The cyberattack on the consulting firm Ayesa by the Black Basta group highlights the vulnerability of corporate data and the uncertainty surrounding its actual exposure. Although a threat was made to leak terabytes of sensitive information, including employees’ personal identifiers, the download links are not working. This blockage has sparked debate among experts: some suggest that the company itself launched a denial-of-service attack to prevent the leak, while others argue that the company paid the ransom so that the cybercriminal would remove access to the files. The relevance in the realm of open data and transparency lies in the critical nature of the compromised information, which affects essential infrastructure and employees. The fact that the data is hidden or inaccessible does not guarantee its security, as cybercriminals often retain copies for future sales or selective leaks. This situation underscores the fragility of information management in large companies that interact with public administration, where the confidentiality of workers’ data and projects is vital to the integrity of public services. Furthermore, the incident reveals tensions between the company and trade unions regarding the right to information and data protection. The lack of transparency about the exact scope of the theft generates distrust, especially when there are suspicions that data related to social security contributions or citizen information may be involved. This case illustrates the critical importance of data governance and the need for clear frameworks that balance cybersecurity with accountability, ensuring that the protection of personal data is not compromised by corporate opacity.

Source:
Published on 2024-05-27