Are Fake COVID Testing Sites Harvesting Data?

Over the past few weeks, I’ve seen a bunch of writing about what seems to be fake COVID-19 testing sites. They take your name and info, and do a nose swab, but you never get test results. Speculation centered around data harvesting, but that didn’t make sense because it was far too labor intensive for that and — sorry to break it to you — your data isn’t worth all that much.

It seems to be multilevel marketing fraud instead:

The Center for COVID Control is a management company to Doctors Clinical Laboratory. It provides tests and testing supplies, software, personal protective equipment and marketing services — online and printed — to testing sites, said a person who was formerly associated with the Center for COVID Control. Some of the sites are owned independently but operate in partnership with the chain under its name and with its guidance.

[…]

Doctors Clinical Lab, the lab Center for COVID Control uses to process tests, makes money by billing patients’ insurance companies or seeking reimbursement from the federal government for testing. Insurance statements reviewed by Block Club show the lab has, in multiple instances, billed insurance companies $325 for a PCR test, $50 for a rapid test, $50 for collecting a person’s sample and $80 for a “supplemental fee.”

In turn, the testing sites are paid for providing samples to the lab to be processed, said a person formerly associated with the Center for COVID Control.

In a January video talking to testing site operators, Syed said the Center for COVID Control will no longer provide them with PCR tests, but it will continue supplying them with rapid tests at a cost of $5 per test. The companies will keep making money for the rapid tests they collect, he said.

“You guys will continue making the $28.50 you’re making for the rapid test,” Syed said in the video.

Read the article for the messy details. Or take a job and see for yourself.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

IRS Will Soon Require Selfies for Online Access

If you created an online account to manage your tax records with the U.S. Internal Revenue Service (IRS), those login credentials will cease to work later this year. The agency says that by the summer of 2022, the only way to log in to irs.gov will be through ID.me, an online identity verification service that requires applicants to submit copies of bills and identity documents, as well as a live video feed of their faces via a mobile device.

The IRS says it will require ID.me for all logins later this summer.

McLean, Va.-based ID.me was originally launched in 2010 with the goal of helping e-commerce sites validate the identities of customers who might be eligible for discounts at various retail establishments, such as veterans, teachers, students, nurses and first responders.

These days, ID.me is perhaps better known as the online identity verification service that many states now use to help stanch the loss of billions of dollars in unemployment insurance and pandemic assistance stolen each year by identity thieves. The privately-held company says it has approximately 64 million users, and gains roughly 145,000 new users each day.

Some 27 states already use ID.me to screen for identity thieves applying for benefits in someone else’s name, and now the IRS is joining them. The service requires applicants to supply a great deal more information than typically requested for online verification schemes, such as scans of their driver’s license or other government-issued ID, copies of utility or insurance bills, and details about their mobile phone service.

When an applicant doesn’t have one or more of the above — or if something about their application triggers potential fraud flags — ID.me may require a recorded, live video chat with the person applying for benefits.

Since my credentials at the IRS will soon no longer work, I opted to create an ID.me account and share the experience here. An important preface to this walk-through is that verifying one’s self with Id.me requires one to be able to take a live, video selfie — either with the camera on a mobile device or a webcam attached to a computer (your webcam must be able to open on the device you’re using to apply for the ID.me account).

Also, successfully verifying your identity with ID.me may require a significant investment of time, and quite a bit of patience. For example, stepping away from one part of the many-step application process for a little more than five minutes necessitated another login, and then the re-submission of documents I’d previously uploaded.

After entering an email address and picking a password, you are prompted to confirm your email address by clicking a link sent to that address. After confirmation, ID.me prompts users to choose a multi-factor authentication (MFA) option.

The MFA options range from a six-digit code sent via text message or phone call to code generator apps and FIDO Security Keys. ID.me even suggests using its own branded one-time code generating app, which can “push” a prompt to your mobile device for you to approve whenever you log in. I went with and would encourage others to use the strongest MFA option — a physical Security Key. For more on the benefits of using a Security Key for MFA, see this post.

When the MFA option is verified, the system produces a one-time backup code and suggests you save that in a safe place in case your chosen MFA option is unavailable the next time you try to use a service that requires ID.me.

Next, applicants are asked to upload images of their driver’s license, state-issued ID, or passport — either via a saved file or by scanning them with a webcam or mobile device.

If your documents get accepted, ID.me will then prompt you to take a live selfie with your mobile device or webcam. That took several attempts. When my computer’s camera produced an acceptable result, ID.me said it was comparing the output to the images on my driver’s license scans.

After this, ID.me requires the verification of your phone number, which means they will ask your mobile or landline provider to validate you are indeed an existing, paying customer who can be reached at that number. ID.me says it currently does not accept phone numbers tied to voice-over-IP services like Google Voice and Skype.

My application got stuck interminably at the “Confirming Your Phone” stage, which is somewhere near the middle of the entire verification process.

An email to ID.me’s support people generated a message with a link to complete the verification process via a live video chat. Unfortunately, clicking that link brought up prompts to re-upload all of the information I’d already supplied, and then some.

Some of the primary and secondary documents requested by ID.me.

For example, completing the process requires submitting at least two secondary identification documents, such as as a Social Security card, a birth certificate, health insurance card, W-2 form, electric bill, or financial institution statement.

After re-uploading all of this information, ID.me’s system prompted me to “Please stay on this screen to join video call.” However, the estimated wait time when that message first popped up said “3 hours and 27 minutes.”

I appreciate that ID.me’s system relies on real human beings seeking to interview applicants in real-time, and that not all of those representatives can be expected to handle all of these immediately. And I get that slowing things down is an important part of defeating identity fraudsters who are seeking to exploit automated identity verification systems that largely rely on static data about consumers.

That said, I started this “Meet an agent” process at around 9:30 in the evening, and I wasn’t particularly looking forward to staying up until midnight to complete it. But not long after the message about waiting 3 hours came up, I got a phone call from an ID.me technician who was CC’d on my original email to ID.me’s founder. Against my repeated protests that I wanted to wait my turn like everyone else, he said he would handle the process himself.

Sure enough, a minute later I was connected with the ID.me support person, who finished the verification in a video phone call. That took about one minute. But for anyone who fails the automated signup, count on spending several hours getting verified.

When my application was finally approved, I headed back to irs.gov and proceeded to log in with my new ID.me account. After granting the IRS access to the personal data I’d shared with ID.me, I was looking at my most recent tax data on the IRS website.

I was somewhat concerned that my ID verification might fail because I have a security freeze on my credit file with the three major consumer credit bureaus. But at no time during my application process did ID.me even mention the need to lift or thaw that security freeze to complete the authentication process.

The IRS previously relied upon Equifax for its identity proofing process, and even then anyone with frozen credit files had to lift the freeze to make it through the IRS’s legacy authentication system. For several years, the result of that reliance was that ID thieves massively abused the IRS’s own website to impersonate taxpayers, view their confidential tax records, and ultimately obtain fraudulent tax refunds in their names.

The IRS canceled its “taxpayer identity” contract with Equifax in October 2017, after the credit bureau disclosed that a failure to patch a four-month-old zero-day security flaw led to the theft of Social Security numbers and personal and financial information on 148 million Americans.

Perhaps in light of that 2017 megabreach, many readers will be rightfully concerned about being forced to provide so much sensitive information to a relatively unknown private company. KrebsOnSecurity spoke with ID.me founder and CEO Blake Hall in last year’s story, How $100 Million in Jobless Claims Went to Inmates. I asked Hall what ID.me does to secure all this sensitive information it collects, which would no doubt serve as an enticing target for hackers and identity thieves.

Hall said ID.me is certified against the NIST 800-63-3 digital identity guidelines, employs multiple layers of security, and fully segregates static consumer data tied to a validated identity from a token used to represent that identity.

“We take a defense-in-depth approach, with partitioned networks, and use very sophisticated encryption scheme so that when and if there is a breach, this stuff is firewalled,” Hall said. “You’d have to compromise the tokens at scale and not just the database. We encrypt all that stuff down to the file level with keys that rotate and expire every 24 hours. And once we’ve verified you we don’t need that data about you on an ongoing basis.”

ID.me’s privacy policy states that if you sign up for ID.me “in connection with legal identity verification or a government agency we will not use your verification information for any type of marketing or promotional purposes.”

Signing up at ID.me requires users to approve a biometric data policy that states the company will not sell, lease, or trade your biometric data to any third parties or seek to derive any profit from that information. ID.me says users can delete their biometric data at any time, but there was no apparent option to do so when I logged straight into my new account at ID.me.

When I asked the support technician who conducted the video interview to remove my biometric data, he sent me a link to a process for deleting one’s ID.me account. So, it seems that removing one’s data from ID.me post-verification equals deleting one’s account, and potentially having to re-register at some point in the future.

Over the years, I’ve tried to stress the importance of creating accounts online tied to your various identity, financial and communications services before identity thieves do it for you. But all of those places where you should “Plant Your Flag” conduct identity verification in an automated fashion, using entirely static data points about consumers that have been breached many times over (SSNs, DoBs, etc).

Love it or hate it, ID.me is likely to become one of those places where Americans need to plant their flag and mark their territory, if for no other reason than it will probably be needed at some point to manage your relationship with the federal government and/or your state. And given the potential time investment needed to successfully create an ID.me account, it might be a good idea to do that before you’re forced to do so at the last minute (such as waiting until the eleventh hour to pay your quarterly or annual estimated taxes).

If you’ve visited the sign-in page at the U.S. Social Security Administration (SSA) lately, you’ll notice that on or around Sept. 18, 2021 the agency stopped allowing new accounts to be created with only a username and password. Anyone seeking to create an account at the SSA is now steered toward either ID.me or Login.gov, a single sign-on solution for U.S. government websites.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

ReliaQuest Opens Office in India

ReliaQuest Opens Office in India

Florida cybersecurity company ReliaQuest has opened its first office in India.

The new location for the Tampa-based company is in Pune, in the state of Maharashtra. ReliaQuest aims to have more than 50 employees on its India team by the end of the year.

ReliaQuest, which reached a valuation of more than $1bn in its latest round of funding, announced its international expansion on January 11. 

“2021 was an incredible year of growth and milestones for ReliaQuest, and we are continuing that momentum into 2022, beginning with this new office location in India,” said Greg Farrell, chief financial officer of ReliaQuest. 

The team in India will form part of the ReliaQuest product development group, fulfilling roles in backend development, quality assurance, user interface and DevOps.

Farrell said that the choice of Pune as the location for the company’s first India site was no accident. 

“Pune is known as a major IT hub with an exceptional talent pool, which makes it a perfect location for our first expansion into the country,” said Farrell.

He added: “ReliaQuest is uniquely positioned for major growth this year, and we are incredibly excited to welcome new team members in India as an impactful part of that growth.”

Brian Foster, ReliaQuest’s chief product officer, said the new India office would aid innovation.

“This expansion will give us the quality of technical talent to continuously innovate and deliver an OpenXDR platform that will help security operators be more efficient and proactive with their security posture,” said Foster.

The news follows the opening of ReliaQuest’s eighth global office in Sandy, Utah, just outside Salt Lake City, in November 2021. The company’s said this new workspace encompasses 64,000 square feet and can house more than 400 employees. 

Last August, ReliaQuest announced a new corporate headquarters at Thousand & One in Tampa’s new Water Street neighborhood. The cybersecurity company now occupies the top six stories of the building, totaling 120,000 square feet of office space.

ReliaQuest’s clientele includes household names Abercrombie & Fitch, the Boston Celtics, AAA The Auto Club Group, Southwest Airlines and TSC Tractor Supply Co.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Italian Denies Literary Wire Fraud

Italian Denies Literary Wire Fraud

An Italian citizen, employed in London’s publishing industry, has refuted charges that he fraudulently obtained unpublished manuscripts by impersonating other people online.

The United States Department of Justice unsealed an indictment on January 5 accusing 29-year-old Filippo Bernardini of using digital deception to amass the unpublished manuscripts of hundreds of books. 

“Filippo Bernardini allegedly impersonated publishing industry individuals in order to have authors, including a Pulitzer Prize winner, send him prepublication manuscripts for his own benefit,” said US attorney Damian Williams.

It is alleged that from at least August 2016 through July 2021, Bernardini created fake email accounts which he used to impersonate genuine literary talent agencies, publishing houses and literary scouts.

“Bernardini created these accounts by registering more than 160 internet domains that were crafted to be confusingly similar to the real entities that they were impersonating, including only minor typographical errors that would be difficult for the average recipient to identity during a cursory review,” said the US Attorney’s Office for the Southern District of New York in a statement.

One tactic allegedly employed by Bernardini was to replace the letter’ m’ used in a genuine domain name with the lower-case letters’ r’ and ‘n’ when registering a look-alike domain.

Reportedly among the list of individuals allegedly defrauded by Bernardini are American actor, director and screenwriter Ethan Hawke, and renowned author of The Handmaid’s Tale, Margaret Atwood.

Bernardini is further accused of phishing two employees of a New York City-based literary scouting company to gain access to a database maintained by that company. 

The defendant was arrested at John F. Kennedy International Airport on January 5. He was charged with one count of wire fraud and one count of aggravated identity theft. 

Following the allegations, Bernardini was suspended from his position at the UK arm of the American publishing company and ViacomCBS subsidiary, Simon & Schuster

In a statement released Wednesday, Simon & Schuster said it was “shocked and horrified” by Bernardini’s alleged crimes. 

On Thursday, Bernardini entered a plea of not guilty before Manhattan federal court. Judge Lewis Liman set bail at $300,000 and said Bernardini could be released once he had been placed under electronic monitoring.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

New Data Center Coming to Georgia

New Data Center Coming to Georgia

Data center solution provider T5 Data Centers has announced plans to build a new 200-megawatt government and enterprise cloud data center campus in Georgia.

The 140-acre T5@Augusta development will be sited in the Southeast’s cybersecurity hub, Augusta, next to Fort Gordon and the US Army’s Cyber Command Headquarters. 

T5 Data Centers said the campus location “is ideal for secure federal hyperscale, or government contracted enterprise businesses and builds on the cluster for advanced cybersecurity initiatives based in Augusta.” 

Initiatives of this kind already up and running in Augusta include the Georgia Cyber Center, a collaboration between state, federal and higher education institutions, whose first building opened in July 2018. Costing $100m, the Georgia Cyber Center is the single largest investment in a cybersecurity facility by a state government in the US to date.

“The vast, premium location of this property makes it ideal for federal cloud space and government contractors, with access to a large labor force with required security clearances, access to lit, dark and black fiber, and any necessary physical security measures,” said T5 Data Centers CEO, Pete Marin.

“In addition, our clients get a business-friendly and stable tax environment, with 100% sales tax abatement on IT purchases, property tax rebates, and low-cost reliable power,” he added.

T5 Data Centers, which has created 54 data centers, described the telecommunications infrastructure at the new campus location as “superior.” The site has access to 16 carriers and low latency connectivity to existing federal cloud zones.

Augusta’s new data center is supported by the Augusta Economic Development Authority (AEDA).

Augusta has made a name for itself as a hub for the cybersecurity industry. With T5’s development of this vast tract of land, the company is helping spur more tech-centric economic development for the community,” said AEDA chairperson Steven Kendrick.

He added: “We are pleased to support new projects in the area that will cement our city’s cybersecurity stronghold.”

The new site will have round-the-clock security, advanced biometric security access, and a critical facility operations team. In a nod to sustainability, the center will feature solar and renewable energy options and zero-water cooling designs

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Less Than a Fifth of Cyber Leaders Feel Confident Their Organization is Cyber-Resilient

Less Than a Fifth of Cyber Leaders Feel Confident Their Organization is Cyber-Resilient

Less than one-fifth (17%) of cyber leaders feel confident that their organizations are cyber-resilient, according to the World Economic Forum (WEF)’s inaugural Global Cybersecurity Outlook 2022 report.

The study, written in collaboration with Accenture, revealed there is a wide perception gap between business executives and security leaders on the issue of cybersecurity. For example, 92% of businesses believe cyber-resilience is integrated into their enterprise risk-management strategies, compared to just 55% of cyber leaders.

This difference in attitude appears to be having worrying consequences. The WEF said that many security leaders feel that they are not consulted in security decisions, and only 68% believe cyber-resilience forms a major part of their organization’s overall corporate risk management.

In addition, over half (59%) of all cyber leaders admitted they would find it challenging to respond to a cybersecurity incident due to a shortage of skills within their team.

Supply chain security was another major concern among cyber leaders, with almost nine in 10 (88%) viewing SMEs as a key threat to supply chains.

Interestingly, 59% of cyber leaders said cyber-resilience and cybersecurity are synonymous, with the differences not well understood.

The report, compiled of various sources, including a survey of global cyber leaders, also looked at the surging ransomware threat. Four in five (80%) cyber leaders said they considered this vector a dangerous and evolving threat to public safety, while 50% indicated ransomware is one of their greatest concerns.

Jeremy Jurgens, managing director at the WEF, commented: “Companies must now embrace cyber-resilience – not only defending against cyber-attacks but also preparing for swift and timely incident response and recovery when an attack does occur.”

Julie Sweet, chair and CEO of Accenture, stated: “Organizations need to work more closely with ecosystem partners and other third parties to make cybersecurity part of an organization’s ecosystem DNA, so they can be resilient and promote customer trust.

“This report underscores key challenges leaders face – collaborating with ecosystem partners and retaining and recruiting talent. We are proud to work with the WEF on this important topic because cybersecurity impacts every organization at all levels.”

While broadly welcoming the new annual report, Ed Williams, director of Trustwave SpiderLabs EMEA, believes future editions can expand in focus. “If I were to criticize the report, I would have liked to see more detail around security fundamentals and appropriate mitigations; while patching is acknowledged as an issue, greater focus on its importance would be useful. Similarly, passwords and MFA, key components to a robust security program, were found to be missing. Broad level mitigations will help mitigate a large number of attacks/ransomware,” he outlined.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Joint Law Enforcement Action Takes Down VPN Service

Joint Law Enforcement Action Takes Down VPN Service

An international law enforcement collaboration has targeted the users and infrastructure of VPNLab.net, rendering it no longer available.

The action was taken in response to the use of the VPN provider’s service to support cybercrime activities, including ransomware deployment.

Europol worked with 10 national law enforcement agencies to conduct the coordinated operation in Germany, the Netherlands, Canada, the Czech Republic, France, Hungary, Latvia, Ukraine, the US and the UK. This led to the seizure or disruption of 15 servers that hosted VPNLab.net’s service on January 17, making it unavailable.

The operation, led by the Central Criminal Office of the Hannover Police Department in Germany, took place under Europol’s EMPACT security framework objective Cybercrime – Attacks Against Information Systems.

Europol revealed the strike followed multiple investigations showing that cyber-criminals were using VPNLab.net’s service to facilitate activities such as malware distribution. In addition, it was regularly used to help set up infrastructure and communications behind ransomware campaigns and as its actual deployment. Investigators even discovered the service was being advertised on the dark web.

Law enforcement also identified over 100 businesses at risk of cyber-attacks as a result of these investigations. They are now helping potential victims to mitigate their exposure.

VPNLab.net was established in 2008, offering users online anonymity via services based on OpenVPN technology and 2048-bit encryption. It also provided double VPN, with servers located in multiple countries. This offering made it attractive to cyber-criminals seeking to avoid detection by law enforcement.

Commenting on the action, head of Europol’s European Cybercrime Centre, Edvardas Šileris, said: “The actions carried out under this investigation make clear that criminals are running out of ways to hide their tracks online. Each investigation we undertake informs the next, and the information gained on potential victims means we may have pre-empted several serious cyber-attacks and data breaches.”

Chief of Hanover Police Department, Volker Kluwe, added: “One important aspect of this action is also to show that, if service providers support illegal action and do not provide any information on legal requests from law enforcement authorities, that these services are not bulletproof. This operation shows the result of effective cooperation of international law enforcement agencies, which makes it possible to shut down a global network and destroy such brands.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

Microsoft Issues Out-of-Band Update for Patch Tuesday Problems

Microsoft Issues Out-of-Band Update for Patch Tuesday Problems

Microsoft has been forced to issue an out-of-band update to fix several problems reported by system administrators following this month’s Patch Tuesday.

After installing the January Windows update, customers complained of Hyper-V not starting, Windows resilient file system (ReFS) being no longer accessible, unwanted system reboots and other issues.

Microsoft responded on Monday with a new update designed to fix the problems.

“This update addresses issues related to VPN connectivityWindows Server Domain Controllers restartingvirtual machines start failures and ReFS-formatted removable media failing to mount,” it noted.

“All updates are available on the Microsoft Update Catalog, and some are also available on Windows Update as an optional update. Check the release notes for your version of Windows for more information.”

Updates for Windows 8.1, Windows Server 2012 R2 and Windows Server 2012 are available only on the Microsoft Update Catalog. Updates for all other versions are available on Windows Update as an optional update.

Microsoft kicked off 2022 with fixes for 97 CVEs last week, including six publicly disclosed but not exploited.

Among these were CVE-2022-21839, a denial of service vulnerability in the Windows event tracing discretionary access control list; an elevation of privilege flaw in Windows user profile service (CVE-2022-21919); and a Windows certificates spoofing vulnerability (CVE-2022-21836).

The remaining three publicly disclosed flaws were remote code execution bugs in Windows Security Center API (CVE-2022-21874), libarchive (CVE-2021-36976) and open-source curl (CVE-2021-22947).

The Patch Tuesday release also included fixes for nine critical vulnerabilities, the largest number since July 2021.

Last year was a record-setter regarding new CVEs published to the US National Vulnerability Database.

By early December, the figure had reached 18,376, the fifth year in a row that it hit an all-time high.

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

NCA: Kids as Young as Nine Have Launched DDoS Attacks

NCA: Kids as Young as Nine Have Launched DDoS Attacks

UK police have launched another initiative designed to persuade young people not to get involved in cybercrime after claiming that children as young as nine have launched DDoS attacks in the past.

The National Crime Agency (NCA) has teamed up with Schools Broadband, part of ISP the Talk Straight Group, on a new education campaign.

It said that students searching for specific terms associated with DDoS and other cybercrimes would be shown a warning message and suggested redirection to the Cyber Choices website. The aim is to educate young people about the Computer Misuse Act and the consequences of cybercrime.

A trial scheme is said to have significantly reduced searches for terms such as “stresser” and “booter” associated with DDoS, and it will now be rolled out nationwide to over 2000 primary and secondary schools.

The NCA said data from its National Cyber Crime Unit (NCCU) reveals a 107% increase in reports from the police cyber prevent network of students deploying DDoS attacks from 2019 to 2020.

The median age for referrals to the NCCU’s Prevent team is reportedly 15, but some offenders are as young as nine.

“Education is a key pillar in preventing crime and these messages highlight the risks and consequences of committing cyber offenses, which can result in a criminal record,” said John Denley, deputy director of the NCA’s NCCU.

“Law enforcement plays a critical role in tackling cybercrime and keeping the country safe. School outreach is important to educate a younger audience and this initiative will continue to help divert young people away from criminality.”

A National Cyber Security Centre (NCSC) report from 2019, which polled 430 schools across the UK, found that over a fifth (21%) reported unauthorized use of computers, networks or servers by pupils – almost twice the number (11%) who claimed the same of staff.

The report warned that such schools might be at risk of failing GDPR compliance as a result

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains

European Regulators Hand Out €1.1bn in GDPR Fines

European Regulators Hand Out €1.1bn in GDPR Fines

Europe’s data protection regulators issued over €1bn ($1.1bn) in GDPR fines since January 2021, a massive 594% year-on-year increase, according to international law firm DLA Piper.

The firm’s annual figures are a useful indication of the level of regulatory activity among the region’s privacy regulators.

It claimed that there had been an 8% rise in breach notifications, to 130,000 for the region since January 28 last year.

The study applies to the 27 EU member states plus the UK, Norway, Iceland and Liechtenstein, which also follow the GDPR.

Interestingly it is tiny land-locked Luxembourg that imposed the most significant individual fine: a €746m penalty for Amazon for failing to process customers’ data in accordance with the law.

Ireland came in second place with a €225m fine levied against WhatsApp, and France rounded out the top three by fining Google €50m, although that was issued several years ago.

However, the size of GDPR fines is something of a distraction from the biggest challenge for data protection officers around Europe: complying with the provisions of the “Schrems II” judgment.

According to DLA Piper, organizations risk suspension orders, fines, claims for compensation and service disruption if they export data to third countries outside the remit of the GDPR without first carrying out detailed assessments. These are required to ascertain the risk of interception of EU citizens’ data by public authorities such as local police and intelligence services in those countries.

“The nearly sevenfold increase in fines may grab the headlines but the Schrems II judgment and its profound implications for data transfers has established itself as the top data protection compliance challenge for many organizations caught by GDPR,” argued Ross McKean, chair of the UK Data Protection and Security Group.

“The threat of suspension of data transfers is potentially much more damaging and costly than the threat of fines and compensation claims. The focus on transfers and the significant work required to achieve compliance inevitably means that organizations have less time, money and resource to focus on other privacy risks.”

—————
Free Secure Email – Transcom Sigma
Boost Inflight Internet
Transcom Hosting
Transcom Premium Domains