Ashley Madison told to delete accounts

A joint Australian and Canadian privacy commission report has advised affair dating site Ashley Madison to delete more accounts after a mass breach last year.

Ashley Madison, affair, hack

Source: Getty Images

The company that owns the affair dating site Ashley Madison, which was behind a mass privacy breach, has agreed to court-enforceable improvements in handling personal information.

A joint Australian and Canadian privacy commissioner investigation into how the details of millions of users were published online by hackers has released a "highly critical" report of the website's privacy.

Among the users were hundreds of Australian government employees and thousands of citizens, including some who had paid Ashley Madison to delete their accounts.

The hacked data, released on the dark web last year, included credit card details, email accounts and home addresses.

The joint report investigated the privacy practices of parent company Avid Life Media, and found it did not have an adequate information security framework.

In the first ever joint Australian and Canadian privacy investigation, the commissioners investigated ALM's retention of personal information after profiles were deactivated.

They also looked at ALM's practice not to confirm the accuracy of users' email addresses and its transparency over handling of personal information.

The report made a series of recommendations, all of which ALM has agreed to implement.

Among them are reviewing protections of personal information, advising staff of security procedures, stopping retention of information from deactivated accounts and no longer charging users to delete their information.

The hackers, who called themselves the Impact Team, demanded the site be shut down before releasing the data in retaliation.

The commissioners say the report contains important lessons for other organisations that hold personal information.

"The findings of our joint investigation reveal the risks to businesses when they do not have a dedicated risk management process in place to protect personal information," Australian privacy commissioner Timothy Pilgrim said.

Companies must think beyond IT systems to staff training, policies, oversight and clear lines of authority, he said.

The commissioner also used the report to warn customers to guard their personal data.

"While ALM fell well short of the requirements we would expect for an organisation managing personal information, breaches can occur in the best-run companies," Mr Pilgrim said.

"Be clear about what you are providing, the value you are getting in exchange, and understand that no organisation is breach-proof."


Share

2 min read

Published

Source: AAP



Share this with family and friends


Get SBS News daily and direct to your Inbox

Sign up now for the latest news from Australia and around the world direct to your inbox.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Download our apps
SBS News
SBS Audio
SBS On Demand

Listen to our podcasts
An overview of the day's top stories from SBS News
Interviews and feature reports from SBS News
Your daily ten minute finance and business news wrap with SBS Finance Editor Ricardo Gonçalves.
A daily five minute news wrap for English learners and people with disability
Get the latest with our News podcasts on your favourite podcast apps.

Watch on SBS
SBS World News

SBS World News

Take a global view with Australia's most comprehensive world news service
Watch the latest news videos from Australia and across the world