Individual entrepreneur

€980($1K USD)final

Date Issued

1970-01-01

Regulation

Authority

Czech Data Protection Authority (UOOU)

Country

Czech Republic

Violation Type

Failure to implement sufficient measures to ensure information security

Currency

EUR

Violation Summary

An online game operator was exposed to a DDoS attack that led to the malfunctioning of the game serves. The attackers blackmailed the operator into paying money for the attacks to stop. As part of the “deal”, the attackers offered the operator to create and implement a better firewall protection system that would prevent any future attacks from other parties. The operator agreed to this “deal”. The game operator then implemented the new code which indeed proved to be better than the old one used but – let’s be honest, unsurprisingly – also included a backdoor that allowed the attacker to steal all the data that was on the server which included player details and personal information. The attacker uploaded this information on their website after that.

Articles Violated

Art. 32 GDPR

Other Fines for Individual entrepreneur

DateRegulationAmount (USD)Type
--GDPR$1,058Failure to implement sufficient measures to ensure information security