¶ ile paragrafa bağlantı verin veya alıntıyı künyesiyle kopyalayın. Üretilen bağlantı kimlikleri resmî paragraf numarası değildir.
Berlin, 13 July 2020
Berlin Commissioner for
Data Protection and
Freedom of Information
Friedrichstr. 219
631.184.2 10969 Berlin
535.1133
Visitors’ entrance:
A56ID 109329 Puttkamer Str. 16-18
DD 129684
The building is fully accessible to
FD 135781 disabled members of the public.
Contact us
Final Decision
Phone: +49 (0)30 13889-0
Fax: +49 (0)30 215 50 50
The Berlin DPA closes the case. Use our encrypted contact form
for registering data protection
complaints:
www.datenschutz-berlin.de/be-
1. Facts concerning the data breach schwerde.html
For all other enquiries, please
- Controller: Xara GmbH send an e-mail to:
[email protected]
- Incident: Hacker attack on email account
- Date of occurrence: 16 August 2019 Fingerprint of our
PGP-Key:
- Date of acknowledgement of the incident: 5 September 2019
D3C9 AEEA B403 7F96 7EF6
- EU/EEA Member States concerned, with the number of data C77F B607 1D0F B27C 29A7
subjects concerned:
o Establishment in Germany: 17
Office hours
o Establishment in UK: 20
o Data subjects who are employed both in Germany and the Daily from 10 am to 3 pm,
Thursdays from 10 am to 6 pm
UK (in home-office): 16 (or by appointment)
- Category of data subjects: Employee data How to find us
- Category of the data types/data records concerned: First name, The underground line U6 to
surname, email-address Kochstraße / Bus number M29
and 248
- Likely consequences of the violation of the protection of per-
sonal data: data misuse
Visit our Website
2. Description of the data breach from a technical-organizational per- https://privacy.de
spective
It is highly probable that unknown persons captured Office365 account
login data via an e-mail containing modified hyper-links. Utilising this login
data, they created an administrator account and gained access to the e-
mail accounts of several employees. Afterwards fake e-mails were sent.
3. Description and analysis of the effectiveness of the measures taken
to address the personal data breach or to mitigate its adverse effects
(Art. 33 (3) (d) GDPR)
Once the activities were detected, the passwords of all accounts, including
accounts with other services, were changed and a multi-factor authentica-
tion was immediately activated for accounts with access to sensitive data
(including all employees in the finance department). As a further measure,
-2-
the introduction of multi-factor authentication for all accounts is planned. In
addition, all affected workstations were subjected to a virus scan.
The technical measures are considered to be effective, since login data is
much more difficult to be misused when multi-factor authentication is acti-
vated.
4. Communication to the data subjects concerned or public communi-
cation (Art. 34(1) or Art. 34(3) (c) GDPR)
All data subjects concerned were notified on 6 September 2019 via email.
5. Technical and organisational security measures that the controller
had already taken when the incident occurred, e.g. encryption (Article
34 (3) (a) GDPR)
Standard Microsoft security features for Office 365, no multi-factor authenti-
cation.
6. Subsequent measures by which the controller has ensured that a
high risk to the data subjects concerned is no longer likely to materi-
alise (Article 34 (3) (b) GDPR)
As a further measure, the introduction of multi-factor authentication for all
accounts is planned.
7. Intended measures by the LSA Berlin DPA
7.1 Intended measures regarding Articles 33, 34 GDPR
In the light of the above-mentioned considerations regarding Articles
33, 34 GDPR, the Berlin DPA closes the case.
7.2 Intended measures regarding data protection violations be-
yond Articles 33, 34 GDPR
Furthermore, the Berlin DPA has not identified any data protection
violations beyond Articles 33, 34 GDPR.