Data breached in translation

Before September, translation didn’t matter — at least, from an infosec standpoint. Taking content written in one language and changing it to another wasn’t at the top of most CSOs’ lists of data risks. Then Norwegian news network NRK uncovered a breach at Statoil, one of the world’s biggest oil and gas companies.
NRK reports that the $46 billion business used Translate.com, a free online tool, to translate “notices of dismissal, plans of workforce reductions and outsourcing, passwords, code information, and contracts.” Then, the story continued, Lise Lyngsnes Randeberg, a college professor, Googled Statoil: In her results were the company’s translations.
“Wow! What is this?” Randeberg thought, telling NRK, “This was information from organizations, private companies, government agencies.” In other words, stuff Statoil may not have wanted Randeberg — or any Google user — to read.
The translation industry saw the breach coming. “It was something that we had been warning companies about [for] 10 years or so,” says Don DePalma, Chief Strategist at Cambridge-based think tank Common Sense Advisory. “It’s been a question that’s been coming up, given the way [free online translation] works: Is that something that would expose information?”
So how did it happen? Only Translate.com knows for certain. Neither they nor Chicago-based parent company Emerge Media responded to CSO’s requests for comment.
In general, here’s how free online translation works: Every word you enter is stored in a translation engine where machine learning uses your entry — and its translation — to improve future results. That means anyone who uses the tool after you either has use of or access to your data, if not both. Whether your information winds up on Google from there depends on where and how the tool provider stores it.
When it comes to preventing your own translation-related data breach, the first step is to determine when employees can — and can’t — use free tools. At BASF, that answer is never. After learning employees were translating “important emails about new products, business plans, [and] PowerPoint presentations” online, independent technology consultant Kirti Vashee says the company blocked all free translation sites.
For an option that’s less severe, you can always limit the use of free translation tools by topic. Maybe it’s okay to enter product shipment details in the software, but not receiver contracts. Vashee says this is problematic, though: Employees often use free translation to see what something’s about. “People will use Google [Translate] and Bing [Translator] because they get a memo in Chinese and just want to know, ‘What is he talking about?’” Employees who don’t speak a language might not realize content is about a sensitive topic until they’ve already translated it.
A more secure option is to create your own machine learning engines and move translation in-house. That’s what Volkswagen did, Vashee explains: “They specifically don’t want to use outside engines because of the risk of exposure.” Of course, in 2016 Volkswagen’s revenue was $251.6 billion. That’s more than the GDP of many sovereign nations, including Chile and Finland. At a company that large, internalizing translation is easy. For other businesses, it’s simply not realistic.
So what can those companies do? Instead of plugging data in random tools online, tell employees to route all translation through a professional provider. Translation vendor selection is usually based on quality, turnaround and cost. To ensure data security, ask prospective resources how they receive and deliver files for translation. If they say email, watch out.


