A Third of Serious Cyberattacks in Israel in the Past Year Went Unreported, Report Says
Since new regulations requiring companies and nonprofits to report on significant breaches came into force in May 2018, Israel’s Privacy Protection Authority has handled 146 severe cybersecurity events, only 103 of which were reported by the organizations targeted
Cases in which hackers used an inherent security flaw in the organization’s database accounted for 15% of the attacks. Theft of passwords and usernames were conducted in 7% of cases, human errors and malware were spotted on 9% of cases, and unintentional loss of media or unauthorized delivery of data was the case in 8% of attacks.A spokesperson for the Privacy Protection Authority told Calcalist that the authority can fine offenders who fail to report attacks or fail in other ways to conform with the regulations meant to protect personal data. The authority is also authorized to cancel or temporarily suspend an organization’s license to hold a database and to make any infringement public.