South Korea fines McDonald's for data leak from raw SMB share
- Reference: 1679538551
- News link: https://www.theregister.co.uk/2023/03/23/south_korea_privacy_fines_mcdonalds/
- Source link:
McDonald's was slapped with a ₩696 million ($530,000) fine for storing backup files that contained users of its McDelivery service on a Server Message Block (SMB) volume that left sharing enabled. Hackers waltzed in and accessed 4,876,106 users' info.
In a separate incident, another 766,846 burger-buyers whose data should have been destroyed after a retention period expired also saw their info leak, attracting a ₩10 million ($7,700) wrist slap.
[1]
The burgermeister's mess was [2]revealed alongside news that British American Tobacco didn't take sufficient steps to mask customers' IP addresses. The company therefore coughed up info about 1,540 customers, and earned ₩40 million in fines.
[3]
[4]
Samsung Securities did a lousy job securing a web server, an error that saw data describing 48,122 users leak. The data was visible for a month, earning the chaebol a ₩100 million fine.
The commission also fined local outfits iMarket, JK Club, and Kara for leaking customer info.
[5]
Kara's fail was spectacular: it exposed admin creds to a search engine, and data inevitably leaked.
[6]South Korea’s data watchdog barks warnings at Microsoft and five local firms
[7]South Korea to treat crypto tokens and virtual assets as if they were securities
[8]IBM adds side order of NLP to McDonald's AI drive-thru chatbots
[9]McDonald's AI drive-thru bot accused of breaking biometrics privacy law
The Commission also fined four entities for bad CCTV security – among them a plastic surgery clinic that left the cameras running as its clients undressed in a changing room.
Another used the cameras it installed for security purposes to monitor employee attendance. ®
Get our [10]Tech Resources
[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZBvc9jXHaH1DoXdsMYY2OwAAAMw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[2] https://www.pipc.go.kr/np/cop/bbs/selectBoardArticle.do?mCode=C020010000
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZBvc9jXHaH1DoXdsMYY2OwAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZBvc9jXHaH1DoXdsMYY2OwAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZBvc9jXHaH1DoXdsMYY2OwAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://www.theregister.com/2021/06/10/koreas_government_data_watchdog_org/
[7] https://www.theregister.com/2023/02/07/south_korea_crypto_securities_regulation/
[8] https://www.theregister.com/2022/05/30/ibm/
[9] https://www.theregister.com/2021/06/10/mcdonalds_ai_lawsuit/
[10] https://whitepapers.theregister.com/
"The Commission also fined four entities for bad CCTV security – among them a plastic surgery clinic that left the cameras running as its clients undressed in a changing room."
Isn't it illegal even to have CCTV in a changing room? Even in Korea?