[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$futS-v7I04_vrZz96E9epU-lnQeMfuRwhdhxbEmd3wrs":3},{"article":4,"iocs":50},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":27,"category":28,"article_tags":32},"456c9d48-365e-41dc-9ff5-0452256c81ec","SG Nürnberg - S 5 SF 65\u002F24 DS","sg-nurnberg-s-5-sf-65-24-ds-0a8cb3","← Older revision Revision as of 08:12, 22 July 2026 Line 90: Line 90: }} }} A court dismissed a data subject's €3,000 damages claim against a health insurer and its processor, holding that a zero-day hack did not violate security requirements under [[Article 32 GDPR]]. A court dismissed a data subject's €3,000 damages claim against a health insurer and its processor, holding that a zero-day vulnerability, which led to a data breach, did not violate security requirements under [[Article 32 GDPR]]. == English Summary == == English Summary ==","A German court has ruled that a zero-day vulnerability exploited in a data breach did not violate GDPR security requirements. The case involved a health insurer and its IT processor, who were targeted by the Clop ransomware group via a MOVEit Transfer zero-day vulnerability. Despite the data breach, the court found that the processor had not violated Article 32 GDPR, leading to the dismissal of a €3,000 damages claim.","German court dismisses GDPR damages claim over zero-day hack of health insurer.","Help SG Nürnberg - S 5 SF 65\u002F24 DS: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 09:02, 17 July 2026 view sourceAv (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators87 editsmTag: Visual edit← Older edit Latest revision as of 08:12, 22 July 2026 view source Av (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators87 editsmTag: Visual edit Line 90: Line 90: }}}} A court dismissed a data subject's €3,000 damages claim against a health insurer and its processor, holding that a zero-day hack did not violate security requirements under [[Article 32 GDPR]].A court dismissed a data subject's €3,000 damages claim against a health insurer and its processor, holding that a zero-day vulnerability, which led to a data breach, did not violate security requirements under [[Article 32 GDPR]]. == English Summary ==== English Summary == Latest revision as of 08:12, 22 July 2026 SG Nürnberg - S 5 SF 65\u002F24 DS Court: SG Nürnberg (Germany) Jurisdiction: Germany Relevant Law: Article 4(7) GDPR Article 4(8) GDPR Article 4(10) GDPR Article 4(12) GDPR Article 5(1)(f) GDPR Article 24(1) GDPR Article 24(1) GDPR Article 26 GDPR Article 28 GDPR Article 32(1) GDPR Article 32(2) GDPR Article 82(1) GDPR Article 82(2) GDPR Article 85 GDPR § 183 SGG§ 81b(1) SGB X Decided: 10.06.2026 Published: 18.06.2026 Parties: National Case Number\u002FName: S 5 SF 65\u002F24 DS European Case Law Identifier: Appeal from: Appeal to: Unknown Original Language(s): German Original Source: sozialgerichtsbarkeit.de (in German) Initial Contributor: n\u002Fa A court dismissed a data subject's €3,000 damages claim against a health insurer and its processor, holding that a zero-day vulnerability, which led to a data breach, did not violate security requirements under Article 32 GDPR. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts The data subject (a child born in 2018), represented by her parents, was insured with the controller (a statutory health insurance provider) and participated in its digital bonus programme. The bonus programme was managed via an app. To handle the information technology operations of this programme, the controller hired the processor (an IT service provider), establishing a data processing agreement under Article 28 GDPR alongside specific information security guidelines. To provide these services, the processor utilised \"MOVEit Transfer,\" a market-leading file transfer software developed by Progress Software Corp. On 31 May 2023, the software developer publicly announced a critical, previously unknown \"zero-day\" vulnerability in the software (later assigned CVE-2023-34362). At that exact moment, no security patch was available. On the very same day, 31 May 2023, the processor – alongside thousands of other companies worldwide – became the victim of a global cyberattack carried out by the hacker group \"Clop.\" The hackers exploited this zero-day vulnerability to install a \"web-shell\" backdoor (typically named human2.aspx), bypassing authentication to exfiltrate database records. The compromised data included the data subject's first and last name, health insurance number, bonus points balance, and a bank account number (IBAN) belonging to her mother. No medical, health, or social security data was exfiltrated. On 1 June 2023, the developer released a security patch, which the processor installed immediately. On 2 June 2023, the German Federal Office for Information Security (BSI) issued a formal IT security warning (No. 2023-240133-1100, Version 1.1). The BSI classified the IT threat level as \"3 \u002F Orange\" (business-critical), confirming active exploitation with data exfiltration. The BSI recommended immediately blocking all HTTP and HTTPS traffic to MOVEit environments, checking for specific Indicators of Compromise (IoCs) in the web server directories, and applying the newly released patch before reconnecting systems to the network. On 16 June 2023, the processor informed the controller about the incident. On 17 June 2023, the controller issued a public press release confirming that its external service provider for the bonus programme had been targeted on 31 May 2023. The release stated that the security vulnerability had been closed, that there was never any connection to the controller's internal IT systems, and that relevant supervisory authorities had been notified. The controller subsequently notified the data subject's parents. On 27 March 2024, the data subject, via legal counsel, sent a formal warning letter to the controller demanding an injunction, a declaration of liability for all potential future damages, and non-material damages of at least €3,000. Following the controller's refusal, the data subject filed a lawsuit with the Nuremberg Social Court (Sozialgericht Nürnberg), later expanding the claim to the processor as a joint defendant. Holding The Court dismissed the lawsuit as partly inadmissible and otherwise unfounded, establishing the following legal principles: First, the Court held that a successful third-party cyberattack does not establish an irrebuttable presumption that a controller or processor failed to implement appropriate security measures under Article 32(1) GDPR and Article 5(1)(f) GDPR. To escape liability under Article 82(3) GDPR, an operator must prove they implemented robust baseline security controls (such as multi-factor authentication, encryption, and lockout policies) and applied a security patch immediately upon its release by the vendor, even if this occurred before formal alerts were issued by national IT security authorities. Second, the Court held that a claim for non-material damages under Article 82(1) GDPR based on the fear or distress of future data misuse cannot be established if the data subject is a minor who has no subjective knowledge or cognitive awareness of the data breach. Furthermore, if the compromised financial data (such as an IBAN) does not belong to the data subject personally, there is no direct risk of financial harm to them, rendering the alleged fear of financial damage unfounded. Third, the Court held that an injunction claim is inadmissible due to a lack of specificity if it merely demands that a controller stop making personal data accessible to third parties without implementing \"state-of-the-art\" security measures, without specifying the concrete technical or organisational measures the controller is required to take. Fourth, the Court held that a declaratory claim for potential future material damages is inadmissible under national procedural law (§ 55(1) SGG) if there is no realistic probability of future financial harm, particularly because the compromised bank account belonged to a third party (the mother) and the software vulnerability was immediately patched. Comment This judgment is legally and technically flawed because the Court fundamentally misapplied the concept of the \"state of the art\" under Article 32(1) of the General Data Protection Regulation. By treating a classic SQL injection vulnerability as an unavoidable, force-majeure \"zero-day\" event, the Court collapsed the strict statutory requirement of the state of the art into a much weaker standard of mere \"common market practice.\" Under Article 32(1) GDPR, both controllers and processors are legally bound to ensure a level of security appropriate to the risk, explicitly taking into account the state of the art. As in commentary (e.g. Hansen, in: Simitis\u002FHornung\u002FSpiecker gen. Döhmann, Datenschutzrecht, 2nd edition 2025, Article 32, Paragraphs 15–16), while Article 32 does not directly bind software manufacturers, it creates a strict indirect obligation for controllers and processors. They must carefully select, evaluate, and deploy only those products and services that actively enable them to fulfill their data prote","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=SG_N%C3%BCrnberg_-_S_5_SF_65\u002F24_DS&diff=52437&oldid=52339","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F4\u002F4c\u002FCourts_logo1.png","2026-07-22T08:12:38+00:00","2026-07-22T10:00:21.282064+00:00",7,[18,21,24],{"name":19,"type":20},"Clop","threat_actor",{"name":22,"type":23},"MOVEit Transfer","product",{"name":25,"type":26},"Progress Software Corp","vendor","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":27,"icon":29,"name":30,"slug":31},null,"Policy","policy",[33,38,43,45],{"category":34},{"id":35,"icon":29,"name":36,"slug":37},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":39},{"id":40,"icon":29,"name":41,"slug":42},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":44},{"id":27,"icon":29,"name":30,"slug":31},{"category":46},{"id":47,"icon":29,"name":48,"slug":49},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",[51,55],{"type":52,"value":53,"context":54},"cve","CVE-2023-34362","Zero-day vulnerability in MOVEit Transfer exploited by Clop group.",{"type":56,"value":57,"context":58},"malware","human2.aspx","Web-shell backdoor used by attackers."]