News

Ticketmaster, Snowflake, and the Third-Party Credential Problem

Ticketmaster, Snowflake, and the Third-Party Credential Problem In May and June 2024, a wave of breaches hit major companies with a common thread: all of them traced back to stolen credentials for Snowflake, the cloud data platform. Ticketmaster lost data on approximately 560 million customers. Santander Bank was breached. Advance Auto Parts, LendingTree, and dozens […]

June 11, 2024

Read More →

Change Healthcare: The Cyberattack That Broke the US Healthcare System

Change Healthcare: The Cyberattack That Broke the US Healthcare System In February 2024, a ransomware group called ALPHV/BlackCat breached Change Healthcare, a subsidiary of UnitedHealth Group that processes roughly one in three US patient records. The attackers used stolen credentials — there was multi-factor authentication absent from the targeted remote access portal — and deployed […]

February 6, 2024

Read More →

ChatGPT and the Question Nobody Wants to Answer: Where Does the Data Go?

When ChatGPT crossed 100 million users in early 2023, it became the fastest-growing consumer application in history. It also became one of the most consequential unresolved data privacy questions of the year. By default, conversations with ChatGPT are used to train future models. Users who paste in sensitive information — internal business documents, patient information, […]

November 14, 2023

Read More →

The SEC’s New Cybersecurity Rules Change What “Material” Means for Public Companies

In July 2023, the Securities and Exchange Commission adopted new rules requiring public companies to disclose material cybersecurity incidents within four business days of determining they are material. The rules also require annual disclosures describing a company’s cybersecurity risk management program, governance, and the board’s oversight of cyber risk. The four-day clock is aggressive. Many […]

September 12, 2023

Read More →

The EU-US Data Privacy Framework: What Changed and What It Means

In July 2023, the European Commission formally adopted the EU-US Data Privacy Framework, establishing a new legal mechanism for transferring personal data from the European Union to the United States. The Framework replaces the Privacy Shield arrangement that was invalidated by the Court of Justice of the European Union in 2020. Under the new agreement, […]

July 11, 2023

Read More →