Adobe To Pay $1M For Data Breach, Bolster Security, North Carolina AG Says
ncdoj.gov
ncdoj.gov
For example
Social security number $5000
Credit card number $1000
Address $500
Telephone $200
Email $100
but the op might have been meaning over a 10 year period... ?
every year I see numbers going up in discussions here, with a recent claim that a netflix engineer cost was $430k (salary + overhead). sr engineers at netflix on glassdoor were touching $200k - the "cost" (wild-ass guess on part of the poster) seems a bit out of whack, and I was negatively exaggerating for effect.
But also I originally thought this was damages for a long-running practice - it wasn't. A 2013 data breach, from the article.
NC is getting a whopping $70k from this - likely many multiples of that eaten up in time/money and opportunity costs. I've seen a bit of "yay, there's precedent for paying a fine for this sort of thing" but this fine just put a price on this sort of activity. Data breach affecting someone in NC? You'll face a fine of $1.50 per account. :/
And also 152,989,508 email addresses were leaked, with sufficient information to derive the password in many cases.
I got interested in this at the time and was pretty stunned at how easily I could mine passwords: http://olivernash.org/2014/01/03/dna-of-a-password-disaster/...
The requirements for compliance are absolutely non-trivial, so I suggest that startups (and older companies) start designing compliance and privacy into their business processes and systems already today.
Leaves corporates with very little motivation to take such breaches seriously.