Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Articles - Who Had Leaked This Information?
Articles

Who Had Leaked This Information?

ISBuzz TeamBy ISBuzz TeamApril 10, 2014Updated:May 2, 20254 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Pepsi Bottling Ventures Breached Following Malware Attack
Pepsi Bottling Ventures Breached Following Malware Attack
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

It is interesting that, we are now of an opinion that companies are being used to store, and communicate Child Abuse Images on, and from their systems, but I feel someone, somewhere may have been enjoying a deep slumber, as this has been going on for at least 10 years. Take the Detroit based automotive business, with offices and plants located in a wide range of countries, from Asia Pacific, and from Turkey to Germany [where this case is focused on] with evolving interests established in Russia – in fact at one time, this was one of the largest companies in the world, with a very prestigious badge of corporate responsibility and a reputation to match. For the sake of this article, let us call this Company ‘G’.

To that date Company ‘G’ had driven deep rooted paper-based compliance, governance, and security missions within all of its business areas, establishing a centralised core of security expertise, out of which its team engaged with various global units, and their security representatives, assuring the company worked to one tick-box standard. However, that was until such time a discovery was made, which was found to be alien to the reputational interest of the business!

Company ‘G’ had suffered a breach which implied both internal and external actors were in play and had implemented an unauthorised e-commerce facility right in the heart of an operations centre of one of its international engineering plants.

The unauthorised facility in question had been populated with a large amount of unauthorised information-assets, which were being made available to an external non-company subscribed user base. However, whilst this was bad enough from the point of what was an internal/external breach, linked to the fact that a number of external non-company users were being granted subscribed access to internal company assets rear of the perimeter firewall, it got even worse when the real purpose of this ‘environment’ was understood. It was being used to store and distribute materials which were classified under the COPINE, and SAP scales in the form of extreme paedophilic images!

The on-site First Responder who became aware of this security breach realised the serious implications, not just relative to the security aspects of the event, but in the wider context given the type of hosted subject materials, accompanied by a database populated with the details of all subscribed users. It was at this juncture that the decision was arrived at to report this discovery to a trusted individual in the core Company security operations centre. On the next visit to the companies HQ, given there was some concern about retribution, the report was made with an assurance that the source would not be revealed, and this was agreed. As amazing as it may seem, it was also shared that the security breach in question was known by a number of key executives back at the Germany based location in question, and that it had been said that ‘if this got out, anyone involved should not stand too close to open windows’!

The recipient of the report then documented it and took it forward to the higher level of local HQ management. After some time and a telephone call back to the subject business unit, the reporting security professional was called back into a closed door meeting with two of their superiors. The content of the meeting did ‘not’ discuss the event, the breach, or the fact that the Company was hosting a global database of paedophilic images. The only question they had was ‘who had leaked this information from the plant’ a question I can attest was never satisfied.

As of this day, as far as I understand from first-hand knowledge, this matter was handled internally and simply ‘went away’. There were no signs of any action being taken against any employee and in fact furthermore, there was no indication that the serious matter of paedophilia was ever reported to the Police and certainly did not appear in the press.

This is I can attest is a factual case around circa 1999 – as I was the person it was reported to!

Professor John Walker  FMFSoc FBCS FRSA CITP CISM CRISC ITPCjohn walker

Visiting Professor at the School of Science and Technology at Nottingham Trent University (NTU), Visiting Professor/Lecturer at the University of Slavonia[to 2015], CTO and Company, Director of CSIRT, Cyber Forensics, and Research at INTEGRAL SECURITY XASSURNCE Ltd, Practicing Expert Witness, ENISA CEI Listed Expert, Editorial Member of the Cyber Security Research Institute (CRSI), Fellow of the British Computer Society (BCS), Fellow of the Royal Society of the Arts, an Associate Researcher working on a Research Project with the University of Ontario, and a Member, and Advisor to the Forensic Science Society.

 

ISBuzz Team
  • ISBuzz Team
    Air Canada Data Breach: BianLian Extortion Group Claims A Massive Heist Contrary To Airline’s Earlier Statement
  • ISBuzz Team
    Unprecedented DDoS Attack Rocks The Web: Tech Giants Reveal A Digital Tsunami
  • ISBuzz Team
    CISA Flags High-Severity Adobe Acrobat Reader Flaw Amid Active Exploits
  • ISBuzz Team
    Curl Security Alert: Patching A Critical Bug Averting Potential Cyber Catastrophe

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

Exploited Faster, Patched Slower: Verizon DBIR 2026 Shows Security Teams Losing Ground

May 20, 20265 Mins Read

Security’s Blind Spot: The Threats Hiding in “Low-Severity” Alerts

May 6, 20265 Mins Read

Why OSINT deserves the same status as other intelligence disciplines

March 17, 20266 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}