ABA Banking Journal
No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
SUBSCRIBE
ABA Banking Journal
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive
No Result
View All Result
No Result
View All Result
Home Cybersecurity

Data Theft Damages: Who Pays?

September 1, 2016
Reading Time: 3 mins read

By Dawn Causey, Thomas Pinder and Andrew Doersam

When it comes to data breaches, the hack of the archaic Myspace—the failed social media platform that was rendered obsolete by Facebook—proves nothing is safe. After Time Inc. acquired Myspace earlier this year, it discovered that in June 2013, a hacker named “Peace” stealthily stole username and password information from 360 million accounts.

The question posed by this particular breach is simple: did it matter? Was anyone injured as a result of the breach and, if so, did Time Inc. have cyber insurance that covered it? These are the same questions financial institutions of all sizes should ask themselves when confronted with a data compromise, whether it their own data or that of some other vendor or merchant.

Companies spend approximately $2 billion annually purchasing cyber insurance premiums with varying degrees of success, as reflected in current case law. For example, Medidata, a research technology company, sued its insurer for failing to cover $4.8 million in losses caused by an email scam that impersonated the company’s CEO. The email included the CEO’s picture and a “cc” to a pseudo attorney. After several email exchanges and phone calls with the scammers, a Medidata employee transferred $4.8 million to an account in China. The insurer argued that its $5 million policy only covered hacking, not voluntary transfers of money. In March, the judge ordered more discovery and refused to issue a ruling, claiming the record was insufficient regarding the manner in which Medidata’s database was compromised.

P.F. Chang’s 2014 data breach resulted in a mixed outcome from its insurer. While P.F. Chang’s recovered $1.7 million for claims directly resulting from the data breach, the insurer refused to reimburse an additional $2 million in fees and assessments charged back by MasterCard to its payment processor, BAMS. An Arizona federal court sided with the insurer and denied P.F. Chang’s claim for reimbursement. The court ruled that the contractual liability exclusion barred recovery because P.F. Chang’s agreed that its credit card acquirer could charge back the credit card brand costs and assessments.

Depending on the nature of the breach, victims may find it difficult to demonstrate any actual harm resulting from their compromised information. Potential data breach plaintiffs, such as the former Myspace users, commonly claim they have standing to sue based on the risk of possible injury and expenses incurred dealing with that risk. Although most of the Myspace accounts were dormant, many of the users may still be using the same or similar username and password combination on other websites. However, the Supreme Court’s recent decision in Spokeo v. Robins made clear that plaintiffs who claim statutory violations but have not suffered any real harm do not have standing.

Although Spokeo did not involve a data breach, the Court examined the level of harm required for a successful pleading. The Court held that a plaintiff must allege an injury that is both concrete and particularized—in other words, real and tangible. Although the risk of real harm may satisfy the concreteness requirement, the Court explained that bare allegations of a statutory violation, such as the publication of an incorrect zip code, would not qualify as a concrete injury. This new standard was recently applied by a Maryland federal court in Khan v. Children’s National Health System. That court ruled that plaintiffs must allege an injury showing actual or intended misuse of personal data for identity fraud in order to sue.

Case law is evolving concerning data breaches. Insurance coverage cases are becoming more frequent and suggest needing a clear understanding of what is and what is not covered. On the other hand, just because a breach occurs, it is not an automatic payday for plaintiffs. Real, demonstrable harm is required. Are we Myspace accountholders truly injured consumers or just remnants of outdated technology? Time will tell.

Dawn Causey is general counsel at ABA, where Thomas Pinder is SVP for litigation and Andrew Doersam is a paralegal.

Tags: CybersecurityData breaches
ShareTweetPin

Related Posts

Bill would strengthen criminal penalties for ATM robberies

State attorneys general express support for ATM crime bill

Compliance and Risk
August 14, 2026

Fifteen state attorneys general urged Congress to pass legislation ensuring that robberies of off-site ATMs carry the same legal consequences as bank robberies. ABA also supports the bill.

ABA urges ‘same risk, same regulation’ for digital assets

ABA urges federal regulation of AI, level playing field for financial services

Compliance and Risk
August 14, 2026

Congress should establish a nationally harmonized, risk-based framework for regulating artificial intelligence in the financial services sector, which would preempt state laws while assuring strong consumer protection and cybersecurity outcomes, ABA told House Financial Services Committee members.

ABA survey: Americans strongly support prohibiting crypto companies from offering yield-like rewards for holding stablecoin

ABA cautions against allowing state regulation that could expand stablecoin issuer activities

Newsbytes
August 13, 2026

As it seeks to implement the Genius Act, the Treasury Department should not allow states to greatly expand the scope of services offered by payment stablecoin issuers beyond what is spelled out in the law, ABA said.

FBI and CISA release updated cybersecurity advisory on Scattered Spider

White House announces new push to combat cybercrime, fraud

Compliance and Risk
August 13, 2026

President Trump directed federal law enforcement to create a new program that partners with the private sector to target transnational criminal organizations responsible for ransomware attacks, phishing campaigns and other cybercrimes.

State coalition seeks to block OCC preemption of interest-on-escrow laws

State coalition seeks to block OCC preemption of interest-on-escrow laws

Legal
August 12, 2026

A coalition of 10 states has filed a lawsuit to block two recent rulemakings by the OCC designed to establish a uniform federal framework for national banks operating across state lines.

Senate Democrats seek proposals for regulatory changes following recent bank closures

Senate adjourns with no vote on Clarity Act

Newsbytes
August 8, 2026

The Senate adjourned without holding a final vote on the Clarity Act, punting further action on the bill until at least September.

NEWSBYTES

Preliminary: Consumer sentiment fell in August

August 14, 2026

State attorneys general express support for ATM crime bill

August 14, 2026

ABA urges federal regulation of AI, level playing field for financial services

August 14, 2026

SPONSORED CONTENT

Beyond Surveillance: Rethinking Security for Modern Financial Institutions

Beyond Surveillance: Rethinking Security for Modern Financial Institutions

August 12, 2026
Relationship Banking at Scale: Why Banks Need The Digital Sales & Service Platform

Relationship Banking at Scale: Why Banks Need The Digital Sales & Service Platform

August 1, 2026
Why Your Systems Keep Slowing Down — and What to Do About It

Examiners Are Now Looking at Your Non-Core Systems

June 11, 2026
Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

Your Floorplan Audit and Your Credit Decision Are Weeks Apart. That Gap Has a Price.

June 1, 2026

PODCASTS

Podcast: Banking the brave new world of college athletics

August 4, 2026

Podcast: Tactics for meaningful strategic planning

July 28, 2026

Podcast: Why it might be time to revisit a key FDIC ratio

July 23, 2026

American Bankers Association
1333 New Hampshire Ave NW
Washington, DC 20036
1-800-BANKERS (800-226-5377)
www.aba.com
About ABA
Privacy Policy
Contact ABA

ABA Banking Journal
About ABA Banking Journal
Media Kit
Advertising
Subscribe

© 2026 American Bankers Association. All rights reserved.

No Result
View All Result
  • Topics
    • Ag Banking
    • Commercial Lending
    • Community Banking
    • Compliance and Risk
    • Cybersecurity
    • Economy
    • Human Resources
    • Insurance
    • Legal
    • Mortgage
    • Mutual Funds
    • Payments
    • Policy
    • Retail and Marketing
    • Tax and Accounting
    • Technology
    • Wealth Management
  • Newsbytes
  • Podcasts
  • Magazine
    • Subscribe
    • Advertise
    • Magazine Archive
    • Newsletter Archive
    • Podcast Archive
    • Sponsored Content Archive

© 2026 American Bankers Association. All rights reserved.