{"id":7227,"date":"2011-04-08T13:24:12","date_gmt":"2011-04-08T17:24:12","guid":{"rendered":"https:\/\/abovethelaw.com\/?p=66568"},"modified":"2011-04-08T13:24:12","modified_gmt":"2011-04-08T17:24:12","slug":"hackers-probably-stole-your-email-address-last-weekend","status":"publish","type":"post","link":"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/","title":{"rendered":"Hackers Probably Stole Your Email Address Last Weekend"},"content":{"rendered":"<p>Raise your hand if you are a <a href=\"http:\/\/www.jpmorganchase.com\/\">JPMorgan Chase<\/a> customer. Now raise your hand if you\u2019ve shopped at <a href=\"http:\/\/www.bestbuy.com\/\">Best Buy<\/a>. How about <a href=\"http:\/\/www.citibank.com\/us\/home.htm\">Citibank<\/a>, <a href=\"http:\/\/www.target.com\/\">Target<\/a> or <a href=\"http:\/\/www.walgreens.com\/\">Walgreens<\/a>?<\/p>\n<p>Has everybody in the world raised their hands yet? Congratulations &#8212; your email address may have been stolen.<\/p>\n<p>There was a data breach at <a href=\"http:\/\/www.epsilon.com\/\">Epsilon<\/a>, a Texas-based marketing firm, last weekend, exposing the names and email addresses of potentially millions of their clients\u2019 customers. I first found out about it when Chase emailed me. You might have gotten a similar alert from one of the affected companies.<\/p>\n<p>Read part of the bank&#8217;s announcement and more about the breach, after the jump.<\/p>\n<p><!--more--><\/p>\n<p>Here&#8217;s what Chase had to say:<\/p>\n<blockquote><p>Chase is letting our customers know that we have been informed by Epsilon, a vendor we use to send emails, that an unauthorized person outside Epsilon accessed files that included email addresses of some Chase customers.<\/p><\/blockquote>\n<p>The theft of millions of email addresses from almost <a href=\"http:\/\/www.databreaches.net\/?p=17374\">60 companies<\/a> is not as potentially dangerous as leaking credit card numbers or bank passwords, but it\u2019s still significant. The main danger from this is an increase in \u201cspear phishing\u201d attacks &#8212; nerd-speak for targeted email spam.<\/p>\n<p>From the <a href=\"http:\/\/www.nytimes.com\/2011\/04\/05\/business\/05hack.html?_r=2&amp;ref=technology\">New York Times<\/a>:<\/p>\n<blockquote><p>In traditional phishing attacks, criminals email millions of people with a message that appears to be from a bank or other real business, hoping that some of the recipients will be customers of that business and will follow instructions to, for example, \u201cupdate your account information.\u201d<\/p>\n<p>A spear-phishing email is far more dangerous because it can include a person\u2019s name and is sent only to people who are known to be customers of a certain business, greatly increasing the likelihood that the targets will be duped.<\/p><\/blockquote>\n<p>I have received this type of scam email before. It is unsettling to get a message that looks and smells like spam, yet includes my name and some correct, esoteric information about my life and shopping preferences.<\/p>\n<p>(You might also ask, \u201cDoes anyone actually click on spam email? Aren\u2019t we past that?\u201d The answer, as this <a href=\"http:\/\/www.maawg.org\/consumers-don%E2%80%99t-relate-bot-infections-risky-behavior-millions-continue-click-spam\">study<\/a> explains, is solidly, \u201cYes they do, and no we aren\u2019t.\u201d)<\/p>\n<p>These days, companies &#8212; especially financial institutions &#8212; are pushing more of their business online and using third parties to handle customer data. Our own <a href=\"https:\/\/abovethelaw.com\/author\/khill\/\">Kashmir Hill<\/a> wrote an <a href=\"http:\/\/blogs.forbes.com\/kashmirhill\/2011\/04\/05\/how-did-epsilon-expose-your-email-address-to-hackers\/\">interesting piece<\/a> over at Forbes about the business of data tracking and Epsilon\u2019s part within it:<\/p>\n<blockquote><p>When you opt to get emails from a company or organization, you\u2019re often asked to choose between html and plain text. Choosing the html version means more than just pretty pictures; it also allows for tracking of that email. A company like Epsilon can determine whether their client\u2019s email is going to your junk folder, or whether you opened it (and when), and what you clicked on when reading the email.<\/p><\/blockquote>\n<p>It seems I see a big new data breach every few months. The news reports often echo what the Times said about Epsilon: \u201cthe breach may be among the largest ever.\u201d<\/p>\n<p>The <a href=\"http:\/\/www.privacyrights.org\/\">Privacy Rights Clearinghouse<\/a> maintains a <a href=\"http:\/\/www.privacyrights.org\/data-breach\">database<\/a> of every data breach since 2005. A quick glance at the list will make you shiver. Data gets out for all kinds of reasons. In addition to problems with hackers, equipment gets lost or stolen, companies inadvertently sell information to the wrong people, and disgruntled employees steal data.<\/p>\n<p>Most breaches never make the news.<\/p>\n<p>Large breaches are a pain in the rear for everyone involved, and they also represent a legal risk for the companies that expose the data. It\u2019s only a matter of time before someone files a class action relating to the Epsilon breach. Even if no one finds actual damage to consumers, there may be some kind of settlement.<\/p>\n<p>Depending on the severity of a breach and the actual damage to consumers, the settlements in these suits can range from several hundred thousand dollars to <a href=\"http:\/\/www.bankinfosecurity.com\/articles.php?art_id=2498\">several million<\/a>. And depending on the state, data breaches may violate privacy laws.<\/p>\n<p>Kash sums the current situation up well:<\/p>\n<blockquote><p>I, for one, am going to be extra wary of any emails I get from Hilton Honors or TD Ameritrade moving forward. Hopefully, I don\u2019t miss out on any legitimate free night specials. \u2026<\/p>\n<p>So kiddies, watch out for sophisticated phishers, and think twice before opting for the html version of email subscriptions.<\/p><\/blockquote>\n<p>Words for the wise. Don&#8217;t ever say we don&#8217;t give you practical advice around here!<\/p>\n<hr \/>\n<p><strong><em>Christopher Danzig is a writer in Oakland, California. He previously covered legal technology for InsideCounsel magazine. Follow Chris on Twitter <a href=\"http:\/\/twitter.com\/chrisdanzig\">@chrisdanzig<\/a> or email him at <a href=\"mailto:cdanzig@gmail.com\">cdanzig@gmail.com<\/a>. You can read more of his work at <a href=\"http:\/\/chrisdanzig.com\/\">chrisdanzig.com<\/a>.<\/em><\/strong><\/p>\n","protected":false},"excerpt":{"rendered":"<p class=\"summary\">Raise your hand if you are a JPMorgan Chase customer. Now raise your hand if you\u2019ve shopped at Best Buy. How about Citibank, Target or Walgreens? Has everybody in the world raised their hands yet? Congratulations &#8212; your email address may have been stolen. There was a data breach at Epsilon, a Texas-based marketing firm, [&hellip;]<\/p>\n","protected":false},"author":62,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[3915,655,4123,11],"tags":[1987,4879,4881,2289,257,363,222,223,4883,1225,4885,4887,4793,79,4889,4891,4893,226,4795,4895,7,4897,227],"class_list":["post-7227","post","type-post","status-publish","format-standard","hentry","category-cyberlaw","category-privacy","category-screw-ups","category-technology","tag-best-buy","tag-chase","tag-citibank","tag-class-actions","tag-cyberlaw","tag-data-breach","tag-email","tag-emails","tag-epsilon","tag-hacking","tag-jpmorgan-chase","tag-kashmir-hill","tag-phishing","tag-privacy","tag-privacy-law","tag-privacy-rights","tag-privacy-rights-clearing-house","tag-screw-ups","tag-spear-phishing","tag-target","tag-technology","tag-walgreens","tag-whoops"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.3 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Hackers Probably Stole Your Email Address Last Weekend - Above The Law&#039;s Legal Tech Non-Event<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Hackers Probably Stole Your Email Address Last Weekend - Above The Law&#039;s Legal Tech Non-Event\" \/>\n<meta property=\"og:description\" content=\"Raise your hand if you are a JPMorgan Chase customer. Now raise your hand if you\u2019ve shopped at Best Buy. How about Citibank, Target or Walgreens? Has everybody in the world raised their hands yet? Congratulations &#8212; your email address may have been stolen. There was a data breach at Epsilon, a Texas-based marketing firm, [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/\" \/>\n<meta property=\"og:site_name\" content=\"Above The Law&#039;s Legal Tech Non-Event\" \/>\n<meta property=\"article:published_time\" content=\"2011-04-08T17:24:12+00:00\" \/>\n<meta name=\"author\" content=\"Christopher Danzig\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@http:\/\/twitter.com\/chrisdanzig\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Christopher Danzig\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/\",\"url\":\"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/\",\"name\":\"Hackers Probably Stole Your Email Address Last Weekend - Above The Law&#039;s Legal Tech Non-Event\",\"isPartOf\":{\"@id\":\"https:\/\/abovethelaw.com\/legal-innovation-center\/#website\"},\"datePublished\":\"2011-04-08T17:24:12+00:00\",\"dateModified\":\"2011-04-08T17:24:12+00:00\",\"author\":{\"@id\":\"https:\/\/abovethelaw.com\/legal-innovation-center\/#\/schema\/person\/ee449b9eb8d6da865c42626d3948cff6\"},\"breadcrumb\":{\"@id\":\"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/abovethelaw.com\/legal-innovation-center\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Hackers Probably Stole Your Email Address Last Weekend\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/abovethelaw.com\/legal-innovation-center\/#website\",\"url\":\"https:\/\/abovethelaw.com\/legal-innovation-center\/\",\"name\":\"Above The Law&#039;s Legal Tech Non-Event\",\"description\":\"A Legal Tech Adoption Guide For Perplexed Lawyers\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/abovethelaw.com\/legal-innovation-center\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/abovethelaw.com\/legal-innovation-center\/#\/schema\/person\/ee449b9eb8d6da865c42626d3948cff6\",\"name\":\"Christopher Danzig\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/abovethelaw.com\/legal-innovation-center\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/a79eea4ba71fc05e639aa8c99293e0a3782e667a4429abdb679e92931e87949d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/a79eea4ba71fc05e639aa8c99293e0a3782e667a4429abdb679e92931e87949d?s=96&d=mm&r=g\",\"caption\":\"Christopher Danzig\"},\"description\":\"Chris graduated from the Medill School of Journalism at Northwestern University. He is a former freelance journalist and assistant editor at InsideCounsel Magazine, where he covered legal technology. In his spare time, he listens to and plays loud music. He lives in San Francisco, California. He is in no way related to the singer of seminal punk band The Misfits.\",\"sameAs\":[\"https:\/\/x.com\/http:\/\/twitter.com\/chrisdanzig\"],\"url\":\"https:\/\/abovethelaw.com\/legal-innovation-center\/author\/christopher-danzig\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Hackers Probably Stole Your Email Address Last Weekend - Above The Law&#039;s Legal Tech Non-Event","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/","og_locale":"en_US","og_type":"article","og_title":"Hackers Probably Stole Your Email Address Last Weekend - Above The Law&#039;s Legal Tech Non-Event","og_description":"Raise your hand if you are a JPMorgan Chase customer. Now raise your hand if you\u2019ve shopped at Best Buy. How about Citibank, Target or Walgreens? Has everybody in the world raised their hands yet? Congratulations &#8212; your email address may have been stolen. There was a data breach at Epsilon, a Texas-based marketing firm, [&hellip;]","og_url":"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/","og_site_name":"Above The Law&#039;s Legal Tech Non-Event","article_published_time":"2011-04-08T17:24:12+00:00","author":"Christopher Danzig","twitter_card":"summary_large_image","twitter_creator":"@http:\/\/twitter.com\/chrisdanzig","twitter_misc":{"Written by":"Christopher Danzig","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/","url":"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/","name":"Hackers Probably Stole Your Email Address Last Weekend - Above The Law&#039;s Legal Tech Non-Event","isPartOf":{"@id":"https:\/\/abovethelaw.com\/legal-innovation-center\/#website"},"datePublished":"2011-04-08T17:24:12+00:00","dateModified":"2011-04-08T17:24:12+00:00","author":{"@id":"https:\/\/abovethelaw.com\/legal-innovation-center\/#\/schema\/person\/ee449b9eb8d6da865c42626d3948cff6"},"breadcrumb":{"@id":"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/abovethelaw.com\/legal-innovation-center\/2011\/04\/08\/hackers-probably-stole-your-email-address-last-weekend\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/abovethelaw.com\/legal-innovation-center\/"},{"@type":"ListItem","position":2,"name":"Hackers Probably Stole Your Email Address Last Weekend"}]},{"@type":"WebSite","@id":"https:\/\/abovethelaw.com\/legal-innovation-center\/#website","url":"https:\/\/abovethelaw.com\/legal-innovation-center\/","name":"Above The Law&#039;s Legal Tech Non-Event","description":"A Legal Tech Adoption Guide For Perplexed Lawyers","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/abovethelaw.com\/legal-innovation-center\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/abovethelaw.com\/legal-innovation-center\/#\/schema\/person\/ee449b9eb8d6da865c42626d3948cff6","name":"Christopher Danzig","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/abovethelaw.com\/legal-innovation-center\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/a79eea4ba71fc05e639aa8c99293e0a3782e667a4429abdb679e92931e87949d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a79eea4ba71fc05e639aa8c99293e0a3782e667a4429abdb679e92931e87949d?s=96&d=mm&r=g","caption":"Christopher Danzig"},"description":"Chris graduated from the Medill School of Journalism at Northwestern University. He is a former freelance journalist and assistant editor at InsideCounsel Magazine, where he covered legal technology. In his spare time, he listens to and plays loud music. He lives in San Francisco, California. He is in no way related to the singer of seminal punk band The Misfits.","sameAs":["https:\/\/x.com\/http:\/\/twitter.com\/chrisdanzig"],"url":"https:\/\/abovethelaw.com\/legal-innovation-center\/author\/christopher-danzig\/"}]}},"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/abovethelaw.com\/legal-innovation-center\/wp-json\/wp\/v2\/posts\/7227","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/abovethelaw.com\/legal-innovation-center\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/abovethelaw.com\/legal-innovation-center\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/abovethelaw.com\/legal-innovation-center\/wp-json\/wp\/v2\/users\/62"}],"replies":[{"embeddable":true,"href":"https:\/\/abovethelaw.com\/legal-innovation-center\/wp-json\/wp\/v2\/comments?post=7227"}],"version-history":[{"count":0,"href":"https:\/\/abovethelaw.com\/legal-innovation-center\/wp-json\/wp\/v2\/posts\/7227\/revisions"}],"wp:attachment":[{"href":"https:\/\/abovethelaw.com\/legal-innovation-center\/wp-json\/wp\/v2\/media?parent=7227"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/abovethelaw.com\/legal-innovation-center\/wp-json\/wp\/v2\/categories?post=7227"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/abovethelaw.com\/legal-innovation-center\/wp-json\/wp\/v2\/tags?post=7227"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}