2022 Teaches Hard Lessons in Botched Data Breach Responses

A review of 2022's worst data breach responses shows that poor communication often causes more damage than the hacks themselves. Companies like Nvidia, DoorDash, and Samsung fail to provide basic transparency to affected users.

Effective crisis communication is just as crucial as cybersecurity itself, yet 2022 serves as a masterclass in how not to handle a data breach. While organizations like the Red Cross earn praise for their transparency, many other major companies severely mishandle these incidents by withholding vital information from the public and downplaying the severity of the compromises.

Nvidia sets a poor example early in the year by staying completely tight-lipped after the Lapsus$ hacking group steals a terabyte of proprietary source code and the credentials of over 71,000 employees. Rather than providing clear details about the attack vector or the scope of the damage, the chipmaker refuses to answer basic questions, allowing the hackers to control the narrative. DoorDash similarly botches its incident response in August by offering TechCrunch an exclusive scoop on its own breach but subsequently refusing to answer almost any questions about the incident, including the total number of affected customers.

Samsung also joins the ranks of poorly managed breach responses by choosing to quietly disclose a massive hack just hours before a major holiday weekend. By prioritizing stealth and secrecy over honest communication, these tech giants ultimately cause more harm to their reputations and leave their users in the dark about potential risks to their personal information.

Read More at the original source →