Earlier quoted context omitted.
Have their been any GDPR fines that amount to more than a rounding error of Oracle's revenue? Admittedly, I don't watch too closely, but from the ones I am aware of, I haven't seen any GDPR fines that made me finally think "wow, that might actually count as a punishment". (I would honestly be happy to learn of some!) There are disclosure laws in the US as well, but again, the fines are like a days worth of revenue. M…
Several of the fines have been in the hundreds of millions of dollars - and while not crushing to Oracle, that's actual money that will definitely change behavior.. https://www.enforcementtracker.com/
Oracle customers confirm data stolen in alleged cloud breach is valid
31–40 of 85 posts
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#32Earlier quoted context omitted.
Have their been any GDPR fines that amount to more than a rounding error of Oracle's revenue? Admittedly, I don't watch too closely, but from the ones I am aware of, I haven't seen any GDPR fines that made me finally think "wow, that might actually count as a punishment". (I would honestly be happy to learn of some!) There are disclosure laws in the US as well, but again, the fines are like a days worth of revenue. M…
In the UK, and I presume the EU also, the fines for losing customer data are set as a % of company annual worldwide turnover. https://ico.org.uk/for-organisations/law-enforcement/guide-t...
They're not fines though if no money changes hands.
So far very few if any of these supposed penalties have actually been paid.
There have been a few good articles published about the total Euro amount of "penalties" and actual enforcement actions, and the ratio is something like 100:1 or worse.
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#33> BleepingComputer has confirmed with multiple companies that associated data samples shared by the threat actor are valid. > In addition to the data, rose87168 shared an Archive.org URL with BleepingComputer for a text file hosted on the "login.us2.oraclecloud.com" server that contained their email address. This file indicates that the threat actor could create files on Oracle's server, indicating an actual breach.…
> It's not like there are any real penalties to a breach. Not in the US maybe. In the EU under GDPR you have to disclose within 48h of you realizing (or made aware of) the breach. There are fines (at least) if you don't disclose it afaik. Oracle is gonna have issue with the EU, most likely.
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#34Earlier quoted context omitted.
> It's not like there are any real penalties to a breach. Not in the US maybe. In the EU under GDPR you have to disclose within 48h of you realizing (or made aware of) the breach. There are fines (at least) if you don't disclose it afaik. Oracle is gonna have issue with the EU, most likely.
SEC Fact Sheet: Public Company Cybersecurity Disclosures; Final Rules - https://www.sec.gov/files/33-11216-fact-sheet.pdf
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#35Alone the fact that Oracle was hosting their login gateway on a product with a known vulnerability from 2021 with a CVSS score of 9.8 is quite disturbing.
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#36Earlier quoted context omitted.
SEC Fact Sheet: Public Company Cybersecurity Disclosures; Final Rules - https://www.sec.gov/files/33-11216-fact-sheet.pdf
I mean it's true that there's a rule, but at this point in US history I think we have reason to be sceptical that it will be enforced.
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#37Earlier quoted context omitted.
7 days of revenue, 1 whole week out of 52 that all of your workforce production went to pay a fine? Yeah, that's quite noticeable for a corporation.
If this breach receives a fine in the top 5 fines ever issued in the entire history of GDPR enforcement . Don't forget to subtract out the money they saved from reduced investment in security over that time, as well. Noticeable? Sure. Nowhere near noticeable enough, though, in my opinion. Especially if we're serious about it and recognize this isn't going to be a top 5 fine.
If it happens repeatedly presumably the percentage will go up.
I think the only way this gets written off is if saving the money opens you up to such a low level of additional risk that you don't reasonably expect the event to happen more than once (if ever). But if the risk level is actually that low (I don't believe this to be the case, just playing out a hypothetical here) then arguably they wouldn't be in the wrong.
To put this in regular person terms, 3% of a 6 figure salary is $3k. That's more than enough to get most people's attention.
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#38Earlier quoted context omitted.
we pay millions to Oracle. We hit a bug and it took 6months for them to reproduce and acknowledge there is a bug. they now seem to be on the lookout for someone being able to produce a fix: sales and indian after-sales can't do that... curious! Oracle seems just a moneygrabbing shell company at this point and I suppose the whole hyperscaler-cloud is developing towards that point with the leaders of those corporations…
Why are you still on Oracle? (genuine question, no snark)
Re: Oracle customers confirm data stolen in alleged cloud breach is valid
#39Classic, Oracle denying breach despite clear evidence.
Deny deny deny. Those that have already drunk the kool-aid will believe your denial. Those that are too lazy to look or only get their info from one source will not know any different than your denial. The rest are just wrong from being in opposition anyways.
It works anywhere as long as you are large enough of an entity