Datos de acceso comprometidos: cómo las fugas de información personal facilitan los ataques
Tabla de contenido
- 1. ¿Qué es PII? ¿Qué significa PII?
- ¿Qué es una filtración de PII?
- ¿Quién puede acceder a la PII?
- 2. ¿Por qué la PII resulta atractiva para los ciberdelincuentes?
- 3. ¿Cómo roban los ciberdelincuentes los datos de PII?
- 4. ¿Cuál de los siguientes es un ejemplo de filtración de PII?
- 5. ¿Cuál es la diferencia entre una filtración de datos de PII típica y una no típica?
- 6. ¿Cómo se reporta una filtración de PII?
- ¿Y qué pasa si no reporta una filtración de PII?
- 7. ¿Cómo pueden las organizaciones prevenir las fugas de datos de PII?
- Bono: ¿Cómo se puede aconsejar a las personas para prevenir fugas de datos de PII?
- Conclusión
- Aquí está su lista de verificación de ciberseguridad de PII:
El robo de credenciales es actualmente la principal vía de acceso de los atacantes a los entornos empresariales, y esta tendencia se está acelerando. Recorded Future detectó 50% más credenciales robadas en la segunda mitad de 2025 que en la primera. Cada dispositivo comprometido expuso, de media, 87 credenciales. Y 276 millones de ellas incluían cookies de sesión activas, lo que permitía a los atacantes eludir por completo la autenticación multifactorial (MFA).
Sin fuerza bruta necesaria. Sin alertas activadas. Solo un inicio de sesión válido.
Esta guía explica cómo ocurren las filtraciones de credenciales, qué hacen los atacantes con ellas y cómo detectar la exposición antes de que se convierta en una brecha de seguridad.
1. ¿Qué es PII? ¿Qué significa PII?
PII significa ‘Información de Identificación Personal’ y se refiere a los datos personales de cualquier persona.
Es la información que se puede utilizar para identificar, contactar o localizar a un individuo, ya sea por sí sola (por ejemplo, el nombre o el número de la seguridad social), o combinada con otros datos (por ejemplo, la empresa y el cargo).
Algunos ejemplos de PII podrían incluir...
- Identidad (nombre, fecha de nacimiento, firma, género, raza, situación familiar)
- Información de contacto (dirección, número de teléfono, dirección de correo electrónico)
- Información profesional (puesto, empresa, cargo, fecha de contratación, evaluación de recursos humanos, salario)
- Documentos administrativos (cédula de identidad, número de pasaporte, licencia de conducir, número de seguro social)
- Salud (datos biométricos, registros médicos)
- relacionado con TI (contraseña(s), cookies, registros)
¿Qué es una filtración de PII?
Una filtración de PII se produce cuando se comparte información confidencial sin el conocimiento o consentimiento de la persona. Esto puede ocurrir a través de piratería informática, amenazas internas, violaciones de datos o divulgaciones accidentales, como a través de un servidor mal configurado.
¿Quién puede acceder a la PII?
Mucha información de identificación personal (PII) ya está disponible públicamente. Si visitas LinkedIn, por ejemplo, ya puedes saber el nombre completo y la información de la empresa de alguien. Y puedes encontrar fácilmente un número de teléfono en un directorio electrónico.
Por supuesto, las fuentes públicas no incluirán información más sensible como números de pasaporte y números de tarjeta de crédito. Pero a medida que se recopila más información, el perfil de la persona se vuelve más y más valioso para los piratas informáticos.
He aquí por qué.
2. ¿Por qué la PII resulta atractiva para los ciberdelincuentes?
La PII es valiosa para los ciberdelincuentes porque los datos personales se pueden utilizar para crear el perfil de una persona con el fin de explotarlo.
Cuando tienes el nombre, el cargo, el pasaporte y el número de tarjeta de crédito de alguien, entonces tienes todo lo que necesitas para hacerte pasar por ellos y aprovecharte de sus bienes.
Esto suele hacerse con fines económicos y para atacar a otras personas a su vez. Por ejemplo, los ciberdelincuentes podrían utilizar la PII para:
- Robo de identidad: Para obtener acceso a las finanzas de alguien, realizar una compra fraudulenta, solicitar una tarjeta de crédito o un préstamo, o cometer otros tipos de fraude.
- Ingeniería social: Con los datos personales adecuados, los ciberdelincuentes pueden crear correos electrónicos, mensajes y estafas telefónicas convincentes para manipular a las personas y que compartan más PII.
- Beneficio financiero: La información de identificación personal se puede vender en la dark web a otros ciberdelincuentes. Cuanto más completo sea el perfil, mayor será el precio por el que se puede vender.
- Toma de control de cuentas: Los ciberdelincuentes pueden utilizar la información de identificación personal (PII) para tomar el control de cuentas en línea, como las de correo electrónico, redes sociales y cuentas bancarias. A partir de ahí, pueden cometer fraudes y atacar también a otras personas.
- Chantaje La información confidencial puede utilizarse como incentivo para que las víctimas paguen un rescate, especialmente si estos datos son embarazosos o comprometedores de alguna manera.
Y a medida que el mundo se digitaliza cada vez más, el potencial de filtraciones de información de identificación personal (PII), robo de información financiera y ciberdelincuencia es mayor que nunca.
Veamos algunos ejemplos de cómo puede suceder esto.
3. ¿Cómo roban los ciberdelincuentes los datos de PII?
There are a variety of ways that cybercriminals can get unauthorized access to PII data, including:
- Via misconfigured servers: If companies are using unsecured database providers, such as ElasticSearch, then it will be easy for cybercriminals to find a way through. They can then exploit the data through ransomware, impersonation, corporate espionage, phishing, or simply by selling it on.
- Through social engineering: If cybercriminals can gain trust with authentic-looking emails or calls, they can then exploit people’s vulnerabilities to get more PII.
- With unsecured connected storage devices: These include file servers, NAS, or other synchronisation protocols which reveal detailed organizational datasets. This is often the result of negligence, misconfiguration, by-default settings, or automatic shadow backups.
For example, in 2020, CybelAngel discovered confidential documents that were exposed by open connected storage devices. The documents revealed the HR evaluations of hundreds of employees, along with internal reports of 16,000 accidents at work in an industrial company.
4. ¿Cuál de los siguientes es un ejemplo de filtración de PII?
Any piece of information that can lead back to the person must be protected—even if it looks inconsequential.
Here are 8 quick case studies of compromised credential leaks to prove it:
- Yahoo: Holding the record for the most people ever affected by a cyberattack, over 3 billion Yahoo user accounts were exposed by a team of Russian hackers
- LinkedIn: In 2021, hackers shared the user profiles of 700 million people, representing most of LinkedIn’s total user base
- Cathay Pacific: In 2018, the airline suffered a mass data breach which revealed the personal information of 94 million travelers
- Equifax: In 2017, Equifax suffered a data breach that compromised the personal data of 147 million people, and had to pay around $425 million to help those who were affected
- Microsoft: Due to a misconfiguration, 47 companies’ databases became publicly accessible and exposed at least 38 million records in 2021
- Real Estate Wealth Network: One of the biggest leaks in US history, this education platform exposed 1.5 billion records due to a lack of password protection
- First American Financial Corp.: In 2019, 885 million file records were leaked—not due to hackers—but due to a poor website design and inadequate data privacy measures
- Facebook: In 2021, Facebook had a huge data breach, sharing the names, phone numbers and passwords of more than 530 million people
From these stories, we can see that not all PII data breaches are necessarily facilitated by cybercriminals. Sometimes, they’re simply the consequence of human error or badly configured systems.
But whatever the cause, these examples show that even the biggest brands aren’t immune to PII data breaches—meaning that PII data security should be a priority for everyone.
5. ¿Cuál es la diferencia entre una filtración de datos de PII típica y una no típica?
There are two main types of PII data breaches in cybercrime.
- A typical PII data breach is when common types of personal information (like financial information) are stolen for conventional cybercrime purposes—such as identity theft
- A non-typical PII data breach is when less conventional types of data (like biometric or behavioral data) are stolen for a more diverse motive—such as sabotage or political manoeuvring
Regardless of the type of PII data breach, or the motives behind it, they always present a serious security risk to organizations and individuals alike.
6. ¿Cómo se reporta una filtración de PII?
No one wants a PII leak to happen.
But if it does, companies are legally obliged to make a data breach report within 72 hours of it occurring, in accordance with General Data Protection Regulation (GDPR) guidelines.
For US-based organizations, the Federal Trade Commission (FTC) offers guidance on data breach responses, and it recommends the following:
- Secure your infrastructure: Safeguard your physical and digital operations, check for any improperly posted information online, get legal advice, and do not destroy any evidence
- Fix any vulnerabilities: Review third-party permissions, check your network server, work with cybersecurity experts, and have a clear communication policy in place
- Notify the right people: Check your legal requirements, inform law enforcement of what’s happened, and—if it involved electronic personal health records—then you should notify the FTC as well
¿Y qué pasa si no reporta una filtración de PII?
If you don’t report a PII leak or data breach, it could have severe consequences, both legally and for your reputation.
- You might pay regulatory penalties, which can reach up to €20 million under GDPR guidelines in Europe
- You could face lawsuits from people who have been affected by the data breach
- Your reputation will be damaged, due to loss of trust and negative publicity associated with your brand
In addition to this, your operations might be affected if the data breach has not been reported, as it will take more time to resolve it.
Alongside this, lack of reporting can exacerbate the impact on any individuals whose PII has been compromised, as they won’t have received any notifications to change their passwords, check their financial information, or freeze their credit cards, for example.
A well-known case is Yahoo, which paid a $35 million fine in 2018 after it emerged that it had failed to report a data breach for almost two years (linked to the case study we discussed earlier).
7. ¿Cómo pueden las organizaciones prevenir las fugas de datos de PII?
There are 10 main best practices that every organization can adopt to reduce their PII data security risks.
- Encrypt your data: Sensitive PII should always be encrypted, whether in transit or at rest, using strong algorithms to keep the data safe.
- Implement access control: Use measures such as role-based access controls (RBAC) and multi-factor authentication (MFA) to reduce the risk of unauthorized access to sensitive data.
- Only collect and store the data you need: “Data minimization” refers to only collecting and keeping PII data that is truly essential for your business purposes, and regularly removing any other unnecessary data.
- Keep things anonymous: If you’re sharing data with third parties for analytics or testing, you could always anonymize or hide any PII data to avoid sharing more information than necessary.
- Train your employees: Cybersecurity measures only work when the whole team is on board. Educate your team about the importance of safeguarding PII data, and how to recognize potential cyber attacks.
- Invest in a Data Loss Prevention (DLP) solution: DLP software can detect and stop any unauthorized data transfers, downloads, and uploads.
- Keep an eye on your digital ecosystem: Keep your software, applications and systems up to date and address any vulnerabilities straight away.
- Have an incident response plan: Create a tried-and-tested system to respond promptly to any PII data breaches that could occur.
- Involve your third-party vendors, too: Set up security assessments, monitoring and contractual agreements for any third-party providers who might have access to PII data on your behalf.
- Audit your cybersecurity posture regularly: Run audits and assessments to catch any weaknesses in your system—before they become a problem.
These best practices will help you to secure your PII data against any leaks or cyber attacks. However, these tips are only effective when your whole organization is on board. Cybersecurity measures should be a natural part of everyone’s daily workflow and processes.
Bono: ¿Cómo se puede aconsejar a las personas para prevenir fugas de datos de PII?
It’s always best for people to proactively take steps to secure their personal information. As a company, you can share recommendations with your user base so that they can be a part of your cybersecurity initiatives, too.
Here are 4 quick and easy suggestions you can share with your clients:
- Use strong and unique passwords, and change them regularly
- Activate multi-factor authentication (MFA) whenever possible
- Monitor banking apps for any suspicious activity
- Watch out for phishing or social engineering scams
For example, some businesses will send reminders to their customers to change their passwords after a certain timeframe or share information about how to recognize a potential scam.
Conclusión
PII is a vulnerable asset that cybercriminals can exploit, or it can be exposed simply through human error or misconfigured systems. But with the right measures in place, both organizations and individuals can protect their sensitive data.
Aquí está su lista de verificación de ciberseguridad de PII:
- Always report any data breaches within 72 hours of them occurring, and follow the FTC’s recommendations to resolve them
- Invest in encryption, access control, employee training, and other measures to protect your organization against PII threats
Credential exposure rarely announces itself. By the time a breach is confirmed, the credentials have often been circulating on dark web markets for weeks. CybelAngel monitors those markets continuously, alerting you when your organisation’s credentials appear before attackers can use them.
