Privacy and Cybersecurity Investigations
Overview
Data thefts, cyber hacking, denial-of-service attacks, ransomware, and other threats to electronically stored information are growing in both scope and sophistication. The costs associated with preventing and responding to such events—whether in lost revenues, tarnished reputations, regulatory fines, government investigations, and consumer class action lawsuits—are also increasing.
Insights
Firm News | 9 min read | 06.06.24
Crowell Attains Leading Rankings in Chambers USA 2024
Washington – June 6, 2024: Crowell & Moring earned 78 rankings for 67 lawyers, as well as 41 national and statewide practice area rankings, in the Chambers USA 2024 guide. The rankings are driven by independent interviews of clients and lawyers at peer firms.
Publication | 10.09.23
Cybersecurity Threats Increase Civil And Criminal Liability For Government Contractors
Client Alert | 6 min read | 07.28.23
Five Key Takeaways from the SEC’s Final Cybersecurity Rules for Public Companies
Publication | 01.10.23
Representative Matters
- Defended a health care client in two separate breaches. In incidents that both involved more than 1.5 million plan members, we represented the client throughout the breach response process, including the internal investigation and investigations by state attorneys general and departments of insurance and the U.S. Health and Human Services Office of Civil Rights (OCR). We also defended the client against numerous related class action lawsuits, and ultimately resolved the OCR investigation without payment of fines or mandatory corrective actions.
- Represented a HIPAA-covered entity. When an employee of our client’s business associate stole and sold data regarding the client’s employees, we persuaded the business associate to pay for all costs related to the incident investigation and notification, and obtained a broad indemnity agreement.
- Represented a Fortune 500 company in cyber theft litigation. In addition to providing litigation counsel, we coordinated forensics efforts to track down and prove improper download of company computer files and addressed issues relating to computer management and inventory of data.
- Represented a global provider of software to the energy industry in response to a security incident. We handled all aspects of the incident response, including the investigation and notifications to individuals, state attorneys general, and our client’s utility clients. We also worked with the company to develop post-incident processes that were satisfactory to their utility clients, including recommending changes to the customer application and data collection process for utility rebate programs.
- Advised and represented energy and energy transportation companies on multiple and simultaneous investigations. These investigations were in connection with an intrusion by an advanced threat actor related to industrial control and business systems.
- Represented a transportation industry client in a breach involving sensitive employee information. We coordinated the forensic investigation, reported to and assisted the FBI and local law enforcement in the criminal investigation, prepared notification to individuals and authorities, negotiated credit services, and assisted with public relations issues. No enforcement actions were brought, and the client received multiple letters from attorneys general praising its prompt and effective response to the situation.
- Represented a Fortune 500 health care services provider in response to a stolen laptop containing sensitive information. We assisted with forensics, notification to individuals and authorities, coordination of public communications, and the defense of state and federal regulator investigations.
- Represented a global financial institution on a sophisticated international criminal attack involving theft of significant funds. Our investigation involved coordinating with the client’s insurance company and multiple federal law enforcement agencies, and resulted in the criminal prosecution and arrest of the attackers.
- Advised a national retail chain on theft of millions of financial information records. This matter required an extensive investigation involving federal and state law enforcement coordination and nationwide disclosures.
- Represented a defense contractor targeted by a hacktivist group. The system of our client’s vendor was accessed by a hacktivist group and employee travel information and PII was compromised. We assisted with the forensic investigation and coordinated with the vendor organization to provide notification to individuals and authorities. We also assisted our client with internal notifications and employee-relations issues.
- Represented a trade association in investigating and responding to a cybersecurity attack. We prepared notifications to individuals whose information may have been accessed, retained and directed a forensic consultant to investigate the cyber incident, provided guidance to our client’s employees to prevent similar incidents, and assisted with outreach to law enforcement.
- Advised a large company on the payment of a “ransom” and the legal and policy issues surrounding such action. We engaged in time sensitive discussions to evaluate for this client the legal issues surrounding the payment of funds to an unknown third party in exchange for the unlocking of data, and the policy and reputational implications of doing so.
Insights
Firm News | 9 min read | 06.06.24
Crowell Attains Leading Rankings in Chambers USA 2024
Washington – June 6, 2024: Crowell & Moring earned 78 rankings for 67 lawyers, as well as 41 national and statewide practice area rankings, in the Chambers USA 2024 guide. The rankings are driven by independent interviews of clients and lawyers at peer firms.
Publication | 10.09.23
Cybersecurity Threats Increase Civil And Criminal Liability For Government Contractors
Client Alert | 6 min read | 07.28.23
Five Key Takeaways from the SEC’s Final Cybersecurity Rules for Public Companies
Publication | 01.10.23
Insights
Cybersecurity Threats Increase Civil And Criminal Liability For Government Contractors
|10.09.23
Corporate Compliance Insights
Insights
Firm News | 9 min read | 06.06.24
Crowell Attains Leading Rankings in Chambers USA 2024
Washington – June 6, 2024: Crowell & Moring earned 78 rankings for 67 lawyers, as well as 41 national and statewide practice area rankings, in the Chambers USA 2024 guide. The rankings are driven by independent interviews of clients and lawyers at peer firms.
Publication | 10.09.23
Cybersecurity Threats Increase Civil And Criminal Liability For Government Contractors
Client Alert | 6 min read | 07.28.23
Five Key Takeaways from the SEC’s Final Cybersecurity Rules for Public Companies
Publication | 01.10.23