Security

CSO

Block sued after ex-staffer siphons customer data

'Don't be such a Square' hits different these days


Block – the digital payments giant formerly known as Square – faces allegations it failed to take adequate measures to protect customers' personal information.

A lawsuit [PDF], filed Tuesday in a federal district in Oakland, California, on behalf of two users of Cash App, operated by Block subsidiary Cash App Investing, claims the company failed to implement reasonable security. As a result, a former employee was able to download internal reports containing personal information after leaving the firm.

Coincidentally, Twitter – another venture co-founded by Block Head Jack Dorsey – was accused of subpar security by its former security chief in a recent whistleblower complaint.

Block disclosed the December 10, 2021 data theft on April 4, 2022, and stated it was contacting 8.2 million current and former customers about the privacy snafu. The biz said, "a former employee downloaded certain reports of its subsidiary Cash App Investing LLC … that contained some US customer information."

The employee had access to those reports while employed but in this instance downloaded the files after leaving the company. The data obtained included customers' full name and brokerage account numbers, and in some cases, brokerage portfolio values, brokerage portfolio holdings and/or stock trading activity for one trading day.

As far as the litigants are concerned, Block didn't meet its security obligations, failed to notify customers in a timely manner, provided too little information about the incident, and failed to offer credit or identity monitoring services.

Twitter founder Dorsey beats hasty retweet from the board

FROM MAY

"The breach occurred because [Block] failed to take reasonable measures to protect the Private Information it collected and stored," reads the complaint, which aspires to be certified in the United States as a class action. "Among other things, [Block] failed to implement data security measures designed to prevent this release of information to former employees."

Both of the plaintiffs – Michelle Salinas and Raymel Washington – saw unauthorized charges to their Cash App accounts in the wake of the December privacy breach, the lawsuit claims, and had to spend many hours trying to undo the damage. The pair are seeking damages and other punishment.

No evidence is presented that those unwanted charges were made by someone using data obtained as a result of the Block security fiasco. And in its disclosure notice, Block explicitly stated that the downloaded reports "did not include usernames or passwords," or other sensitive personal information. At the same time, a recent report claimed Cash App accounts are being actively targeted by hackers using information obtained from fraud sites peddling account information.

The Register asked Block to comment and to say whether the company has any reason to believe that reported Cash App cyber-heists may be linked to the company's December 2021 data breach.

So far, we've had no word from Block. ®

Send us news
8 Comments

Dump C++ and in Rust you should trust, Five Eyes agencies urge

Memory safety vulnerabilities need to be crushed with better code

Polish train maker denies claims its software bricked rolling stock maintained by competitor

Says it was probably hacked, which isn't good news either

Weak session keys let snoops take a byte out of your Bluetooth traffic

BLUFFS spying flaw present in iPhones, ThinkPad, plenty of chipsets

Atlassian security advisory reveals four fresh critical flaws – in mail with dead links

Bitbucket, Confluence and Jira all in danger, again. Sigh

Boffins devise 'universal backdoor' for image models to cause AI hallucinations

Data poisoning appears open to all

Amazon on the hook for predictably revolting use of concealed clothes hook spy cam

Judge finds plaintiff's claim – that Amazon knew about illicit usage – credible enough for case to proceed

Senate bill aims to stop Uncle Sam using facial recognition at airports

Legislation would eliminate TSA permission to use the tech, require database purge in 90 days

Five Eyes nations warn Moscow's mates at the Star Blizzard gang have new phishing targets

The Russians are coming! Err, they've already infiltrated UK, US inboxes

Google, Amazon, Microsoft make the Mozilla naughty list for Christmas shopping

Big Tech's toys have privacy problems. Why not buy utterly unconnected dead-tree books instead?

MOVEit victim count latest: 2.6K+ orgs hit, 77M+ people's data stolen

Real-life impact of buggy software laid bare – plus: Avast tries to profit from being caught up in attacks

Google Chrome coders really, truly, absolutely ready to cull third-party cookies from 2024

Bonfire of the web trackers is coming, industry ready or not

Microsoft issues deadline for end of Windows 10 support – it's pay to play for security

Limited options will be available into 2028, for an undisclosed price