Data Breach News, Legal News, News, Vendor News
July 24, 2025
521 views 26 secs 0

Clorox lawsuit says help-desk contractors handed over passwords in 2023 cyberattack

The Record reports: Cleaning product giant Clorox has filed a lawsuit against Cognizant, a company it hired to operate its IT services call-in help desk, accusing the contractor of being directly responsible for a 2023 cyberattack that cost hundreds of millions. The case, filed on Tuesday in California Superior Court, alleges that contractors working for […]

Data Breach News, Legal News, News
July 23, 2025
429 views 22 secs 0

Major Russian-language hacking forum administrator arrested; forum seized

Help Net Security reports that an alleged administrator of xss.is, a dominant Russian-speaking cybercrime forum, was arrested in Kyiv, Ukraine, on 22 July. The takedown followed a long-running investigation led by the French Police and Paris Prosecutor, in close cooperation with Ukrainian authorities and Europol. As Help Net summarizes the allegations: The forum’s administrator is […]

Data Breach News, Legal News, Malware Ransomware
July 22, 2025
250 views 6 secs 0

UK moves forward with plans for mandatory reporting of ransomware attacks

The Record reports: The British government’s proposals to overhaul its ransomware strategy reached a minor milestone on Tuesday as the Home Office published its formal response to a consultation on amending the law, but questions remain regarding how effective the measures will be. Public consultations are a regular part of the British legislative process. In […]

Insurance News, Legal News
July 17, 2025
1177 views 5 secs 0

Mississippi Law Firm Sues Cyber Insurer Over Coverage for Scam

Bloomberg reports: A Mississippi law firm is suing its cyber insurer, alleging the carrier wrongfully denied coverage for a roughly $150,000 loss stemming from an “elaborate” email scheme. Gore, Kilpatrick & Dambrino PLLC was duped into wiring funds to an account controlled by scammers posing as representatives from a company that was dissolved years earlier, […]

Legal News, Insurance News
July 15, 2025
1132 views 39 secs 0

For the Record: Cyber Coverage “For” a Security Breach is Ambiguous under New Mexico Law

Wiley Rein explains: The New Mexico Court of Appeals has held that cyber policy language affording coverage “for” a security breach was ambiguous and must be construed broadly to provide coverage for a breach of contract claim “because of,” “resulting from,” or “on account of” a security breach. Kane ex rel. N.M. Health Connections, Inc. v. Syndicate […]

Legal News
July 11, 2025
927 views 2 mins 0

OCR Enters into Two More Settlements for Failure to Conduct Security Risk Assessments

The Office for Civil Rights (OCR) entered into two recent settlements with HIPAA covered entities alleging that they failed to conduct security risk assessments. Robinson & Cole LLP discusses the enforcement actions. Deer Oaks On July 7, 2025, OCR announced a settlement with Deer Oaks, a behavioral health provider, for alleged violations of HIPAA. The settlement resolves […]

Legal News, Finance
July 08, 2025
953 views 9 secs 0

North Dakota’s New InfoSec Requirements for Financial Corporations

Earlier this year, North Dakota’s Governor signed HB 1127, which imposes new obligations for financial corporations operating in North Dakota. The law will take effect on August 1, 2025. From JacksonLewis, an explainer on the new law’s requirements for a comprehensive, written information security programs: Read more of the required elements at Workplace Privacy, Data Management & […]

Legal News
July 06, 2025
993 views 27 secs 0

Obligations under Canada’s data breach notification law

Data breach notification law is governed by the Personal Information and Electronic Documents Act (PIPEDA). This federal law regulates the handling of personal information during commercial transactions. This includes the collection, use, and disclosure of personal data. As Lexpert explains, by extension, this also includes the storage of information while in use: Read more at […]

Legal News, Malware Ransomware
July 02, 2025
923 views 15 secs 0

US Sanctions Russian Cybercrime Group Aeza for Hosting Ransomware and Global Attacks

United24 reports: The United States has imposed sanctions on the Russian cybercrime group Aeza Group and its associated global network, the US Department of the Treasury’s Office of Foreign Assets Control (OFAC) announced on June 1 [sic]. OFAC designated Aeza Group for its role in supporting cybercriminal operations targeting victims in the United States and […]