3 ms·
According to the article they were contacted via email and DMs first, many days before it went public. They were given enough time to verify this and respond ac
by mr__y 7y ago
According to the article they were contacted via email and DMs first, many days before it went public. They were given enough time to verify this and respond accordingly. Also due to GDPR they are obliged to inform the users (at least those from EU) about the data breach - it is not their right to decide whether to inform or not anymore. They do not have to make a public announcement and could just send emails directly to affected users, but considering the total number of affected users I really doubt it would not become a public issue anyways.
But one thing holds: it is still not their legal right to remain silent, they are required to inform the affected users (at minimum those from EU)
- iafrikan 7y agoNot only based on GDPR, but also Nigeria's NDPR. They failed horribly. See here - https://www.iafrikan.com/2020/01/06/nigeria-data-protection-regulation-surebet247-national-information-technology-development-agency-nitda-breach-security-leak-soccer-betting-sports-gambling/ https://www.iafrikan.com/2020/01/06/nigeria-data-protection-...
- mr__y 7y agoDo you know what possible fines or other consequences they could be facing? I'm really corious about that. (this paragraph does not refer to NDPR or Nigeria) I have a general impression that very often the possible fines are far too low and it could be perfectly sound business decision to ignore the security or just keep it to a very minimum. Why spend a lot of money on auditing, improving the software, buying additional infrastructure when the cost of ignoring those and even the probability of anything happening is relatively low. For example why spend hundreds of thousands or possibly millions of dolars on security when the worst thing that could happen is a low fine with a marginal probability of breach happening then being discovered, then being reported, then being investigated and then actually a legal action actually being taken. My point is that it might actually be a lot cheaper to face the consequences of a breach than to improve security. I'm not sure what could be done to improve that situation.