---
title: 4 Infamous Tech Security Mistakes
description: Some of the biggest data breaches in history have happened when people fumbled basic security measures. Don't make these foolish tech mistakes.
image: https://blog.integrityts.com/hubfs/4-infamous-tech-security-mistakes.jpg
---

[![Integrity Technology Solutions](https://blog.integrityts.com/hs-fs/hubfs/IntegrityTechnologySolutions_February2026/images/integrity_color_logo.png?width=284&height=53&name=integrity_color_logo.png "Integrity Technology Solutions")](https://www.integrityts.com/)

- [Who We Are](https://www.integrityts.com/who-we-are/)
  
  
  
    - [Our Team](https://www.integrityts.com/who-we-are/our-team/)
    - [Partners & Certifications](https://www.integrityts.com/who-we-are/partners-certifications/)
    - [NIST Cybersecurity Framework](https://www.integrityts.com/who-we-are/nist-cybersecurity-framework/)
    - [Careers](https://www.integrityts.com/careers/)
- [Industries](https://www.integrityts.com/industries/)
  
  
  
    - [Financial Institutions](https://www.integrityts.com/industries/financial-institutions/)
    - [Healthcare](https://www.integrityts.com/industries/healthcare/)
    - [Insurance](https://www.integrityts.com/industries/insurance/)
    - [Manufacturing](https://www.integrityts.com/industries/manufacturing/)
- [Services](https://www.integrityts.com/services/)
  
  
  
    - [Co-Managed IT Support](https://www.integrityts.com/services/co-managed-it-support/)
    - [IT Cybersecurity](https://www.integrityts.com/services/it-cybersecurity/)
    - [IT Support](https://www.integrityts.com/services/it-support/)
      
      
      
          - [Technology Advisement](https://www.integrityts.com/services/it-support/technology-advisement/)
          - [Managed Security](https://www.integrityts.com/services/it-support/managed-security/)
          - [RemoteFix Help Desk](https://www.integrityts.com/services/it-support/remotefix-help-desk/)
          - [Security Awareness Program](https://www.integrityts.com/services/it-support/security-awareness-program/)
          - [Managed Cloud Security](https://www.integrityts.com/services/it-support/managed-cloud-security/)
          - [Vulnerability Management](https://www.integrityts.com/services/it-support/vulnerability-management/)
          - [Managed Detection & Response](https://www.integrityts.com/services/it-support/managed-detection-response/)
          - [Managed Backup & Disaster Recovery](https://www.integrityts.com/services/it-support/managed-backup-disaster-recovery/)
          - [Teams Phones (Voice)](https://www.integrityts.com/services/it-support/teams-phones-voice/)
          - [IT Tool Kit](https://www.integrityts.com/services/it-support/it-tool-kit/)
          - [Password Management / LAPS – Copy](https://www.integrityts.com/services/it-support/password-management-laps/)
          - [Secure Cloud / Hosted Infrastructure](https://www.integrityts.com/services/it-support/secure-cloud-hosted-infrastructure/)
          - [Microsoft 365 Licensing/New Commerce Experience](https://www.integrityts.com/services/it-support/microsoft-365-licensing-new-commerce-experience/)
    - [IT Professional Services & Consulting](https://www.integrityts.com/services/it-professional-services-consulting/)
      
      
      
          - [Network Infrastructure](https://www.integrityts.com/services/it-professional-services-consulting/network-infrastructure/)
          - [Cloud Migrations](https://www.integrityts.com/services/it-professional-services-consulting/cloud-migrations/)
          - [Incident Response](https://www.integrityts.com/services/it-professional-services-consulting/incident-response/)
          - [SharePoint Consulting](https://www.integrityts.com/services/it-professional-services-consulting/sharepoint-consulting/)
          - [Security Risk Assessments](https://www.integrityts.com/services/it-professional-services-consulting/security-risk-assessments/)
          - [Tabletop Exercises](https://www.integrityts.com/services/it-professional-services-consulting/tabletop-exercises/)
          - [AI Capabilities](https://www.integrityts.com/services/it-professional-services-consulting/ai-capabilities/)
          - [Administrative Policies & Controls](https://www.integrityts.com/services/it-professional-services-consulting/administrative-policies-controls/)
          - [HIPAA Risk Assessments](https://www.integrityts.com/services/it-professional-services-consulting/hipaa-risk-assessments/)
          - [MIPS Consulting](https://www.integrityts.com/services/it-professional-services-consulting/mips-consulting/)
          - [SAFER Guides Consulting](https://www.integrityts.com/services/it-professional-services-consulting/safer-guides-consulting/)
- [Pricing](https://www.integrityts.com/pricing/)
- [Blog](https://blog.integrityts.com/)
- [Contact](https://www.integrityts.com/contact/)

# Blog

## 4 Infamous Tech Security Mistakes

[Integrity Staff](https://blog.integrityts.com/author/integrity-staff)

August 16, 2018 at 10:00 AM

![4-infamous-tech-security-mistakes](https://blog.integrityts.com/hs-fs/hubfs/4-infamous-tech-security-mistakes.jpg?width=1200&name=4-infamous-tech-security-mistakes.jpg)

For much of the past decade, the biggest security mistakes have boiled down to fumbling some basic tech security practices.

Find out what these mistakes are and how to mitigate your risk.

 

**1. Falling Victim To Phishing**

The biggest security breach in history, targeted at Yahoo, affected more than 3 billion accounts in total.

Russian agents hired hackers to infiltrate Yahoo’s user database that contained:

1. Names
2. Phone numbers
3. Password challenge questions and answers
4. Password recovery emails
5. A cryptographic value unique to each account

The Russians used this information to access certain accounts.

[CSO](https://www.csoonline.com/article/3180762/data-breach/inside-the-russian-hack-of-yahoo-how-they-did-it.html)’s analysis of FBI documents reveal that the Russians did this by sending a spear-phishing link via email.

“It's unclear how many employees were targeted and how many emails were sent,” CSO writes, “but it only takes one person to click on a link, and it happened.”

A business’s employees must be aware of [phishing](https://blog.integrityts.com/6-security-awareness-training-topics-to-review-with-your-team) attacks and how to avoid them.

 

**2. Not Having Robust Security Practices**

Former Equifax CEO Richard Smith testified before the Digital Commerce and Consumer Protection committee that one person was responsible for the data breach that exposed the Social Security numbers and driver’s licenses of 143 million people in 2017.

[He said](https://docs.house.gov/meetings/IF/IF17/20171003/106455/HHRG-115-IF17-Wstate-SmithR-20171003.pdf) that on March 8, a team noticed “the need to patch a particular vulnerability.” The company then sent an email to the appropriate personnel responsible to deploy the software upgrades within 48 hours.

“The notion that just one person didn’t do their job and led to the biggest breach in history is quite an amazing claim and shows a fundamental lack of good security practices,” writes [Sarah Buhr at TechCrunch](https://techcrunch.com/2017/10/03/former-equifax-ceo-says-breach-boiled-down-to-one-person-not-doing-their-job/).

Regardless of how the breach happened, there are two important takeaways about the Equifax breach.

First and foremost, have a security plan at your organization. Secondly, if the lack of patch deployment was the culprit, that points the need for applying timely software updates.  

 

**3. Failing To Enable Multifactor Authentication**

The Guardian broke in 2016 that hackers had access to Deloitte’s [350](https://www.theguardian.com/business/2017/oct/10/deloitte-hack-hit-server-containing-emails-from-across-us-government) clients’:

- Usernames
- Passwords
- IP addresses
- Architectural diagrams for businesses
- Health information

The hackers exploited an administrator’s lack of multifactor authentication, also known as two-factor authentication or 2FA. “The account required only a single password,” says [The Guardian](https://www.theguardian.com/business/2017/sep/25/deloitte-hit-by-cyber-attack-revealing-clients-secret-emails).

Credential theft is preventable by enabling [multifactor authentication](https://blog.integrityts.com/protect-email-logins-with-multi-factor-authentication).

 

**4. Being Non-Compliant**

In 2008, hackers stole more than 130 million credit and debit card numbers from payroll processing company Heartland Payment Systems.

The fallout from this breach continues more than a decade later. [Dark Reading](https://www.darkreading.com/application-security/insurers-sue-trustwave-for-$30m-over-08-heartland-data-breach/d/d-id/1332248) reports that two insurers have sought restitution from the security vendor who certified Heartland as [PCI DSS](https://blog.integrityts.com/pci-changes)-compliant.

In 2009, [a Visa executive challenged](https://www.bankinfosecurity.com/heartland-data-breach-visa-questions-processors-pci-compliance-a-1309)Heartland’s compliance, saying that a compliant business had never been breached. Visa even investigated Heartland and found multiple violations.

Overall, you can do a few things to mitigate security risks for your business.

- Draft stringent security policies.
- Educate your team about phishing and other social engineering strategies.
- Enable multifactor authentication.
- Ensure compliance.

Rise above these tech security mistakes.

[![New Call-to-action](https://no-cache.hubspot.com/cta/default/2136188/419d6876-083c-4c40-a40e-f4178b21ff17.png)](https://cta-redirect.hubspot.com/cta/redirect/2136188/419d6876-083c-4c40-a40e-f4178b21ff17)

### Leave a Reply

## CONTACT US

### PROTECT YOUR BUSINESS.

Integrity helps businesses dealing with sensitive data protect against looming cybersecurity threats.

### Address:

816 South Eldorado Road, Suite #4  
Bloomington, IL 61704

### Call Us:

[+1 309.662.7723](tel:13096627723)

### Email:

[info@integrityts.com](mailto:info@integrityts.com)

[![x](https://blog.integrityts.com/hs-fs/hubfs/IntegrityTechnologySolutions_February2026/images/x.png?width=512&name=x.png "x")](https://x.com/integrityts)

<https://www.facebook.com/integritytechnologysolutions>

<https://www.linkedin.com/company/integrity-technology-solutions/>

#### Customers: Need Assistance Now?

### Call Customer Support:

[+1 888.764.8181](tel:18887648181)

### Email Customer Support:

[remotefix@integrityts.com](mailto:remotefix@integrityts.com)

#### Information & Sales

[![Integrity Technology Solutions](https://blog.integrityts.com/hubfs/IntegrityTechnologySolutions_February2026/images/footer-logo.svg "Integrity Technology Solutions")](https://www.integrityts.com/)

- [Who We Are](https://www.integrityts.com/who-we-are/)
- [Industries](https://www.integrityts.com/industries/)
- [Services](https://www.integrityts.com/services/)
- [Pricing](https://www.integrityts.com/pricing/)
- [Blog](https://blog.integrityts.com/)

©2026 [Integrity Technology Solutions](https://www.integrityts.com/).

- [Privacy Policy](https://www.integrityts.com/privacy-policy/)
- [Terms & Conditions](https://www.integrityts.com/terms-and-conditions/)

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Integrity Staff",
    "url" : "https://blog.integrityts.com/author/integrity-staff"
  },
  "datePublished" : "2018-08-16T15:00:00.000Z",
  "headline" : "4 Infamous Tech Security Mistakes",
  "image" : [ "https://blog.integrityts.com/hubfs/4-infamous-tech-security-mistakes.jpg" ],
  "mainEntityOfPage" : {
    "@id" : "https://blog.integrityts.com/4-infamous-tech-security-mistakes",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://blog.integrityts.com/hubfs/Logos/integrity_1000x187.png"
    },
    "name" : "Integrity Technology Solutions"
  }
}
```