Information Security News mailing list archives

Ex-employee sues Citrix for negligence after 6TB data breach


From: InfoSec News <alerts () infosecnews org>
Date: Tue, 4 Jun 2019 08:57:04 +0000 (UTC)

https://www.itpro.co.uk/security/33758/ex-employee-sues-citrix-for-negligence-after-6tb-data-breach

By Keumars Afifi-Sabet
ITPRO.co.uk
3 Jun, 2019

A former Citrix employee has filed a class-action lawsuit against the virtualisation company for failing to safeguard current and former employees' personal information during a devastating hack disclosed earlier this year.

Attackers made away with employees' and their dependents personal and financial details after infiltrating the firm's systems last year and lingering for up to six months. The volume of data stolen totalled approximately 6TB, and comprised emails, blueprints and other business documents.

But the criminals were only able to compromise this data due to Citrix's own actions and omissions, and a failure to properly protect the personal information of its staff, according to court filings submitted in Florida.

The former employee, Lindsey Howard, alleges the method of entry, known as password-spraying, is a well-known and preventable intrusion tactic. The breach could have been easily prevented, moreover, had the company adopted "industry-standard security protocols".

[...]



--
Subscribe to InfoSec News
https://www.infosecnews.org/subscribe-to-infosec-news/
https://twitter.com/infosecnews_


Current thread: