The excellent post-mortem of the City of Helsinki data breach (summary at https://www.turvallisuustutkinta.fi/en/index/tutkintaselostukset/poikkeuksellisettapahtumat/p2024-01160databreachtargetingthecityofhelsinkiin2024.html, link to the full report at the bottom) says one thing I'm suspicious of. See screenshots below.
Problem: FileZilla server supports on-the-fly encryption, and 70% is a typical compression ratio for a heterogeneous data stream. To me, it seems possible (perhaps even likely) that the attacker downloaded _all_ the data with compression, not just 30% of it.
#infosec #breach #PostMortem #Helsinki #KASKO