
Bad, but not as bad as it could have been
The crooks may have the owner’s address but at least they don’t have their current break-down location!
Italian automaker Ferrari has warned its well-heeled customers that their personal data may be at risk. “We regret to inform you of a cyber incident at Ferrari, where a threat actor was able to access a limited number of systems in our IT environment,” opens a letter sent to Ferrari owners, including one Reg reader who was …
A rather sane and reasoned argument why not paying a ransom makes sense.
Sure it's crap that they were breached in the first place, and perhaps also that they only learned about it after being asked for ransom, but their decision to not pay is absolutely the right thing to do, and there overall response seems reasonable.
May others learn from this (and preferrably spend money on their defences beforehand)...
I came to say exactly this. Very limited damage (names, addresses, emails phone numbers, in other words what is often easily obtainable elsewhere), they fessed up to the customers and public, and they are NOT going to fund a criminal enterprise. Minus a number of points for (apparently) getting hacked in the first place, but plus a bunch for handling it appropriately.