News & Analysis as of

Banking Sector Data Breach

Clark Hill PLC

The Learned Concierge - May 2025, Vol. 19

Clark Hill PLC on

Welcome to your monthly legal insights on the trends impacting the Retail, Hospitality, and Food & Beverage Industries. Alcohol Law - New Colorado Law Limits Grocery Stores’ Ability to Sell Hard Alcohol - Michael...more

Orrick, Herrington & Sutcliffe LLP

OCC provides an update on its security breach given institutional risk

On April 14, the OCC released a letter providing more details on the recent security breach involving its email systems. The breach — identified as a major incident under the Federal Information Security Modernization Act...more

Orrick, Herrington & Sutcliffe LLP

OCC announces major information security incident

On April 8, the OCC announced it had notified Congress of a major information security incident, as required by the Federal Information Security Modernization Act. The incident involved unauthorized access to emails and their...more

Alston & Bird

Consumer Finance State Roundup - March 2025

Alston & Bird on

The latest edition of the Consumer Finance State Roundup highlights recently enacted measures of potential interest from two states: California: Effective January 1, California Assembly Bill 3108 addresses mortgage fraud. ...more

Arnall Golden Gregory LLP

Preparing for Enhanced POPIA Enforcement in South Africa

Recent statements by South Africa’s Information Regulator (“IR”) indicate an impending crackdown on data privacy compliance, specifically within the banking and insurance sectors. The IR has announced its intention to enforce...more

HaystackID

Santander Faces Major Cyber Attack Compromising Millions of Customers’ Data

HaystackID on

In May, Santander Bank faced a significant cybersecurity breach that affected millions of its customers and employees worldwide. The hacking group ShinyHunters claimed responsibility for the attack, which also targeted...more

Sheppard Mullin Richter & Hampton LLP

For Limited Use Only: Guidance on National Security Delay Determinations under the SEC Cyber Reporting Rule

On December 12, 2023, the Department of Justice (“DOJ”) issued guidance related to the process by which companies may request the United States Attorney General authorize delays of cyber incident disclosures, pursuant to a...more

Hogan Lovells

FTC amends Safeguards Rule to require non-banking financial institutions to report data breaches

Hogan Lovells on

Against the backdrop of the National Cybersecurity Strategy’s stated goal of harmonizing federal cyber incident reporting requirements, new requirements still continue to emerge. Among the latest is a Federal Trade Commission...more

Eversheds Sutherland (US) LLP

Updata: Your quarterly privacy & cybersecurity update - July - September 2023

Welcome to the latest edition of Updata – the international update from Eversheds Sutherland’s dedicated Privacy and Cybersecurity team. Updata provides you with a compilation of privacy and cybersecurity regulatory and...more

Orrick, Herrington & Sutcliffe LLP

FTC approves amendment to Safeguards Rule requiring nonbanks to report data breaches

On October 27, the FTC approved an amendment to the Safeguards Rule to require nonbanks to report data breaches. Under the amended rule, financial institutions, including mortgage brokers, motor vehicle dealers, and payday...more

Katten Muchin Rosenman LLP

New FTC Rule Requires Certain Financial Institutions to Report Loss of Unencrypted Customer Data

On October 27, the Federal Trade Commission (FTC or Commission) published a final rule expanding data breach notification requirements for certain financial institutions (Final Rule). Federal Register, will require entities...more

Console and Associates, P.C.

Over 36k Customers of City National Bank of Florida Affected by MOVEit Data Breach

On June 30, 2023, City National Bank of Florida (“CNBF”) filed a notice of data breach with the Attorney General of Maine, explaining that 36,306 of the bank’s customers were affected by a data breach involving software...more

EDRM - Electronic Discovery Reference Model

[Webinar] Banks in the Crosshairs: Cyberattacks and Aggressive Regulators - May 25th, 1:00 pm - 2:00 pm ET

Financial institutions are in a tough spot- caught between the “bad guys” (state-sponsored cyberattacks and cyber criminals) and “good guys” (ever more aggressive regulators)- what’s a bank to do??? Tune in to find out!...more

Foley Hoag LLP - Security, Privacy and the...

As If Bank Failures Aren’t Enough – Hackers Are Exploiting the Chaos to Breach Security

The Massachusetts State Police Commonwealth Fusion Center (CFC) believes that cyber actors may use the current bank failures for future phishing and business email compromise (BEC) attacks. Cyber actors often use current...more

Davis Wright Tremaine LLP

Federal Court Holds Financial Institution Liable for Business Email Compromise Loss

While ransomware attacks usually grab the headlines, business email compromise (BEC) attacks continue to cause massive financial losses for businesses. The FBI’s Internet Crime Complaint Center (IC3), reported BEC losses in...more

Alston & Bird

Payments Docket - June 2022

Alston & Bird on

Welcome to the first edition of the Payments Docket, our roundup of key litigation involving the payment industry. This edition features a stolen cell phone number used to buy cryptocurrency, a pair of class actions accusing...more

Blank Rome LLP

What Banks Need to Know About New Data Breach Notification Requirements

Blank Rome LLP on

Given the omnipresent concern about cyber attacks targeting the banking industry, the FDIC, OCC and Federal Reserve recently published a new joint final rule establishing enhanced security incident notification requirements...more

Benesch

Federal Agencies Issue New Breach Notification Rules for Banking Organizations and Banking Service Providers

Benesch on

Banking organizations must notify the appropriate agency within 36 hours of certain computer-security incidents; and banking service providers must notify affected banking organizations as soon as possible in the event of an...more

BakerHostetler

Federal Banking Regulators Issue 36-Hour Computer-Security Incident Notification Requirement

BakerHostetler on

As the federal government continues its whole-of-government response to cyber incidents, federal banking regulators took action to impose a new notice requirement on federally regulated banks. In November, the Federal Deposit...more

Dorsey & Whitney LLP

The Prudential Bank Regulators Adopt Federal Data Interruption Notice Requirements for FDIC-Insured Institutions and Service...

Dorsey & Whitney LLP on

On November 23, 2021, the Office of the Comptroller of the Currency (the “OCC”), the Federal Deposit Insurance Corporation (the “FDIC”) and the Federal Reserve Board (the “Prudential Regulators”) exercised their collective...more

Sheppard Mullin Richter & Hampton LLP

Beginning in May 2022 Banks Will Have 36 Hours to Disclose Certain Types of Cyber Incidents

Federal banking regulators issued a final rule that impacts how banks and other regulated entities report certain data incidents. Those subject to these new reporting requirements include U.S. banks and bank service...more

Cooley LLP

36-Hour Breach Notification Rule to Go into Effect for Banking Organizations

Cooley LLP on

On November 18, 2021, three US agencies – the Office of the Comptroller of the Currency (OCC), the Federal Reserve Board (FRB) and the Federal Deposit Insurance Corporation (FDIC) – issued a joint rule concerning...more

Steptoe & Johnson PLLC

Computer-Security Incident Rule Creates New Notification Requirements for Banking Organizations and Bank Service Providers

Steptoe & Johnson PLLC on

On November 18, 2021, the Federal Deposit Insurance Corporation (FDIC), the Board of Governors of the Federal Reserve System (FRB), and the Office of the Comptroller of the Currency (OCC) issued a joint final rule (the...more

Morgan Lewis - All Things FinReg

Federal Banking Agencies Adopt New Computer-Security Incident Notification Requirements

The three federal banking agencies (i.e., the Federal Reserve Board, the Federal Deposit Insurance Corporation, and the Office of the Comptroller of the Currency—collectively, the Agencies) published a final rule (the Rule)...more

Troutman Pepper Locke

Think Fast: Banking Regulators Release Final Computer-Security Incident Notification Requirements

Troutman Pepper Locke on

Introduction - On November 18, federal banking agencies issued the long-awaited final rule, establishing data security incident response notification requirements for “banking organizations” and “bank service providers”...more

134 Results
 / 
View per page
Page: of 6

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
- hide
- hide