¶ ile paragrafa bağlantı verin veya alıntıyı künyesiyle kopyalayın. Üretilen bağlantı kimlikleri resmî paragraf numarası değildir.
631.92.3
Berlin Commissioner for
Berlin, 05 August 2020 Data Protection and
Freedom of Information
535.1000 Friedrichstr. 219
10969 Berlin
A56ID 75410
Visitors’ entrance:
CR 126887 Puttkamer Str. 16-18
DD 126889
The building is fully accessible to
FD 142710 disabled members of the public.
Final Decision Contact us
Phone: +49 (0)30 13889-0
1. Facts concerning the data breach Fax: +49 (0)30 215 50 50
- Controller: AWIN AG
Use our encrypted contact form
- Incident: Credential stuffing (see bullet point 2) for registering data protection
- Date of occurrence: 08.07.2019 complaints:
www.datenschutz-berlin.de/be-
- Date of acknowledgement of the incident: 10.07.2019 schwerde.html
- EU/EEA Member States concerned, with the number of data For all other enquiries, please
subjects concerned: send an e-mail to:
[email protected]
o Ireland: 7 organisations
o Italy: 3 data subjects Fingerprint of our
PGP-Key:
o Spain: 4 data subjects
o United Kingdom: 23 organisations D3C9 AEEA B403 7F96 7EF6
C77F B607 1D0F B27C 29A7
- Category of data subjects: customers (publishers)
- Category of the data types/data records concerned: First name,
Office hours
last name, address, email address, and bank account details of data
subjects; name and email address of organisations Daily from 10 am to 3 pm,
Thursdays from 10 am to 6 pm
- Likely consequences of the violation of the protection of per- (or by appointment)
sonal data: misuse of data
How to find us
2. Description of the data breach from a technical-organizational per-
The underground line U6 to
spective Kochstraße / Bus number M29
and 248
An attacker used a stolen list of user names - typically email addresses and
passwords - to try to gain access to the systems. Typically, these lists con- Visit our Website
tain millions of email and password combinations. https://privacy.de
This type of attack, known as credential stuffing, is based on people reus-
ing the same username (typically an email address) and password on many
different systems and Web sites.
On the night of July 8, 2019, an attacker used a leased botnet (a network of
hacked computers or servers typically under the control of a hacker or crim-
inals) to automatically send many thousands of requests to systems from
about 100 different IP addresses. During this attack, the attacker could then
match some of the stolen credentials with those on the systems.
The attack was logged in the systems, but did not generate any warnings or
trigger any of the defence mechanisms. The activity was noticed on July 9,
2019, but was originally attributed to a known bug in the publisher login
-2-
process, which is occasionally exploited by attackers to bypass a registra-
tion fee.
3. Description and analysis of the effectiveness of the measures taken
to address the personal data breach or to mitigate its adverse effects
(Art. 33 (3) (d) GDPR)
The passwords of the affected accounts have been reset. A check for
changes to the affected accounts was performed and these were reset if
necessary. Improved detection and prevention of brute force attacks has
been implemented and multi-factor authentication for platform user logins is
under active development.
The password reset of the affected accounts prevented further conse-
quences (redirection of payments was mentioned).
The detection and prevention of brute force attacks is inevitably only possi-
ble to a limited extent. As described above, the attacker has also invested a
great deal of effort. Although the improvement of the corresponding
measures is to be welcomed, it will only make future attacks more difficult.
The attack described is not due to a security leak, but to the fundamental
weakness of knowledge-based authentication methods such as user
name/password. It is therefore to be welcomed that the platform will intro-
duce multi-factor authentication (e.g. adding the factor possession, such as
TAN generators). However, given the limited amount and type of personal
data accessible per account, we could not demand this at present (weigh-
ing of interests).
The implementation of multi-factor authentication prevents the success of
the attack that has taken place.
4. Communication to the data subjects concerned or public communi-
cation (Art. 34(1) or Art. 34(3) (c) GDPR)
The controller has notified all data subjects and organisations concerned on
12 July 2019 via email about the incident.
5. Technical and organisational security measures that the controller
had already taken when the incident occurred, e.g. encryption (Article
34 (3) (a) GDPR)
No particular measures beyond the standard IT security measures.
6. Subsequent measures by which the controller has ensured that a
high risk to the data subjects concerned is no longer likely to materi-
alise (Article 34 (3) (b) GDPR)
See bullet point 3.
7. Intended measures by the LSA Berlin DPA
7.1 Intended measures regarding Articles 33, 34 GDPR
In the light of the above-mentioned considerations regarding Articles 33,
34 GDPR, the Berlin DPA closes the case.
-3-
7.2 Intended measures regarding data protection violations beyond
Articles 33, 34 GDPR
Furthermore, the Berlin DPA has also not identified any data protection
violations beyond Articles 33, 34 GDPR.
The problem lies with the users (publishers) who have used compro-
mised passwords more than once. At best, the attack detection could be
criticized. However, the high effort that the attackers have put in must be
taken into account, which makes detection considerably more difficult.
The violation would be considered minor at best. In addition, the possi-
bility of a future attack will be closed by introducing multi-factor authenti-
cation.