News BriefsParasram warns of possible GDPR fines after assessing TSTT data dump

Parasram warns of possible GDPR fines after assessing TSTT data dump

Above: Shiva Parasram.

Shiva Parasram is a cybersecurity expert who has been examining the dump of data exfiltrated from TSTT’s servers. When he spoke with me, he was coming to the end of 22 hours of examining the files, which were captured as unencrypted, plain text files in txt and csv formats. Images of customer documents and identification are in standard JPEG and PDF formats.

“I was talking to one of my friends who works at a pretty high position in the Big Four ( Deloitte, Ernst & Young (EY), KPMG, and PwC) about the implications with data privacy and the GDPR. If they have customer information (for anyone in the) EU at the moment or (someone) who falls under the EU GDPR, when the EU gets wind of this and they do their own investigations and analyse it, there could be fines for this. And those fines are nothing minimal”

Parasram wonders if TSTT still has the staff capabilities to mount a forensic analysis of what was taken. He’s been informed that after recent layoffs, TSTT may be operating with a skeleton staff for cybersecurity.

“We are trying to figure out if TSTT was actually aware of the full extent of the dump, if they actually took the dump to analyse it. One of my guys tried to open one of the Excel files. The file is so large that even with 64 gigs of RAM, it was taking forever.”

Parasram is a long way from reviewing all the data in the dump, but notes. I have seen information for many people that I know, accurate information, you know the the photos with IDs and stuff like that. Whether people pay with cash or Linx. But that’s from the client-side database.”

“But even on the company side, there’s a lot of internal stuff. There’s a password file called SYS_password.xls for example (with) names of systems and what appear to be passwords. It’s a lot of information. Everybody is exhausted, and we are probably just scratching the surface. It’s a big nightmare because honestly, if they were part of the EU, this could be billions of dollars in fines

Shiva Parasram

Shiva Parasram, is an Enterprise Risk Consultant, Senior Cybersecurity Lecturer and Forensic Investigator. He has written four books about digital forensics and leads the Computer Forensics and Security Institute.

 

 

 

Related Posts

An app to make co-parenting more accountable

An app to make co-parenting more accountable

“I built Zuko because everyday matters could become conflict when communication was scattered or misunderstood.”
Read More
In a US university film lab, a Trini is working and learning

In a US university film lab, a Trini is working and learning

Most people are pressing buttons. The work is in defining what the buttons do.
Read More
The Global Lense – The one about data and tech stack sovereignty

The Global Lense – The one about data and tech stack sovereignty

Most recent technology development appears to be companies outside the region tapping the market within the region.
Read More
Declaring independence from mobile roaming

Declaring independence from mobile roaming

Most modern smartphones, even those with a physical SIM tray, will also accept an e-SIM.
Read More
Intellico introduces AI agency service with 150 agents

Intellico introduces AI agency service with 150 agents

The proper use of AI can help flatten the world and make opportunities available to small nations that they could not achieve previously.
Read More
CANTO summarises 2026 conference discussions

CANTO summarises 2026 conference discussions

Government leaders from Estonia, Curaçao, Jamaica, the Cayman Islands, and St. Vincent and the Grenadines pressed the case for closer collaboration between the public and private sectors on national digital...
Read More
Effectively incorporate AI into your business

Effectively incorporate AI into your business

A tool can save an employee 30 minutes and still be a poor business decision.
Read More
Urgency, awareness needed to combat sextortion

Urgency, awareness needed to combat sextortion

While social platforms make it easy for crimes to cross borders and infiltrate households, law enforcement remains limited by the transnational agreements that enable effective policing across borders.
Read More
What Trinidad and Tobago’s new AI Practice Direction means for lawyers (and you)

What Trinidad and Tobago’s new AI Practice Direction means for lawyers (and you)

AI can generate a chronology of events from a stack of documents that would take a paralegal hours to work through. What they cannot do is guarantee accuracy.
Read More
Hands on: BOSGAME VTA-439

Hands on: BOSGAME VTA-439

I chose Ubuntu to demonstrate that an enterprise Linux distribution works well on the system.
Read More
An app to make co-parenting more accountable An app to make co-parenting more...
In a US university film lab, a Trini is working and learning In a US university film lab,...
The Global Lense – The one about data and tech stack sovereignty The Global Lense – The one...
Declaring independence from mobile roaming Declaring independence from mobile roaming
Intellico introduces AI agency service with 150 agents Intellico introduces AI agency service with...
CANTO summarises 2026 conference discussions CANTO summarises 2026 conference discussions
Effectively incorporate AI into your business Effectively incorporate AI into your business
Urgency, awareness needed to combat sextortion Urgency, awareness needed to combat sextortion
What Trinidad and Tobago’s new AI Practice Direction means for lawyers (and you) What Trinidad and Tobago’s new AI...
Hands on: BOSGAME VTA-439 Hands on: BOSGAME VTA-439

🤞 Get connected!

A once weekly email notification of new stories on TechNewsTT. Just that. No spam.

1 COMMENT

Subscribe
Notify of
guest

This site uses Akismet to reduce spam. Learn how your comment data is processed.

1 Comment
Oldest
Newest Most Voted
trackback
2 years ago

[…] Trinidad and Tobago – Shiva Parasram is a cybersecurity expert who has been examining the dump of data exfiltrated from TSTT’s servers. When he spoke with me, he was coming to the end of 22 hours of examining the files, which were captured as unencrypted, plain text files in txt and csv formats. Images of customer documents and identification are in standard JPEG and PDF formats… more […]

RELATED POSTS