Preceptics, a company that provides license plate readers, license plate recognition systems and vehicle identification products has been hacked and the consumer information gleaned from that hack is being offered on the Dark Web for free.
A company responsible for providing the US government with technology to read license plates has been hacked. #Hackhttps://t.co/n69II0Gg2r
— Sarah Marville, SHRM-CP (@sarahmarville) May 28, 2019
Expert Comments:
Dov Goldman, Director of Risk & Compliance at Panorays:
“When we drive through an electronic toll gate, we’re happy that our license plate is scanned and the toll is charged to our credit card. Most likely, we don’t think about the privacy implications of this great convenience. The data breach at Perceptics, the largest manufacturer of license plate scanning systems, will force us to consider all the private data collected in this seemingly innocent transaction. The colorfully named “Boris Bullet-Dodge” hacking group has gained access to much more than just our license plate numbers by penetrating this government contractor’s information systems. Perceptics collects personal data for payment (credit card, bank account) and vehicle inspection status, not to mention exactly where we are at a given date and time. Responsible government procurement and outsourcing depends on rigorous assessment of each contractor’s information security and privacy capabilities. It goes way beyond determining the level of their cybersecurity policies and procedures, which should be standard operating procedure for any procurement process, before a contract is awarded. It must extend to the continuous monitoring of these contractors and their data systems, without which it’s impossible to safeguard citizens’ privacy and the security of their personal data.”
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional
Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes.The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.