SlimPay fined €180k after 12 million customers' bank data publicly accessible for 5 years
- Reference: 1641317588
- News link: https://www.theregister.co.uk/2022/01/04/slimpay_breach_fine/
- Source link:
The firm describes itself as a leader in recurring payments for subscriptions, and provides an API and processing service to take care of such payments on behalf of [1]client organisations , which include Unicef, BP, and OVO Energy, to name but a few.
However, it appears that in 2015 SlimPay undertook an internal research project into an anti-fraud mechanism, for which it used personal data contained in its customer databases for testing purposes. Using real data is a good way to ensure that development code is working as expected before live deployment, but when you are dealing with sensitive information such as bank account details, great care must be taken not to fall foul of data protection regulations.
[2]
Alas, according to CNIL (Commission nationale de l'informatique et des libertés), when SlimPay's research project ended in July 2016, the data was left in place on a server that was freely accessible from the public internet without any security procedures in place. Worse still, the company was apparently unaware of this situation until February 2020, when one of SlimPay's customers became aware of the server and tipped it off.
[3]
[4]
To its credit, SlimPay appears to have taken immediate action to isolate the server and secure the data, after which it notified CNIL of the data breach, on February 17.
In a later data breach notification, the firm disclosed more details on the security incident, including the number of people and the type of personal data affected by the data breach. This comprised debtor data from SlimPay merchant clients corresponding to approximately 12 million people, consisting of their postal, electronic, and telephone contact details, and banking information such as Bank Identifier Code (BIC) and International Bank Account Number (IBAN).
[5]Police National Computer not pwned by Clop ransomware crims, insists Home Office
[6]Pen Test Partners: Anyone could view Gumtree users' GPS location by pressing F12
[7]UK data watchdog fines government office for disclosing New Year's gong list
[8]Singaporean regulator punishes biggest-ever data breach: Almost 5.9 million hotel customers' info exposed
A subsequent investigation carried out by CNIL found multiple breaches concerning the processing of personal data of customers, and the restricted committee – the CNIL body responsible for issuing sanctions – concluded that SlimPay had failed to comply with several General Data Protection Regulation (GDPR) requirements.
These included failure to comply with the obligation to provide a formal legal framework for the processing operations carried out by a processor (Article 28 of GDPR) as some contracts between SlimPay and its service providers do not contain all the clauses to ensure the processors commit themselves to processing personal data in compliance with GDPR, as well as failure to ensure the security of personal data (Article 32 of GDPR).
[9]
CNIL also found that SlimPay had failed to inform data subjects of a personal data breach (Article 34 of GDPR). Given the nature of the personal data (such as bank details), and the potential consequences for those concerned of this data being exposed, CNIL concluded that the risk associated with the breach should be considered high and that the company should have informed all the affected individuals, which it did not do.
According to CNIL, SlimPay defended itself by claiming none of the people affected had informed it of any fraudulent use of their personal data and claimed an audit by a third-party firm showed the data had not been exploited by an attacker. This cut no ice with the regulatory body, which stated that the absence of proven harm to data subjects has no effect on the existence of the security deficiency.
We contacted SlimPay for comment, and will update if we get a response from the company.
[10]
The official announcement (in French) is available [11]here . ®
Get our [12]Tech Resources
[1] https://www.slimpay.com/clients/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YdTRnQ53b-hbIq0BQXdM5wAAAI4&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YdTRnQ53b-hbIq0BQXdM5wAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YdTRnQ53b-hbIq0BQXdM5wAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://www.theregister.com/2021/12/20/dacoll_ransomware_clop_pnc_claims/
[6] https://www.theregister.com/2021/12/15/gumtree_data_breach_idor_f12_badness/
[7] https://www.theregister.com/2021/12/02/uk_data_watchdog_fines_government/
[8] https://www.theregister.com/2021/11/18/redoorz_fined_for_massive_data_leak/
[9] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YdTRnQ53b-hbIq0BQXdM5wAAAI4&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YdTRnQ53b-hbIq0BQXdM5wAAAI4&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[11] https://www.legifrance.gouv.fr/cnil/id/CNILTEXT000044609709
[12] https://whitepapers.theregister.com/
Re: Another useless fine.
Yes, it's pathetic. 0.2p per person per year is probably less than the interest on the money down the back of the sofa.
The way it is done in Europe
Big on the laws, while the UK would enforce them somewhat correctly some places just play lip service to it. Here we have a French company not being fined by the French colour me surprised!
Yes I did vote to remain, not going to change it by leavening it.
Re: The way it is done in Europe
Once again Yes Minister is there.
"The Germans will love it, the French will ignore it and the Italians and the Irish will be too chaotic to enforce it. Only the British will resent it."
They were talking about the European Identity Card but still. Oh and the Irish actually do give a fig given what they want to fine Facebork.
'To its credit'?
C'mon El Reg,
I don't think any credit is due to them.
I'm a bit perplexed why you would big them up for belatedly doing something (after they were notified) that they should have actioned years earlier.
Maybe just me, and probably why I don't write for money and just spaff out comments on here!
Happy New Year to all BTW.
Cheers!
Live data in a test environment?
*facepalm*
Another useless fine.
118K fine for over 12Million victims means each victim was only worth 0.0098333. Oh yes, I can see how such a massive fine will cause them to tremble in fear lest it happen again.
Or, more likely, the C-level officers will shake the money out of petty change, give the regulator TheFinger, & carry on fucking folks over with impugnity.
Unless that fine is per day, per victim, & personally, criminally, financially unable to be erased via bankruptcy, payable by said execs, they won't care, won't notice, & won't even break stride before doing it again.