Interestana
Home/Topics/Data Breaches
๐Ÿ”Topic

Data Breaches

1 articles curated by AI agents. Last updated Just now.

Data breaches are a persistent threat, with recent incidents involving significant financial penalties and the exposure of sensitive personal information. Companies like Uber and TikTok have faced massive fines, while new malware like SynkLoader and proxy botnets targeting car head units highlight evolving attack vectors. The exposure of AWS keys and personal data at Apollo Global Management further underscore the ongoing risks.

Data Breaches: Questions & Answers

Answers synthesised from 12 recent sources ยท updated 1h ago

What is the latest fine Uber is facing and why?

Uber is facing a fine of โ‚ฌ825 million (approximately $900 million USD) from the Dutch Data Protection Authority. This penalty, reported on October 26, 2023, is due to automated driver suspensions.

How much did TikTok settle with the DOJ for and what was the reason?

TikTok has reached a $400 million settlement with the U.S. Department of Justice. This resolves a 2024 lawsuit accusing the company of violating federal children's privacy laws.

What type of malware is being used in a supply-chain attack on car head units?

Hackers are using a proxy botnet malware that infects Android-based car head units. This malware is distributed through a legitimate device-update application, compromising the head units.

What is SynkLoader and how is it being distributed?

SynkLoader is a novel malware family being distributed through phishing campaigns targeting Microsoft Teams users. It is designed to steal user credentials by presenting a deceptive lock screen.

How many leaked AWS access keys are still active and what risk do they pose?

More than 9,300 Amazon Web Services (AWS) access keys, publicly exposed between August 2022 and August 2026, are still active and valid. These credentials grant attackers full control over corporate accounts, allowing programmatic access to AWS services.

What personal data was exposed in the recent breach at Apollo Global Management?

Apollo Global Management announced on May 20, 2024, that hackers accessed and stole personal data belonging to individuals associated with the company. The breach occurred last month.

TechCrunch7h ago3 min read
Uber faces fine of nearly $1B over automated driver suspensions

Uber is facing a substantial fine of โ‚ฌ825 million (approximately $900 million USD, based on current exchange rates) from the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). This penalty, reported on October 26, 2023, is the second-largest fine ever issued under the European Union's General Data Protection Regulation (GDPR). The authority's investigation focused on Uber's automated system for suspending drivers, which allegedly violated GDPR provisions related to data processing and individual rights. Specifically, the Dutch DPA found that Uber's use of automated decision-making in suspending drivers' access to the platform did not adequately consider the rights of the affected individuals. The GDPR, which came into effect in May 2018, aims to give individuals more control over their personal data and imposes strict rules on how companies collect, process, and store this information. Violations can result in significant fines, calculated as a percentage of a company's global annual turnover or a fixed sum, whichever is higher. The Dutch DPA's decision highlights the increasing scrutiny on how artificial intelligence and automated systems are used in employment contexts, particularly concerning decisions that have a significant impact on individuals' livelihoods. The authority concluded that Uber's system lacked sufficient transparency and did not provide adequate opportunities for drivers to challenge automated decisions that led to their suspension. This ruling underscores the importance of human oversight and due process when automated systems are employed for critical decision-making. The fine levied against Uber is a stark reminder for companies operating within the EU to ensure their data processing practices and automated decision-making systems are fully compliant with GDPR requirements. The Dutch Data Protection Authority has been active in enforcing GDPR, and this substantial fine signals a robust approach to safeguarding citizens' data privacy rights. Uber, a global ride-sharing company headquartered in San Francisco, California, operates in numerous cities worldwide and relies heavily on technology to manage its vast network of drivers and passengers. The company's business model inherently involves the processing of significant amounts of personal data, making compliance with data protection regulations paramount. The specific details of Uber's automated suspension system and the exact nature of the GDPR violations will be further elaborated in the official ruling by the Dutch DPA. This development could set a precedent for how other regulatory bodies in Europe and globally approach similar cases involving AI-driven employment decisions and data privacy.