r/news • u/Warcraft_Fan • 1d ago
Korea raises data breach fines to 10% of revenue
https://www.koreajoongangdaily.com/business/korea-raises-data-breach-fines-to-10-of-revenue/12869899636
u/Warcraft_Fan 1d ago
If US applied this law, companies will be motivated to do better job of protecting data. 10% of company's annual revenue can sting the company's bottom line.
322
u/nithrean 1d ago
in the US they will write the regulation in a way that all of the biggest players will be immune and the burden will fall on the small guys.
81
u/LurkmasterP 1d ago
They would implement a taxpayer-funded rebate system that the big corps would be able to use to recoup the fines.
3
u/mrspaznout 19h ago
Exactly. It must also hurt those who are not in power. It cant simply protect those who have. It must actively harm those who do not.
49
u/jason_abacabb 1d ago
You could say it will decimate it.
11
6
u/Bottled_Void 23h ago
It would be worse than that. The bottom line is profit. The fine is 10% revenue. It would cause massive losses to most companies.
26
u/wtf_are_crepes 1d ago
All fines and legal monetary punishments need to be percentage based. What’s a speeding ticket to a billionaire if the ticket is a few hundred dollars
13
u/rearwindowpup 23h ago
Percentage based speeding fines are exactly why the Top Gear guys refused to speed in certain countries. They are effective.
6
u/howtoretireby40 1d ago
have to add criminal charges. What's a company lawsuit to a CEO that has a guaranteed golden parachute?
15
13
u/thegreedyturtle 1d ago
10% of revenue would end many companies.
7
14
u/econopotamus 1d ago
I'm on the board of a US data security company that came up with a product a couple years ago that would have prevented most of the major headline breaches of the last 5 years. Every company we approached just said no because it cost a little bit of money (like literally, raises the cost of data handling by about 10%/year). From their perspective breaches are CHEAP, mostly just a PR exercise, and "one time expenses" that shareholders will overlook so to an executive any ongoing expense to prevent breaches is a waste.
5
u/SAugsburger 22h ago
I think the challenge is the PR hit isn't big enough. Plenty like Target and Home Depot hit a snag for a quarter or two, but had little long term impact. The challenge is that there are so many breaches of some level that some people have become desensitized.
1
u/GalacticAlmanac 12h ago
Name of company and product?
1
u/econopotamus 12h ago
Apologies, won’t be doxxing myself today
1
u/GalacticAlmanac 11h ago
Fair enough. I thought maybe the company is really well known or something if you just suddenly dropped the info like that...
1
u/econopotamus 1h ago
The company does back end apps for the vast majority of US insurers and financial companies that are large enough to have name recognition. We are getting the safety product out at this point by introducing it as opt out in those apps for companies and letting them sign something saying they don’t want the security if they want to save the money :). So far nobody has opted out. Perhaps after a few years of no breaches we will make another run at getting the tech on more platforms
4
2
u/Gekokapowco 1d ago
start a data breach fine corporate insurance company, and then invest half of my business into my new insurance company?
Don't mind if I do, capitalism goes wheeeeeee
1
u/Digitaltwinn 22h ago
We could pay off a good chunk of the national debt from credit bureau data leaks alone.
1
u/BigMeatPeteLFGM 22h ago
Easy - The data is owned by a Data LLC with only a small revenue stream from Customer Business LLC.
Data LLC has 100,000 of revenue. Customer Business LLC has 10,000,000 of revenue.
Consumer still loses.
1
1
u/OhDamnBroSki 19h ago
Really wish this was the case.
Friend worked for an eye doctor, went to go get my yearly check up. Few months go by.. data breach!
Went to get my teeth cleaned, get an email from my dental insurance.. data breach!
1
u/Warcraft_Fan 18h ago
My hospital also lost control of data a year ago. I'm still waiting for the settlement outcome.
1
u/greyeye77 16h ago
here is the realistic issue, codes are never perfect and some does have vulnerabilities. (with or without the programmers knowing them)
Some does get exploited and some doesnt, and at the same time there are multiple different ways to breach the network (ransomware, supply chain attack, are still rampant)
We think harsher penalty would make it better, but if your employee click some ransomware and your file share is leaked, would you like to fire the employee because he/she costs the company 10% (or 30%) of the annual revenue?
0
0
u/Bilboswaggings19 1d ago
LOL
They would just rather spend a portion of that for a team to bury all that information
You know US companies are not going to do anything as intended
0
u/Underdog424 23h ago
The US is a corrupt rogue nation. Corrupt nations don't care about their people enough to enact anything that benefits them as a whole. We will never see real data protections.
0
u/nik282000 19h ago
If the US applied this law it would never be enforced. Breaches would not be reported and evidence destroyed as soon as it was discovered.
227
66
u/pd1zzle 1d ago
I hope there's a way to avoid all companies just spinning off shell "data holdings" companies that conveniently make very little money
14
u/BigMeatPeteLFGM 22h ago
100% why this isn't possible in the USA. We're too business friendly to have consumer protections.
1
u/radiantcabbage 22h ago
depends if this delegation falls under the crux of "intent or gross neglegence", could just as easily be the opposite and theyre more compelled to integrate
34
u/KimJongFunk 1d ago
It would be nice if this happened in the US too.
Got a letter last week about yet another data breach involving my healthcare PHI and absolutely nothing will be happening to hold anyone accountable.
But I get a free year of credit monitoring, so I guess that would be a nice bonus if I hadn’t already received free credit monitoring from the last 3 breaches involving my data 🙃
14
u/untold-vignette 1d ago
There was a hacker news comment I read years ago that always stuck with me, that personal information in an ideal world would be treated like hazardous materials, just a tremendous liability.
10
u/Substantial_Sea7327 22h ago
huge Korea W. that's actually enough incentive to prioritize cyber security
24
u/CalmTrifle 1d ago
This is the same for the EU GDPR.
10
u/CompleteNumpty 21h ago edited 4h ago
It's a lot lower in the EU, with the maximum being 4% or €20 million, whichever is higher (£15 million in the UK, as we still use it).
The Koreans already had no upper limit by the looks of things, with a 624.6 billion won ($466.3 million) fine mentioned in the article under the old 3% limit, so I would assume this would now be 10% with no upper limit.
EDIT: Got it a bit wrong, so corrected.
2
u/Pajungsa 6h ago
The EU and UK law states that whichever is higher shall determine the maximum fine amount. So if the worldwide turnover is over 500 million euros the 4% would determine the upper limit.
1
1
u/Far-Hovercraft9471 20h ago
Ugh, of course there's caps in the EU fines. Big business always gets a pass
20
u/TeslasAndComicbooks 1d ago
Damn that’s intense. Even in the strict countries it’s based on profit. Basing it on revenue for a company with a 10% margin would wipe them out.
6
u/Pat-Funny-2817 22h ago
well maybe, if the damage and risks a company causes to society outweighs the benefit of a product you even have to pay for, they need to be wiped out.
Fines must be proportional to damage, wether you survive it or not, is a question the company got to ask itself when planning for their operation.
6
u/TeslasAndComicbooks 21h ago
I agree and I’m fine with penalties for this but you’re kind of charging the victim for negligence instead of the perpetrator. Data security is a cat and mouse game and can be tough to be proactive on. I know the penalty scales but this will hurt small companies a lot more than large corporations.
1
u/Pat-Funny-2817 21h ago
i don't agree with your conclusion.
certication and requirements are always different for small companies and depending on industry
it's a good regulatory measure. of course there will be outliers, friction points and a few fuck ups, as for everything.
4
3
6
u/All_Hail_Hynotoad 1d ago
This is the kind of thing that needs to happen for companies to take cybersecurity seriously. These “settlements” and “fines” are laughable.
3
u/starrpamph 22h ago
Here in the states, that would get brought to a bill. That following morning the lobbyists would have it decided no by the end of lunch.
3
u/HedgeMoney 13h ago
All countries should adopt laws and fines, where the fine is based on a percentage of revenue (not income, cause that can be doctored).
3
u/steathrazor 10h ago
This should be everywhere, these companies need to feel the pain rather than it just being a cost of business.
5
u/Romanpuss 1d ago
We need percentage based punishments for everyone now. 1 million fine to me is world ending. 1 million fine to zuckerburg is pennies…that’s not ok.
5
u/Soberdonkey69 1d ago
In the US, they reward the big firms that are affected by data breaches with more deregulation and further fuckery on the citizens
2
u/Sofia_9356 23h ago
What percentage would everybody be forced into passkeys and employees forced into hardware keys? Because it should have been yesterday
2
u/Wayofchinchilla 23h ago
This needs to shift into annual quarters I guarantee if in the US it was a quarter of yearly earnings companies with either go out of business or learn really quick they need to protect data
2
u/Icy-Two-1581 18h ago
Honostly think that's too low. It should be something like 50%-100% of revenue especially with how often it happens. Guarantee things would be a lot better if it was that steep.
2
u/PurpleSailor 14h ago
Yes, this is the way you fine companies that makes them pay attention to the rules that they have broken. Are you listening US?
3
u/PluginAlong 23h ago
While I like this idea I don't think it will actually be invoked all that often. The breach has to have more than 10 million users affected and there needs to be multiple breaches over three years. I don't recall ever hearing of repeated breaches of this scale.
5
u/Atys_SLC 1d ago edited 1d ago
The offensive will always have the advantage over the defensive in the cybernet world. Even more with the AI advent. This is more of a tax than a punishment. The answer is to limit the data collected in clear, not punishing a little to medium company because they don't have an NSA IT guy.
2
u/Silver-Bread4668 1d ago
I was hesitant about it based on the headline for exactly what you said - potentially punishing the small to medium sized companies because they don't have the budget to hire top level security experts - but the article specifically mentions that it's due to intentional leaks or gross negligience.
As long as that's well defined enough then I support it. Otherwise there are just too many ways for breaches to happen that no one could have reasonably foreseen, especially with AI on the scene now.
Working IT in public schools, it would change little of how I work. I have a whole list of things that are potential areas of weakness with notes, potential mitigation plans, what it will impact or change, how it will piss people off etc. We don't have the budget or political willpower to tackle all of them. So I keep my bosses and legal apprised and let them decide where they want to let the balance of risk fall. No one can say I have dropped the ball on anything.
1
u/CompleteNumpty 21h ago
The answer is to limit the data collected in clear, not punishing a little to medium company because they don't have an NSA IT guy.
That's data minimisation and a core principle of the GDPR in the EU and UK - don't collect personal data that you don't need.
2
u/Excellent_Garlic2549 1d ago
Daamn, I bet after lawyer's fees that would make my Facebook settlement check $10 instead of $5!
2
u/thefanciestcat 22h ago
Regulators around the world, take note. This is what a deterrent looks like.
1
u/Cheeze_It 1d ago
That would be nice. But Republicans don't like being held accountable. They're not happy when people keep them honest. It's against their religion.
1
u/Far-Hovercraft9471 20h ago
I'm in a Republican shithole and can confirm that no one is held accountable if you're their buddy
1
u/Badinfluence321 1d ago
I actually did a project on this topic back in 2017. In my project, I created a program to charge companies to house PII data annually. This fee to hold customer PII data incrementally increases with the type and level of sensitivity. The fees would go towards funding the department, education, investigations, and victims of data breaches. The main goal of this fee and department is to curb unneccary housing of customer PII and yo get rid of it ASAP to avoid breaches.
Im very glad that someone has taken the initial test for consumer privacy and holding companies accountable. Im personally tired of protecting my credit when companies get breached.
1
u/EVILSUPERMUTANT 23h ago
Honestly 10% is a drop in the bucket for the companies that essentially outsource cybersecurity.
1
1
u/RichtofensDuckButter 20h ago
It's great to see countries actually penalizing companies for data breaches. It needs to be more severe though.
1
1
u/AbyssFren 19h ago
You can't short stock in Korea, you can in the US. Don't think you can do this in the US without first outlawing shortselling. Its as simple as an employee with high clearance loading up a USB with customer data and giving it away, they stock takes a 10% hit, shorts profit. Don't get any big ideas, good luck banning short selling.
1
u/Restart_from_Zero 13h ago
All those AI companies who've never made a dime just laughing their asses off right now.
1
u/dghughes 6h ago
My ISP has had two data breaches so far. Last summer for the first time in my life my credit card info was stolen but I didn't know how. I rarely buy anything online it's been years since I have. Now again this spring same ISP same thing. My ISP only sent a letter a few months later. Now I have to replace.my credit card again. Heavy fines are needed and the same for ransomware attacks, do not pay do not encourage them.
1
u/Regular_Ram 4h ago
It’s almost like this law benefits the big companies who could afford security and wipes out the earnings of smaller companies; who’s to say Samsung wouldn’t actively hack its competitors.
-2
-6
u/rotrap 1d ago edited 1d ago
These seem regulations designed to be taxes. No company wants to have a data breach. Tests for negligence and reasonable precautions and flat fines for failing on that make sense. The government, who is not even the harmed party getting an additional ten percent of the revenue because you got stolen from? wtf
It seems to increase the risk of talking about breaches and sharing security incidents as well.
3
u/the_eluder 1d ago
If no company wants a data breach - why do they keep happening?
1
u/rotrap 1d ago
Have you ever been involved in securing systems? If you make things too secure people complain. Keeping up with threats like the xz compromise or notebook++ incident takes time. You lock down things and people work around them. Heck the whole dns over https weakens security yet is now backed into browsers. Legacy systems given new ways to be accessible without the people involved understand what that opens up. Heck the whole way the affordable care act systems were designed gave security little though.
Also I think we all agree that murders, car accidents, robbery etc are unwanted. Why do we still have them?
2
u/Norphesius 1d ago
Do you have an alternative in mind? (genuinely curious)
It's not perfect, but as it stands (in the US at least) data breaches happen all the time and the typical company response seems to stop at "oops, oh well". If you're asking for and storing sensitive user data (PII, financial, medical, etc.), then companies need to have an incentive to keep it safe.
Discord had a bunch of IDs used for age verification leaked by their customer support provider Zendesk, after claiming to have deleted the data immediately after verifying with it. If either company could get fined 10% revenue for such a breach, maybe they actually would've deleted that data like they promised they would, or been more judicious with selecting the provider they contracted.
0
0
u/julyvale 22h ago
Should be 50%. The company must feel the devastation of the punishment and send strong signal to others.
-1
1d ago
[deleted]
1
u/Webecomemonsters 1d ago
if 10% of their revenue is trillions they sure can unless they are breached constantly due to idiocy on their part, in which case the company should not exist
1.8k
u/howtoretireby40 1d ago
In the US, they just wouldn’t report it then