cciia.org.cn 2025-1-24 10:10:18 正義網
企(qi)(qi)業(ye)數據(ju)(ju)日益成(cheng)為現代企(qi)(qi)業(ye)不可或缺(que)的發(fa)(fa)(fa)展資(zi)源(yuan)。檢察(cha)(cha)辦案發(fa)(fa)(fa)現,近年來,不法分子侵害企(qi)(qi)業(ye)數據(ju)(ju)安全案件(jian)時有發(fa)(fa)(fa)生,損(sun)害企(qi)(qi)業(ye)合法權益,影響企(qi)(qi)業(ye)創新(xin)發(fa)(fa)(fa)展。2024年,全國(guo)檢察(cha)(cha)機關共起訴各類(lei)侵害企(qi)(qi)業(ye)數據(ju)(ju)安全犯罪近千(qian)人,需依法懲治犯罪、促(cu)進源(yuan)頭防(fang)范,助力企(qi)(qi)業(ye)守牢數據(ju)(ju)安全防(fang)線。
一是個別黑客通過技術手段非法獲取企業數據。個別不法(fa)(fa)(fa)(fa)分子通(tong)過(guo)安裝遠程(cheng)操控程(cheng)序(xu)(xu)、非(fei)(fei)法(fa)(fa)(fa)(fa)外掛(gua)程(cheng)序(xu)(xu)等(deng)入(ru)侵企(qi)業(ye)后(hou)臺(tai),非(fei)(fei)法(fa)(fa)(fa)(fa)獲(huo)(huo)(huo)取企(qi)業(ye)數據(ju),損(sun)害企(qi)業(ye)合法(fa)(fa)(fa)(fa)權(quan)益。如,檢察(cha)機關辦(ban)理的上海Z網絡科(ke)技(ji)公司(si)(si)非(fei)(fei)法(fa)(fa)(fa)(fa)獲(huo)(huo)(huo)取計算機信息(xi)系統數據(ju)案中,Z公司(si)(si)為吸引客戶,通(tong)過(guo)爬蟲程(cheng)序(xu)(xu)非(fei)(fei)法(fa)(fa)(fa)(fa)獲(huo)(huo)(huo)取E公司(si)(si)運營的外賣平臺(tai)店鋪、訂單信息(xi)等(deng)數據(ju),造成E公司(si)(si)直(zhi)(zhi)(zhi)接經濟損(sun)失(shi)4萬(wan)余(yu)元。又如,檢察(cha)機關辦(ban)理的劉某(mou)(mou)(mou)某(mou)(mou)(mou)、羅(luo)(luo)某(mou)(mou)(mou)某(mou)(mou)(mou)等(deng)9人(ren)非(fei)(fei)法(fa)(fa)(fa)(fa)獲(huo)(huo)(huo)取計算機信息(xi)系統數據(ju)、提(ti)供侵入(ru)計算機信息(xi)系統程(cheng)序(xu)(xu)案中,羅(luo)(luo)某(mou)(mou)(mou)某(mou)(mou)(mou)等(deng)3人(ren)設計可以入(ru)侵某(mou)(mou)(mou)科(ke)技(ji)公司(si)(si)直(zhi)(zhi)(zhi)播應用(yong)(yong)后(hou)臺(tai)的外掛(gua)程(cheng)序(xu)(xu),向劉某(mou)(mou)(mou)某(mou)(mou)(mou)等(deng)6人(ren)出售,劉某(mou)(mou)(mou)某(mou)(mou)(mou)等(deng)人(ren)利用(yong)(yong)該(gai)(gai)程(cheng)序(xu)(xu)非(fei)(fei)法(fa)(fa)(fa)(fa)獲(huo)(huo)(huo)取該(gai)(gai)公司(si)(si)直(zhi)(zhi)(zhi)播應用(yong)(yong)后(hou)臺(tai)數據(ju),并通(tong)過(guo)自動(dong)進入(ru)直(zhi)(zhi)(zhi)播間(jian)查找紅(hong)包、分享直(zhi)(zhi)(zhi)播間(jian)、助(zhu)力等(deng)方式搶紅(hong)包,非(fei)(fei)法(fa)(fa)(fa)(fa)獲(huo)(huo)(huo)利37萬(wan)余(yu)元。
二是個別企業“內鬼”利用職務之便竊取、泄露數據后非法牟利。一些企業(ye)工(gong)(gong)(gong)作人員(yuan)(yuan)利用(yong)職務(wu)(wu)之便,竊(qie)取、泄露企業(ye)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)并牟取不當利益(yi),成為侵害企業(ye)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)安全的(de)(de)(de)“內(nei)鬼”。如(ru)(ru),檢(jian)(jian)察(cha)機關辦(ban)理的(de)(de)(de)馮某(mou)(mou)(mou)(mou)(mou)(mou)(mou)某(mou)(mou)(mou)(mou)(mou)(mou)(mou)職務(wu)(wu)侵占(zhan)案中(zhong),馮某(mou)(mou)(mou)(mou)(mou)(mou)(mou)某(mou)(mou)(mou)(mou)(mou)(mou)(mou)利用(yong)負責某(mou)(mou)(mou)(mou)(mou)(mou)(mou)科技公(gong)(gong)司(si)(si)(si)電(dian)(dian)商(shang)服(fu)(fu)務(wu)(wu)商(shang)業(ye)務(wu)(wu)的(de)(de)(de)職務(wu)(wu)便利,與外(wai)部(bu)(bu)電(dian)(dian)商(shang)服(fu)(fu)務(wu)(wu)商(shang)相(xiang)互勾結,非法提(ti)供公(gong)(gong)司(si)(si)(si)掌握(wo)的(de)(de)(de)電(dian)(dian)商(shang)ID等數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)信息,外(wai)部(bu)(bu)電(dian)(dian)商(shang)服(fu)(fu)務(wu)(wu)商(shang)虛(xu)構已為上(shang)述電(dian)(dian)商(shang)提(ti)供服(fu)(fu)務(wu)(wu)的(de)(de)(de)事實,套(tao)取公(gong)(gong)司(si)(si)(si)獎勵金(jin)1億余(yu)(yu)元。又如(ru)(ru),檢(jian)(jian)察(cha)機關辦(ban)理的(de)(de)(de)司(si)(si)(si)馬某(mou)(mou)(mou)(mou)(mou)(mou)(mou)某(mou)(mou)(mou)(mou)(mou)(mou)(mou)侵犯商(shang)業(ye)秘(mi)密案中(zhong),某(mou)(mou)(mou)(mou)(mou)(mou)(mou)公(gong)(gong)司(si)(si)(si)網(wang)絡(luo)管(guan)理員(yuan)(yuan)司(si)(si)(si)馬某(mou)(mou)(mou)(mou)(mou)(mou)(mou)某(mou)(mou)(mou)(mou)(mou)(mou)(mou)利用(yong)工(gong)(gong)(gong)作權限(xian),私自將(jiang)公(gong)(gong)司(si)(si)(si)部(bu)(bu)分核心(xin)產品(pin)技術圖紙等電(dian)(dian)子數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)下載到移動硬(ying)盤,再交給其他公(gong)(gong)司(si)(si)(si)利用(yong)這些數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)生(sheng)產同類(lei)產品(pin)并低價占(zhan)領市場,導(dao)致所在公(gong)(gong)司(si)(si)(si)銷售利潤(run)損(sun)失(shi)(shi)500余(yu)(yu)萬元。個別企業(ye)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)監管(guan)措施不到位,部(bu)(bu)分員(yuan)(yuan)工(gong)(gong)(gong)為達牟利或(huo)泄憤目的(de)(de)(de),在職期間違規獲取、存(cun)儲(chu)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju),離(li)職后(hou)借數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)牟利,又或(huo)在被辭退后(hou)利用(yong)原(yuan)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)管(guan)理權限(xian)進入辦(ban)公(gong)(gong)系統破壞(huai)企業(ye)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)庫,從(cong)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)的(de)(de)(de)“守(shou)護者”變成“破壞(huai)者”。如(ru)(ru),檢(jian)(jian)察(cha)機關辦(ban)理的(de)(de)(de)楊(yang)某(mou)(mou)(mou)(mou)(mou)(mou)(mou)某(mou)(mou)(mou)(mou)(mou)(mou)(mou)侵犯商(shang)業(ye)秘(mi)密案中(zhong),某(mou)(mou)(mou)(mou)(mou)(mou)(mou)網(wang)絡(luo)技術公(gong)(gong)司(si)(si)(si)工(gong)(gong)(gong)程(cheng)師楊(yang)某(mou)(mou)(mou)(mou)(mou)(mou)(mou)某(mou)(mou)(mou)(mou)(mou)(mou)(mou)將(jiang)參與研(yan)發(fa)(fa)的(de)(de)(de)一App部(bu)(bu)分模塊源代碼(ma)違規存(cun)儲(chu)于個人電(dian)(dian)腦及云端,跳槽到其他公(gong)(gong)司(si)(si)(si)工(gong)(gong)(gong)作后(hou),將(jiang)上(shang)述代碼(ma)用(yong)于研(yan)發(fa)(fa)同類(lei)App,幫助(zhu)其他公(gong)(gong)司(si)(si)(si)營(ying)收3350余(yu)(yu)萬元,致原(yuan)公(gong)(gong)司(si)(si)(si)損(sun)失(shi)(shi)440余(yu)(yu)萬元。再如(ru)(ru),檢(jian)(jian)察(cha)機關辦(ban)理的(de)(de)(de)呂某(mou)(mou)(mou)(mou)(mou)(mou)(mou)某(mou)(mou)(mou)(mou)(mou)(mou)(mou)非法控制計算機信息系統案中(zhong),呂某(mou)(mou)(mou)(mou)(mou)(mou)(mou)某(mou)(mou)(mou)(mou)(mou)(mou)(mou)離(li)職前曾與公(gong)(gong)司(si)(si)(si)負責人員(yuan)(yuan)發(fa)(fa)生(sheng)矛盾、懷(huai)恨在心(xin),遂使(shi)用(yong)其原(yuan)公(gong)(gong)司(si)(si)(si)共享(xiang)服(fu)(fu)務(wu)(wu)器管(guan)理員(yuan)(yuan)賬號和(he)(he)密碼(ma),刪除服(fu)(fu)務(wu)(wu)器磁盤中(zhong)的(de)(de)(de)數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)和(he)(he)操作日志(zhi),造成公(gong)(gong)司(si)(si)(si)大量工(gong)(gong)(gong)作數(shu)(shu)(shu)據(ju)(ju)(ju)(ju)(ju)丟失(shi)(shi),影響工(gong)(gong)(gong)作正常開展。
三是個別數據服務商或虛假入職人員擅自篡改、竊取、非法利用企業數據。一(yi)些企(qi)業(ye)選擇第(di)三方機(ji)構或企(qi)業(ye)專門進行數據(ju)維(wei)護、軟件(jian)(jian)開發等工(gong)(gong)作(zuo),個(ge)別數據(ju)服(fu)務商及其工(gong)(gong)作(zuo)人員借此擅(shan)自篡改數據(ju),給(gei)企(qi)業(ye)造(zao)(zao)成經濟損(sun)失。如,檢察機(ji)關辦(ban)理的(de)(de)白某某破壞計(ji)算機(ji)信(xin)(xin)息系(xi)統(tong)案(an)(an),某軟件(jian)(jian)公(gong)(gong)(gong)(gong)(gong)司(si)(si)(si)員工(gong)(gong)白某某負(fu)責為某工(gong)(gong)業(ye)公(gong)(gong)(gong)(gong)(gong)司(si)(si)(si)提(ti)供生產管理系(xi)統(tong)升級服(fu)務。為讓該(gai)(gai)工(gong)(gong)業(ye)公(gong)(gong)(gong)(gong)(gong)司(si)(si)(si)盡快支付(fu)服(fu)務費用,白某某在編(bian)寫程序(xu)時故(gu)意加入(ru)(ru)(ru)(ru)錯誤代碼,導致(zhi)該(gai)(gai)工(gong)(gong)業(ye)公(gong)(gong)(gong)(gong)(gong)司(si)(si)(si)系(xi)統(tong)無(wu)法(fa)登錄,造(zao)(zao)成經濟損(sun)失4萬余元。還有個(ge)別不法(fa)分子虛假應聘(pin)(pin)入(ru)(ru)(ru)(ru)職后,伺(si)機(ji)將木(mu)馬(ma)病(bing)毒植入(ru)(ru)(ru)(ru)企(qi)業(ye)辦(ban)公(gong)(gong)(gong)(gong)(gong)電腦(nao)(nao)(nao)(nao),再(zai)由(you)“后端”技術人員遠程入(ru)(ru)(ru)(ru)侵并竊(qie)取企(qi)業(ye)內部(bu)數據(ju),作(zuo)案(an)(an)手法(fa)更為隱蔽,被害(hai)(hai)企(qi)業(ye)不易(yi)察覺。如,檢察機(ji)關辦(ban)理的(de)(de)王某某、白某某等17人侵犯(fan)公(gong)(gong)(gong)(gong)(gong)民個(ge)人信(xin)(xin)息案(an)(an)中,犯(fan)罪(zui)團伙先后到多家互聯(lian)網公(gong)(gong)(gong)(gong)(gong)司(si)(si)(si)應聘(pin)(pin)并短暫入(ru)(ru)(ru)(ru)職,在公(gong)(gong)(gong)(gong)(gong)司(si)(si)(si)辦(ban)公(gong)(gong)(gong)(gong)(gong)電腦(nao)(nao)(nao)(nao)植入(ru)(ru)(ru)(ru)具有遠程竊(qie)取電腦(nao)(nao)(nao)(nao)信(xin)(xin)息功能(neng)的(de)(de)木(mu)馬(ma)程序(xu),再(zai)由(you)同伙遠程入(ru)(ru)(ru)(ru)侵該(gai)(gai)電腦(nao)(nao)(nao)(nao)并竊(qie)取公(gong)(gong)(gong)(gong)(gong)司(si)(si)(si)客戶個(ge)人信(xin)(xin)息1400余萬條。該(gai)(gai)案(an)(an)一(yi)被害(hai)(hai)公(gong)(gong)(gong)(gong)(gong)司(si)(si)(si)當年3月(yue)發現(xian)服(fu)務器被侵入(ru)(ru)(ru)(ru)、客戶信(xin)(xin)息被竊(qie)取,直至5月(yue)才(cai)發現(xian)系(xi)公(gong)(gong)(gong)(gong)(gong)司(si)(si)(si)電腦(nao)(nao)(nao)(nao)被植入(ru)(ru)(ru)(ru)木(mu)馬(ma)程序(xu)所致(zhi);另一(yi)被害(hai)(hai)公(gong)(gong)(gong)(gong)(gong)司(si)(si)(si)經公(gong)(gong)(gong)(gong)(gong)安機(ji)關告知才(cai)發現(xian)公(gong)(gong)(gong)(gong)(gong)司(si)(si)(si)13臺電腦(nao)(nao)(nao)(nao)被侵入(ru)(ru)(ru)(ru),客戶信(xin)(xin)息被竊(qie)取。
針對上(shang)述情況,檢(jian)(jian)(jian)察(cha)機關依(yi)法(fa)(fa)(fa)加大涉企(qi)(qi)數(shu)(shu)(shu)據(ju)(ju)(ju)犯罪打(da)擊力度(du),嚴(yan)懲企(qi)(qi)業“內(nei)鬼”等(deng)不法(fa)(fa)(fa)分子,以典型案例引導企(qi)(qi)業加強(qiang)數(shu)(shu)(shu)據(ju)(ju)(ju)安全、風(feng)險內(nei)控等(deng)工作,切實維護(hu)企(qi)(qi)業合(he)法(fa)(fa)(fa)權益、助(zhu)力企(qi)(qi)業創新發展(zhan)。下一(yi)步,檢(jian)(jian)(jian)察(cha)機關將深入貫徹落實中央經(jing)濟工作會議(yi)精神,持續優(you)化檢(jian)(jian)(jian)察(cha)履職,充(chong)分發揮檢(jian)(jian)(jian)察(cha)職能作用,依(yi)法(fa)(fa)(fa)平等(deng)保(bao)護(hu)各類經(jing)營主體(ti),為企(qi)(qi)業發展(zhan)營造(zao)良好環境(jing)。同(tong)時,檢(jian)(jian)(jian)察(cha)機關提(ti)醒(xing),盡早建立健全企(qi)(qi)業數(shu)(shu)(shu)據(ju)(ju)(ju)管理(li)制度(du),嚴(yan)格(ge)數(shu)(shu)(shu)據(ju)(ju)(ju)訪問權限(xian)管理(li),加強(qiang)對從(cong)業人(ren)員(yuan)(yuan)及離職人(ren)員(yuan)(yuan)管理(li),明確(que)數(shu)(shu)(shu)據(ju)(ju)(ju)泄露應急響應流程,強(qiang)化安全審計與風(feng)險評(ping)估(gu),及時堵塞漏洞,形成全方位、多層次的企(qi)(qi)業數(shu)(shu)(shu)據(ju)(ju)(ju)安全防護(hu)體(ti)系。
日期:2025-1-24 10:10:18 | 關閉 |
Copyright © 1999-2021 法律圖書館
.
.