Craig A. Newman of Patterson Belknap writes: Yesterday, a Superior Court judge in Santa Clara, California approved what is believed to be the first monetary award to a company in a data breach-related derivative lawsuit. Until now, such breach-related derivative cases have settled through a combination of governance changes and modest awards of attorney’s fees. But…
Category: Of Note
Massachusetts Enacts Significant Changes to Its Data Breach Notification Law
David M. Brown of Baker Hostetler writes: On Jan. 10, 2019, Massachusetts Gov. Charlie Baker signed legislation that will significantly amend the state’s data breach notification law. The amendments become effective on April 11, 2019. One of the significant changes includes a new requirement to provide an offer of complimentary credit monitoring for “a period…
PH: Locsin says ‘pissed’ contractor ‘took all’ passport data
Updated January 15: Locsin subsequently clarified his claim and said that no data had been removed or stolen, but had been made inaccessible. See this report. Original post: Katrina Domingo reports: MANILA – Some Filipinos renewing their passports may have to present their birth certificates as an additional requirement after a passport production contractor the…
A Nasty Trick: From Credential Theft Malware to Business Disruption
Kimberly Goody, Jeremy Kennelly, Jaideep Natu, Christopher Glyer write: FireEye is tracking a set of financially-motivated activity referred to as TEMP.MixMaster that involves the interactive deployment of Ryuk ransomware following TrickBot malware infections. These operations have been active since at least December 2017, with a notable uptick in the latter half of 2018, and have…
UK hacker “BestBuy” sentenced for Mirai botnet attack on Lonestar
Catalin Cimpanu does some great reporting on the sentencing of “BestBuy:” A UK court sentenced today a 30-year-old man to two years and eight months in prison for using a DDoS botnet to viciously attack and take down internet connectivity in Liberia in the fall of 2016. The man is 30-year-old Daniel Kaye, also known…
Attributions Have Consequences: The Danger of Calling Out Cyberattackers
Leonid Bershidsky reports: The $100 million lawsuit that Mondelez, the maker of Oreos and Cadbury chocolate, has brought against Zurich Insurance Group shows that governments should be more careful about identifying the would-be culprits in putative cyberwars: Such claims can have unintended consequences, and can sometimes harm businesses. […] Mondelez claimed $100 million on its…