Cupid Breaches Privacy of its 254,000 Australian Members
By Athena Yenko | June 26, 2014 5:03 PM EST
Cupid Media Pty Ltd (Cupid) is found to have breached the Privacy Act 1988 as it exposes personal information of its 254,000 Australian Cupid site users.
Cupid, which operates 35 niche dating web sites, failed to take proper actions to secure and protect its members' information. Investigations found that the site was hacked in January 2013 and hackers were able to gain access to member's personal information that includes full name, date of birth, email addresses and passwords.
According to Commissioner Timothy Pilgrim businesses are expected to observe due diligence in keeping information security.
"This case highlights the importance of organisations conducting ongoing testing and maintenance of security systems to minimise the risk of a hack succeeding, and to ensure they are able to respond quickly if one occurs. Cupid's vulnerability testing processes did allow it to identify the hack and respond quickly. Hacks are a continuing threat these days, and businesses need to account for that threat when considering their obligation to keep personal information secure," Pilgrim said in a statement.
It was found out that Cupid was negligent as it did not have password encryption processes in place, hence, hackers were able to gain access conveniently.
"Password encryption is a basic security strategy that may prevent unauthorised access to user accounts. Cupid insecurely stored passwords in plain text, and I found that to be failure to take reasonable security steps as required under the Privacy Act," Pilgrim explained.
The investigation had also found that Cupid did not permanently de-identified personal information that is no longer required.
"Holding onto old personal information that is no longer needed does not comply with the Privacy Act and needlessly places individuals at risk. Organisations must identify out of date or unrequired personal information and have a system in place for securely disposing with it," Pilgrim noted.
Pilgrim is also calling all users of dating sites to regularly change password and update privacy settings of their accounts.
"I would also remind consumers using internet dating sites to regularly update your privacy settings, change your passwords and be careful about the personal information you share. You don't want to become a victim of identity theft or a scam."
To contact the editor, e-mail:
Most Popular Slideshows
- Reasons Why Michael Jordan Is Better Than LeBron James [PHOTOS And VIDEO]
- Dwyane Wade, Joe Johnson, Amare Stoudemire Among Worst Contracts In The NBA (Part 2 - Eastern Conference)
- Brawl-Marred Game in NFL Week 3: Philadelphia Eagles 37, Washington Redskins 34 [PHOTOS]
- NFL Monday Night Football Recap: Chicago Bears 27, New York Jets 19
Join the Conversation
- Kate Middleton Pregnancy Update: Duchess Of Cambridge ‘Dissed’ By Camilla Parker-Bowles; Delivery Expected In April- Reports
- 'Green Alien Eggs' Spotted on Sydney's Dee Why Beach
- The Pirate Bay Founder Peter Sunde Attends Father’s Funeral Without Handcuffs, Brother Thanks TPB Founder’s Supporters on Facebook
- Drag Queens Fume That Facebook Is Banning Aliases And Threaten to Drop Out Of It
- Robin Williams Confessed To Loving Billy Connolly Like A Brother In A Final Goodbye Call
- Nexus 6, 8 Release Date is Halloween 2014 as Android L Intro Set for October 16
- New Samsung Galaxy Note 4 and Galaxy S5 Android 5.0 L Killer Features, Encryption and More
- Moto G 2014 v Asus Zenfone 5 – Specification Comparison Shows Zenfone 5 Is A Good Alternative for Moto G
- Android 5.0 L Nexus 4, Nexus 5, Nexus 7 Release in October, Google Employees Offer Hint
- U.S and Canada Fighter Jets Chase Out Russian Jets Near Alaska: Air Space Violation Not Confirmed
- Microsoft Doubles OneDrive Space To 30GB Due To iOS 8 Update Issues
- Nexus 8, Nexus 9 Release Date, Device Name And Price Conundrum: What To Expect?