HomeSecurityProgrammer accused of system breach

Developer accused of system breach

A German judge has convicted a programmer investigating an IT problem as a hacker and fined him €3,000 for allegedly unauthorized access to external computer systems and data monitoring.

See also: Samsung: Data breach affects customers
programmer

According to Heise, the developer, operating as an independent IT services provider, was initially called in by a client to resolve excessive log generation issues with the inventory management software they were using.

The developer examined the software and found that a MySQL connection was established to a remote server owned by Modern Solution GmbH, the management software vendor.

After connecting to the database, it was found that it contained not only his customers' data, but also data for almost 700,000 other customers of Modern Solution, constituting a significant data privacy issue.

After realizing that the database contained data for other companies, the developer disconnected from the remote database and worked with a tech blogger to help educate the software vendor on the cybersecurity and privacy issue.

The company Modern Solution GmbH disconnected the server to fix the problem, denying the existence of a security flaw in their systems. The programmer and the tech blogger quickly disclosed the issue on the same day without waiting for a comment from the management software vendor.

Shortly thereafter, the company reported the developer to the police for unauthorized access to the exposed data and their database server.

See also: Okta data breach: 134 customers affected

The developer reported to the technology blog Word Filters that the management software was detected connecting to a MySQL server over the Internet. To determine the purpose of the database connection, the developer eliminated the password per unit from the executable files of the MySQL connection management software.

The indictment alleged that the defendant went so far as to disassemble the software. However, Heise confirmed that the developer simply recorded the strings in the MSConnect.exe executable file to find the password text.

However, the court ruled that unauthorized access to password-protected data violates Article 202c of the German criminal code, also known as the hacker article

system violation

The judge referred to a 2007 legislative amendment on hacking, emphasizing that protection does not need to be resilient to be considered a violation.

However, the judge showed some leniency towards the programmer, taking into account his clean record, and imposed a smaller fine than the prosecution requested.

The defendant's lawyer argued that his client acted in the public's general interest, responsibly informing the software supplier about the security issue, and criticizing the court's view on the matter as outdated.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

The programmer decided to file an appeal, resulting in the case being transferred to a higher regional court in Aachen. This decision could have significant repercussions, as it may create an important legal precedent.

See also: 1Password: Affected by Okta breach

The consequences of not complying with cybersecurity standards can be serious and multidimensional. First, there is the possibility of a leak of sensitive data, such as customer information, corporate documents or personal data.

Second, the failure to adhere to cybersecurity standards can lead to financial losses. This can arise from loss of customer trust, loss of business opportunities, expenses for damage remediation, or fines from regulatory authorities.

Third, failure to comply with standards can cause damage to corporate reputation and public trust. This can have long-term consequences for the business, as recovering from such damage can be difficult and time-consuming.

Finally, failure to adhere to cybersecurity standards can lead to legal consequences. This can include fines from regulators, lawsuits from customers or other stakeholders, or even criminal penalties for serious violations.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS