認証情報の漏洩:個人識別情報(PII)の流出が攻撃を助長する仕組み

pii leak_cybelangel_which of the following is responsible for most of the recent pii data breaches

現在、認証情報の窃取は、攻撃者が企業環境に侵入する主な手段となっており、その勢いは加速しています。Recorded Futureの調査によると、2025年下半期には上半期に比べて50%件多くの認証情報が盗まれました。侵害されたデバイス1台あたり、平均87件の認証情報が流出していました。 そのうち2億7600万件にはアクティブなセッションクッキーが含まれており、これにより攻撃者は多要素認証(MFA)を完全に迂回することが可能になっていた。.

総当たり攻撃は不要。アラートも発報されない。ただの有効なログインだ。.

このガイドでは、認証情報の漏洩が発生する仕組み、攻撃者が漏洩した認証情報で何を行うか、そして侵害に至る前に漏洩を検知する方法について解説します。.

1. PIIとは何ですか?PIIは何の略ですか?

PIIとは「Personally Identifiable Information(個人特定可能情報)」の略であり、あらゆる個人の個人データを指します。.

それは、単独で(例:氏名や社会保障番号)、または他のデータ(例:会社名と役職)と組み合わせて、個人を特定、連絡、または所在を突き止めるために使用できる情報です。.

PIIの例としては、以下のようなものが挙げられます:

  • アイデンティティ (氏名、生年月日、署名、性別、人種、家族状況)
  • 連絡先情報 (住所、電話番号、メールアドレス)
  • 職歴情報 (職歴、会社、役職、入社日、人事評価、給与)
  • 行政文書 (ID、パスポート番号、運転免許証、社会保障番号)
  • ヘルスケア (生体認証データ、医療記録)
  • IT関連 (パスワード、クッキー、ログ)

PII漏洩とは何ですか?

PIIの漏洩とは、個人が知ることなく、または同意を得ることなく機密情報が共有されることを指します。これは、ハッキング、内部不正、データ侵害、あるいは設定ミスのあるサーバーを通じた偶発的な開示などによって発生する可能性があります。.

誰がPII(個人識別情報)にアクセスできますか?

多くの個人情報はすでに一般に公開されています。例えばLinkedInにアクセスすれば、誰でもフルネームや会社情報を知ることができます。また、電子ディレクトリから電話番号も簡単に見つけることができます。.

もちろん、公開情報にはパスポート番号やクレジットカード番号などの機密情報は記載されません。しかし、さらなる情報が集められるにつれて、その人物のプロファイルはハッカーにとってますます価値の高いものとなっていきます。.

これがその理由です。.

2. なぜサイバー犯罪者はPIIに魅力を感じるのでしょうか?

PIIはサイバー犯罪者にとって価値がある。なぜなら、個人データは誰かのプロファイルを構築し、それを悪用するために使用できるからだ。.

誰かの名前、役職、パスポート、クレジットカード番号が揃えば、その人になりすまし、その資産を悪用するために必要なものはすべて揃ったことになります。.

これは通常、金銭的な利益を得るため、そして今度は他の人々を標的にするために行われます。例えば、サイバー犯罪者は個人情報(PII)を次のような目的で使用する可能性があります。

  1. なりすまし 他者の財産へアクセスするため、不正な購入を行うため、クレジットカードやローンの申請をするため、またはその他の種類の詐欺を働くため。.
  2. ソーシャルエンジニアリング 適切な個人データがあれば、サイバー犯罪者は説得力のあるメール、メッセージ、電話による詐欺を作成し、人々を操作してさらに多くのPIIを共有させることができます。.
  3. 経済的利益 個人情報はダークウェブ上で他のサイバー犯罪者に売却される可能性がある。プロファイルが完全であればあるほど、より高値で売却できる。.
  4. アカウント乗っ取り: サイバー犯罪者は、個人情報(PII)を使用して、メール、ソーシャルメディア、銀行口座などのオンラインアカウントを乗っ取ることができます。そこから、詐欺を行ったり、他の人々をも標的にしたりすることが可能です。.
  5. 脅迫 機密情報は、特にそのデータが恥ずかしいものや弱みになるものである場合、被害者に身代金を支払わせるためのインセンティブとして利用される可能性がある。.

そして世界がますますデジタル化するにつれて、個人情報(PII)の漏洩、財務情報の盗難、サイバー犯罪の潜在的リスクはかつてないほど高まっています。.

Let’s look at some examples of how this can happen.

3. サイバー犯罪者はどのように個人識別情報(PII)を盗み出すのですか?

There are a variety of ways that cybercriminals can get unauthorized access to PII data, including:

  1. Via misconfigured servers: If companies are using unsecured database providers, such as ElasticSearch, then it will be easy for cybercriminals to find a way through. They can then exploit the data through ランサムウェア, impersonation, corporate espionage, phishing, or simply by selling it on.
  2. Through social engineering: If cybercriminals can gain trust with authentic-looking emails or calls, they can then exploit people’s vulnerabilities to get more PII.
  3. With unsecured connected storage devices: These include file servers, NAS, or other synchronisation protocols which reveal detailed organizational datasets. This is often the result of negligence, misconfiguration, by-default settings, or automatic shadow backups.

For example, in 2020, CybelAngel discovered confidential documents that were exposed by open connected storage devices. The documents revealed the HR evaluations of hundreds of employees, along with internal reports of 16,000 accidents at work in an industrial company.

4. 次のうち、PII(個人識別情報)の漏洩の例はどれですか?

Any piece of information that can lead back to the person must be protected—even if it looks inconsequential.

Here are 8 quick case studies of compromised credential leaks to prove it:

  • Yahoo: Holding the record for the most people ever affected by a cyberattack, over 3 billion Yahoo user accounts were exposed by a team of Russian hackers
  • LinkedIn In 2021, hackers shared the user profiles of 700 million people, representing most of LinkedIn’s total user base
  • Cathay Pacific: In 2018, the airline suffered a mass data breach which revealed the personal information of 94 million travelers
  • Equifax: In 2017, Equifax suffered a data breach that compromised the personal data of 147 million people, and had to pay around $425 million to help those who were affected
  • Microsoft: Due to a misconfiguration, 47 companies’ databases became publicly accessible and exposed at least 38 million records in 2021
  • Real Estate Wealth Network: One of the biggest leaks in US history, this education platform exposed 1.5 billion records due to a lack of password protection
  • First American Financial Corp.: In 2019, 885 million file records were leaked—not due to hackers—but due to a poor website design and inadequate data privacy measures
  • Facebook: In 2021, Facebook had a huge data breach, sharing the names, phone numbers and passwords of more than 530 million people

From these stories, we can see that not all PII data breaches are necessarily facilitated by cybercriminals. Sometimes, they’re simply the consequence of human error or badly configured systems.

But whatever the cause, these examples show that even the biggest brands aren’t immune to PII data breaches—meaning that PII data security should be a priority for everyone.

5. 通常のPIIデータ侵害と非定型(非通常)のPIIデータ侵害の違いは何ですか?

There are two main types of PII data breaches in cybercrime.

  • A typical PII data breach is when common types of personal information (like financial information) are stolen for conventional cybercrime purposes—such as identity theft
  • A non-typical PII data breach is when less conventional types of data (like biometric or behavioral data) are stolen for a more diverse motive—such as sabotage or political manoeuvring

Regardless of the type of PII data breach, or the motives behind it, they always present a serious security risk to organizations and individuals alike.

6. PIIの漏えいはどのように報告しますか?

No one wants a PII leak to happen.

But if it does, companies are legally obliged to make a data breach report within 72 hours of it occurring, in accordance with General Data Protection Regulation (GDPR) guidelines.

For US-based organizations, the Federal Trade Commission (FTC) offers guidance on data breach responses, and it recommends the following:

  • Secure your infrastructure: Safeguard your physical and digital operations, check for any improperly posted information online, get legal advice, and do not destroy any evidence
  • Fix any vulnerabilities: Review third-party permissions, check your network server, work with cybersecurity experts, and have a clear communication policy in place
  • Notify the right people: Check your legal requirements, inform law enforcement of what’s happened, and—if it involved electronic personal health records—then you should notify the FTC as well

PII(個人識別情報)の漏洩を報告しなかった場合はどうなりますか?

If you don’t report a PII leak or data breach, it could have severe consequences, both legally and for your reputation.

  • You might pay regulatory penalties, which can reach up to €20 million under GDPR guidelines in Europe
  • You could face lawsuits from people who have been affected by the data breach
  • Your reputation will be damaged, due to loss of trust and negative publicity associated with your brand

In addition to this, your operations might be affected if the data breach has not been reported, as it will take more time to resolve it.

Alongside this, lack of reporting can exacerbate the impact on any individuals whose PII has been compromised, as they won’t have received any notifications to change their passwords, check their financial information, or freeze their credit cards, for example.

A well-known case is Yahoo, which paid a $35 million fine in 2018 after it emerged that it had failed to report a data breach for almost two years (linked to the case study we discussed earlier).

7. 組織はどのようにしてPIIデータの漏洩を防ぐことができますか?

There are 10 main best practices that every organization can adopt to reduce their PII data security risks.

  1. データを暗号化してください Sensitive PII should always be encrypted, whether in transit or at rest, using strong algorithms to keep the data safe.
  2. Implement access control: Use measures such as role-based access controls (RBAC) and multi-factor authentication (MFA) to reduce the risk of unauthorized access to sensitive data.
  3. Only collect and store the data you need: “Data minimization” refers to only collecting and keeping PII data that is truly essential for your business purposes, and regularly removing any other unnecessary data.
  4. Keep things anonymous: If you’re sharing data with third parties for analytics or testing, you could always anonymize or hide any PII data to avoid sharing more information than necessary.
  5. Train your employees: Cybersecurity measures only work when the whole team is on board. Educate your team about the importance of safeguarding PII data, and how to recognize potential cyber attacks.
  6. Invest in a Data Loss Prevention (DLP) solution: DLP software can detect and stop any unauthorized data transfers, downloads, and uploads.
  7. Keep an eye on your digital ecosystem: Keep your software, applications and systems up to date and address any vulnerabilities straight away.
  8. Have an incident response plan: Create a tried-and-tested system to respond promptly to any PII data breaches that could occur.
  9. Involve your third-party vendors, too: Set up security assessments, monitoring and contractual agreements for any third-party providers who might have access to PII data on your behalf.
  10. Audit your cybersecurity posture regularly: Run audits and assessments to catch any weaknesses in your system—before they become a problem.

These best practices will help you to secure your PII data against any leaks or cyber attacks. However, these tips are only effective when your whole organization is on board. Cybersecurity measures should be a natural part of everyone’s daily workflow and processes.

ボーナス:個人がPII(個人識別情報)データの漏洩を防ぐためには、どのようなアドバイスができるでしょうか?

It’s always best for people to proactively take steps to secure their personal information. As a company, you can share recommendations with your user base so that they can be a part of your cybersecurity initiatives, too.

Here are 4 quick and easy suggestions you can share with your clients:

  • Use strong and unique passwords, and change them regularly
  • Activate multi-factor authentication (MFA) whenever possible
  • Monitor banking apps for any suspicious activity
  • Watch out for phishing or social engineering scams

For example, some businesses will send reminders to their customers to change their passwords after a certain timeframe or share information about how to recognize a potential scam.

結論

PII is a vulnerable asset that cybercriminals can exploit, or it can be exposed simply through human error or misconfigured systems. But with the right measures in place, both organizations and individuals can protect their sensitive data.

以下はPIIサイバーセキュリティチェックリストです:

  • Always report any data breaches within 72 hours of them occurring, and follow the FTC’s recommendations to resolve them
  • Invest in encryption, access control, employee training, and other measures to protect your organization against PII threats

Credential exposure rarely announces itself. By the time a breach is confirmed, the credentials have often been circulating on dark web markets for weeks. CybelAngel monitors those markets continuously, alerting you when your organisation’s credentials appear before attackers can use them.

See what’s already exposed

著者について