More and less spectacular data breaches

26 czerwca 2015

We have recently heard a lot about spectacular data breaches. Almost simultaneously, we were able to familiarize ourselves in detail with the prosecutorial case files from the so-called wiretapping scandal, published on a social media platform, and we also learned about a hacking incident involving the theft of customer data from one of the banks.

In the first case, the prosecutor's office was obliged to provide the case files to the parties involved in the proceedings, and it fulfilled this obligation. The data leak likely occurred elsewhere. Someone who had the right to access the files, and even to copy them, is to blame. Among the disclosed data were also personal data of individuals participating in the proceedings – parties, witnesses, prosecutors, etc.

GDPR Bulletin
Receive a package of free GDPR guides and micro-trainings
Join the ranks of our newsletter readers, receive a free package, and stay informed.
RECEIVE PACKAGE

The second case appears to be a deliberate act to harm the bank. Moreover, after the data theft, the hacker contacted the bank demanding a ransom in exchange for not publishing the stolen data. The bank did not yield to the blackmail, resulting in the blackmailer publishing part of the data and changing the demand to a payment of a specified amount not for himself, but to the account of any chosen orphanage. He threatened to disclose further information. Initially, the bank did not want to officially confirm that a breach had occurred and that someone had indeed gained access to customer data. However, we now know both that such an event took place and that the desire for profit or to harm the bank coincided with the bank's weak security measures… The case has already attracted the attention of the prosecutor's office and the Chief Inspector of Personal Data Protection. An investigation is underway.

Both of these cases are so spectacular and shocking that probably everyone has heard about them by now. Many companies have started to wonder whether their IT systems and security procedures are capable of effectively protecting the data collected within their organizations. Therefore, both IT departments and information security administrators have likely been quite busy in their companies recently. The only question is whether this is not a temporary enthusiasm that will fade as quickly as it appeared?

It is important to realize that aside from high-profile data breaches, smaller incidents occur in companies almost every day! Sometimes they go completely unnoticed, sometimes we quickly cover them up, and at other times we can only hope that no one will find out. These are very mundane incidents such as incorrectly addressing an email that accidentally reaches the wrong recipient, failing to use blind carbon copy in group correspondence, or leaving candidates' CVs in a conference room. It happens that as a result, nothing actually occurs, but it also happens that individuals whose data has been unlawfully disclosed or processed may wish to file a complaint or even notify the media about the incident. In such cases, what seems like a minor event can escalate to incredible proportions and negatively impact the reputation of the respective company or institution.

Unfortunately, the fact is that nowadays it is impossible to guarantee one hundred percent security for your data and to prevent all incidents. However, it is important to minimize such risks. It is well known that the weakest link is usually the human element, which is why it is worthwhile to educate and train your employees (our training) so that they are aware of the threats, avoid them, and if an incident does occur, they know how to behave in such a situation.

Read also:

Receive a free package of 4 tutorials and 4 e-learning trainings
The controller of your data is ODO 24 sp. z o. o.