Latest Posts › Enforcement Actions

Share:

SEC Turning Up the Heat: SolarWinds and Its CISO Charged with Fraud Regarding Cyber-related Disclosures

Key Takeaways - With the SolarWinds enforcement action, the SEC continues to ratchet up its enforcement against companies that fail to properly disclose their cybersecurity incidents and risks. By naming the SolarWinds CISO...more

Government Contractors Beware: New Cybersecurity Rules and False Claims Act Enforcement Actions on the Rise

Two years after the Department of Justice (DOJ) established its Civil-Cyber Fraud Initiative, there has been a recent uptick in enforcement and regulatory activity related to cybersecurity. September opened with the unsealing...more

FTC Commercial Data Surveillance Crack Down: Kochava Gains a Win in Data Privacy Suit

On May 4, 2023, an Idaho federal judge ruled that the Federal Trade Commission (FTC) needs stronger assertions of consumer harm in order for its data privacy suit against data broker/mobile analytics provider Kochava Inc....more

FTC’s First-of-Its-Kind Health Breach Notification Rule Enforcement Action

On February 1, 2023, the Federal Trade Commission (FTC) announced that it had taken enforcement action against prescription drug discount company GoodRx, which agreed to injunctive relief and to pay a $1.5 million civil...more

State and Federal Crackdown on Data Breach: EyeMed, Carnival Cruise & CafePress Settlements

This year has seen some substantial new data breach settlements including a $500,000 Federal Trade Commission (FTC) fine against CafePress, a $1.25 million multi-state class action settlement and $5 million New York...more

First CCPA Enforcement Action: “There Are No More Excuses” for Companies Who Do Not Comply

On August 24, 2022, California Attorney General Rob Bonta (AG) announced a proposed settlement with beauty retailer Sephora USA, Inc. to resolve claims that Sephora violated the California Consumer Privacy Act (CCPA). Under...more

SEC Cyber Enforcement Actions – Lessons for Private Fund Managers

On August 30, 2021, the Securities and Exchange Commission announced three enforcement actions against registered investment advisers for alleged cybersecurity failures involving cloud-based email systems. All three actions...more

New York Department of Financial Services Issues Millions of Dollars in Penalties, Signaling Increased Cybersecurity Enforcement

On April 14, 2021, the New York Department of Financial Services (DFS) announced it settled an enforcement action against National Securities Corporation (“National Securities”) related to claims under the Cybersecurity...more

National Defense Authorization Act Boosts SEC’s Disgorgement Authority and Ability to Seek Other Equitable Relief

Amendments Come on the Heels of Supreme Court Decisions on SEC Disgorgement - On January 1, 2021, Congress passed the National Defense Authorization Act (NDAA). Embedded in the NDAA’s more than 1,400 pages is Section...more

Vermont Attorney General Provides Guidance on Security Breach Notice Act

On March 5, 2020, Gov. Phil Scott (VT-R) signed into law amendments to the Security Breach Notice Act (the “Act”). The amendments, which originated in the State Senate as part of an initiative addressing a number of data...more

First Enforcement Action by New York Department of Financial Services Under Cybersecurity Regulation

On July 21, 2020, the New York Department of Financial Services (DFS) filed a “Statement of Charges and Notice of Hearing” (the “Charges”) against First American Title Insurance Company (the “Company”) alleging violations of...more

A Year of GDPR: Five Recommendations to Help Limit Regulatory Scrutiny

A year ago, on May 25, 2018, the European Union’s General Data Protection Regulation (GDPR) came into force. With its extraterritorial scope and detailed requirements, the GDPR aimed to change the approach to personal data...more

U.S. Supreme Court: Disseminators of False Statements with Intent to Defraud can be Held Liable Under Securities Exchange Act Rule...

• The United States Supreme Court held that a disseminator of a false statement with intent to defraud can be held liable under subsections (a) and (c) of Rule 10b-5, §10(b) of the Exchange Act and §17(a)(1) of the Securities...more

Podcast: Cybersecurity and the Boardroom

In this episode, the third of three building on Akin Gump’s annual Top 10 Topics for Directors report, partner Michelle Reed discusses the critical question of cybersecurity and the corporate world. Among the topics...more

SEC Warns Companies of Potential Internal Accounting Control Violations with Business Email Compromise

• The SEC issued guidance in the form of a rare “21(a) report” this week after investigating a series of email frauds impacting 9 unnamed companies. • These email-based frauds, referred to as “CEO scams” or “vendor scams,”...more

California Passes Landmark Consumer Privacy CCPA—What it Means for Businesses

• California recently passed the landmark California Consumer Privacy Act that goes into effect in 2020, which grants California residents new privacy rights. • The CCPA creates a private right of action for California...more

Government Agencies Face Uncertainty After Supreme Court Rules That SEC ALJs Must Be Appointed

• SEC ALJs are “Officers of the United States” within the meaning of the Appointments Clause and therefore must be appointed directly by the SEC. The Court’s decision may permit litigants in prior and pending administrative...more

Morgan Stanley Fined $1 Million by SEC for Cybersecurity Violations

The SEC has taken a new enforcement action, demonstrating its expectations of industry and the willingness to use the variety of tools at its disposal to address concerns with cybersecurity previously signaled by an...more

SEC Brings Enforcement Action Against a Broker-Dealer for Weak Cybersecurity Controls

On April 12, 2016, the U.S. Securities and Exchange Commission (“SEC”) continued its enforcement of reasonable cybersecurity controls, announcing cease and desist proceedings against a broker-dealer and two of its principals...more

SEC Brings Enforcement Action Against Investment Adviser

Just one week after the Securities and Exchange Commission (SEC) Office of Compliance Inspections and Examinations issued a new risk alert on cybersecurity, the SEC brought an enforcement action against an investment adviser...more

3rd Circuit Affirms FTC’s Cybersecurity Oversight

If you read one thing: - The Federal Trade Commission (FTC) secured a major appellate victory in its quest to challenge lax corporate cybersecurity practices - In light of the 3rd Circuit’s decision,...more

21 Results
 / 
View per page
Page: of 1

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide