Research · Breach case studies

What went wrong in eight public breaches,
from the official record.

Root cause, regulatory outcome and the control that addresses it, for breaches documented by regulators, courts, government advisories and the companies themselves.

Last updated Published by TryTrustableNot legal advice

01

The incidents

YearIncidentRoot causeAffectedRegulatory outcome
2016UberCredentials in code, slow disclosure57 million riders and drivers worldwideFTC expanded consent order (2018); $148 million multistate settlement (September 2018)
2017EquifaxUnpatched vulnerabilityAbout 147 million peopleFTC, CFPB and 50 states and territories: $575 million, up to $700 million (July 2019)
2019Capital OneCloud configurationAbout 106 million people (US and Canada)US OCC civil money penalty of $80 million (August 2020)
2020SolarWindsSoftware supply chainFewer than 18,000 customers installed affected updatesCISA advisory AA20-352A; SEC charges against the company and its CISO (October 2023, contested)
2021Colonial PipelineRemote access without MFAOperational: 5,500 miles of pipeline shut downTSA security directive for critical pipelines (May 2021)
2022OptusInternet-facing exposureAbout 9.5 million Australians (OAIC)OAIC civil penalty proceedings in the Federal Court (filed August 2025, before the court)
2023MOVEit TransferThird-party product zero-dayMany organisations; no official consolidated countCISA and FBI advisory AA23-158A; SEC closed its inquiry into Progress without action (August 2024)
2023CircleCISession token theft, CI secretsCustomer secrets in the platform; fewer than 5 customers reported onward accessNone identified in official sources; company incident report

Figures are as stated by the regulator, government body or company named on each page. Where proceedings are open, the outcome column says so.

02

Patterns across the cases

Eight incidents across seven years, regulators in two countries and very different attackers. The failures underneath them are few and repeat.

Credentials and authentication

Uber's attackers found a cloud key in code and reached the repository with reused passwords and no MFA. Colonial's attacker logged into a VPN with a username and password because the profile asked for nothing more. CircleCI's attacker skipped authentication entirely by stealing a session that had already passed it. CISA's SolarWinds advisory lists password spraying and poorly secured administrative credentials as further ways in. MFA everywhere, short sessions, no secrets in code, and short-lived credentials address most of this.

Access that should not have existed

Colonial's VPN profile was not meant to be in use. Equifax's attackers reached 48 unrelated databases because nothing separated them, and found plain-text credentials for more. The OCC found weak network security controls at Capital One. Access reviews, least privilege and segmentation are dull controls; these cases are what their absence looks like.

Patching and knowing what you run

Equifax had a patch policy and a 48-hour deadline. The notice went to an out-of-date list and the scan was not configured to cover every asset. MOVEit was a zero-day, so there was nothing to patch at first, and organisations that did not know where they ran it lost time. An accurate inventory is the control under both.

Third parties and the supply chain

SolarWinds customers installed legitimate updates that carried malicious code from a compromised build system. MOVEit victims were breached through a vendor's product. CircleCI customers lost secrets held by their CI provider. A supplier register that records what each vendor touches is where response starts.

Exposure nobody owned

The OAIC's first lesson from Optus is clear ownership of internet-facing domains, and its second is authorisation on every request for personal data. Capital One's data was reachable from outside because of a configuration gap. What faces the internet needs an owner, a test and a log.

Detection and disclosure

Equifax's inspection tool was blind for ten months because a certificate had expired. Capital One and CircleCI learned of their breaches from outsiders. Uber paid the attackers and told no one for a year, and its largest settlement was about that delay. Monitoring that works and an incident process with clear notification duties are the controls; the regulatory outcomes in these cases show what their absence costs.

03

How these pages are written

  • Official sources only. Every figure links to a regulator, government body, court filing or the company's own disclosure. News coverage is not used as a source of fact.
  • No speculation. Root causes are described as the sources describe them. Where a source could not be read, the detail is left out and the page says so.
  • No hindsight claims. We do not say any tool would have prevented these incidents. Each page names the control, its SOC 2 and ISO 27001:2022 references, and how TryTrustable checks it.
  • Open matters stay open. Where proceedings have not concluded, the pages say they are allegations.

Related: SOC 2 guide · SOC 2 requirements · compliance as code · incident management · Research

Questions

The things people ask us

Which breaches are covered?

Uber (2016), Equifax (2017), Capital One (2019), SolarWinds (2020), Colonial Pipeline (2021), Optus (2022), CircleCI (2023) and MOVEit Transfer (2023). Each is documented by a regulator, a court filing, a government advisory or the company's own disclosure.

Where do the facts come from?

Only from official sources: regulators such as the FTC, the OCC and the OAIC, the US GAO, CISA advisories, congressional testimony, SEC filings and the companies' own incident pages. Each page links its sources. Where an official source could not be read, the fact is left out.

Would a compliance tool have prevented these breaches?

We do not claim that, and nobody can show it. Each page names the controls that address the gap, with SOC 2 and ISO 27001 references, and describes how TryTrustable checks whether those controls are in place in your own environment.

What is the most common root cause across the cases?

Credentials and access: a key in code, a password with no second factor, a stolen session, an unused access path still open. Unpatched or unknown software and internet-facing systems nobody was watching come next.

Book a walkthrough

See which of these controls you can evidence today.

We connect GitHub and one cloud account in a demo and show the checks behind each control, with the evidence an auditor would ask for.