812
classic opsec mistake (discuss.tchncs.de)
submitted 7 months ago by [email protected] to c/[email protected]

cross-posted from: https://discuss.tchncs.de/post/10692187

so, the company was Vastaamo. was because it got bankrupt after the breach, and GDPR violations.

the "hacker"(or rather cracker) was extradited from France to Finland.
you can read about how terrible the company's security was here: https://tietosuoja.fi/en/-/administrative-fine-imposed-on-psychotherapy-centre-vastaamo-for-data-protection-violations

or watch mental outlaw's video on the matter, or the Wikipedia article on the breach.

now there are several things that shouldn't have happened (e.g.: don't do these things on your main OS, have root access disabled, etc.), but I'll leave that to you experts.

you are viewing a single comment's thread
view the rest of the comments
[-] [email protected] 54 points 7 months ago

Sad that the company was able to declare bankruptcy, rather than the directors being held criminally liable.

[-] [email protected] 34 points 7 months ago
[-] [email protected] 27 points 7 months ago

Not even remotely enough

[-] [email protected] 10 points 7 months ago

That's a start, but on its own pretty meaningless. A suspended sentence means he does not go to prison, so long as he behaves himself for a year or however long.

The article doesn't go into it, but I hope he was also fined heavily. All we have is "the court determined it could not be resolve through fines, a prison sentence is warranted".

[-] [email protected] 2 points 7 months ago

See? CEOs get criminal liabilities! Capitalism works!

(/s alas)

this post was submitted on 11 Feb 2024
812 points (98.2% liked)

linuxmemes

20765 readers
1470 users here now

I use Arch btw


Sister communities:

Community rules

  1. Follow the site-wide rules and code of conduct
  2. Be civil
  3. Post Linux-related content
  4. No recent reposts

Please report posts and comments that break these rules!

founded 1 year ago
MODERATORS