Lawyers cough up $200k after health data stolen in Microsoft Exchange pillaging
theregister.com
theregister.com
Other companies may be taking note, but more of the sheer affordability of that.
I think 200k for each person involved would be entirely reasonable and make the companies and people really fear these crimes.
I think "damage" and "importance" are important distinctions. I'd find it worse if a person non-violently stole $100 worth of goods from the homes of 50,000 people than stealing a Van Gogh from the home of one person. And I'd find the Van Gogh theft a bit worse than an equivalent theft from a bank.
This is one case of negligence that led to the theft of all of these records. It also seems, at worst, negligence that led to the theft, not a purposeful disclosure. And not negligence in their license specialty (law), but IT negligence. Did Redmond take affirmative action to ensure all instances of its server software was patched? Redmond knows who it sold software to. Why would they not also be at fault? Servers are their specialty.
Harsh penalties for negligence, even for serious events such as human death, should probably be limited to negligence within the scope of a person's or business' specialty. With less harsh penalties for incidental negligence.
If probable harm happens to people because of these record leaks I believe the law firm should be part of the joint liability to make that harm as financially whole as possible. But that's what a civil suit is for, not a DA enforcement.
This was a highly publicized vulnerability, with a patch readily available.
There are degrees to negligence, and this one is only slightly better than literally leaving the door to their office open at night.
https://web.archive.org/web/20220930183225/https://threadrea...
They could very well have ran on-prem Exchange and standalone/boxed copies of Office 2013, paid for once long ago. Now come and say
>"oh you have to pay again for newer versions or pay for per-user Office 365"
>"why? what we have works fine, we dont need the new features"
>"for security"
>"thats your job"
etc ect
You have only worked with certain clients I hear.
Maybe the IT folks properly and accurately described the risk, and were stopped by non-IT management. Alternatively, maybe IT didn't push as hard, describe the risk properly, or want to deal with an annoying patching process. Microsoft also deserves blame for the difficult of patching, as your link describes.
Either way, the real victims are the 114,979 folks who had their information stolen. If a bank gets robbed because they didn't do basic things like locking the doors or hiring a security guard, they don't get to raise their hands and say "BuT cRiMInAlS". This is literally the same as what IT does whenever they get hit by a highly publicized exploit that's had a patch for months.
A $5 million Van Gogh would be a very bad one. You can keep it.
So, in this case, they would only be able to advertise: “We value your privacy at $2.” And see how many takers they would get. If they want to make a more compelling privacy case, then they would be required to take on the risk of their increased promises in the event of breach.
This allows small companies with no security to not get slaughtered as long as they accurately inform you of the risk profile of using their service, while preventing large companies that you would expect to be stable from lying about their guarantees.
My point being, I have doubts that this business made it months after the fact, unless there was something else involved. I saw a colleague building sandboxes, just put online, not yet on shodan, with this exploit being a few days old, and they would see ransomware within the hour.