What are the bets that none of the records were encrypted at rest?
Sensitive information like this really only ought to be accessible with a FIDO2 key, or something similar.
I’m not technically knowledgeable enough to know how you’d set things up, but I kinda doubt enough is mandated.
I got a few emails like this over the years. Like oh by the way, remember when you got bracers 20 years ago? Yeah we still kept all your private information forever and then we lost it. Gee, thanks
Unfortunately, working in IT you get the inside knowledge of how abysmal some users protect their credentials. An email comes in: “Oh no my password will expire!”, enters credentials without any consideration, 3 minutes later their emails are cloned and access to their companies system has been provided to the world.
The kicker? They don’t even report it until they notice something unusual like emails bouncing when they send out or no emails coming in, etc. Companies really need to push cybersecurity training on their staff and MFA enforcement above all else, there is no silver bullet for this sort of thing, but throw up enough roadblocks and access will come too difficult for the average script kiddy.




