News & Analysis as of

Data Breach Banking Sector

HaystackID

Santander Faces Major Cyber Attack Compromising Millions of Customers’ Data

HaystackID on

In May, Santander Bank faced a significant cybersecurity breach that affected millions of its customers and employees worldwide. The hacking group ShinyHunters claimed responsibility for the attack, which also targeted...more

Sheppard Mullin Richter & Hampton LLP

For Limited Use Only: Guidance on National Security Delay Determinations under the SEC Cyber Reporting Rule

On December 12, 2023, the Department of Justice (“DOJ”) issued guidance related to the process by which companies may request the United States Attorney General authorize delays of cyber incident disclosures, pursuant to a...more

Hogan Lovells

FTC amends Safeguards Rule to require non-banking financial institutions to report data breaches

Hogan Lovells on

Against the backdrop of the National Cybersecurity Strategy’s stated goal of harmonizing federal cyber incident reporting requirements, new requirements still continue to emerge. Among the latest is a Federal Trade Commission...more

Eversheds Sutherland (US) LLP

Updata: Your quarterly privacy & cybersecurity update - July - September 2023

Welcome to the latest edition of Updata – the international update from Eversheds Sutherland’s dedicated Privacy and Cybersecurity team. Updata provides you with a compilation of privacy and cybersecurity regulatory and...more

Orrick, Herrington & Sutcliffe LLP

FTC approves amendment to Safeguards Rule requiring nonbanks to report data breaches

On October 27, the FTC approved an amendment to the Safeguards Rule to require nonbanks to report data breaches. Under the amended rule, financial institutions, including mortgage brokers, motor vehicle dealers, and payday...more

Katten Muchin Rosenman LLP

New FTC Rule Requires Certain Financial Institutions to Report Loss of Unencrypted Customer Data

On October 27, the Federal Trade Commission (FTC or Commission) published a final rule expanding data breach notification requirements for certain financial institutions (Final Rule). Federal Register, will require entities...more

Console and Associates, P.C.

Over 36k Customers of City National Bank of Florida Affected by MOVEit Data Breach

On June 30, 2023, City National Bank of Florida (“CNBF”) filed a notice of data breach with the Attorney General of Maine, explaining that 36,306 of the bank’s customers were affected by a data breach involving software...more

EDRM - Electronic Discovery Reference Model

[Webinar] Banks in the Crosshairs: Cyberattacks and Aggressive Regulators - May 25th, 1:00 pm - 2:00 pm ET

Financial institutions are in a tough spot- caught between the “bad guys” (state-sponsored cyberattacks and cyber criminals) and “good guys” (ever more aggressive regulators)- what’s a bank to do??? Tune in to find out!...more

Foley Hoag LLP - Security, Privacy and the...

As If Bank Failures Aren’t Enough – Hackers Are Exploiting the Chaos to Breach Security

The Massachusetts State Police Commonwealth Fusion Center (CFC) believes that cyber actors may use the current bank failures for future phishing and business email compromise (BEC) attacks. Cyber actors often use current...more

Davis Wright Tremaine LLP

Federal Court Holds Financial Institution Liable for Business Email Compromise Loss

While ransomware attacks usually grab the headlines, business email compromise (BEC) attacks continue to cause massive financial losses for businesses. The FBI’s Internet Crime Complaint Center (IC3), reported BEC losses in...more

Alston & Bird

Payments Docket - June 2022

Alston & Bird on

Welcome to the first edition of the Payments Docket, our roundup of key litigation involving the payment industry. This edition features a stolen cell phone number used to buy cryptocurrency, a pair of class actions accusing...more

Blank Rome LLP

What Banks Need to Know About New Data Breach Notification Requirements

Blank Rome LLP on

Given the omnipresent concern about cyber attacks targeting the banking industry, the FDIC, OCC and Federal Reserve recently published a new joint final rule establishing enhanced security incident notification requirements...more

Benesch

Federal Agencies Issue New Breach Notification Rules for Banking Organizations and Banking Service Providers

Benesch on

Banking organizations must notify the appropriate agency within 36 hours of certain computer-security incidents; and banking service providers must notify affected banking organizations as soon as possible in the event of an...more

BakerHostetler

Federal Banking Regulators Issue 36-Hour Computer-Security Incident Notification Requirement

BakerHostetler on

As the federal government continues its whole-of-government response to cyber incidents, federal banking regulators took action to impose a new notice requirement on federally regulated banks. In November, the Federal Deposit...more

Dorsey & Whitney LLP

The Prudential Bank Regulators Adopt Federal Data Interruption Notice Requirements for FDIC-Insured Institutions and Service...

Dorsey & Whitney LLP on

On November 23, 2021, the Office of the Comptroller of the Currency (the “OCC”), the Federal Deposit Insurance Corporation (the “FDIC”) and the Federal Reserve Board (the “Prudential Regulators”) exercised their collective...more

Sheppard Mullin Richter & Hampton LLP

Beginning in May 2022 Banks Will Have 36 Hours to Disclose Certain Types of Cyber Incidents

Federal banking regulators issued a final rule that impacts how banks and other regulated entities report certain data incidents. Those subject to these new reporting requirements include U.S. banks and bank service...more

Cooley LLP

36-Hour Breach Notification Rule to Go into Effect for Banking Organizations

Cooley LLP on

On November 18, 2021, three US agencies – the Office of the Comptroller of the Currency (OCC), the Federal Reserve Board (FRB) and the Federal Deposit Insurance Corporation (FDIC) – issued a joint rule concerning...more

Steptoe & Johnson PLLC

Computer-Security Incident Rule Creates New Notification Requirements for Banking Organizations and Bank Service Providers

Steptoe & Johnson PLLC on

On November 18, 2021, the Federal Deposit Insurance Corporation (FDIC), the Board of Governors of the Federal Reserve System (FRB), and the Office of the Comptroller of the Currency (OCC) issued a joint final rule (the...more

Morgan Lewis - All Things FinReg

Federal Banking Agencies Adopt New Computer-Security Incident Notification Requirements

The three federal banking agencies (i.e., the Federal Reserve Board, the Federal Deposit Insurance Corporation, and the Office of the Comptroller of the Currency—collectively, the Agencies) published a final rule (the Rule)...more

Troutman Pepper

Think Fast: Banking Regulators Release Final Computer-Security Incident Notification Requirements

Troutman Pepper on

Introduction - On November 18, federal banking agencies issued the long-awaited final rule, establishing data security incident response notification requirements for “banking organizations” and “bank service providers”...more

Balch & Bingham LLP

Financial Regulators Issue New Cyber Incident Reporting Rule for U.S. Banks and Service Providers

Balch & Bingham LLP on

On November 18, 2021, the Federal Reserve, Federal Deposit Insurance Corporation (FDIC), and the Office of the Comptroller of the Currency (OCC) approved a new final rule regarding reporting of cyber incidents for U.S. banks...more

Ballard Spahr LLP

FTC Strengthens GLBA Financial Safeguards and Privacy Rules

Ballard Spahr LLP on

On October 27, the Federal Trade Commission (FTC) announced a final rule (Final Rule) and supplemental notice of proposed rulemaking (NPRM) to amend the Safeguards Rule promulgated under the Gramm-Leach-Bliley Act (GLBA),...more

Wiley Rein LLP

FTC Releases Detailed Information Security Requirements and Proposes Breach Notification for Financial Institutions

Wiley Rein LLP on

On October 27, 2021, the Federal Trade Commission (FTC) announced revisions to its Safeguards Rule (Revised Safeguards Rule), which requires certain financial institutions to implement information security programs to protect...more

Oberheiden P.C.

5 Keys to Performing A GLBA Audit

Oberheiden P.C. on

Purpose and Background of the GLBA - The Gramm-Leach-Bliley Act (“GLBA”), also known as the Financial Services Modernization Act of 1999, is a federal statute enacted by Congress in 1999 that requires financial...more

Goodwin

NYDFS Consent Order Signals Regulator’s Growing Focus On Financial Institutions’ Incident Response And Security Practices

Goodwin on

In early March, the New York State Department of Financial Services (“NYDFS”) announced a consent order that required Maine-based mortgage servicer Residential Mortgage Services, Inc. (“Residential”) to pay a $1.5 million...more

133 Results
 / 
View per page
Page: of 6

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide