News: 1694104215

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Lawsuit claims Tesla corp data security is far less advanced than its cars

(2023/09/07)


An ex-Tesla staffer has filed a proposed class action lawsuit that blames poor access control at the carmaker for a data leak, weeks after Tesla itself sued the alleged leakers, two former employees.

Benson Pai, who was a production associate on Tesla's California campus, working on the construction and assembly of the electric car company's vehicles, said the leak was a "direct result" of poor security controls on Tesla's part. The suit, filed on Tuesday, claims the personally identifiable info of 75,000 current and former employees could be sold on the dark web because of the company's "inadequate data security."

Pai, who is looking to front the people whose data was stolen, [1]claimed [PDF] in the filing that Tesla:

... failed to implement or follow reasonable data security procedures as required by law and failed to protect Plaintiff and the proposed Class members' Sensitive Information from unauthorized access. As a result of Defendant's inadequate data security and inadequate or negligent training of its employees, on or around May 10, 2023, a foreign media outlet, Handelsblatt, informed Tesla that it had obtained Tesla confidential information.

The sueball comes weeks after Tesla said in a data breach filing with the state of Maine* that it had [2]itself sued two former employees whom it accused of stealing 75k staffers' records – including, supposedly, Elon Musk's own social security number (SSN).

As The Reg has [3]mentioned before, many class action lawsuits are launched on the premise that SSNs are something of a security fraud goldmine. Possession of only a person's SSN, name, and address, for example, means criminals can take out a credit card or loan in the victim's name. They can use it to obtain medical care (and rack up bills) under the person's identity, or identify themselves using the purloined SSN when arrested – giving the victim a [4]criminal record . Elon Musk, at least, would have a name recognizable enough to potentially swerve that fate.

[5]

Tesla discovered the breach in May, when notified by German business paper [6]Handelsblatt [paywalled], which gave details on the data it believed was included in the breach. The publication said it went well beyond just that of Tesla staffers – and allegedly included info from customers and business partners.

[7]

[8]

The Handelsblatt story said that the company had failed to adequately protect the 100 gigabytes of confidential data handed to it by a whistleblower, which it assured Tesla it was legally forbidden from publishing. Tesla is also [9]reportedly under investigation by Euro data protection authorities over the leak.

[10]Mozilla calls cars from 25 automakers 'data privacy nightmares on wheels'

[11]The Anti Defamation League is Musk's latest excuse for Twitter's tanking ad revenue

[12]Tesla's purported hands-free 'Elon mode' raises regulator's blood pressure

[13]Silicon Valley billionaires secretly buy up land for new California city

The complaint claims the car manufacturer took too long to inform affected data leak victims, accusing it, among other things, of negligence, invasion of privacy, breach of implied contract, breach of fiduciary duty, breach of confidence and violation of the California Unfair Competition Law.

Pai claimed in the suit that waiting until August to inform class members increased the risk of fraud.

The filing also said the "unencrypted, unredacted information" could be sold on the dark web "at a price ranging from $40 to $200," noting that SSNs "are especially valuable to identity thieves."

[14]

When Tesla notified employees, it offered a year's membership of Experian's IdentityWorks monitoring services to members whose social security numbers were leaked. The complaint called the offer "wholly inadequate" as it "fails to account for the fact that victims of data breaches and other unauthorized disclosures commonly face multiple years of ongoing identity theft, and financial fraud, and it entirely fails to provide sufficient compensation for the unauthorized release and disclosure of Plaintiff's and Class members' Sensitive Information."

The suit seeks damages and costs, not disclosed in the complaint but more than $5 million.

We've asked Tesla for comment. ®

[15]

*Maine state law has a data breach notification statute on the books requiring businesses who buy and sell to its residents to notify affected parties "as expediently as possible and without unreasonable delay." It's triggered when someone breaks into an org's computer system (or helps themselves if admins have left things public facing) and personal information is acquired, released, or "used without authorization." It's why you'll see a lot of disclosures turning up there first.

Get our [16]Tech Resources



[1] https://regmedia.co.uk/2023/09/07/pai_v_tesla.pdf

[2] https://www.theregister.com/2023/08/21/breach_of_75k_employee_records/

[3] https://www.theregister.com/2023/06/06/mercer/

[4] https://www.lexingtonlaw.com/blog/negative-items/4-things-identity-thieves-can-do-with-your-social-security-number.html

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZPpIA7GGH111dap-7RDnxwAAA9Q&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[6] https://www.handelsblatt.com/unternehmen/industrie/elektromobilitaet-mein-autopilot-hat-mich-fast-umgebracht-tesla-files-naehren-zweifel-an-elon-musks-versprechen/29166564.html

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPpIA7GGH111dap-7RDnxwAAA9Q&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZPpIA7GGH111dap-7RDnxwAAA9Q&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.reuters.com/article/tesla-dataprotection-idCAKBN2XG1N0

[10] https://www.theregister.com/2023/09/06/mozilla_vehicle_data_privacy/

[11] https://www.theregister.com/2023/09/05/twitter_adl_lawsuit/

[12] https://www.theregister.com/2023/08/30/tesla_elon_mode_nhtsa/

[13] https://www.theregister.com/2023/08/28/silicon_valley_new_city/

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZPpIA7GGH111dap-7RDnxwAAA9Q&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[15] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZPpIA7GGH111dap-7RDnxwAAA9Q&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[16] https://whitepapers.theregister.com/



Seems Reasonable

aerogems

I mean, if two employees can walk off with that much data, that right there is a sign of a massive problem. And if I remember my training on PII from past jobs, the law generally puts the onus on the employer to maintain this information securely and they are automatically assumed to be at fault for breaches unless they can show miscreants used some hereto unknown 0-day exploit or something that couldn't reasonably be foreseen.

So, hopefully the pitched sueball ends up hitting the batter, because it sounds like it's deserved.

Genuine Question

Lis

I live in England so I am not sure I understand what these S.S.N's are. But they seem to be an important means of I.D.

In that case, could the victims just be issued with new numbers?

Re: Genuine Question

Woodnag

It's like your NI number, innit.

No.

Re: Genuine Question

aerogems

A social security number, as the article points out, is kind of a universal ID number assigned to every citizen at birth, or when they're granted citizenship in terms of immigrants. It was never really intended to be used that way, but since when has that ever stopped us (happy coincidence)? If you want to buy a car, get a loan for a house, get a credit card, or a number of other things, you provide that number as a means of proving your citizenship and thus eligibility. Technically it's just meant for when you reach retirement age in the US you get a small pittance from the govt. Not really enough to live off of anymore, but a pittance.

I assume in the UK you have some kind of unique ID for tax purposes, so it'd be like that.

People can be given new numbers, but since it's generally so intertwined with so many other systems it's not as easy as it may seem. You have to change hundreds, maybe thousands, of individual records across hundreds, maybe thousands, of databases which are not necessarily connected in any way. And if the social security administration just sent out some kind of missive saying this is the new number for Joe Blow, you can bet ne'er do-wells all over would be looking to intercept those.

Re: Genuine Question

Blazde

Didn't Equifax already leak every financially relevant SSN in existence as of 2017? So realistically for those over 24 these lawsuits are a bit flaky.

Also might be an idea to start backfilling this particular 'security fraud goldmine'

This is now. Later is later.