opinion

Preventing Data Breaches Staves Off Big Legal Claims

Preventing Data Breaches Staves Off Big Legal Claims

Did you hear about the Kimpton Hotel hacking last year? If you are like most of us, probably not. Kimpton was one of thousands of data breach victims in 2016 and their story was lost in the flood of attacks.

In New York state alone, another record breaking year of data breaches saw a total of 1282 breaches reported to the state attorney general comprising 1,596,207 records exposed in 2016.

The costs of keeping data secure pales in comparison to the costs of cleaning up after a hit.

Data security breaches are becoming so commonplace they don’t make news unless millions of records are exposed all at once.

Just last month, a federal judge approved an $11.2 settlement in a class-action lawsuit against Ashley Madison related to a data breach that exposed information stolen from the adult dating website for those seeking extra-marital affairs.

The small breaches just aren’t newsworthy, but Kimpton’s experience should be an important lesson to any business that uses computers.

In a fairly routine data breach, hackers were able to insert malware into Kimpton computer systems that found credit card numbers, expiration dates, verification codes and cardholder names.

Anyone that used a credit card at the front desk of a Kimpton Hotel between Feb. 16, 2016 and July 7 of that year was at risk of compromised credit card information, and the first report of unauthorized charges on a customer’s credit card was made July 15.

Kimpton publicly acknowledged the breach Aug. 31 with few details and without an explanation for why it took so long to disclose the intrusion.

It is likely the delay in notification and other alleged mishandling of the incident only increased customers’ anger, leading Lee Walters, a Kimpton Hotel customer who checked in once during the vulnerable time period, to file a class-action suit against the boutique hotel chain.

It is significant that Mr. Walters does not make a claim that his credit card was used to make unauthorized charges as a result of the breach. Walters claims that his card information is likely among the information copied and now in the hands of ill-intentioned criminals, and that he has had to expend time and effort to monitor his credit card activity for unauthorized use or identity theft. Surviving a motion to dismiss earlier this year, this case moves on to the next stage.

“The theft of Walters’s payment card data and the time and effort he has expended to monitor his credit are sufficient to demonstrate injury for standing purposes,” according to a ruling in Walters v. Kimpton Hotel & Restaurant Group.

This case is important to every business that accepts credit cards for two reasons. First, it shows that a customer who may have had his data copied but hasn’t had any fraudulent charges has the right to sue for damages. Second, it is important because it is another example of a data breach that could have been avoided.

Normally a person needs to incur some sort of damage before he can bring a lawsuit, commonly referred to as “standing.” If you don’t have any damages, you don’t have standing to bring a lawsuit.

Here, the credit card Lee Walters used to check in to the Kimpton Hotel had not been used for any fraudulent charges, but having to monitor his credit report is enough to give “standing” to file a lawsuit for damages.

This is important because every customer can make this claim after a data breach, so the business that gets hacked can be sued by any customer whose data was stolen.

This dramatically increases the potential cost of a data breach and increases the value of maintaining data securely. Remember the old saying, “An ounce of prevention is worth a pound of cure”?

According to the Poneman Institute Cost of a Data Breach Study, sponsored by IBM, in 2016 the average total cost of a data breach exceeded $4 million. This is an average, so half of breaches cost more and half cost less, but data breaches can be extraordinarily costly events, threatening the ability of some business to continue as a going concern.

The costs of keeping data secure pales in comparison to the costs of cleaning up after a hit. A good business will take the necessary steps, and apportion the necessary budget, to keep all assets safe, including electronic data assets.

The second reason why this case is important is that the breach could have been avoided if Kimpton had taken some reasonable steps to protect customer data against known threats.

The malware allegedly used in the breach was a variant of “BlackPOS,” a malware strain that had been used to breach security at several of Kimpton’s competitors, including Hilton, Starwood, Mandarin Oriental, White Lodging, and the Trump Collection.

If Kimpton had simply acted quickly to protect itself from the very same attacks that had been carried out against other hotels, it could have avoided the data breach altogether.

A simple hack that could have been avoided by upgrading systems to fend off known threats became a federal class-action suit, with damage to reputation tagging along for the ride.

Conclusion

Maintaining security is a cost of doing business in any field. We know the importance of things like locks, cameras, and security guards to protect the physical assets of a business but when it comes to protecting electronic data, many businesses still do not realize the risks of underestimating the need for ongoing cybersecurity efforts and take chances.

Kimpton was not the first, and certainly not the last, company to roll the dice and lose big. What does your company do to protect valuable data, and is that enough?

Chad Anderson is an Arizona attorney working in the area of cybersecurity and data privacy. He can be reached at chad@chadknowslaw.com.

Related:  

Copyright © 2024 Adnet Media. All Rights Reserved. XBIZ is a trademark of Adnet Media.
Reproduction in whole or in part in any form or medium without express written permission is prohibited.

More Articles

trends

AI Is Coming: A Look at What's Ahead and Its Implications

The AI era has dawned, and the impact of this technology is beginning to be felt in the online adult industry. We are already seeing a plethora of content, synthetic interactions and customizable avatars enabled by artificial intelligence.

Alejandro Freixes ·
opinion

Navigating Fraud Prevention in Credit Card Transactions

In the digital age, credit card transactions are essential to global commerce, providing unmatched convenience for consumers and businesses alike. With this convenience, however, comes the risk of credit card fraud, which can result in considerable financial losses and harm brand reputation.

Jonathan Corona ·
opinion

A Guide to Avoiding Scams in Hard Link Media Buying

‘If it sounds too good to be true, it probably is.” So cautionary wisdom reminds us, yet people still get scammed all the time. Fortunately, there are “red flags” you can watch for to help you identify scams and thereby avoid them.

Juicy Jay ·
opinion

The Dos and Don'ts of AI-Generated Content

AI is a hot topic. From automation to personal assistance to content generation, AI technology is already impacting our daily lives. Many industries, including adult, have had positive results using AI for customer support and marketing.

Cathy Beardsley ·
opinion

Strategic Upscaling of Non-4K Content

If content is king in adult, then technical quality is the throne upon which it sits. Technical quality drives customer acquisition and new sales, while cementing retention and long-term loyalty.

Brad Mitchell ·
profile

'Traffic Captain' Andy Wullmer Braves the High Seas as Spirited Exec

Wullmer networked and hobnobbed, gaining expertise in everything from ecommerce to SEO and traffic, making connections and over time rising through the ranks of several companies to become CEO of the mobile business arm of TrafficPartner.

Alejandro Freixes ·
opinion

To Cloud or Not to Cloud, That Is the Question

Let’s be honest. It just sounds way cooler to say your business is “in the cloud,” right? Buzzwords make everything sound chic and relevant. In fact, someone uninformed might even assume that any hosting that is not in the cloud is inferior. So what’s the truth?

Brad Mitchell ·
opinion

Upcoming Visa Price Changes to Registration, Transaction Fees

Visa is updating its fee structure. Effective April 1, both the card brand’s initial nonrefundable application fee and annual renewal fee will increase from $500 to $950. Visa is also introducing a fee of 10 cents for each settled transaction, and 10 basis points — 0.1% — on the payment volume of certain merchant accounts.

Jonathan Corona ·
opinion

Unpacking the New Digital Services Act

Do you hear the word “regulation” and get nervous? When it comes to the EU’s Digital Services Act (DSA), you shouldn’t worry. If you’re complying with the most up-to-date card brand regulations, you can breathe a sigh of relief.

Cathy Beardsley ·
opinion

The Perils of Relying on ChatGPT for Legal Advice

It surprised me how many people admitted that they had used ChatGPT or similar services either to draft legal documents or to provide legal advice. “Surprised” is probably an understatement of my reaction to learning about this, as “horrified” more accurately describes my emotional response.

Corey D. Silverstein ·
Show More