An example of an organization that has been a recent victim of information theft is
Alibaba Group Holding Ltd., a technology company based in China. The company suffered
leakage of sensitive data from their customers in November 2019. This malicious activity
took place for several months before being discovered and shut down. The attack was an
outside activity because it was conducted by a developer who was working with one of
Alibaba's affiliate marketers. The developer partnered with his employee to collect
sensitive data of Alibaba's customers without permission. Luckily the attackers did not
sell the stolen data, as this could have heightened the situation. Instead, they stored the
information for themselves. However, they were still charged for unlawful retrieval of
sensitive information from Alibaba and were sentenced to a prison term of three years
each. Investigations conducted after the illegal scraping discovered that the developer
had extracted over one billion pieces of data from Alibaba's users (Hill & Swinhoe, 2021).
In sum, the incident described shows how companies can be attacked and their
information systems jeopardized irrespective of their size or popularity.
Alibaba responded effectively by taking countermeasures to prevent such an attack from