Tag Archive for: Poll

Smartmatic man, hacker behind poll data breach


The National Privacy Commission (NPC) has recommended data privacy charges against an employee of election technology firm Smartmatic and a suspected hacker for the “breach” of election data months before the May polls last year.

But the commission cleared Smartmatic and the Commission on Elections (Comelec) of liability for concealing the data leak, ruling that they were under no obligation to report the matter to the NPC.

In a decision dated Sept. 22 but released only this week, the NPC accepted Smartmatic worker Ricardo Argana’s confession to the National Bureau of Investigation that he gave a certain Winston Steward access to the company’s servers through his computer in the Comelec office.

He said he did so in exchange for an offer of P50,000 to P300,000 in cash.

In his sworn statement to the NBI dated Feb. 2, 2022, Argana said he worked for Smartmatic from August 2021 to January 2022 as a quality assurance tester in the Comelec office.

He said he received a private message from Steward on Facebook Messenger offering him money in exchange for access to his computer.

“When he went to the Comelec office for work, he gave access to his computer using AnyDesk app through the internet while connected to Smartmatic servers in the last week of December 2021,” the NPC said.

But Steward did not fulfill his end of the deal, only paying Argana with online computer lessons such as for CobaltStrike and Lateral Movement, the NPC said.

Argana said he had connived with the hackers to earn money as he had a two-month-old baby.

Other than Argana and Steward, NPC did not name other persons who should be prosecuted for unauthorized access or intentional breach under Section 29 of the Data Privacy Act of 2012.

Overseas voters list

The breach may have led to external parties obtaining illegal access to data from the Comelec’s site survey forms and, possibly, its overseas absentee voters list, according to the NPC.

“These individuals committed unauthorized access or intentional breach when they broke into Smartmatic’s servers that store personal or sensitive personal information,” the NPC said in the decision signed by Deputy Privacy Commissioner Leandro Aguirre and Privacy…

Source…