What does the TSTT breach mean for customers?

Above: Rishi Maharaj.

Data protection consultant Rishi Maharaj on the TSTT Breach

From a Data Protection standpoint (which we don’t have but other countries in the region have adopted) there are several areas of concern.

Timing of the Disclosure: TSTT mentions that they became aware of the cyber-attack on October 9th, 2023. The gap between the attack and public disclosure appears to be significant, which could be concerning under Data Protection principles, especially as people’s personal data was comprised. From a data Protection perspective, reports should be made to a regulator within a specific time frame, namely 3 to 5 days and individuals must be informed, but alas we have no laws that place these requirements on companies here.

Nature of the Data: The breach reportedly includes customer lines, ID scans, and database dumps. ID scans can be considered as sensitive data, and its exfiltration poses significant risks for identity theft and fraud.

Assertion of ‘No Loss or Compromise’: TSTT states that there was “no loss or compromise of customer data”. However, considering the purported evidence available on the dark web, this claim may appear to contradict the presented data by RansomEXX. Under Data Protection best practice, transparency and accuracy in communication are critical.

Data Volumes and Relevance: TSTT points out that its platforms generate terabytes of data, possibly attempting to downplay the significance of the purported 6GB of exfiltrated data. While this might be accurate in the context of total data volume, GDPR focuses on the quality and sensitivity of data, not quantity. The sheer number of affected customers and the types of data involved make this breach significant.

In light of the recent cyber-attack on TSTT, their statement raises several concerns from a Data Protection perspective. The delayed disclosure, and the apparent contradiction between their claims and evidence presented by the hackers are alarming.

While TSTT’s proactive response in securing their systems is commendable, the nature of the data involved—especially the ID scans—poses a significant risk.

TSTT’s emphasis on the vast amounts of data they handle might be an attempt to downplay the breach’s gravity. However, from a Data Protection standpoint, it’s not the volume but the sensitivity and relevance of the data that counts. The situation underscores the need for transparent, accurate, and prompt communication in the face of security breaches.

Again, it places the need for revised legislation not only from a Data Protection perspective but also a cyber crime perspective to provide for an independent regulator and also to empower TT CSIRT with the ability to independently act and ensure accuracy and timely release of information and investigations and also to hold companies honest and accountable.

About Rishi Maharaj

Rishi Maharaj is a graduate of the University of the West Indies with a BSc. and MSc. in Government. He is a Certified Information Privacy Manager and provides consultancies through Privicy Advisory Services which assists organizations through data expansion and digital transformation, emphasizing the reduction of compliance burdens.

With over 15 years in the public and privacy sectors, he offers deep insights into government workings and the challenges of digital transformation. Notably, Rishi spearheaded the finalization and partial proclamation of Trinidad and Tobago’s Data Protection Act in 2011 and contributed to international model data protection legislation.

In the private sector, he helps businesses to align with GDPR and regional data protection standards, using compliance as a unique differentiator to boost organizational value and foster trust and engagement. He is a member of both the Canadian Institute of Access and Privacy Professionals and the International Association of Privacy Professionals.

Related Posts…

Site maintenance and upgrade in progress…

Site maintenance and upgrade in progress…

Making a UI change while a website is running is like changing a wheel on a car while it's moving.
Read More
Visa partners with OpenAI for the next generation of AI commerce

Visa partners with OpenAI for the next generation of AI commerce

Visa’s payment capabilities will be integrated into OpenAI experiences giving developers and merchants a streamlined way to accept Visa payments initiated by agents.
Read More
Privicy introduces Assura for DPO compliance

Privicy introduces Assura for DPO compliance

Build a complete record of processing activities using a structured 5-step wizard.
Read More
What the heck is chip binning?

What the heck is chip binning?

Instead of manufacturing multiple versions of a processor with different numbers of active cores, manufacturers create one master processor and then test the yields.
Read More
Two Hats, One Breach

Two Hats, One Breach

When an incident is discovered, retain a different provider to conduct the forensic investigation — one with no authorship of the compromised environment.
Read More
New MoF based phishing scheme in play

New MoF based phishing scheme in play

A new phishing scheme is masquerading as official communcation from the Ministry of Finance
Read More
Solving the region’s journalism problem

Solving the region’s journalism problem

There's formulaic approach to the content that we produce that sometimes totally denies or is ignorant of audience interest.
Read More
When “It wasn’t a breach” actually was

When “It wasn’t a breach” actually was

Breaches go unreported because IT says it is not a breach and no one in the room can push back with confidence.
Read More
Tambini to journalists: “Keep doing what you’re doing”

Tambini to journalists: “Keep doing what you’re doing”

There are lots of international standards to support that idea of the state supporting the media, but that support is often abused, so it has to be based on real...
Read More
How do we unfetter journalism from the shackles of business?

How do we unfetter journalism from the shackles of business?

Journalism must dissect information, deepen the understanding of it and bring clarity to the news consumer.
Read More
Site maintenance and upgrade in progress… Site maintenance and upgrade in progress…
Visa partners with OpenAI for the next generation of AI commerce Visa partners with OpenAI for the...
Privicy introduces Assura for DPO compliance Privicy introduces Assura for DPO compliance
What the heck is chip binning? What the heck is chip binning?
Two Hats, One Breach Two Hats, One Breach
New MoF based phishing scheme in play New MoF based phishing scheme in...
Solving the region’s journalism problem Solving the region’s journalism problem
When “It wasn’t a breach” actually was When “It wasn’t a breach” actually...
Tambini to journalists: “Keep doing what you’re doing” Tambini to journalists: “Keep doing what...
How do we unfetter journalism from the shackles of business? How do we unfetter journalism from...

🤞 Get connected!

A once weekly email notification of new stories on TechNewsTT. Just that. No spam.

Possible UI Glitch. Click top right corner to dismiss 👉

Get Connected!

A once weekly email notification of new stories on TechNewsTT.

Just that. No spam.