Close Menu
5gantennas.org5gantennas.org
  • Home
  • 5G
    • 5G Technology
  • 6G
  • AI
  • Data
    • Global 5G
  • Internet
  • WIFI
  • 5G Antennas
  • Legacy

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
5gantennas.org5gantennas.org
  • Home
  • 5G
    1. 5G Technology
    2. View All

    Deutsche Telekom to operate 12,500 5G antennas over 3.6 GHz band

    August 28, 2024

    URCA Releases Draft “Roadmap” for 5G Rollout in the Bahamas – Eye Witness News

    August 23, 2024

    Smart Launches Smart ZTE Blade A75 5G » YugaTech

    August 22, 2024

    5G Drone Integration Denmark – DRONELIFE

    August 21, 2024

    Hughes praises successful private 5G demo for U.S. Navy

    August 29, 2024

    GSA survey reveals 5G FWA has become “mainstream”

    August 29, 2024

    China Mobile expands 5G Advanced, Chunghwa Telecom enters Europe

    August 29, 2024

    Ateme and ORS Boost 5G Broadcast Capacity with “World’s First Trial of IP-Based Statmux over 5G Broadcast” | TV Tech

    August 29, 2024
  • 6G

    India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

    August 29, 2024

    Vodafonewatch Weekly: Rural 4G, Industrial 5G, 6G Patents | Weekly Briefing

    August 29, 2024

    Southeast Asia steps up efforts to build 6G standards

    August 29, 2024

    Energy efficiency as an inherent attribute of 6G networks

    August 29, 2024

    Finnish working group launches push for 6G technology

    August 28, 2024
  • AI

    Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

    August 29, 2024

    Why Honeywell is betting big on Gen AI

    August 29, 2024

    Ethically questionable or creative genius? How artists are engaging with AI in their work | Art and Design

    August 29, 2024

    “Elon Musk and Trump” arrested for burglary in disturbing AI video

    August 29, 2024

    Nvidia CFO says ‘enterprise AI wave’ has begun and Fortune 100 companies are leading the way

    August 29, 2024
  • Data
    1. Global 5G
    2. View All

    Global 5G Enterprise Market is expected to be valued at USD 34.4 Billion by 2032

    August 12, 2024

    Counterpoint predicts 5G will dominate the smartphone market in early 2024

    August 5, 2024

    Qualcomm’s new chipsets will power affordable 5G smartphones

    July 31, 2024

    Best Super Fast Download Companies — TradingView

    July 31, 2024

    Crypto Markets Rise on Strong US Economic Data

    August 29, 2024

    Microsoft approves construction of third section of Mount Pleasant data center campus

    August 29, 2024

    China has invested $6.1 billion in state-run data center projects over two years, with the “East Data, West Computing” initiative aimed at capitalizing on the country’s untapped land.

    August 29, 2024

    What is the size of the clinical data analysis solutions market?

    August 29, 2024
  • Internet

    NATO believes Russia poses a threat to Western internet and GPS services

    August 29, 2024

    Mpeppe grows fast, building traction among Internet computer owners

    August 29, 2024

    Internet Computer Whale Buys Mpeppe (MPEPE) at 340x ROI

    August 29, 2024

    Long-term internet computer investor adds PEPE rival to holdings

    August 29, 2024

    Biden-Harris Administration Approves Initial Internet for All Proposals in Mississippi and South Dakota

    August 29, 2024
  • WIFI

    4 Best Wi-Fi Mesh Networking Systems in 2024

    September 6, 2024

    Best WiFi deal: Save $200 on the Starlink Standard Kit AX

    August 29, 2024

    Sonos Roam 2 review | Good Housekeeping UK

    August 29, 2024

    Popular WiFi extender that eliminates dead zones in your home costs just $12

    August 29, 2024

    North American WiFi 6 Mesh Router Market Size, Share, Forecast, [2030] – அக்னி செய்திகள்

    August 29, 2024
  • 5G Antennas

    Nokia and Claro bring 5G to Argentina

    August 27, 2024

    Nokia expands FWA portfolio with new 5G devices – SatNews

    July 25, 2024

    Deutsche Telekom to operate 12,150 5G antennas over 3.6 GHz band

    July 24, 2024

    Vodafone and Ericsson develop a compact 5G antenna in Germany

    July 12, 2024

    Vodafone and Ericsson unveil new small antennas to power Germany’s 5G network

    July 11, 2024
  • Legacy
5gantennas.org5gantennas.org
Home»Data»FTC files first independent Section 5 unfairness claims for unreasonable data retention and inaccurate breach notifications | Perkins Coie
Data

FTC files first independent Section 5 unfairness claims for unreasonable data retention and inaccurate breach notifications | Perkins Coie

5gantennas.orgBy 5gantennas.orgFebruary 10, 2024No Comments7 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


On February 1, 2024, the Federal Trade Commission (FTC) announced a complaint and proposed consent order against Blackbaud, Inc. regarding a 2020 data security incident involving ransomware requests and payments. According to the FTC’s complaint, Blackbaud’s unfair and misleading practices include not only poor data security practices but also false statements about the scope and severity of the breach, including misrepresentations about the scope and severity of the breach. It is said that this included a delay in notifying the parties accurately. Initial notification to those customers. The FTC asserts that this action raises independent Section 5 tortiousness claims stemming from the failure to (1) implement and enforce reasonable data retention practices and (2) accurately communicate the seriousness and scope of the breach. He emphasized that it was his first time doing so.

Blackbaud Security Incident and Customer Notice

Blackbaud provides a variety of software products and services to nonprofit organizations, foundations, educational institutions, and healthcare organizations, including database services to track donors and donations. The complaint alleges that on February 7, 2020, an attacker used the customer’s login information to access the customer’s Blackbaud-hosted database. According to the complaint, the attacker used the vulnerability to move between Blackbaud-hosted environments and on the Blackbaud network, including millions of items of consumer personal information controlled by Blackbaud customers. I was able to leak the files. The FTC states that personal information includes name, date of birth, Social Security number, home address, telephone number, email address, financial information (such as bank account information, estimated wealth, and identified assets), and medical information (such as patient and medical information). information, etc.). record identifier, attending physician’s name, health insurance information, date of visit, reason for visit), gender, religious beliefs, marital status, spouse’s name, spouse’s contribution history, employment information (including salary), educational information, and account information. Credentials. According to the complaint, the aforementioned data was not encrypted because (1) Blackbaud tells its customers that it stores social security numbers and bank account information in unencrypted fields not specifically designated for that purpose; was allowed. (2) Blackbaud allowed its customers to upload attachments containing consumers’ personal information, which Blackbaud did not encrypt; (3) Blackbaud did not encrypt his files, database backups containing complete records from customers and former customers;

The complaint alleges that the attackers demanded a ransom after the intrusion was discovered on May 20, 2020. Blackbaud paid $235,000 in Bitcoin, but the FTC stressed in its complaint that Blackbaud has not been able to “conclusively verify” that the stolen data has been deleted. The complaint alleges that Blackbaud did not notify customers about the incident for another two months, until July 16, 2020, following an investigation it characterized as “highly inadequate.” Additionally, the FTC alleges that this initial notice to the customer stated that his credit card information, bank account information, and Social Security number were not accessed, alleging that: I am.[n]o No action is required on your part as no personal information about your voters is accessed.Blackbaud allegedly knew as of July 31, 2020 that bank account numbers and Social Security numbers had been compromised, but this fact was not disclosed to customers until October 2020.

FTC Claims and Proposed Order

All five FTC claims are brought under Section 5 of the FTC Act, 15 USC § 45(a) for deceptive or unfair acts or practices. Notably, the complaint includes three novel allegations:

  • Unfair data retention practices. The FTC alleges that Blackbaud engaged in unfair conduct by failing to implement and enforce reasonable data retention practices for sensitive consumer data held by customers in its network. According to the complaint, Blackbaud kept its customers’ consumer data for longer than necessary, including in some cases data about former and prospective customers, contrary to its own policies.
  • Unfair and inaccurate initial infringement notification. The FTC alleges that Blackbaud first notified customers of the breach in July 2020, but failed to accurately communicate the scope and seriousness of the breach, which was unfair. The allegation of impropriety stems from Blackbaud’s inaccurate statements about the scope of personal information exposed and the months-long delay before Blackbaud provided a second accurate notification of the scope of that data. It assumes both. (Blackbaud’s March 2023 settlement with the SEC also relates to a July 2020 notice to Blackbaud’s customers, which the SEC said misled investors about the impact of the incident.) (He claimed that it was a thing.)
  • Deceptive Initial Infringement Notification. Relatedly, the FTC also alleges that the initial notification in July 2020, which contained inaccurate statements regarding the scope of consumer data that had been compromised, was deceptive under Section 5.

Additionally, the complaint raises two allegations familiar from FTC data security litigation.

  • Unfair Information Security Practices. The FTC alleges that Blackbaud failed to take various reasonable steps to prevent unauthorized access to sensitive personal information (e.g., using insufficient encryption techniques and allowing weak passwords). , a long list of allegedly lax security practices, such as lack of multi-factor authentication, insufficient protection of sensitive information, inadequate threat monitoring, and failure to timely patch outdated software and systems).
  • False Security Statements. The FTC alleges that Blackbaud’s website privacy policy was deceptive in stating that Blackbaud provided “adequate” safeguards to protect personal information collected through its website.

suggested order

Like the complaint, the proposed order includes a mix of standard provisions of FTC data security consent orders, as well as other, less common provisions. The former category includes provisions prohibiting Blackbaud from making any misrepresentations about its privacy and data security practices, and the establishment of a comprehensive data security program subject to independent biennial evaluation by a third party. and provisions requiring the FTC to provide data breach reports. As a result, Blackbaud may report the incident to authorities under federal, state, or local law. The order also includes several additional requirements, which, while not without precedent, the FTC has included only in a subset of its data security orders, depending on the alleged facts of the case.

  • Required data deletion. Request that Blackbaud delete any customer backup files that contain consumer personal information that is not maintained in connection with the provision of products or services to Blackbaud’s customers.
  • Data retention. Require Blackbaud to release customer backup files containing consumers’ personal information and adhere to retention schedules. (1) the purposes for which the personal information is retained; (2) Blackbaud’s specific business needs for retaining the personal information; and (3) the established period of time for deletion of the personal information ( (that is, there is no indefinite retention).

Take-out

  • As three FTC commissioners emphasized in a joint statement on this case: This is the first time the FTC has asserted that retaining data for longer than necessary is itself an unfair practice under Section 5.-However, such data retention has previously been subject to several data security shortcomings that allegedly made practices unfair under Sec. Such). By asserting this as an “independent” claim, the FTC emphasizes the importance it places on data deletion from both privacy and data security perspectives.
  • The case is also the first time the FTC has alleged misconduct by failing to accurately communicate the scope and severity of the violations., as the commissioner also pointed out in the statement. This highlights the FTC’s tendency to scrutinize messages that provide reassurance that data security incidents are limited in scope, even if they apply to most affected individuals. If a message pertains to some of the affected people and is later found to be inaccurate, the FTC may conclude that the statement was deceptive at the time it was made and reflects insufficient investigation. It may be considered that there is.
  • Finally, the FTC claims that even though Blackbaud paid the ransom to the attackers, it could not “conclusively verify” that the leaked data was destroyed. Given the many ways data can be copied, transferred, hidden, and restored, how can remote data deletion be “conclusively verified”, let alone when involving criminal organizations operating in unknown locations? ” It is difficult to understand how it can be done. There are no confirmed reports that the data at issue in the Blackbaud incident was subsequently released or misused. What the complaint does not mention is that companies in Blackbaud’s situation should have provided consumers with stronger protections in their negotiations with the attackers.

[View source.]



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleMaryland senators spar with prosecutors over lack of data on juvenile delinquency laws – The Baltimore Sun
Next Article Is Chex Mix the ultimate expensive airport snack? The Internet thinks so.
5gantennas.org
  • Website

Related Posts

Crypto Markets Rise on Strong US Economic Data

August 29, 2024

Microsoft approves construction of third section of Mount Pleasant data center campus

August 29, 2024

China has invested $6.1 billion in state-run data center projects over two years, with the “East Data, West Computing” initiative aimed at capitalizing on the country’s untapped land.

August 29, 2024
Leave A Reply Cancel Reply

You must be logged in to post a comment.

Latest Posts

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024

Crypto Markets Rise on Strong US Economic Data

August 29, 2024
Don't Miss

Apple focuses on 6G for future iPhones

By 5gantennas.orgDecember 11, 2023

iPhone 15 Pro and Pro MaxWith Apple’s recent listing of cellular platform architects to work…

All connectivity technologies will be integrated in the 6G era, says Abhay Karandikar, DST Secretary, ET Telecom

January 31, 2024

5G-Advanced and 6G networks require additional spectrum

January 24, 2024

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to 5GAntennas.org, your reliable source for comprehensive information on 5G technology, artificial intelligence (AI), and data-related advancements. We are passionate about staying at the forefront of these cutting-edge fields and bringing you the latest insights, trends, and developments.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Most Popular

Will 5G make 2024 the most connected year in the industry?

December 1, 2023

The current state of 5G in the US and how it can improve

September 28, 2023

How 5G technology will transform gaming on the go

January 31, 2024
© 2025 5gantennas. Designed by 5gantennas.
  • Home
  • About us
  • Contact us
  • DMCA
  • Privacy Policy
  • About Creator

Type above and press Enter to search. Press Esc to cancel.