"Due to inadequate log data, only an approximate idea of the numbers of leaked files can be formed. The files were downloaded to the attacker's server using a FileZilla’s encrypted FTP. The total volume of traffic could be determined from firewall logs, but due to encryption, file names or other details could not be established."
"Based on the total data volume (two terabytes) the attacker downloaded in proportion to the total number of files on the network drive (6.73 terabytes), it can be estimated that 30% of the files were copied. In other words, the attacker gained access to around 1.3 million files, of which around 750,000 were documents (Office and PDF files)."
The excellent post-mortem of the City of Helsinki data breach (summary at www.turvallisuustutkinta.fi/en/index/tutkintaselostu... link to the full report at the […]
[Original post on federate.social]