Internal threats where employees copying company data with bad intentions e.g. to trade.
Most of those breaches are not published & advertised to media.
Information might include e.g. credit numbers, social security numbers
Data loss
Deleting data stored on the cloud through viruses and malware
❗ High impact if there are no back-ups
Attack on sensitive information
Stealing information about other users e.g. financial data.
Attacker utilization of cloud infrastructure e.g.
Using compute power to crack passwords with many password attempts per seconds
DDoS attacks using cloud computing
Shadow IT
IT systems or solutions that are developed to handle an issue but aren't taken through proper approval chain
Abusing cloud services
Insecure interfaces and APIs
E.g. weak authentication
Insufficient due diligence
Moving an application without knowing the security differences
Shared technology issues
Multi-tenant environments that don't provide proper isolation
If the hypervisor is compromised, all hosts on that hypervisor are as well
Unknown risk profile
Subscribers don't know what security provisions are made behind the scenes.
Inadequate infrastructure design and planning
Conflicts between client hardening procedures and cloud environment
Malicious insiders
Illegal access to the cloud
E.g. in US data breach in 2020 a compromised global administrator account has assigned credentials to cloud service principals that allowed malicious access to cloud systems 1
Virtualization level attacks
Privilege escalation via error
Service termination and failure
Hardware failure
💡 Can be mitigated by using more zones in cloud.
Natural disasters
💡 Can be mitigated by using more regions in cloud.
Weak authentication
E.g. burden of managing identity both on-premises and on cloud
Allows compromise on on-premises systems to spread to cloud.
Allows adding a malicious certificate trust relationship in cloud for forging SAML tokens on-premises.
Compliance risks
E.g. laws regarding data transfer across borders
Cloud cryptojacking
📝 Hijacking cloud resources to mine for cryptocurrency