi, QR code systems used to centralize sensitive information, etc.)
  • the lack of protection on certain shopping sites online
  • etc.

The potential causes are numerous, and creating an exhaustive list is nearly impossible. Between technical and technological issues, and erratic human behavior, it is clear that all this data remains unsecured. This lack of security can have dire consequences.

The consequences of identity theft

The theft or loss of sensitive data is one of the major consequences of cyberattacks. These can involve company assets, intellectual property, or patent theft, for instance in cases of corporate espionage.

It is also important to measure the impact that personal data theft can have on an individual or their family.

Personal consequences

Other consequences that are more personal and less tangible for a business include reputational damage. Once a reputation is tarnished, it can lead to the loss of key personnel, damaged relationships with clients or business partners, and a degradation of the image portrayed in the media.

On a daily basis, this can have a sociological, psychological, and even physical impact.

Having your identity stolen can be traumatic, not to mention the fact that you then have to go through the process of proving and recovering it. This journey is often described as a nightmare by victims, who sometimes take several years to regain full control of their identity.

The psychological, social, and physical consequences of identity theft

The psychological and social consequences are not the only ones. Others, just as devastating, can also manifest.

Legal consequences

The rise in cyber risks is forcing companies to shift from a security policy to a safety policy. They will therefore need to prepare a legal arsenal, such as insurance or contractual clauses with their partners. In the event of an attack, they find themselves both a victim (facing administrative, ethical, and criminal liability, as well as GDPR compliance issues) and responsible. It is therefore in their best interest to protect themselves.

Financial consequences

The financial impact is the first thing we think of in the event of a cyberattack.

But indirect costs are sometimes overlooked (for example, investigation fees). People often forget that business interruption leads to recovery costs related to repairing or replacing damaged networks and equipment.

Intangible consequences due to lost opportunities or loss of trust can also lead to a freeze in a company's competitiveness, or even its profitability. This indirect cost, which is difficult to estimate in most cases, should not be overlooked.

Data breaches: a complex issue

Data breaches are complex issues that bring a multitude of technical, legal, financial, and psychological complications in their wake.Beyond common sense, there are a number of simple measures to implement that fall under what is known as "cyber hygiene." Some of these are clearly explained on the official website cybermalveillance.fr. Other measures are more technical in nature.

Technologies that offer a comprehensive approach, or those that focus on mobile protection, for example, are part of this. The TEHTRIS XDR Platform, as well as TEHTRIS MTD in particular, effectively protect devices from any deviant behavior and serve as an effective first line of defense against losing control of your data.

[1] https://ico.org.uk/for-organisations/guide-to-data-protection/guide-to-the-general-data-protection-regulation-gdpr/personal-data-breaches/

[2] https://www.cnil.fr/fr/definition/donnee-personnelle

[3] https://www.lefigaro.fr/actualite-france/2011/10/05/01016-20111005ARTFIG00700-usurpation-d-identite-les-francais-inquiets.php

[4] https://comarketing-news.fr/lost-in-data-les-francais-ne-se-sentent-plus-maitres-de-leurs-donnees/

[5] https://www.intotheminds.com/blog/statistiques-rgpd-europe/

[6] By 2025, it is estimated that 75 billion devices will be connected to the Internet, compared to 25 billion in 2019.

Continue reading
Blog
Contactez Tehtris
Nos équipes vous recontacteront au plus vite afin d'échanger sur vos challenges cyber et évaluer comment nous pouvons vous accompagner pour les adresser.
Tehtris EDR : conçu, développé et opéré en Europe
Voir nos preuves
Derniers articles
See all