Skip to content

menu

Data Protection Report logo
HomeAboutContact
Search
Close
Compliance and risk managementRegulatory responseData breachCybersecurity
View topics Archives
Subscribe

Data Protection Report

Data protection legal insight at the speed of technology

Ransomware

Subscribe to Ransomware via RSS

Dutch DPA publishes report on personal data breaches

Photo of Naomi SchuitemaPhoto of Jurriaan JansenPhoto of Alexander McGuirePhoto of Tim Jones
By Naomi Schuitema, Jurriaan Jansen, Alexander McGuire & Tim Jones on September 3, 2025

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) (Dutch DPA) recently published a report on personal data breaches, which provides valuable insights into the Dutch DPA’s views on incident response. It also contains some helpful statistics.

Increase…

Rare recovery in a complex ransomware case: Major NetWalker arrest leads to significant asset seizure

Photo of Andrew McCoomb
By Andrew McCoomb on December 8, 2022

Norton Rose Fulbright Canada’s cyber litigation team recently obtained an order in favour of an insurer, granting it relief from forfeiture in respect of more than 11 bitcoins from the assets seized from a prolific ransomware gang.[1] This case…

Subscribe to Data Protection Report

Subscribe to this publication

FTC Signals Additional Scrutiny for Data Breaches

Photo of Anna Rudawski (US)Photo of Chris Cwalina (US)
By Anna Rudawski (US) & Chris Cwalina (US) on May 25, 2022

On May 20, 2022, the Federal Trade Commission (FTC) stated that failure to disclose a data breach may be a violation of Section 5 of the FTC Act.  Historically, the FTC has not been explicit about its notification…

The UK’s ICO issues a monetary penalty notice to professional services firm after ransomware attack

Photo of Steven Hadwin (UK)Photo of Tim Jones
By Steven Hadwin (UK) & Tim Jones on March 22, 2022

On 10 March 2022, the Information Commissioner’s Office (ICO) issued a monetary penalty notice to a professional services firm (the Firm) to the tune of £98,000 for a breach of Article 5(1)(f) of the General Data Protection…

Congress Agrees – 72-Hour Cyber Incident Reporting Requirement to Take Effect

Photo of Chris Cwalina (US)Photo of Ashley Zatloukal (US)Photo of Anna Rudawski (US)Photo of Will Daugherty (US)Photo of Alexis Wilpon (US)
By Chris Cwalina (US), Ashley Zatloukal (US), Anna Rudawski (US), Will Daugherty (US) & Alexis Wilpon (US) on March 16, 2022

On March 15, 2022, President Biden signed an omnibus spending bill into law, which, in part, requires companies to report cyber incidents and ransom payments.  The relevant portions of the law, titled the Cyber Incident Reporting for Critical Infrastructure Act…

Who gets to decide to pay the ransom in a ransomware attack?

Photo of Chris Cwalina (US)Photo of Kevin J. Harnisch (US)Photo of Ilana Beth Sinkin (US)Photo of Ashley Zatloukal (US)
By Chris Cwalina (US), Kevin J. Harnisch (US), Ilana Beth Sinkin (US) & Ashley Zatloukal (US) on January 18, 2022

The onslaught of ransomware attacks since the pandemic began has not slowed.  Organizations have been faced with the task of continuously reviewing their cybersecurity programs to ensure they are following best practices to protect against ransomware groups.  But organizations also…

Cyber authorities sound the alarm on critical vulnerability In Java Library

Photo of Chris Cwalina (US)Photo of Anna Rudawski (US)Photo of David Kessler (US)Photo of Will Daugherty (US)
By David Kitchen (US), Chris Cwalina (US), Anna Rudawski (US), David Kessler (US) & Will Daugherty (US) on December 13, 2021

On December 9, 2021 a critical vulnerability (CVE-2021-44228) was reported within the Apache Log4j Java logging framework. The vulnerability allows threat actors to remotely execute code on both on-premises and cloud-based application servers, thereby obtaining control of the impacted servers.…

US Senate considers mandating 24-hour reporting requirement for ransom payments

Photo of Kate Nelson (US)
By David Kitchen (US) & Kate Nelson (US) on October 5, 2021

On September 28, 2021, the US Senate Homeland Security and Governmental Affairs Committee released a draft bill that would, among other things, require nearly all entities that make a ransom payment as the result of a ransomware attack against the…

OFAC Announces New Measures to Address Ransomware Attacks

Photo of Chris Cwalina (US)Photo of Ashley Zatloukal (US)Photo of Stefan H. Reisinger (US)
By Chris Cwalina (US), Ashley Zatloukal (US) & Stefan H. Reisinger (US) on September 21, 2021

The U.S. Department of Treasury, Office of Foreign Assets Control (“OFAC”) implemented additional measures today to combat the growing ransomware problem.  OFAC’s measures consist of: (1) the designation of the entire SUEX OTC, S.R.O. (“SUEX”) crypto-currency exchange (SUEX) to the…

Data Protection Report

Facebook Twitter RSS LinkedIn YouTube
Published by
Norton Rose Fulbright LLP logo
DisclaimerPrivacy policy

About

More than a news source, the Data Protection Report provides thought leadership on emerging privacy, data protection and cybersecurity issues, and helps its readers proactively address risks and anticipate next steps in this crucial emerging field.

Read more

Topics

Archives

Copyright © 2025, Norton Rose Fulbright LLP. All rights reserved.