| ▲ | Roark66 7 hours ago | |
You know, recently a medical SaaS provider's system was hacked here in Poland as well. Medical records of 20mln people covering pre 2024 back leaked. The attackers claim to have got it via a vulnerability that any company could've had. Fine. But inside that network the security was a joke. Basically developers used real non anonymised archival data uploaded to s3 all devs had access to, to test the software. Data containing all the private stuff mentioned. Absolute peak of incompetence. It wouldn't be hard to anonymised the data even just by hashing the names and certain other records or replace them with dummy data. But what annoyed me the most is there is no info about huge fine for the company. No article written by the company explaining what internal failures they will fix to prevent it happening in future. Nothing. Those things have to be prosecuted and punished. Otherwise no one has any incentive to keep the systems secure. | ||