Canton Cybersecurity
Vehicle owner data breach also hits canton Ticino
An automated attack collected license plates, names and addresses of vehicle owners on a large scale, including in canton Ticino. The canton has filed a criminal complaint and will not pay a ransom.
Canton Ticino has also been affected by the automated collection of public data on vehicle owners, the same incident already reported in recent days by other Swiss cantons. Cantonal authorities specify that this was not an intrusion into the canton's IT systems: the data collected was already publicly accessible through an online service.
The stolen data includes license plate numbers, names and addresses of vehicle owners. People who had asked not to have their information made public are not affected.
Whoever carried out the attack exploited the online form that allows users to search for a vehicle's owner using its license plate. The form, designed for individual searches, was queried automatically a very large number of times, bypassing the mechanisms meant to limit the number of requests and prevent large-scale data collection.
The cantonal road traffic office acted already last week, contacting the service provider and the administrations of the other cantons involved. As soon as it was confirmed that the attack also involved Ticino data, the Department of Institutions, through the road traffic office, filed a criminal complaint with the public prosecutor's office.
No ransom, beware of scams
As a precaution, the canton has disabled the "Elenco targhe Cantone Ticino" webpage. Like the other administrations involved, Ticino has ruled out paying any ransom: the payment would not guarantee deletion of the data, would fund the attackers and could encourage further attacks of this kind.
Authorities are urging the public to be wary of unexpected letters, emails or text messages requesting urgent payments or personal and financial data, for example under the pretext of fines, vehicle taxes, technical inspections or foreign tolls. In case of doubt, it is advisable to contact the relevant authority through its official channels, rather than using the contact details given in the suspicious message.
Comments
There are no comments yet. Yours can be the first voice.