DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Attorney General James Reaches Agreement with Marymount Manhattan College to Invest $3.5 Million to Protect Students’ Online Data

Posted on September 21, 2023 by Dissent

NEW YORK – New York Attorney General Letitia James today announced an agreement with Marymount Manhattan College (MMC), a private non-profit liberal arts college in New York City, to invest $3.5 million in data security to protect students’ online data. In 2021, MMC suffered a data breach that affected nearly 100,000 New Yorkers who were current and prospective MMC students, faculty, and alumni. An investigation by the Office of the Attorney General (OAG) found that MMC failed to properly secure its network infrastructure and failed to update its policies to address new security concerns, making it vulnerable to a data breach. As a result of today’s agreement, MMC is required to invest $3.5 million to improve data encryption and security protocols to mitigate the risk of future breaches.

“When institutions like Marymount Manhattan College fail to properly protect online data, thousands of New Yorkers are put at risk as a result,” said Attorney General James. “In the modern digital age, companies and universities alike must do a better job at safeguarding the personal information with which they are entrusted. This agreement will help ensure that future classes of MMC students, faculty, and alumni will have their online data protected.”

In November 2021, a hacker got into MMC’s technical infrastructure and accessed data belonging to 99,097 New Yorkers, which included social security numbers, bank and credit card numbers, passport numbers, driver’s license numbers, and medical information. Some of the data was over 10 years old and from applicants that never attended MMC. The hacker then encrypted the information and demanded a ransom in exchange for the return of the information. MMC paid the ransom and the stolen data was deleted.

Following the cyber-attack, OAG opened an investigation into the breach and MMC’s privacy and data security practices. The investigation concluded that MMC failed to adequately safeguard personal information, including failing to use multi-factor authentication for accounts, not encrypting sensitive data, and failing to update both their security policies and firmware in response to new security threats.

As part of today’s agreement, MMC must invest $3.5 million over the next six years to better protect the personal information of consumers, including by:

  • Maintaining a comprehensive information security program that includes regular updates to keep pace with changes in technology and security threats;
  • Encrypting all personal information, whether stored or transmitted, between documents, databases, or elsewhere;
  • Maintaining reasonable policies to perform security updates and patch management;
  • Enabling multifactor authentication for users logging into MMC’s networks;
  • Scanning for vulnerabilities and potential weaknesses; and
  • Publicly sharing the university’s plan on the purpose of personal information it collected, retained, and timeline for deletion.

Today’s agreement continues Attorney General James’ efforts to protect the personal information of New Yorkers and hold accompanies accountable for their poor data security practices. This past May, Attorney General James secured $300,000 from Sports Warehouse for failing to protect the data of 2.5 million customers. Also in May, Attorney General James recouped $550,000 from a medical management company for failing to protect patient data. In April, Attorney General James released a comprehensive data security guide to help companies strengthen their data security practices. In December 2022, Attorney General James secured $200,000 from student cap and gown producer Herff Jones for failing to protect consumers’ personal information. In October 2022, Attorney General James announced a $1.2 million agreement with the owner of SHEIN and Zoetop for failing to properly handle a data breach that compromised the personal information of million of consumers. In June 2022, Attorney General James secured $400,000 from Wegmans and required the retailer to improve data storage security after a data breach exposed consumers’ personal information. In March 2022, Attorney General James issued a consumer alert advising T-Mobile customers to take appropriate steps to protect their personal information following a data breach.

This matter was handled by Assistant Attorney General Nathaniel Kosslyn and Deputy Bureau Chief Clark Russell, with special assistance from Internet and Technology Analyst Nishaant Goswamy, of the Bureau of Internet and Technology, under the supervision of Bureau Chief Kim Berger. The Bureau of Internet and Technology is a part of the Division for Economic Justice, which is led by Chief Deputy Attorney General Chris D’Angelo and overseen by First Deputy Attorney General Jennifer Levy.

Source: NYS Attorney General Letitia James


Related:

  • ModMed revealed they were victims of a cyberattack in July. Then some data showed up for sale.
  • Protected health information of 462,000 members of Blue Cross Blue Shield of Montana involved in Conduent data breach
  • Resource: NY DFS Issues New Cybersecurity Guidance to Address Risks Associated with the Use of Third-Party Service Providers
  • TX: Kaufman County Faces Cybersecurity Attack: Courthouse Computer Operations Disrupted
  • Attorney General James Announces Settlement with Wojeski & Company Accounting Firm
  • JFL Lost Up to $800,000 Weekly After Cyberattack, CEO Says No Patient or Staff Data Was Compromised
Category: Education SectorFederalLegislationState/LocalU.S.

Post navigation

← Crown Point schools 2022 ransomware attack cost $1M to resolve
Ohio Community College Data Theft Breach Affects Nearly 300K →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Doctor Alliance Data Breach: 353GB of Patient Files Allegedly Compromised, Ransom Demanded
  • St. Thomas Brushed Off Red Flags Before Dark-Web Data Dump Rocks Houston
  • A Wiltshire police breach posed possible safety concerns for violent crime victims as well as prison officers
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Almost two years later, Alpha Omega Winery notifies those affected by a data breach.
  • Court of Appeal reaffirms MFSA liability in data leak case, orders regulator to shoulder costs
  • A jailed hacking kingpin reveals all about the gang that left a trail of destruction
  • Army gynecologist took secret videos of patients during intimate exams, lawsuit says
  • The Case for Making EdTech Companies Liable Under FERPA
  • NHS providers reviewing stolen Synnovis data published by cyber criminals

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Data broker Kochava agrees to change business practices to settle lawsuit
  • Amendment 13 is gamechanger on data security enforcement in Israel
  • Changes in the Rules for Disclosure for Substance Use Disorder Treatment Records: 42 CFR Part 2: What Changed, Why It Matters, and How It Aligns with HIPAAs
  • Always watching: How ICE’s plan to monitor social media 24/7 threatens privacy and civic participation
  • Who’s watching the watchers? This Mozilla fellow, and her Surveillance Watch map

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: +1 516-776-7756
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.