https://www.itpro.co.uk/security/33758/ex-employee-sues-citrix-for-negligence-after-6tb-data-breach
By Keumars Afifi-Sabet
ITPRO.co.uk
3 Jun, 2019
A former Citrix employee has filed a class-action lawsuit against the
virtualisation company for failing to safeguard current and former
employees' personal information during a devastating hack disclosed
earlier this year.
Attackers made away with employees' and their dependents personal and
financial details after infiltrating the firm's systems last year and
lingering for up to six months. The volume of data stolen totalled
approximately 6TB, and comprised emails, blueprints and other business
documents.
But the criminals were only able to compromise this data due to Citrix's
own actions and omissions, and a failure to properly protect the personal
information of its staff, according to court filings submitted in Florida.
The former employee, Lindsey Howard, alleges the method of entry, known as
password-spraying, is a well-known and preventable intrusion tactic. The
breach could have been easily prevented, moreover, had the company adopted
"industry-standard security protocols".
[...]
--
Subscribe to InfoSec News
https://www.infosecnews.org/subscribe-to-infosec-news/
https://twitter.com/infosecnews_