Now on Demand Ransomware Resilience & Recovery Summit - All Sessions Available
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Compliance

California Introduces New Data Breach Notification Law

California Attorney General Xavier Becerra and Assemblymember Marc Levine last week introduced a new piece of legislation that would require organizations to notify consumers if their passport or biometric information has been compromised in a data breach.

California Attorney General Xavier Becerra and Assemblymember Marc Levine last week introduced a new piece of legislation that would require organizations to notify consumers if their passport or biometric information has been compromised in a data breach.

In 2003, California passed a data breach notification law requiring businesses to inform consumers if their personal data was or may have been stolen as a result of security breach. This data includes social security numbers, credit card numbers, driver’s license numbers, and medical and health insurance information.

Officials have now unveiled a new bill, AB 1130, which adds biometric information and passport numbers to that list in an effort to close what they have described as a “loophole” in existing legislation.

“There is a real danger when our personal information is not protected by those we trust,” said Assemblymember Levine. “Businesses must do more to protect personal data, and I am proud to stand with Attorney General Becerra in demanding greater disclosure by a company when a data breach has occurred. AB 1130 will increase our efforts to protect consumers from fraud and affirms our commitment to demand the strongest consumer protections in the nation.”

The new bill comes in response to the massive data breach suffered recently by Marriott, which impacted hundreds of millions of individuals. Attackers reportedly accessed more than 25 million passport numbers, including over 5 million that had not been encrypted.

There have also been some security incidents in recent years that resulted in biometric data getting compromised. One example is the breach suffered in 2017 by micro markets solutions provider Avanti Markets, which revealed that a piece of malware had helped cybercriminals steal, among other types of information, biometric data associated with a fingerprint scanner.

When introducing the new bill, authorities in California mentioned not only fingerprints, but also retina or iris images.

“While the risk of hackers actually recreating your passport with just your number is relatively low, be aware hackers can use your passport number, combined with other information they might have acquired, like your name, date of birth, etc., to ‘verify’ your identity and attempt to access financial accounts or create new ones — that’s why it’s vitally important for breaches like this to be disclosed as soon as possible, so users can take protective measures, like changing passwords, setting up two-factor authentication and keeping a close eye on financial records,” Francis Dinha, CEO of OpenVPN, told SecurityWeek.

Advertisement. Scroll to continue reading.

Drew Lydecker, president and co-founder of AVANT Communications, commented, “Regardless of size or industry, all companies own some kind of intellectual property — and they need to believe there’s someone out there trying to get a hold of this information. In the case of Marriott, a massive organization with thousands of properties and high transaction volume, it’s difficult to respond quickly to threats, especially as the cybersecurity talent crisis continues to intensify. Recent estimates indicate that there could be as many as 3.5 million unfilled cybersecurity positions by 2021.”

Related: California IoT Cybersecurity Bill Signed into Law

Related: California to Ban Weak Passwords

Related: Face Recognition Nabs Fake Passport User at US Airport

Related: Schumer Says Marriott Should Pay to Replace Hacked Passports

Written By

Eduard Kovacs (@EduardKovacs) is a managing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Click to comment

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join the session as we discuss the challenges and best practices for cybersecurity leaders managing cloud identities.

Register

SecurityWeek’s Ransomware Resilience and Recovery Summit helps businesses to plan, prepare, and recover from a ransomware incident.

Register

People on the Move

Bill Dunnion has joined telecommunications giant Mitel as Chief Information Security Officer.

MSSP Dataprise has appointed Nima Khamooshi as Vice President of Cybersecurity.

Backup and recovery firm Keepit has hired Kim Larsen as CISO.

More People On The Move

Expert Insights

Related Content

Application Security

Cycode, a startup that provides solutions for protecting software source code, emerged from stealth mode on Tuesday with $4.6 million in seed funding.

Cybercrime

A recently disclosed vBulletin vulnerability, which had a zero-day status for roughly two days last week, was exploited in a hacker attack targeting the...

Cybercrime

The changing nature of what we still generally call ransomware will continue through 2023, driven by three primary conditions.

Data Protection

The cryptopocalypse is the point at which quantum computing becomes powerful enough to use Shor’s algorithm to crack PKI encryption.

Cybercrime

As it evolves, web3 will contain and increase all the security issues of web2 – and perhaps add a few more.

CISO Strategy

SecurityWeek spoke with more than 300 cybersecurity experts to see what is bubbling beneath the surface, and examine how those evolving threats will present...

Cybercrime

Luxury retailer Neiman Marcus Group informed some customers last week that their online accounts had been breached by hackers.