HomeCyber SoapboxThe danger of delayed notification

The danger of delayed notification

NetworkTigers discusses the disturbing trend of delayed notification of data breaches in multiple industries.

Data breaches, ransomware attacks, and other forms of cybercrime have become so commonplace that it can be hard to keep up.

According to research from Statista, in 2023, 3,205 data breaches affected more than 350 million individuals in the US. The most commonly attacked industry sectors are consistently those that store troves of sensitive client data, such as those in the healthcare or finance sector.

Leaks, hacks, and intrusions are nothing new. More than a decade ago in 2013, Yahoo! experienced a security incident that compromised a whopping one billion records. In 2017, the company reported that the number of records leaked was actually triple that, meaning that every single Yahoo! account had been exposed.

At the time of this revelation, David Kennedy, chief executive of cybersecurity firm TrustedSEC LLC, referred to the magnitude of the exposure as “a real wakeup call.”

As we approach the middle of 2024, however, it seems that many of the companies responsible for safeguarding and protecting customers’ data have decided to hit the snooze button when informing the public about data breaches.

Bank of America

A breach of Bank of America by the LockBit ransomware gang in November of 2023 affected 57,000 customers, exposing their Social Security numbers, birth dates, account numbers, and more highly valuable information that could be leveraged against them.

Time is of the essence when it comes to fortifying against the potential disruption possible when personal data hits illegal marketplaces. Bank of America, however, did not inform its customers that all the ingredients necessary for identity theft were in criminal hands until February 2024. This is a full three months after exposure, and the delay may have violated laws in states that require notification within 30 days.

Bad actors typically don’t sit on valuable assets for longer than they have to, and Bank of America’s spokesperson provided no response to questions about why it took them so long to reach out to affected customers. Individuals who had their data stolen were offered two years of free identity protection through Experian IndentityWorks, an online platform that requires internet access, the creation of a new user account, and participatory monitoring by those using it.

This puts the responsibility right back on the consumer to actively monitor the data that Bank of America did not safeguard even after they knew it had been stolen.

WebTPA

WebTPA, a health insurance and benefit plan provider, suffered an intrusion into their network in April 2023. The unauthorized access to their system wasn’t detected until eight months later in December 2023. The company did not reveal the attack, which exposed the names, contact information, date of birth, date of death, Social Security numbers, and insurance information belonging to nearly 2.5 million people, until May of 2024, nearly a year after the breach took place.

WebTPA did not make any grand gestures regarding the incident. A “Notice of Data Security Incident” is available on their website, which describes the event and provides a phone number for customers to call with any questions. The company offers those affected identity theft protection services for two years through a third party.

WebTPA’s social media accounts make absolutely no mention of the incident.

Live Nation

Live Nation’s Ticketmaster subsidiary doesn’t have the best reputation among customers, so it may come as no surprise that a breach from April 2 to May 18, 2024, was not mentioned on corporate social media accounts or websites. The breach saw a threat actor selling data belonging to 560 million of its customer

Media outlets picked up on news of the breach when the company submitted a Form-8K to the United States Securities and Exchange Commission (SEC) reporting the incident. Live Nation concluded that “the incident has not had, and we do not believe it is reasonably likely to have, a material impact on our overall business operations or on our financial condition or results of operations.”

The threat actor who stole the data in question posted the first 1 million records onto a hacker forum for free, citing Ticketmaster’s refusal to pay a ransom as the incentive to do so.

At the time of writing this article, neither company has made a public statement regarding the breach, seemingly content to allow Time Magazine and other publications to offer people tips on how to prevent getting scammed by criminals using their stolen data.

A notification sent to affected customers informed them of the breach, advised them to “remain vigilant” and offered a year of identity monitoring. This email was sent at 5:00 pm EST on Friday, June 21st. In the world of corporate PR, communicating bad news on a Friday afternoon, especially before a long weekend, is standard practice. This works to limit the spread of it since analysts and reporters have started their weekend, markets are closed, and recipients may miss the message altogether or simply “get over it” by Monday.

Financial Business and Consumer Solutions (FBCS)

Collection agency FBCS, a nationally licensed company specializing in collecting unpaid loan and credit card debts, suffered a data breach in February 2024 that affected more than 3 million people by exposing their Social Security numbers, addresses, names, driver license ID numbers, and more, to threat actors.

The company responded to the incident in May 2024, 90 days after the breach, by offering advice on how those affected can protect themselves from online scams leveraging the data the company failed to secure. Instructions for enrolling in a free credit monitoring and identity restoration service were also included, once again passing the buck to the victims and having them look out for themselves. 

Block

Cash App, a popular mobile payment vendor, suffered a data breach in December 2021 when a former employee of parent company Block accessed customer data “without permission” and downloaded information belonging to 8.2 million customers. 

The breach was not made public until April 2022 when Block filed a report with the SEC. Block has not explained how the employee was able to access company data or how the breach was discovered. Block has also not offered customers any form of identity theft or credit monitoring services.

Block’s response to the incident prompted a class-action lawsuit alleging that customers experienced fraudulent activity on their accounts resulting from the breach. The lawsuit also calls out the company for the unexplained delay in notifying users of the incident. The case has since been settled out of court.

Why are companies delaying notification of data breaches?

In the past, humbly admitting to data breaches was commonplace and seen as a way to retain customer faith and present a brand as conscientious, open, and honest with its clients. Nowadays, some companies seem to be hedging their bets and relying on the fact that the average person simply does not care much about cybersecurity

Perhaps consumers are unaware of the dangers, are becoming numb to news of data breaches, or are comfortable with the amount of sharing that occurs online. Whatever the reason, brands are not investing in PR campaigns and outreach in the way they used to after a cyberattack. Coincidentally, the lack of openness may minimize harm to their bottom lines.

Cybersecurity regulations carry punitive fees that do not incentivize the largest companies to comply. In 2023, five of the biggest tech companies were fined a total of $3.04 billion for breaking laws. This may seem like a huge sum, but these companies bring in revenue that renders these fines nearly invisible. For reference, Amazon earns $1 billion every 16 hours and 10 minutes. This means that the $111.7 million in fines the company was issued last year was “paid off” in less than two hours.

The digital landscape is increasingly plagued by data breaches, exposing our most sensitive information to cybercriminals. Companies responsible for safeguarding this data display a disturbing trend of delaying breach notifications. This lack of transparency may leave consumers vulnerable and raises serious questions about corporate priorities. Stronger regulations and increased consumer awareness are crucial to holding companies accountable and fostering a future where data security and user protection are paramount. By staying informed and demanding higher standards, consumers can push for a safer digital environment where their personal information is better protected.

About NetworkTigers

NetworkTigers logo

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, which built and re-architected data centers for Fortune 500 firms, NetworkTigers provides consulting and network equipment to global governmental agencies, Fortune 2000, and healthcare companies. www.networktigers.com.

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

What do you think?

Popular Articles