Blog

Security, Privacy and the Law

Security and privacy issues encountered by businesses often require immediate and discreet solutions. We cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Security, Privacy and the Law
When AI Becomes the Hacker: What the OpenAI–Hugging Face Breach Means for Your Organization
Blog July 23, 2026
The disclosure that OpenAI's own AI models autonomously broke out of a sandboxed testing environment and hacked into Hugging Face's production infrastructure is, without exaggeration or hyperbole, a watershed moment for anyone advising on data privacy and cybersecurity…
Kaseya VSA Cyberattack:  What Kaseya and the Feds Are Saying
Blog July 06, 2021
If you arent following the ransomware attack on Kaseyas VSA product and approximately 800-1500 of its users, you should be.  Like many cyberattacks, this one came on the verge of a holiday weekend.  As the company itself notes, Kaseya's VSA product has unfortunately been the victim of a sophisticated cyberattack.   Due to our teams' fast response, we believe that this has been localized to a very small number of on-premises customers only…
The SolarWinds Orion Hack: The Basics You Need to Know
Blog December 20, 2020
By now, you have heard about the SolarWinds Orion hack. But what do you need to know about it? First, if you want or need the technical details, the Cybersecurity and Infrastructure Security Agency (CISA) has them. In particular, on December 13, 2020, CISA released Emergency Directive 21-01: Mitigate SolarWinds Orion Code Compromise, ordering federal civilian executive branch departments and agencies to disconnect affected devices…
Is the May 12 Massive Ransomware Attack a Turning Point?
Blog May 14, 2017
Those “in the know” in the cybersecurity world have been aware for more than a year of the threat posed by ransomware, a type of malware that locks victims' access to their files until they pay a ransom.  But discussion of the threat was mostly localized to cybersecurity professionals, blogs like this one, and various guidances released by federal agencies during 2016. But ransomware may just have entered the general public consciousness in a big way…
Google Docs Phishing (in real time, May 3, 2017, 4:30pm)
Blog May 03, 2017
If you check your email this afternoon, you may see a message that someone you know is sharing something on Google Docs. You should verify that separately before opening, as there is a widespread phishing attempt going around using such an invitation…
Quick Thoughts About the Yahoo Breach
Blog September 22, 2016
Another day, another 500 million Yahoo accounts breached. Our friends at the FTC are right on top of this with guidance for individuals with Yahoo accounts.  First and foremost, change your Yahoo password. According to Yahoo, the breached information may have included names, email addresses, telephone numbers, dates of birth, passwords, and security questions. Yahoo believes this information was stolen in late 2014…
Cybersecurity News and Notes – August 29, 2016
Blog August 29, 2016
In Case You Missed It: Sometimes data breaches crop-up in the most unlikely of places.  Last week we learned that the vendor that handles fish and hunting licenses for the states of Idaho, Oregon, and Washington was hacked.  The breach potentially exposed the following information for those with fishing or hunting licenses in those northwest states: names, addresses, driver's license numbers, dates of birth, and the last four digits of Social Security numbers…
Health Insurer Hit With A Record HIPAA Penalty:  What Does It Mean?
Blog March 06, 2014
Triple-S Salud Inc., a Puerto Rican health insurer, has been hit with a $6.8 million penalty from the Office of Civil Rights of the Department of Health and Human Services for a massive data breach.  Triple-S (known as ASES in Spanish) has posted a notice on its website regarding the breach.  The penalty, which also is described in a securities filing, is based a breach involving 13,336 of Triple-S's Dual Eligible Medicare beneficiaries…
TripAdvisor Reports Data Breach
Blog March 25, 2011
If you are like me, you may have received an email fromTripAdvisor, alerting you that an unauthorized third party had stolen part of TripAdvisors member email list. The text of that email was as follows: To our travel community: This past weekend we discovered that an unauthorized third party had stolen part of TripAdvisors member email list. Weve confirmed the source of the vulnerability and shut it down…
1 of 5

ABOUT

The Foley Hoag Security, Privacy and the Law Blog focuses on the security and privacy issues encountered by businesses that often require immediate and discreet solutions. Here we cover topics that arise from guiding our clients through the process of complying with the ever-growing number of state, federal and international laws governing information security, identity theft, surveillance and other privacy issues.

Our lawyers assist clients with questions on how to legally and ethically investigate abusive e-mail, take down infringing Web sites, maintain surveillance of company facilities and information systems, and remediate breaches of security. We work with clients to ensure the legality and success of existing security policies and protocols and help them develop new programs when necessary. Our lawyers have managed unexpected crises ranging from surprise inspections by government investigators to obtaining emergency court orders needed to secure stolen company computers from rogue insiders.

Blog Authors