🔺 What to do when markets are at an all-time high? Find smart bargains, like these.See Undervalued Stocks

Ashley Madison parent broke Canada, Australia privacy laws

Published 2016-08-23, 02:47 p/m
Ashley Madison parent broke Canada, Australia privacy laws

OTTAWA, Aug 23 (Reuters) - The parent company of infidelity dating website Ashley Madison was responsible for numerous violations of privacy laws at the time of a massive release of customer data in a cyber attack last year, privacy watchdogs in Canada and Australia said on Tuesday.

The two countries launched an investigation after the 2015 breach of Avid Life Media Inc's computer network, when hackers exposed the personal details of millions who signed up for the site with the slogan "Life is short. Have an affair."

The probe found the Toronto-based company had inadequate safeguards in place, including poor password management and a fabricated security trustmark on the website's home page.

The company, recently rebranded as Ruby Corp, has entered into agreements with authorities in both countries to comply with investigators' recommendations, which are enforceable in court.

The company is also the target of a U.S. Federal Trade Commission investigation, Avid Life Media executives told Reuters in July. FTC's consumer protection unit investigates cases of deceptive advertising, including instances when consumers are told that their information is secure but then it is handled sloppily.

The FTC could not immediately be reached for comment.

The investigation conducted jointly by the Office of the

Privacy Commissioner of Canada and the Office of the Australian Information Commissioner found that certain information security safeguards were insufficient or absent at the time of the hacking attack.

While the company did have some personal information protections in place, it fell short in implementing those measures, the report found. For instance, it said some passwords and encryption keys were stored as plain, identifiable text on the company's systems.

At the time of the breach, Ashley Madison's home page displayed various trustmarks suggesting a high level of security, including an icon labeled "trusted security award," the report said. Company officials later admitted they had fabricated the trustmark and removed it.

The company also inappropriately retained some personal information after profiles had been deactivated or deleted by users and did not adequately ensure the accuracy of customer email addresses, the report said. This meant that some people who had never signed up for Ashley Madison were included in databases published online after the hack, it said.

Among the investigators' recommendations, Ruby will have until the end of the year to complete a review of the protections it has in place for the protection of personal information. The company said on Tuesday the review was a key priority and already underway.

Latest comments

Risk Disclosure: Trading in financial instruments and/or cryptocurrencies involves high risks including the risk of losing some, or all, of your investment amount, and may not be suitable for all investors. Prices of cryptocurrencies are extremely volatile and may be affected by external factors such as financial, regulatory or political events. Trading on margin increases the financial risks.
Before deciding to trade in financial instrument or cryptocurrencies you should be fully informed of the risks and costs associated with trading the financial markets, carefully consider your investment objectives, level of experience, and risk appetite, and seek professional advice where needed.
Fusion Media would like to remind you that the data contained in this website is not necessarily real-time nor accurate. The data and prices on the website are not necessarily provided by any market or exchange, but may be provided by market makers, and so prices may not be accurate and may differ from the actual price at any given market, meaning prices are indicative and not appropriate for trading purposes. Fusion Media and any provider of the data contained in this website will not accept liability for any loss or damage as a result of your trading, or your reliance on the information contained within this website.
It is prohibited to use, store, reproduce, display, modify, transmit or distribute the data contained in this website without the explicit prior written permission of Fusion Media and/or the data provider. All intellectual property rights are reserved by the providers and/or the exchange providing the data contained in this website.
Fusion Media may be compensated by the advertisers that appear on the website, based on your interaction with the advertisements or advertisers.
© 2007-2024 - Fusion Media Limited. All Rights Reserved.