OpinionTaran Rampersad: Are websites increasing cybersecurity vulnerabilities?

Taran Rampersad: Are websites increasing cybersecurity vulnerabilities?

Above: Illustration by vectorlab/DepositPhotos

Why So Many Breaches in Trinidad?

Taran Rampersad wrote this piece for his website, knowprose.com and it is reproduced here with his permission.

People continue to ask why there are so many data breaches happening in Trinidad and Tobago. I’m not someone who would call himself a security expert by a stretch, but it’s an intriguing enough question that I decided to look into it.

Are there commonalities in Website Technology?

First, I checked the websites of those that had been breached, which might reveal some commonalities. Bear in mind, it’s possible that the websites weren’t how the information was accessed.

TSTT, which had the most noteworthy breach, runs Wix – which was quite a surprise if only because of the vendor lock-in associated with it. I was expecting a more commonly used content management system but instead, Wix.

The Office of the Attorney General’s website, attacked earlier this year and probably the 2nd most important breach overall since it paralyzed the Judiciary is using WordPress. It also is actually not the first time; a teen was charged in 2007 for hacking into the Attorney General’s Office.

MassyStorestt.com also runs WordPress, but is substantially behind in upgrades. Pricesmart.com runs mostly BloomReach and a bit of Drupal. Their breach was reported yesterday.

It’s apparent that this isn’t an issue of common platforms being compromised. Yet there is a hint in here. MassyStoresTT.com being substantially behind in WordPress updates.

Maintenance

When I was heavily into developing CMS websites, I tried doing that locally in Trinidad and Tobago and found that people thought they could just buy a website and it would simply be done and they could go about their business without maintenance contracts. It simply doesn’t work that way.

Maybe even after years, that hasn’t changed. Maybe these websites aren’t being maintained and kept up to date with technology, which includes patching for exploits that allow their data to be breached or otherwise attacked. Maybe.

Personally, with my experience in dealing with local companies and government offices, I don’t see them seeing maintenance as a priority. In fact, I didn’t do business with companies in Trinidad and Tobago for that same reason because… I didn’t want my name associated with poorly maintained sites.

Is this the only conclusion? Definitely not.

Who Has Access Anyway?

Everyone talks about the breaches, but the public always assumes that the people with access to the information had a reason to access the information. In the TSTT data breach, scanned copies of people’s identification were found and I have to wonder what TSTT’s information policy is. Who needs access to that level of information, and why?

I’d be surprised if it were available through the website because that would be just asking for trouble.

Assuming they themselves can be trusted with your personal information, there’s social engineering, which the video below explains…

We forget at times that the people with access to information themselves are open to attack to get to something bigger. Maybe their own computer systems they use to access the data are compromised, maybe they’ve been compromised.
Conclusions

Again, I’m no security expert. Some of the information available from these breaches and the way attacks happened on some websites was clearly associated with the websites themselves. TSTT’s data breach seems different in that regard because no sane company would have that information accessible through their website.

Altogether, it seems like a lack of maintenance for most of these breaches – and maybe there were deeper issues with all of them, but in particular the TSTT data breach.

What is most disturbing is that these are the breaches we’re worried about, which could be a fraction of the number of breaches that happened. The announced breaches we found out about because either someone showed evidence or it created an issue that impacted products and services.

The insidious breaches, the ones where people simply mine the information and don’t get caught or brag, we don’t know about. That’s what concerns me most.

We should be worried.

About the author

Taran Rampersad

Taran Rampersad has over three decades of experience working with technology, the majority of which was as a software engineer.

He is a published author on virtual worlds and was part of the team of writers at WorldChanging.com that won the Utne Award and an outspoken advocate of simplifying processes and bending technology’s use to society’s needs.

His volunteer work related to technology and disasters has been mentioned by the media (BBC), and is one of the plank-owners of combining culture with ICT in the Caribbean (ICT) through CARDICIS and has volunteered time towards those ends.

As an amateur photographer, he has been published in educational books, magazines, websites and NASA’s ‘Sensing The Planet’. These days, he’s focusing more on his writing and technology experiments. Feel free to contact him through Facebook Messenger.

How AI is changing film making

How AI is changing film making

“Disney would be a snack to Meta or Apple. It wouldn't affect their bottom line at all. The question is not, will this happen, but when will this happen?” -...
Read More
An app to make co-parenting more accountable

An app to make co-parenting more accountable

“I built Zuko because everyday matters could become conflict when communication was scattered or misunderstood.”
Read More
In a US university film lab, a Trini is working and learning

In a US university film lab, a Trini is working and learning

Most people are pressing buttons. The work is in defining what the buttons do.
Read More
The Global Lense – The one about data and tech stack sovereignty

The Global Lense – The one about data and tech stack sovereignty

Most recent technology development appears to be companies outside the region tapping the market within the region.
Read More
Declaring independence from mobile roaming

Declaring independence from mobile roaming

Most modern smartphones, even those with a physical SIM tray, will also accept an e-SIM.
Read More
Intellico introduces AI agency service with 150 agents

Intellico introduces AI agency service with 150 agents

The proper use of AI can help flatten the world and make opportunities available to small nations that they could not achieve previously.
Read More
CANTO summarises 2026 conference discussions

CANTO summarises 2026 conference discussions

Government leaders from Estonia, Curaçao, Jamaica, the Cayman Islands, and St. Vincent and the Grenadines pressed the case for closer collaboration between the public and private sectors on national digital...
Read More
Effectively incorporate AI into your business

Effectively incorporate AI into your business

A tool can save an employee 30 minutes and still be a poor business decision.
Read More
Urgency, awareness needed to combat sextortion

Urgency, awareness needed to combat sextortion

While social platforms make it easy for crimes to cross borders and infiltrate households, law enforcement remains limited by the transnational agreements that enable effective policing across borders.
Read More
What Trinidad and Tobago’s new AI Practice Direction means for lawyers (and you)

What Trinidad and Tobago’s new AI Practice Direction means for lawyers (and you)

AI can generate a chronology of events from a stack of documents that would take a paralegal hours to work through. What they cannot do is guarantee accuracy.
Read More
Hands on: BOSGAME VTA-439

Hands on: BOSGAME VTA-439

I chose Ubuntu to demonstrate that an enterprise Linux distribution works well on the system.
Read More
The silent, growing danger of ransomware

The silent, growing danger of ransomware

Victims of ransomware continued to carry critical patch vulnerabilities even after being attacked.
Read More
How should a newsroom of the (very near) future work?

How should a newsroom of the (very near) future work?

When generic content becomes easier to produce, the advantage that we have shifts to what is harder to replicate and that is original journalism.
Read More
How AI is changing film making How AI is changing film making
An app to make co-parenting more accountable An app to make co-parenting more...
In a US university film lab, a Trini is working and learning In a US university film lab,...
The Global Lense – The one about data and tech stack sovereignty The Global Lense – The one...
Declaring independence from mobile roaming Declaring independence from mobile roaming
Intellico introduces AI agency service with 150 agents Intellico introduces AI agency service with...
CANTO summarises 2026 conference discussions CANTO summarises 2026 conference discussions
Effectively incorporate AI into your business Effectively incorporate AI into your business
Urgency, awareness needed to combat sextortion Urgency, awareness needed to combat sextortion
What Trinidad and Tobago’s new AI Practice Direction means for lawyers (and you) What Trinidad and Tobago’s new AI...
Hands on: BOSGAME VTA-439 Hands on: BOSGAME VTA-439
The silent, growing danger of ransomware The silent, growing danger of ransomware
How should a newsroom of the (very near) future work? How should a newsroom of the...

🤞 Get connected!

A once weekly email notification of new stories on TechNewsTT. Just that. No spam.

1 COMMENT

Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

1 Comment
Oldest
Newest Most Voted
trackback
2 years ago

[…] Trinidad and Tobago – People continue to ask why there are so many data breaches happening in Trinidad and Tobago. I’m not someone who would call himself a security expert by a stretch, but it’s an intriguing enough question that I decided to look into it… more […]

RELATED POSTS