
データ漏えいとは? データ漏洩はなぜ起きてしまうのかはフナ(What Is a Data Breach? How Do They Happen?)
What Is a Data Breach?


※お問い合わせ、御見積依頼 はこちらからどうぞ





What Is a Data Breach?


※こちらのページは、 https://www.avast.com/c-b-what-is-a-data-breach を日本語に翻訳したページとなります。
機械語翻訳は、Google® のWEB翻訳を使用していますが、一部、修正をしています。

A data breach happens when data is accessed, modified, or deleted without authorization. Security weaknesses can lead to incidents ranging from an accidental data leak to a malicious database breach – and the effects can be devastating. Learn how data breaches happen and the steps you can take to protect yourself and your business.


How do data breaches happen?

The majority of data breaches are rooted in three main areas:
データ漏洩の大多数は、次の3つの主要な 範疇に起因しています。

  1. Malicious attacks, which involve cybercriminals or insiders

  2. Human error, such as careless employees or contractors

  3. Systems glitches, including business process failures

Let’s take a look at the most common causes of data breaches.

Distributed denial of service (DDoS attack)

Cybercriminals flood a target website or network with requests until its resources become unavailable to legitimate users, resulting in a denial of service. Although it is not a data breach in itself, a DDoS attack can be used to divert the attention of IT or security staff while malware is installed.


A form of malicious software (malware), ransomware allows cybercriminals to encrypt data on the target network and demand a ransom payment to restore it. In the event of a data breach, this may be combined with the attacker viewing, copying, or exporting data from the network before encrypting it and threatening a data leak if the ransom is not paid. However, it’s important to note that payment does not guarantee the safe return of data.

SQL injection

Many web applications use SQL databases to store important data and sensitive information, such as customers’ usernames, passwords, and credit card details. In an SQL injection attack, cybercriminals exploit security flaws to manipulate the queries an application makes to its database, allowing them to access, modify, or delete data.
多くのWebアプリケーションは、SQLデータベースを使用して、顧客のユーザー名、パスワード、クレジットカードの詳細などの重要なデータや機密情報を保存します。 SQLインジェクション攻撃では、サイバー犯罪者は、セキュリティ上の欠陥を悪用して、アプリケーションがデータベースに対して行うクエリを操作し、データへのアクセス、変更、または削除を可能にします。


(fishing, phreaking, sophisticated 等に由来した合成語?)

A cybercriminal may contact a victim by email, phone, or text message pretending to be a trusted contact. The attacker then convinces the victim to download malware or a virus – often by opening an attachment or clicking a link – or they may fool them into handing over data directly.

Criminal insider

A criminal insider is someone – often an employee or contractor who may or may not have legitimate authority to access sensitive information – who abuses their position in order to leak data. Their motivation is usually personal profit or to cause harm to the organization.

Accidental insider

Conversely, an accidental insider is someone who unintentionally causes a cybersecurity breach, such as falling victim to a phishing attack, using an unauthorized personal device, or through poor password management. Employees who have not had basic cybersecurity training are a vulnerability to their employer.

Physical theft or loss

Any physical device, such as an unsecured laptop, hard drive, mobile phone, or USB containing sensitive information that is lost or stolen could put your business at risk.

Examples of data breaches

It may seem like large companies are the main targets of data breaches, possibly because they make headlines when it happens, but small businesses and individuals are equally at risk. The following data breach examples highlight just how much damage they can cause.


In early 2020, Cam4, a small business that provides an adult streaming service, became the victim of one of the largest data breaches ever recorded. A misconfigured database allowed the release of 10.88 billion user records. The data stolen included customers’ personally identifiable information (PII) such as names, email addresses, and chat transcripts.


The popular email service, Yahoo, disclosed two data breaches in 2016, which affected all three billion of its user accounts.

The first attack was initiated by a phishing email. Attackers were able to access the names, email addresses, passwords, dates of birth, and telephone numbers of users. The breaches wiped an estimated $350 million off the company’s market value, and several shareholders filed lawsuits following the disclosures.


The Equifax breach was entirely preventable. In 2017, hackers exploited an unpatched – but known – vulnerability in a system used to build the credit reporting agency’s web application.

The data of more than 143 million individuals was compromised, including names, addresses, dates of birth, and even driving license information. The company reported that the breach cost $1.4 billion. Surprisingly, no fraud or identity theft cases have been connected with the incident.

What are the laws around data breaches?

Data privacy is covered by various laws and regulations around the world, and depending on where you or your customers are located, they may be different. If your business is a victim of a data breach, there are certain steps you must follow, so it’s important to know what is required of you. This will be affected by:

The General Data Protection Regulation (GDPR)

Widely considered the world’s strongest set of rules governing data protection, GDPR was put into force by the European Parliament in May 2018. Here is a brief overview of the requirements relating to data breaches:

Regulations in the US

While the US doesn’t have a federal law governing notification following a data breach, certain states have their own data privacy laws, and you will need to be aware of the provisions for each. Well-known US regulations include the California Consumer Privacy Act (CCPA) and the Health Insurance Portability and Accountability Act (HIPAA).

What should I do if my data is stolen?

If you’re unlucky enough to be on the receiving end of a data breach disclosure, there are several things you can do to improve your security:

How to prevent a data breach

In 2020, the average cost per lost or stolen record in a data breach was $146, so the impact of a significant breach could be devastating, particularly for a small business. Fortunately, there is plenty you can do to make it harder for cybercriminals to infiltrate your systems and get their hands on your data.

Follow the steps below to ensure that you have a solid security foundation in place:

1. Take care of the basics
1. 基本に注意してください

2. Promote employee awareness
2. 従業員の意識を高める

3. Update your starters and leavers process
3. スターターとリーバーのプロセスを更新します

4. Manage ongoing maintenance and planning
4. 継続的なメンテナンスと計画を管理します

Which vulnerabilities could result in a data breach?

While cybercriminals are continuously devising new ways to detect and exploit business vulnerabilities, some security weaknesses can be easily prevented by implementing best practices. Here are some of the most common vulnerabilities and what to do about them.

Weak or stolen passwords

Weak credentials are an easy win for cybercriminals. Create a requirement for employees to use unique, complex passwords for every account, and use two-factor authentication (2FA) on sensitive accounts.

Unsecure mobile devices

If your employees use their personal devices for work – which they often do – you have far less control over security standards, such as passwords, who else has access to the device, and use of public Wi-Fi. Implement a bring your own device (BYOD) policy that sets out clear expectations for each employee, and spend some time on training to highlight the potential threats.
従業員が自分の個人用デバイスを仕事に使用する場合(よくあることですが)、パスワード、デバイスにアクセスできる他のユーザー、パブリックWi-Fiの使用などのセキュリティ標準を制御することははるかに困難です。各従業員に明確な期待を設定するBYOD(Bring Your Own Device)ポリシーを実装し、潜在的な脅威を強調するためのトレーニングに時間を費やします。

Outdated security

If you are running software that has an update or patch available but not installed, you are exposing your business to risk. Ensure that all software is fully patched and updated.

Protect against data breaches with a layered antivirus solution

The most effective way to safeguard your business is to follow best practices and use a wide range of security tools to build multiple layers of protection. Avast Business offers cybersecurity solutions that defend your business against data breaches using a combination of next-gen endpoint protection and cloud-based network security solutions. Keep your data in the right hands.

