What went wrong in eight public breaches,
from the official record.
Root cause, regulatory outcome and the control that addresses it, for breaches documented by regulators, courts, government advisories and the companies themselves.
Last updated Published by TryTrustableNot legal advice
The incidents
| Year | Incident | Root cause | Affected | Regulatory outcome |
|---|---|---|---|---|
| 2016 | Uber | Credentials in code, slow disclosure | 57 million riders and drivers worldwide | FTC expanded consent order (2018); $148 million multistate settlement (September 2018) |
| 2017 | Equifax | Unpatched vulnerability | About 147 million people | FTC, CFPB and 50 states and territories: $575 million, up to $700 million (July 2019) |
| 2019 | Capital One | Cloud configuration | About 106 million people (US and Canada) | US OCC civil money penalty of $80 million (August 2020) |
| 2020 | SolarWinds | Software supply chain | Fewer than 18,000 customers installed affected updates | CISA advisory AA20-352A; SEC charges against the company and its CISO (October 2023, contested) |
| 2021 | Colonial Pipeline | Remote access without MFA | Operational: 5,500 miles of pipeline shut down | TSA security directive for critical pipelines (May 2021) |
| 2022 | Optus | Internet-facing exposure | About 9.5 million Australians (OAIC) | OAIC civil penalty proceedings in the Federal Court (filed August 2025, before the court) |
| 2023 | MOVEit Transfer | Third-party product zero-day | Many organisations; no official consolidated count | CISA and FBI advisory AA23-158A; SEC closed its inquiry into Progress without action (August 2024) |
| 2023 | CircleCI | Session token theft, CI secrets | Customer secrets in the platform; fewer than 5 customers reported onward access | None identified in official sources; company incident report |
Figures are as stated by the regulator, government body or company named on each page. Where proceedings are open, the outcome column says so.
Patterns across the cases
Eight incidents across seven years, regulators in two countries and very different attackers. The failures underneath them are few and repeat.
Credentials and authentication
Uber's attackers found a cloud key in code and reached the repository with reused passwords and no MFA. Colonial's attacker logged into a VPN with a username and password because the profile asked for nothing more. CircleCI's attacker skipped authentication entirely by stealing a session that had already passed it. CISA's SolarWinds advisory lists password spraying and poorly secured administrative credentials as further ways in. MFA everywhere, short sessions, no secrets in code, and short-lived credentials address most of this.
Access that should not have existed
Colonial's VPN profile was not meant to be in use. Equifax's attackers reached 48 unrelated databases because nothing separated them, and found plain-text credentials for more. The OCC found weak network security controls at Capital One. Access reviews, least privilege and segmentation are dull controls; these cases are what their absence looks like.
Patching and knowing what you run
Equifax had a patch policy and a 48-hour deadline. The notice went to an out-of-date list and the scan was not configured to cover every asset. MOVEit was a zero-day, so there was nothing to patch at first, and organisations that did not know where they ran it lost time. An accurate inventory is the control under both.
Third parties and the supply chain
SolarWinds customers installed legitimate updates that carried malicious code from a compromised build system. MOVEit victims were breached through a vendor's product. CircleCI customers lost secrets held by their CI provider. A supplier register that records what each vendor touches is where response starts.
Exposure nobody owned
The OAIC's first lesson from Optus is clear ownership of internet-facing domains, and its second is authorisation on every request for personal data. Capital One's data was reachable from outside because of a configuration gap. What faces the internet needs an owner, a test and a log.
Detection and disclosure
Equifax's inspection tool was blind for ten months because a certificate had expired. Capital One and CircleCI learned of their breaches from outsiders. Uber paid the attackers and told no one for a year, and its largest settlement was about that delay. Monitoring that works and an incident process with clear notification duties are the controls; the regulatory outcomes in these cases show what their absence costs.
How these pages are written
- Official sources only. Every figure links to a regulator, government body, court filing or the company's own disclosure. News coverage is not used as a source of fact.
- No speculation. Root causes are described as the sources describe them. Where a source could not be read, the detail is left out and the page says so.
- No hindsight claims. We do not say any tool would have prevented these incidents. Each page names the control, its SOC 2 and ISO 27001:2022 references, and how TryTrustable checks it.
- Open matters stay open. Where proceedings have not concluded, the pages say they are allegations.
Related: SOC 2 guide · SOC 2 requirements · compliance as code · incident management · Research
The things people ask us
Which breaches are covered?
Uber (2016), Equifax (2017), Capital One (2019), SolarWinds (2020), Colonial Pipeline (2021), Optus (2022), CircleCI (2023) and MOVEit Transfer (2023). Each is documented by a regulator, a court filing, a government advisory or the company's own disclosure.
Where do the facts come from?
Only from official sources: regulators such as the FTC, the OCC and the OAIC, the US GAO, CISA advisories, congressional testimony, SEC filings and the companies' own incident pages. Each page links its sources. Where an official source could not be read, the fact is left out.
Would a compliance tool have prevented these breaches?
We do not claim that, and nobody can show it. Each page names the controls that address the gap, with SOC 2 and ISO 27001 references, and describes how TryTrustable checks whether those controls are in place in your own environment.
What is the most common root cause across the cases?
Credentials and access: a key in code, a password with no second factor, a stolen session, an unused access path still open. Unpatched or unknown software and internet-facing systems nobody was watching come next.
See which of these controls you can evidence today.
We connect GitHub and one cloud account in a demo and show the checks behind each control, with the evidence an auditor would ask for.