By now massive data breaches have become all too familiar to the millions of Americans who have been affected by them and whose private information has been stolen and consequences unknown. What’s going on? The answer is, no one knows except the hackers, and they aren’t talking.
Get Instant Access to This Article
Subscribe to Hartford Business Journal and get immediate access to all of our subscriber-only content and much more.
- Critical Hartford and Connecticut business news updated daily.
- Immediate access to all subscriber-only content on our website.
- Bi-weekly print or digital editions of our award-winning publication.
- Special bonus issues like the Hartford Book of Lists.
- Exclusive ticket prize draws for our in-person events.
Click here to purchase a paywall bypass link for this article.
By now massive data breaches have become all too familiar to the millions of Americans who have been affected by them and whose private information has been stolen and consequences unknown. What's going on? The answer is, no one knows except the hackers, and they aren't talking.
First, some facts: Three separate health insurance companies have reported massive breaches of their recordkeeping systems, involving millions of customers (1.1 million at CareFirst, up to 11 million at Primera and 79 million at Anthem). Even the Internal Revenue Service reports that more than 100,000 of its files were hacked.
And that's just the hacks reported. At a recent conference of cyber-security professionals, 20 percent said they had worked at companies that hid security breaches. Has your personal information — social security number, health information, etc. — been hacked so that criminals now have it? Not unlikely, and if it hasn't been, it may well be before too long.
The Connecticut legislature seems to have awakened to the problem with the passage of a new law requiring those conducting business in the state that own or license the personal information of residents to offer free identity theft protection services for at least one year following a data breach. The law also requires companies to set up protocols to ensure their customers' most private data is kept secure. Companies must also encrypt all data in transit, whether it's sent over the Internet or kept on a laptop or flash drive.
With all the news accounts of hacking, these companies certainly should have known to encrypt their data. Nevertheless, the legislature's move is a good one. The bill was just signed by Gov. Dannel P. Malloy.
So who is doing the hacking? Here's where it gets even creepier. The leading suspects are foreign governments. The New York Times reports that the leading suspect is believed to be China, and there are lots of other governments that may want to get on the bandwagon. But why? What's in it for China — or Russia, North Korea or, who knows, France or Germany — to commit this invasion? Apparently the answer is, we don't know for sure.
On a national level, it may be all to the good that while hackers, from whatever location, are attacking data systems they are at least being detected at some point. Every detection is an opportunity to improve security and help the defense keep up with the offense.
For individuals, this particular kind of invasion of privacy is unprecedented. Is it more or less scary than having our data collected by the government on a gigantic scale? The answer may be different for different people. But at least with this type of hacking there is someone — our government — trying to detect and thwart it. And at least there is some possibility for individuals to do something about it.
Each of these massive data breaches is responded to with class-action lawsuits on behalf of the individuals and families whose personal data has been compromised. The purpose of the private lawsuits is to spur large companies to keep up with the state of the art in thwarting security breaches. The spur, of course, is the requirement that the companies compensate the victims for intrusions that could have been prevented and that cause anxiety or worse for the customers of these giant firms.
Most commonly, we hear about people who discover that a bogus tax return has been filed in their name. Who profits from that kind of nastiness? In the long run, probably no one, but it is not only massively inconvenient, it is scary, like being followed.
So the good news is that most likely this kind of massive breach is not the beachhead for a huge epidemic of fraud and identity theft that will lead to the emptying of tens of millions of bank accounts. The bad news is that we don't know how, or whether, it can be stopped or, to be realistic, just what the implications are for our interconnected society.
David N. Rosen is the lead attorney of New Haven-based David Rosen & Associates P.C., which has filed a class action lawsuit against one large health insurance company as a result of a data breach.
Read more
