This week:

3 – How to comply with GDPR

2 – If it’s very convenient, it’s probably not very secure

1 – Gmail users should expect a scam email & phone call tsunami


 

3 – How to comply with GDPR

“The organisation’s phishing detection systems had disabled the phished account automatically after 17 minutes, but the account was then manually reactivated by their in-house IT team in error.”

Source: Data Protection Commission

 

What’s the story?

Every year, the Data Protection Commission (Ireland’s GDPR regulator) publishes a set of case studies, showing where organisations encounter difficulties with GDPR compliance. The case studies for 2024 are available using the link above.

As happens every year, the difficulties of complying with Subject Access Requests (SAR) continue to be the source of a large number of case studies in this latest report. But there are a few that relate to the security of information.

One relates to a staff member who was fooled by a phishing email into revealing their login details to an attacker. The organisation’s security systems spotted the attack and automatically disabled account access. Unfortunately, an IT staff member (who was probably just trying to help the staff member with their login difficulties) re-enabled the account, which could have allowed the attacker to also regain access. As a result of the incident, the organisation has updated its IT procedures to ensure appropriate checks are carried out before accounts are re-enabled.

 

So what?

I help my clients to ensure their information security controls align to industry best practice and to the expectations of their clients, prospects, board members and regulators.

The DPC case studies are an excellent way to understand the expectations of the data protection regulator.

 

 


 

2 – If it’s very convenient, it’s probably not very secure

“Security flaws in a carmaker’s web portal let one hacker remotely unlock cars from anywhere”

Source: TechCrunch (via Secure The Village)

 

What’s the story?

A security researcher has revealed a critical vulnerability in a major car brand’s US dealership portal that allowed him to bypass login and create a “national admin” account. This gave full access to customer data, vehicle tracking, and features like remote unlock and start – all controllable from the comfort of the attacker’s home.

 

So what?

If your car is accessible to you over the internet, it’s accessible to others too.

And if something is very convenient, it’s probably not very secure.

 

 


 

1 – Gmail users should expect a phishing tsunami

“Victims say the callers pretend to be Google staff, claiming their Gmail accounts are under attack. They then pressure users into “resetting” their passwords and sharing the new credentials, effectively locking account holders out of their own inboxes.”

Source: Esecurity Planet

 

What’s the story?

Google revealed that a breach in one of its Salesforce systems exposed some “business contact information”.

After the breach, around 2.5 billion Gmail users were urged to reset their passwords and tighten their security as the breach has triggered a surge in scam emails (aka ‘phishing’) and scam calls (aka ‘vishing’) attacks targeting Gmail users. Scammers are impersonating Google Support, pressuring users to share their passwords or security codes.

 

So what? 

If someone gains access to your email account, they become you online*.

Your email account needs to be protected by more than just a password.

And just like your toothbrush, you should NEVER share your password or security codes with anyone else.

It’s just good dental security hygiene.

 

(* This also gives me an excuse to mention Face/Off. Someday, this movie will be regarded as a classic!)