The Register Home Page

back to article 3.7M breach notification letters set to flood North America's mailboxes

A trio of companies disclosed data breaches this week affecting approximately 3.7 million customers and employees across North America. Insurance biz Allianz Life confirmed the largest incident. It previously revealed data belonging to approximately 1.4 million customers was hit during a break-in at an unnamed third-party CRM …

  1. Anonymous Coward
    Anonymous Coward

    Fines are too easy..

    It's not like the threat isn't known by now, so executives who either choose systems based on nothing more than a good game of golf or expensive lunches or refuse to fund good security policies, processes and associated technology ought to be fined directly, and companies that despite literally TERAbytes of 'patches' still can't get their sh*t together should no longer be able to avoid liability, regardless of what their Terms state.

    If you get yourself declared 'critical' (read: get a de facto monopoly status handed to you) you should be compelled to accept the associated responsibilities that come with it.

    No more BS.

    There. I feel better now :).

    1. The Dark Side Of The Mind (TDSOTM)

      Re: Fines are too easy..

      I would add those non-critical entities that collect "secure" PID like SSN, ID/driver/passport numbers. That kind of information can land a person in very nasty situations if leaked. That it doesn't get into the headlines doesn't mean it's not a real thing.

      Otherwise, I agree that stakes for data collectors (especially for those compelled to do KYC) must be set a lot higher.

  2. MachDiamond Silver badge

    Once again

    The hollow assurance that credit card numbers weren't divulged is high up on the press release. I would expect that any CRM would need to be fed purchase data, customer ranking, etc. For a travel company, that might include itineraries. Corporate execs often like to keep that sort of thing private if they are in the midst of negotiations to buy or make a substantial investment in another company. Over time, seeing a set of executives traveling to a common destination can indicate sensitive off-site meetings that happen on a regular basis. There is information more valuable than a credit card number.

  3. Andy3

    And here in the UK, we are told we must accept a 'digital ID'. No thanks.

    1. Anonymous Coward
      Anonymous Coward

      Accept or be made a pariah of the State.

      Join the biggest geo-located honeypot with everyone else. Gov depts never suffer breaches. Never give away data. Never share secrets. Make mistakes. Are never inept.

      And no coincidence that the working and middle classes are already trained to accept having their data mined; to provide their secrets at every opportunity; at every request without option or compensation. Then submit to having it on-sold across the planet to the highest bidder, wholesale. And shared with anyone, for any purpose.

      No coincidence that tatooing a unique ID on the Digital forehead of every subject is the cheapest way raise the bar on behalf of the Super Rish.

      No simpler way to prescribe and mandate compliance by all Citizens, excepting only those marauding as Trustees, visiting from offshore jurisdictions, of course ;-)

      Corporates and governments alike are here for anyone in or near the middle class. Prepare to be upstanding for our real Rulers, or face the wrath of their Minions, and soon, Robots!

  4. David Hicklin Silver badge

    tedious

    These notifications are getting tedious now, clearly these companies don't care one iota about the security of our data otherwise this would not keep on happening.

  5. Pu02

    Adobe, or Salesforce?

    Aliianz favour both in their stack. If its SSNs, it'll more likely to be a CRM, and thus probably Salesforce, unless the attacker pulled the data from an API, or gained access to some CSVs just left laying around.

  6. Taliesinawen Bronze badge

    Allianz Group: a leading provider of cyber risk insurance (oh the irony)

    This is the latest excuse when companies IT systems are it. Blame some unnamed third-party IT provider. One wonders who provides cybersecurity to Allianz Life (annual revenue $1.8 billion).

    Allianz provides cyber risk insurance for businesses through Allianz Commercial, offering tailored solutions like stand-alone policies or integrated coverage with traditional property and liability insurance ref...

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like