Block slapped with lawsuit after ex-employee runs off with customer data

Data Breach
Image Credit: Shutterstock (Image credit: Shutterstock)

Two people are suing digital payments powerhouse Block and its subsidiary Cash App Investing for allegedly failing to properly protect sensitive personal data in a December 2021 data breach. 

As per the lawsuit filed in a federal district in Oakland, California, the two individuals saw “unauthorized charges” to their Cash App accounts, and spent many hours trying to fix the problem.

These unauthorized charges came as a result of a data breach in December 2021, when a former employee logged back into Cash App’s systems and downloaded internal reports which held personal information. The data the culprit took includes customers' full names, brokerage account numbers, brokerage portfolio values, brokerage portfolio holdings, and in some cases, stock trading activity for one trading day.

Millions affected

Now, they’re seeking damages, as well as other punishment for the service providers, arguing the company “failed to exercise reasonable care in securing and safeguarding consumer information”. What’s more, they’re claiming the company didn’t notify customers on time, shared too little information about what had happened, and did not offer credit and identity monitoring services.

Block publicly disclosed the incident almost five months after it had happened - in early April 2022. Back then, it said that 8.2 million current and former customers were affected and that it had reached out to notify them of the incident.

The lawsuit doesn’t detail exactly how the unwanted charges came to be, or how they link to the December data breach. According to The Register, when Block first announced the data breach, it said the former employee did not steal usernames or passwords, or other sensitive personal information. 

We have reached out to Block for a comment and will update the article if we hear back from the company. 

Via: The Register

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Representational image of a cybercriminal
Allstate sued for exposing personal customer information in plaintext
Outdoor photograph of a pair of hands holding a smartphone with navigator location points in the background
Millions of phone location records feared leaked as one of the biggest data leaks ever may be a whole lot worse
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
A computer being guarded by cybersecurity.
Zacks Investment hit in data breach - 12 million users potentially at risk
Data Breach
US state sues T-Mobile over 2021 data breach which leaked data of millions
A digital themed isometric showing a neon padlock in the foreground, and a technological diagram of a processor logic board in the background.
Major breach hits employee screening firm - 3.3 million affected as hackers steal DISA data
Latest in Security
DeepSeek on a mobile phone
More US government departments ban controversial AI model DeepSeek
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
These fake GitHub "security alerts" could actually let hackers hijack your account
3d rendering of a submarine power cable on the seabed
Subsea internet cables can now ‘listen’ for sabotage using irregular pulses of light
Latest in News
Lego Pokemon
Pokemon and Lego announce the most electrifying collaboration of all time and I’m going to be first in line
Apple Watch app health
Apple Watch blood pressure monitoring tech revealed in patent
Using Zipped files and folders in Windows 11
Hidden clues suggest Microsoft is moving another part of Windows 11’s Control Panel to the Settings app – and this time it’s mouse options
an image of the Samsung Galaxy S24 Ultra
Finally! One UI 7 has a release date - here are the Samsung phones that’ll get it first
Google Cloud logo
Google to acquire cloud security platform Wiz in $32 billion deal
GIMP 3.0 interface from the website
Our favorite free photo editor finally got the update it deserves - and these are the top 5 features designers should know about