HomeSecurity#KartaGate: The Commissioner for Personal Data Protection confirms the breach

#KartaGate: The Commissioner for Personal Data Protection confirms the breach

#KartaGate: Irene Loizidou confirms the revelations of "Economy Today" regarding the possible leak of personal data of APOEL and Omonia fans.

What "Economy Today" has revealed regarding the exposed personal data of fans through the electronic ticket sales platforms of APOEL and Omonia is confirmed.

See Also: 5 best diagnostic tools for your computer

#KartaGate Data Protection Commissioner confirms breach
#KartaGate: The Commissioner for Personal Data Protection confirms the breach

In her announcement regarding #KartaGate, the Commissioner for Personal Data Protection confirms "the security gap which resulted in an unauthorized person being able to retrieve the details of their fans from the clubs' websites.".

It is noted that since July 27, warnings have been issued about the security gap that still exists on the operational website of the Greek Football Association (KHO) regarding the Fan Card, through which personal data of fans remains exposed even today, while fans who may have been affected have not yet been informed.

See Also: Samsung Wear OS smartwatch: Updates to Google Pay and Messages

The following is the full statement from Irene Loizidou regarding #KartaGate:

In relation to the recent publications regarding the above issue and following the notification of a breach incident submitted to me by APOEL and OMONOIA as well as the investigation carried out by my Office, I issued and sent today to the said clubs and to the contractor company that designed and developed the said systems on their behalf, prima facie Decisions. In the prima facie Decisions, the three parties involved were informed that violations of the General Data Protection Regulation had been established and their positions were requested, before I proceeded to issue final Decisions.

#KartaGate: The Commissioner for Personal Data Protection confirms the breach
#KartaGate: The Commissioner for Personal Data Protection confirms the breach

The said breaches (#KartaGate) concern a security gap which resulted in an unauthorized person being able to retrieve from the clubs' websites, the details of their fans (name, Fan Card number and Identity Card number), who had purchased tickets, at the material time of the breach. Therefore, by registering the last two details on the KOA website, the unauthorized person was able to view and download the Fan Cards of the affected fans.

See Also: Hackers use PrintNightmare to hack Windows servers

It is expected that the unions and the contracting company will submit their positions on the above within a specified deadline, so that I can proceed to issue final Decisions.

Although it was found, after a relevant audit and a written report from the ΚΟ to my Office, that the ΚΟ system regarding the Fan Card had not been breached, I suggested and it was accepted that a safeguard be implemented, so that access and the ability to receive the Fan Card by its holder would be further enhanced by the sending and use of a unique security code.

Source: simerini.sigmalive.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS