Уровень 0 · материалов: 3
В кластер входят документы, посвященные рискам безопасности данных, вызванным человеческими ошибками или организационной халатностью, но не техническим спецификациям сетевых протоколов.
Общие признаки: уязвимости в безопасности, риски утечки данных, человеческий фактор и халатность, информационная гигиена
Группа выше: Утечки персональных данных
Смысл: The text highlights a systemic failure in data integrity and information security practices at a major financial institution, where using a real third-party email as a placeholder for clients without email addresses creates unnecessary security risks and demonstrates institutional negligence.
A Sberbank subsidiary inserted a real third-party email address as a placeholder in clients' official forms, demonstrating poor data security practices and contradictory corporate communication.
Смысл: The main idea is that corporate transparency regarding contact details exposes companies to a constant stream of low-to-mid-level social engineering attacks, requiring a culture of healthy suspicion and employee training to protect internal data and productivity.
An analysis of common corporate social engineering tactics, ranging from annoying sales calls and phishing emails to deceptive identity impersonation used to extract sensitive information.
Смысл: The main idea is that personal data leaks often stem from internal human negligence or malice (insider threats) within institutions rather than sophisticated external hacking or government surveillance.
The author investigates suspicious phone calls and discovers that their private contact data was leaked by an employee of their university.