Got Hacked...The FTC Can Now Sue You

GURPS

INGSOC
PREMO Member
Got Hacked...The FTC Can Now Sue You


For organizations that get hacked like Anthem, Target and recently Ashley Madison, the problems are only starting. Apart from towering legal fees and a damaged reputation, now an appeals court has confirmed that the FTC can slap you with fines as well. This is excellent ammo to get more IT security budget.

Yesterday, the third U.S. Federal circuit court ruled that the Federal Trade Commission (FTC) has the power to take action against organizations that employ poor IT security practices. The ruling was part of a lawsuit between the FTC and hotel chain Wyndham. This court decision affirms the FTC’s role as a digital watchdog with real-life teeth.

This Is A Big Deal

In 2008 and 2009, Wyndham was hacked three times, losing credit card data for more than 619,000 customers and causing 10.6 million dollars in loss due to fraud. Originally, the FTC sued them in 2012 over the lack of security that led to its massive hack. The hotel chain appealed to a higher court to dismiss it, arguing that the FTC didn’t have the authority to punish the hotel chain for its breach. Wrong move. Yesterday's decision states that Wyndham’s breach is exactly the sort of “unfair or deceptive business practice” the FTC is empowered to stop. This means Wyndham now needs to go back and confront the FTC’s lawsuit in a lower court.

The circuit court also stated that the FTC does not have to detail any specific best practices that Wyndham did not apply. The FTC did however, and it's not a pretty picture. Here are some of the highlights: Wyndham allowed its partner hotels to store credit card information in plain text, allowed easily guessable passwords in property management software, failed to use firewalls to limit access to the corporate network, and failed to restrict third-party vendors from access to its network.





I don't really see why the Gov. has to dog pile on top
... a significant hack and any large business and they are going to take a massive monetary hit


this smacks of the GOV. 'Me Too' ism



this will not fix stupid users .... only drive up business costs - from everyone running about applying 'best practices' that are good on paper and poor in execution

conversation in 2004 with my boss;

ME: why do you keep using Symantec Antivirus - it is resource sucking bloatware ....

Company Owner: its an 'industry standard'

ME: it sux monkey balls - this is better for Malware and Adware

CO: If something happens and we get sued, as long as we followed 'best practices' and used industry standard software ...

ME: .... well as long as we are covered in the event of a lawsuit, meanwhile our computers run slower and are not as secure ....
 

somdwatch

Well-Known Member
I don't really see why the Gov. has to dog pile on top
... a significant hack and any large business and they are going to take a massive monetary hit


this smacks of the GOV. 'Me Too' ism





this will not fix stupid users .... only drive up business costs - from everyone running about applying 'best practices' that are good on paper and poor in execution

conversation in 2004 with my boss;

ME: why do you keep using Symantec Antivirus - it is resource sucking bloatware ....

Company Owner: its an 'industry standard'

ME: it sux monkey balls - this is better for Malware and Adware

CO: If something happens and we get sued, as long as we followed 'best practices' and used industry standard software ...

ME: .... well as long as we are covered in the event of a lawsuit, meanwhile our computers run slower and are not as secure ....

I recently went through a Certified Ethical Hacker Class. The instructor from a security firm in NY shared with us that the 26K IRS employees they are planning to hire is exactly for this purpose. The government has seen that there is a big revenue stream from corporations that are not securing there IT systems and if hacked they will be fined by the IRS. I think they have already started, while not the IRS, FTC sounds more likely.

Oh, as for Hotels, worst place you could possibly use a credit card. They usually have that installed on the system behind the counter, with total local Admin access to the folder where your credit information goes to.
 
Top