share_log

FTC Finalizes Order With Blackbaud Related To Allegations The Firm's Security Failures Led To Data Breach

FTC Finalizes Order With Blackbaud Related To Allegations The Firm's Security Failures Led To Data Breach

聯邦貿易委員會與Blackbaud敲定了與該公司安全故障導致數據泄露的指控有關的訂單
Benzinga ·  05/20 11:08

The Federal Trade Commission has finalized an order against Blackbaud Inc. settling allegations that its lax security practices allowed a hacker to breach the company's network and access the personal data of millions of consumers including Social Security and bank account numbers.

聯邦貿易委員會已經敲定了對Blackbaud Inc.的命令,該命令解決了有關其寬鬆的安全措施允許黑客入侵該公司網絡並訪問包括社會保障和銀行賬號在內的數百萬消費者的個人數據的指控。

In a complaint first announced in February 2024, the FTC charged that the South Carolina firm, which provides data services and financial, fundraising, and administrative software services to companies, nonprofits and others, failed to implement appropriate safeguards to secure and protect the vast amounts of personal data it collects. As a result of these failures, a hacker in early 2020 exploited weaknesses in Blackbaud's networks, which went undetected for three months, allowing the hacker to remove massive amounts of unencrypted sensitive consumer data belonging to Blackbaud's customers. The company waited nearly two months to notify its customers about the breach and then misled consumers about the extent of the data that was stolen, according to the complaint.

在2024年2月首次宣佈的投訴中,聯邦貿易委員會指控這家向公司、非營利組織和其他機構提供數據服務以及財務、籌款和管理軟件服務的南卡羅來納州公司未能採取適當的保障措施來保護和保護其收集的大量個人數據。由於這些失敗,一名黑客在2020年初利用了Blackbaud網絡中的漏洞,該漏洞在三個月內未被發現,這使黑客得以刪除屬於Blackbaud客戶的大量未加密的敏感消費者數據。投訴稱,該公司等了將近兩個月才將違規行爲通知客戶,然後在數據被盜程度上誤導了消費者。

Under the order, Blackbaud is required to delete data that it no longer needs to provide its products or services and is prohibited from misrepresenting its data security and data retention policies. The order also requires Blackbaud to develop a comprehensive information security program that would address the issues highlighted by the FTC's complaint and put in place a data retention schedule outlining its data deletion practices. It also requires Blackbaud to notify the FTC if it experiences a future data breach that it is required to report to any other local, state, or federal agency.

根據該命令,Blackbaud必須刪除不再需要提供其產品或服務的數據,並禁止其虛假陳述其數據安全和數據保留政策。該命令還要求Blackbaud制定一項全面的信息安全計劃,以解決聯邦貿易委員會投訴中強調的問題,並制定數據保留時間表,概述其數據刪除做法。它還要求Blackbaud在未來遇到數據泄露時通知聯邦貿易委員會,並必須向任何其他地方、州或聯邦機構報告。

After receiving two comments, the Commission voted 3-0-2 to give final approval to the settlement. Commissioner Andrew Ferguson did not participate and Commissioner Melissa Holyoak was recused.

在收到兩條評論後,委員會以3比0-2票最終批准了和解協議。專員安德魯·弗格森沒有參加,專員梅利莎·霍利奧克被迴避了。

The Federal Trade Commission works to promote competition and protect and educate consumers. The FTC will never demand money, make threats, tell you to transfer money, or promise you a prize. Learn more about consumer topics at consumer.ftc.gov, or report fraud, scams, and bad business practices at ReportFraud.ftc.gov. Follow the FTC on social media, read consumer alerts and the business blog, and sign up to get the latest FTC news and alerts.

聯邦貿易委員會致力於促進競爭,保護和教育消費者。聯邦貿易委員會絕不會索要錢、進行威脅、叫你轉賬或許諾給你獎品。在consumer.ftc.gov上了解有關消費者話題的更多信息,或在Reportfraud.ftc.gov上舉報欺詐、詐騙和不良商業行爲。在社交媒體上關注聯邦貿易委員會,閱讀消費者提醒和商業博客,並註冊以獲取最新的聯邦貿易委員會新聞和提醒。

声明:本內容僅用作提供資訊及教育之目的,不構成對任何特定投資或投資策略的推薦或認可。 更多信息
    搶先評論