<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Arlo personal data breach in Arlo Secure</title>
    <link>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451336#M13323</link>
    <description>&lt;P&gt;Indeed. It's alarmist.&lt;/P&gt;</description>
    <pubDate>Fri, 23 May 2025 05:56:48 GMT</pubDate>
    <dc:creator>Edinburgh_lad1</dc:creator>
    <dc:date>2025-05-23T05:56:48Z</dc:date>
    <item>
      <title>Arlo personal data breach</title>
      <link>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451324#M13320</link>
      <description>&lt;P&gt;So, we got this email saying that there's been a personal data breach at Arlo. I found the email vague. Was there a personal data breach or not. Was any of my data leaked? If there was no evidence of unauthorised access, as the email claims, why is this classified as a&amp;nbsp; personal data breach? The word 'breach' suggests to me that it was indeed breaking/violation/opening. The email also says that as a user, I'm not "adversely" affected by this data breach.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 23:30:09 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451324#M13320</guid>
      <dc:creator>Edinburgh_lad1</dc:creator>
      <dc:date>2025-05-22T23:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: Arlo personal data breach</title>
      <link>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451331#M13322</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.arlo.com/t5/user/viewprofilepage/user-id/830274"&gt;@Edinburgh_lad1&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;So, we got this email saying that there's been a personal data breach at Arlo. I found the email vague. Was there a personal data breach or not. Was any of my data leaked? If there was no evidence of unauthorised access, as the email claims, why is this classified as a&amp;nbsp; personal data breach? The word 'breach' suggests to me that it was indeed breaking/violation/opening. The email also says that as a user, I'm not "adversely" affected by this data breach.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;a href="https://community.arlo.com/t5/user/viewprofilepage/user-id/145791"&gt;@ittroll&lt;/a&gt;&amp;nbsp;posted the text here:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;A href="https://community.arlo.com/t5/Arlo-Secure/When-are-we-getting-custom-modes-back/m-p/2451014#M13290" target="_blank"&gt;https://community.arlo.com/t5/Arlo-Secure/When-are-we-getting-custom-modes-back/m-p/2451014#M13290&lt;/A&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;My assessment of what it means follows his post.&amp;nbsp; Based on the wording in his post, I don't believe anything was actually leaked.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The "security incident" was the login outage back in 6-7 May&amp;nbsp;&lt;SPAN&gt;which resulted in loss of &lt;/SPAN&gt;&lt;U style="font-family: inherit;"&gt;&lt;EM&gt;access&lt;/EM&gt; &lt;/U&gt;&lt;SPAN&gt;to your personal information.&amp;nbsp; &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;A security incident that results in loss of access&amp;nbsp; is included in the GPDR definition of "personal data breach".&amp;nbsp; &lt;/SPAN&gt;&lt;SPAN&gt;The GPDR requires Arlo to notifiy you of such incidents, and I believe the language used in their communication was to make it clear that it was the notification that the law requires.&amp;nbsp; They acknowledge (and apologize for) the loss of access, and go on to say that - despite the "data breach" language - there was no compromise of your data.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Calling the login outage a "security incident" is interesting, as it suggests that the service was taken down by a cyberattack.&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 May 2025 01:17:28 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451331#M13322</guid>
      <dc:creator>StephenB</dc:creator>
      <dc:date>2025-05-23T01:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: Arlo personal data breach</title>
      <link>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451336#M13323</link>
      <description>&lt;P&gt;Indeed. It's alarmist.&lt;/P&gt;</description>
      <pubDate>Fri, 23 May 2025 05:56:48 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451336#M13323</guid>
      <dc:creator>Edinburgh_lad1</dc:creator>
      <dc:date>2025-05-23T05:56:48Z</dc:date>
    </item>
    <item>
      <title>Re: Arlo personal data breach</title>
      <link>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451348#M13325</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.arlo.com/t5/user/viewprofilepage/user-id/830274"&gt;@Edinburgh_lad1&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Indeed. It's alarmist.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;If it sounds alarmist to you, then I think that is really on the GPDR, not Arlo.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The GPDR requires notification whenever a security incident results in a personal data breach (as defined in the law itself, not what you might think a "security incident" or "personal data breach" is).&amp;nbsp; The language Arlo chose ensured that there is no doubt that they are in full compliance with the GPDR - particularly important for a US company operating in Europe.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;That said, I suspect the "loss of access" in the GPDR definition is intended to cover ransomware attacks where the data is encrypted by the attacker, but not compromised (since the attacker never gets it).&amp;nbsp; Even if the company manages to decrypt it (for instance by paying the ransom), they are still required to notifiy you of the attack.&amp;nbsp; But there are other possibilities (like a DDOS attack) that could also be classified as "security incidents".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 May 2025 11:59:20 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451348#M13325</guid>
      <dc:creator>StephenB</dc:creator>
      <dc:date>2025-05-23T11:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: Arlo personal data breach</title>
      <link>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451505#M13334</link>
      <description>&lt;P&gt;On May 19th, some users received an email as mandated by EU’s GDPR requirements that may have caused some confusion. To help clarify, there was a short outage where some users temporarily were unable to log in but no data was compromised and there was no unauthorized access to data. Your account and information remain secure.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Arlo Team&lt;/P&gt;</description>
      <pubDate>Sun, 25 May 2025 17:36:49 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451505#M13334</guid>
      <dc:creator>JamesC</dc:creator>
      <dc:date>2025-05-25T17:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: Arlo personal data breach</title>
      <link>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451585#M13342</link>
      <description>&lt;P&gt;Because of this incident, I'm actually thinking about moving my cameras out of the Arlo cloud.&amp;nbsp;Arlo has been steadily increasing the subscription price while not really improving their service quality, customer service or even the overall cloud security; hence the breach/server outage. All the reasons given in the following video, to cancel Arlo's subscription plan and switch to a basestation/smarthub, are spot on, in my opinion:&amp;nbsp;&lt;A href="https://www.youtube.com/watch?v=dZir_02wFXw" target="_blank"&gt;YouTube Video&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 May 2025 20:23:13 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451585#M13342</guid>
      <dc:creator>rsmith6121</dc:creator>
      <dc:date>2025-05-27T20:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Arlo personal data breach</title>
      <link>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451595#M13344</link>
      <description>&lt;P&gt;Unfortunately, I have to agree with you.&lt;/P&gt;</description>
      <pubDate>Mon, 26 May 2025 17:52:04 GMT</pubDate>
      <guid>https://community.arlo.com/t5/Arlo-Secure/Arlo-personal-data-breach/m-p/2451595#M13344</guid>
      <dc:creator>Edinburgh_lad1</dc:creator>
      <dc:date>2025-05-26T17:52:04Z</dc:date>
    </item>
  </channel>
</rss>

