Biometric data stolen from corporate lunch rooms system

"Rule 1 is to NEVER, EVER even transport the raw data - you pre-process at the point of collection."

If I've read the article and breach notice correctly, the malware was on the kiosks - and was therefore operating at the point of collection.

