---
title: "What the Latest Cybersecurity Breaches Can Teach Us"
description: "Learn critical lessons from recent cybersecurity breaches at U-Haul and OakBend Medical Center to strengthen your organization's defenses and mitigate…"
lang: en
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Person",
      "@id": "https://christianespinosa.com/#person",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "image": "https://christianespinosa.com/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg",
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ],
      "jobTitle": "Bestselling Author, Keynote Speaker, Entrepreneur",
      "worksFor": {
        "@type": "Organization",
        "name": "Blue Goat Cyber",
        "url": "https://bluegoatcyber.com/"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://christianespinosa.com/#website",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "publisher": {
        "@id": "https://christianespinosa.com/#organization"
      },
      "inLanguage": "en-US"
    },
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://christianespinosa.com/#organization",
      "name": "Christian Espinosa",
      "url": "https://christianespinosa.com/",
      "logo": {
        "@type": "ImageObject",
        "url": "https://christianespinosa.com/logo.svg"
      },
      "founder": {
        "@id": "https://christianespinosa.com/#person"
      },
      "sameAs": [
        "https://www.facebook.com/christian.espinosa.official",
        "https://x.com/Ironracer",
        "https://www.instagram.com/christian.espinosa.official/",
        "https://www.youtube.com/@ChristianEspinosaOfficial",
        "https://www.linkedin.com/in/christianespinosa/"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "Article",
      "headline": "What the Latest Cybersecurity Breaches Can Teach Us - Christian Espinosa",
      "description": "Learn critical lessons from recent cybersecurity breaches at U-Haul and OakBend Medical Center to strengthen your organization's defenses and mitigate…",
      "image": "https://christianespinosa.com/__l5e/assets-v1/87baa1e2-4c0b-4a9c-8212-ca152460fd24/what-the-latest-cybersecurity-breaches-can-teach-us-card.png",
      "datePublished": "2022-10-08T15:00:00+00:00",
      "dateModified": "2026-07-19T23:27:03Z",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://christianespinosa.com/blog/what-the-latest-cybersecurity-breaches-can-teach-us"
      },
      "author": {
        "@type": "Person",
        "name": "Christian Espinosa",
        "url": "https://christianespinosa.com/about"
      },
      "publisher": {
        "@type": "Organization",
        "name": "Christian Espinosa",
        "logo": {
          "@type": "ImageObject",
          "url": "https://christianespinosa.com/logo.svg"
        }
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is the core idea behind \"What the Latest Cybersecurity Breaches Can Teach Us - Christian Espinosa\"?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "There’s no shortage of cybersecurity breaches, with fear-inducing headlines. There is much to learn in these situations."
          }
        },
        {
          "@type": "Question",
          "name": "Who is this post for?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Honestly, security leaders, medical device teams, and technical operators who want the honest version, not the vendor version. If you want a listicle, this is not that. If you want the honest version of what I have actually lived and worked through, keep reading."
          }
        },
        {
          "@type": "Question",
          "name": "How do I actually apply this, not just nod along?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Pick the single line in the post that made you flinch or look away, and change one thing in your week because of it. One choice this week beats a whole framework you never touch."
          }
        }
      ]
    }
  ]
---

[Skip to content](#main)

[](/)

[About](/about)[Speaking](/speaking)[Cybersecurity](/cybersecurity)[Programs](/programs)[Books](/books)[Media](/media)

Writing

Search Ctrl K[Connect](/connect)

[Cybersecurity](/blog/category/cybersecurity)

# What the Latest Cybersecurity Breaches Can Teach Us

October 8, 2022 4 min read 979 words 

In a perfect world, breaches and attacks wouldn't happen. Everything would be top-notch secure, and cyber criminals would be foiled at every turn. Unfortunately, that's not the reality. In fact, breaches are rising, and hackers are getting smarter and more sophisticated.

![](/__l5e/assets-v1/013c8f1c-b46f-4cd3-937c-883a5c15a6fc/what-the-latest-cybersecurity-breaches-can-teach-us-hero.webp)

The takeaways

1.  01 
    
    Everything would be top-notch secure, and cyber criminals would be foiled at every turn.
    
    What to do next Open your current everything plan today and identify the one gap you would not want an auditor to find.
    
2.  02 
    
    In fact, breaches are rising, and hackers are getting smarter and more sophisticated.
    
    What to do next Ask your security lead this week for the one-page view of breaches in your environment, and read it end to end.
    
3.  03 
    
    Data breaches exposed 22 billion records in 2021, and ransomware attacks increased by 92.7% from 2020 to 2021.
    
    What to do next Add breaches to the next leadership review as a standing item, not a one-time slide.
    
4.  04 
    
    Aside from these components, the human element is the most important.
    
    What to do next Ask your security lead this week for the one-page view of aside in your environment, and read it end to end.
    

I work in cybersecurity, and I'm always learning. It's a dynamic ecosystem that's always changing in terms of threats. There's also no shortage of cybersecurity breaches, with fear-inducing headlines that can make any company shutter. But I'd also argue there is much to learn in these situations.

In a perfect world, breaches and attacks wouldn't happen. Everything would be top-notch secure, and cyber criminals would be foiled at every turn. Unfortunately, that's not the reality. In fact, breaches are rising, and hackers are getting smarter and more sophisticated. Data breaches exposed [22 billion records in 2021](https://go.flashpoint-intel.com/docs/2021-Year-End-Report-data-breach-quickview), and ransomware attacks increased by [92.7%](https://www.securitymagazine.com/articles/97166-ransomware-attacks-nearly-doubled-in-2021) from 2020 to 2021.

Even with the strongest tools and processes, I can't guarantee my organization won't be a victim. Aside from these components, the human element is the most important. Who I put in charge of protecting data and securing my infrastructure is most often the differentiator. And those people need more than just technical aptitude. They need to be communicators and collaborators. They need to be flexible and open to change and growth.

With that in mind, let’s consider what the latest cybersecurity breaches can teach us.

## U-Haul Data Breach Exposes Customer Information

The moving and storage company [U-Haul reported a data breach](https://www.uhaul.com/Update/) to customers in September 2022. The attack enabled cyber criminals to access rental contracts between November 2021 and April 2022. As a result, over 2 million customers had sensitive data exposed, including names, driver’s licenses, and state identification numbers.

The hack was successful because of the ability to compromise unique passwords that enabled access to customer contract search tools. The company didn’t disclose anything further about the password compromise.

In this scenario, a few things come to mind as learnings. First, it highlights the need for multifactor authentication across the entire enterprise. Second, it’s possible [zero trust architecture](https://christianespinosa.com/blog/what-is-zero-trust-architecture-and-why-should-your-organization-shift-to-it/) could have prevented this. Third, perhaps there wasn’t visibility or transparency across the digital infrastructure, which left this database vulnerable. They could have averted such a breach not with better tools but with better communication.

## OakBend Medical Center Suffers Ransomware Attack

Ransomware in healthcare has become a serious issue, with over 55 of these attacks this year alone. Due to a ransomware attack, the Oakbend [hospital had communication and IT issues](https://www.oakbendmedcenter.org/). They announced they were working under “electronic health downtime procedures.”

The standard response was to take everything offline and rebuild their systems. Healthcare is a key target for hackers, as they know this is a critical industry that will often pay the ransom.

We can learn from this incident that the need for updated and practiced cyber incident response procedures is critical. Also, questions about redundancy and backups are relevant. We don’t know the details, but with healthcare, the weak link is often legacy systems. Human error and apathy are brewing in hospital IT offices.

Healthcare data is a serious business. I would advise any healthcare organization to modernize its approach to cybersecurity, which requires removing legacy systems, updating infrastructure, and driving change in the hearts and minds of the professionals responsible for it. Until these things happen, healthcare will always be an easy target.

## Aon Data Breach Exposes Sensitive Customer Data

[Aon](https://www.jdsupra.com/legalnews/aon-plc-announces-data-breach-after-6655695/) first noted the breach in its Securities & Exchange Commission filing in February 2022. However, the global financial company didn’t advise customers until May. The breach’s root cause was access by an unauthorized third party. The company’s investigation reported no evidence that the stolen data was misused and that they had enacted new controls.

It makes you wonder if these controls were so strong, why weren’t they already in place? And why did third parties have the opportunity to steal customer information?

Aon, like any other financial institution, certainly has a sophisticated cybersecurity footprint with teams of professionals that are experts. Yet, there’s always a way in! Would zero-trust architecture have saved the day? Would all those smart cyber folks have noticed this access vulnerability sooner if they worked more like a team rather than individual contributors? Without more details, it’s hard to know. As someone who’s been in this industry a long time, I know that human blindsides are the worst.

## Social Engineering Scam Exposes Marriott Customers’ Credit Card Information

[Marriott reported](https://www.databreaches.net/exclusive-marriott-hacked-again-yes-heres-what-we-know/) that an employee was a social engineering victim, leading him to turn over credentials. The hackers then tried to extort money, contacting the company boasting of their access. The hotel chain stated that the hacker didn’t reach its core network, but customer data related to the specific location was part of the breach. Marriott refused to pay the cyber criminals and contacted law enforcement.

The obvious learning is around constant and consistent training for employees on cybersecurity. However, even if that’s in place, employees may not give it much credence if it’s not a top-down philosophy that’s part of the company culture. Other points to consider are again about access; who has it, how they get it, and who is trustworthy.

If you take away anything from these cases, the most important thing is going back to your people. How are they protecting your data? What are their misconceptions or flawed reasonings?

The most secure companies don’t get that way because they spend the most money or have all the latest and greatest tools. They don’t end up in the headlines because their people work proactively and are agile in collaborating and communicating. If you can do anything right now to strengthen your company’s defense posture, it’s about getting your technical teams aligned, motivated, and growing their mindset. Without this, everyone stays in the same place, and the hackers will keep succeeding.

Frequently asked

### What is the core idea behind "What the Latest Cybersecurity Breaches Can Teach Us - Christian Espinosa"?

### Who is this post for?

### How do I actually apply this, not just nod along?

### Work with me

I help founders and cybersecurity leaders build teams that ship, not teams that stall. If that's the problem you're trying to solve, let's talk.

[Start a conversation](/contact)

Share this essay

[X ](https://twitter.com/intent/tweet?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fwhat-the-latest-cybersecurity-breaches-can-teach-us&text=What%20the%20Latest%20Cybersecurity%20Breaches%20Can%20Teach%20Us) [LinkedIn](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fwhat-the-latest-cybersecurity-breaches-can-teach-us) [Facebook](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fwhat-the-latest-cybersecurity-breaches-can-teach-us) [Email](mailto:?subject=What%20the%20Latest%20Cybersecurity%20Breaches%20Can%20Teach%20Us&body=https%3A%2F%2Fchristianespinosa.com%2Fblog%2Fwhat-the-latest-cybersecurity-breaches-can-teach-us)Copy link 

![Christian Espinosa, headshot](/__l5e/assets-v1/de07e44b-a8e0-4bcc-bcb0-13aec15421f1/headshot-front.jpg)

About the author

[Christian Espinosa](/about) · Founder & CEO, Blue Goat Cyber

Christian is the founder and CEO of Blue Goat Cyber, a medical device cybersecurity firm. He's an Air Force Academy graduate, 24x Ironman, climber of two of the Seven Summits, and the author of The Smartest Person in the Room and The In-Between: Life in the Micro.

Keep reading

-   [
    
    ### The Urban Legend of the Cybersecurity Skills Gap - Christian Espinosa
    
    Related take on cybersecurity, christian.
    
    Read essay → ](/blog/is-the-cybersecurity-skills-gap-fact-or-fiction-it-depends-on-the-skills)
-   [
    
    ### The Latest Cybersecurity Incidents and What You Can Learn from Them - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/what-the-latest-cybersecurity-breaches-can-teach-us)
-   [
    
    ### The Cybersecurity Status Quo Needs to Change - Christian Espinosa
    
    Same thread: cybersecurity.
    
    Read essay → ](/blog/the-cybersecurity-status-quo-needs-to-change)

[← Previous essay 

What Is Zero Trust Architecture, and Why Should Your Organization Shift to It? - Christian Espinosa

](/blog/what-is-zero-trust-architecture-and-why-should-your-organization-shift-to-it)[Next essay → 

3 Reasons Why Current Cybersecurity Measures Aren’t Working and How to Fix Them - Christian Espinosa

](/blog/3-reasons-why-current-cybersecurity-measures-arent-working-and-how-to-fix-them)

Related, Cybersecurity

### Need medical-device or offensive security expertise?

Blue Goat Cyber, Christian's firm, runs FDA-aligned premarket submissions, penetration testing, and SBOM/SOUP analysis for medtech and high-stakes industries.

[Explore Blue Goat Cyber](/cybersecurity)

Christian Espinosa

Bestselling author, keynote speaker, and Founding CEO of [Blue Goat Cyber](https://bluegoatcyber.com/). Helping technical leaders develop the soft skills that turn brilliance into impact.

[](https://www.linkedin.com/in/christianespinosa/)[](https://x.com/Ironracer)[](https://www.instagram.com/christian.espinosa.official/)[](https://www.youtube.com/@ChristianEspinosaOfficial)[](https://www.facebook.com/christian.espinosa.official)

Explore

-   [About](/about)
-   [Timeline](/timeline)
-   [Speaking](/speaking)
-   [Cybersecurity](/cybersecurity)
-   [Programs](/programs)

Read

-   [Books](/books)
-   [Guides](/guides)
-   [Blog](/blog)
-   [Media](/media)
-   [Podcast Interviews](/podcasts)
-   [Success Stories](/success-stories)

Connect

-   [Contact Christian](/connect)
-   [LinkedIn ↗](https://www.linkedin.com/in/christianespinosa/)
-   [Blue Goat Cyber ↗](https://bluegoatcyber.com/)
-   [Resources](/resources)

© 2026 Christian Espinosa. All rights reserved.

[Privacy](/privacy-policy)[Terms](/terms-of-use)