YTO Express Employees Leak User Data to Criminal Groups

BY  
Seneca ESG  
- November 25, 2020

YTO Express Group , admitted in a statement that its five employees leased their internal accounts to criminal groups for profit, leaking some 400,000 pieces of users’ personal information, as reported by Beijing News on November 16, 2020. According to police based in Hebei province, three suspects in the criminal groups were arrested in September this year, but the rest remain on the run. YTO Express’ employees had leased their accounts for RMB500 per day for each account. The suspects reportedly logged into the system to steal user data and then sold it to domestic and overseas buyers for RMB1 per piece of information. The leaked information included users’ names, ID numbers, phone numbers and addresses. YTO Express apologized to the public on November 17, 2020 and said it would conduct real-time monitoring of internal accounts to discover illegal activities.

This is not the first data breach case for YTO Express. In 2013, the company leaked the information of more than one million customers. In the aftermath, YTO Express stated it had strengthened its internal management to prevent such incidents from happening again.  In its 2019 ESG report released on July this year, YTO Express claims to be committed to ensuring security and privacy for its customer data. But in action, it failed to fulfill this commitment. Companies in the same industry including STO Express, Deppon Logistics, Express Mail Service (EMS), and Yunda Express have also been involved in incidents related to selling user data online. Express users’ details are sold online with each piece of user data ranging from RMB0.8 to RMB10. In August 2019, police found that several employees of Deppon Logistics stole more than 500,000 datapoints of users information and provided them to an e-commerce company. In 2018, police found a criminal group installing malware programs on Cainiao Global’s couriers’ package scanners. The logistics platform is under Alibaba Group, and 10 million pieces of user information had been stolen.

China’s Personal Data Protection Law is looking to address consumer data privacy. The draft law was open for public comments between October 21, 2020 to November 19, 2020. Should it receive approval, it will be China’s first comprehensive law on protection of personal data. This will no doubt impact logistics companies and change the way many Chinese companies handle data security and customer privacy.

Reference

https://news.cgtn.com/news/2020-11-18/YTO-Express-staff-rent-accounts-to-criminals-rip-off-waybill-infoVwijfCSF8s/index.html

https://www.caixinglobal.com/2020-11-18/yto-express-workers-lease-accounts-to-criminals-compromising-400000-users-101629480.html

https://baijiahao.baidu.com/s?id=1683567107315093852&wfr=spider&for=pc

https://baijiahao.baidu.com/s?id=1683687750573206317&wfr=spider&for=pc

https://export.shobserver.com/baijiahao/html/312905.html

http://hwgw-manage.oss-cn-hongkong.aliyuncs.com/20200727/e958e7f3c32b45daa0ebf1c7bcdc4e33.PDF

https://www.sohu.com/a/335877908_783645

https://baijiahao.baidu.com/s?id=1683723890733989746&wfr=spider&for=pc

https://baijiahao.baidu.com/s?id=1683732142776470547&wfr=spider&for=pc

https://baijiahao.baidu.com/s?id=1612241894219862508&wfr=spider&for=pc

立即開始使用 Seneca ESG 工具包

監控投資組合 ESG 表現,自建 ESG 框架,讓商業決策更精準。

Toolkit

Seneca ESG

有興趣?立即聯絡我們

請填寫右側表單,或直接郵件聯絡我們:

sales@senecaesg.com

新加坡辦公室

7 Straits View, Marina One East Tower, #05-01, Singapore 018936

+(65) 6223 8888

巴塞隆拿辦公室

Carrer de la Tapineria, 10

Ciutat Vella, 08002, Barcelona, Spain

+34 612 22 79 06

台北辦公室

台灣台北市大安區敦化南路二段77號7樓,106414

(+886) 02 2706 2108

利馬辦公室

Av. Santo Toribio 143,

San Isidro, Lima, Peru, 15073

(+51) 951 722 377