• LinkedIn
  • Twitter
  • Google+
.
|
TechRecs: Cool Tools & Hot Topics
|
Phishing for Trouble: One Manufacturer’s Mistakes, and How to Avoid Them
Posted on September 12, 2018 by

Imagine the following:

In the height of tax season, an accounting clerk opens an email asking him: “Please send me W-2’s for employees in the marketing department. I need this information ASAP. Thanks very much.” The name on the email is the comptroller’s, so the clerk sends along the information. But the email was not from the comptroller—it was actually from a cybercriminal, and the W-2s are now for sale on the dark web.

The clerk fell victim to an increasingly common scam known as spoofing, or making an email appear it is coming from a legitimate source. It is an alarming trend that only seems to be increasing in its level of sophistication. Spoofing has especially grave implications for employers, who collect and retain significant amounts of employees’ personal information.

But who is to blame in this scenario? The cybercriminal, of course. But who else is at fault—the accounting clerk? The company? As strange as it may seem, the company might be liable for the identity theft suffered by the marketing department.

Just how and why an employer might be liable in this scenario is better explained by taking a look at a recent federal case.

Less than six months ago, the U.S. District Court for the Western District of North Carolina issued a stark ruling in Curry v. Schletter Inc. The case should be a cautionary tale and reminder to employers of the importance of training on how avoid cyber-scams. Failure to do so may be expensive.

In Curry, the plaintiffs were a group of former and current employees of Schletter Inc., a global manufacturer and distributor of solar mountings systems based in North Carolina. Schletter, as does every employer, maintains sensitive personal information about its employees, such as name, address, date of birth and social security number, as part of its ordinary course of business.

In April 2016, an employee responded to a cybercriminal she believed to be her company’s CEO by providing the personal information of over 200 employees. About one week after the disclosure, the company mailed a letter to all of its former and current employees, notifying them of what had happened.

Embarrassing as that was, Schletter’s story only gets worse. Evidence came to light that the company had already been warned about similar phishing e-mail scams. In August 2015, the FBI had issued an alert specifically warning of the lightning-like speed that these scams were occurring. Despite these warnings from the FBI, Schletter did not provide enough training to its employees on how to recognize and respond to spoofing. Indeed, the company failed to educate employees on even basic security measures that could have easily prevented the disclosure.

Unfortunately, that was not the only thing Schletter had failed to do. Even with the notice mailed out one week later, Schletter was found to not have timely disclosed to its employees the extent of the breach and failed to timely notify each affected employee. As a result, the employees were unable to protect themselves from the consequences of the data breach. Compounding matters, Schletter did not compensate to the victims or provide any assistance with the burdens caused by the errant disclosure. The victims took the company to court, asserting claims for monetary losses, lost time, anxiety and emotional distress.

The court found that Schletter had violated the North Carolina Identity Theft Protection Act (“NCITPA”). The NCITPA provides that a business may not intentionally communicate or make available to the general public an individual’s personal information. If the disclosure is intentional, the business may be liable for treble damages, meaning the court can triple the damages amount awarded to a plaintiff.

Schletter argued that the employee intended to communicate the information to the supervisor, not the general public. The court, however, rejected that argument and found that while the employee was “solicited under false pretenses,” her e-mail response was still “intentionally made.” This finding hinged on the distinction between a data breach and a data disclosure. A data breach typically involves a hacker infiltrating a computer system to steal information. A data disclosure, on the other hand, typically involves an individual who is already inside the system intentionally providing highly sensitive information.

The court allowed the employees to seek treble damages—triple the amount of actual damages—but Schletter filed for bankruptcy shortly after the decision, halting the lawsuit. As a result, it is unknown whether Schletter will be found liable for treble damages at this time.

It’s worth noting that treble damages are generally reserved for malicious conduct. For example, an employee that sells a company’s trade secrets to that company’s competitor has engaged in malicious conduct. Curry, however, illustrates that treble damages can come into play even when an employee had the purest of intentions (to comply with a supervisor’s instructions).

How Can Employers Protect Themselves?

North Carolina employers are not the only ones who should be nervous in the wake of Curry. The decision has broader implications for employers throughout the nation. Laws, local ordinances, and regulations are constantly being proposed, enacted, and revised to match the constantly evolving cybersecurity threats, leaving many employers baffled on the extent to which they can be held liable for breaches or disclosures that occur. The decision in Curry sheds light on how other courts may interpret cases with similar issues.

Thankfully, employers are not without recourse. The best defense to a data breach is to ensure one never happens in the first place. Businesses can protect against potential claims by implementing a training program for employees on data disclosure prevention. This training should include a review of (1) basic cyber security protocols and (2) how to recognize common phishing scams that lead to data disclosure. Employers should also have a response plan in place for when a disclosure does occur in order to mitigate possible exposure. For example, the plaintiffs in Curry argued that each passing day the company failed to notify employees of the disclosure increased the chances of their personal information being misused, and they increased their claimed damages accordingly. It also likely did not sit well with the court that Schletter did not offer to pay for identity protection or credit monitoring services for the employees.

It’s important to convey to your employees to never simply hit the reply button in an email. Recheck the email address and, with extremely sensitive information, consider calling the sender to verify that the e-mail is legitimately from that individual first.

And remember: if an employee falls victim to a phishing scam, the company can be on the hook for the damages arising from identity theft.

For more information on solutions for running your businesses’ technology more efficiently, visit our website or contact Megan Meisner at mmeisner@launchpadonline.com or 813 448-7100 x210.

This was originally posted by Industryweek by Peter Hall and Kevin Langley. Image credit Integrify.

Posted in TechRecs: Cool Tools & Hot Topics, Small Business IT Management, Small Business Web Strategies, IT Solutions - Stay Secure
How To Deep Clean Your iPhone
17 Ways to Recycle or Sell Your Smartphone

Related Posts

  • What Is Patch Tuesday? Microsoft’s Monthly Update Explained

    On the second Tuesday of each month, Microsoft and other tech companies release patches for
    read more
  • 10 Ways to Save Time on Your Windows 11 PC

    Windows 11 packs many features that you can use to speed up your tasks and
    read more
  • How to Automatically Fix Column Width to Fit Your Data in Excel

    There are numerous ways to change column widths in Excel, but did you know you
    read more
  • Why I Use a Privacy Screen When Working in Public

    Privacy screens are an affordable way to protect yourself from nosy colleagues and strangers whilst
    read more
Logging In...

Profile cancel

Sign in with Twitter Sign in with Facebook
or

Not published

TO WEBSITE >>
launchpadonline.com

CATEGORIES

  • Launch Pad News
  • TechRecs: Cool Tools & Hot Topics
  • Small Business IT Management
  • Small Business Web Strategies
  • IT Solutions – Cloud | Mobile
  • IT Solutions – Stay Secure
  • ITs Easy Being Green
  • RevITup TechCare Client Forum
  • GreenBack Nonprofit Wish List
  • Launch Pad Franchise Forum
  • Launch Pad Partner News

Cloud Computing in Plain English

Copyright © 2026 | Privacy Policy
  • LinkedIn
  • Twitter
  • Google+

Archives

  • January 2025 (1)
  • December 2024 (3)
  • November 2024 (4)
  • October 2024 (2)
  • September 2024 (4)
  • August 2024 (3)
  • July 2024 (2)
  • June 2024 (1)
  • May 2024 (3)
  • April 2024 (4)
  • March 2024 (2)
  • February 2024 (3)
  • January 2024 (4)
  • December 2023 (3)
  • November 2023 (3)
  • October 2023 (3)
  • September 2023 (3)
  • August 2023 (5)
  • July 2023 (3)
  • June 2023 (5)
  • May 2023 (4)
  • April 2023 (3)
  • March 2023 (4)
  • February 2023 (3)
  • January 2023 (3)
  • December 2022 (2)
  • November 2022 (2)
  • October 2022 (2)
  • September 2022 (3)
  • August 2022 (3)
  • July 2022 (2)
  • June 2022 (3)
  • May 2022 (2)
  • April 2022 (2)
  • March 2022 (2)
  • February 2022 (3)
  • January 2022 (2)
  • December 2021 (2)
  • November 2021 (3)
  • October 2021 (3)
  • September 2021 (3)
  • August 2021 (3)
  • July 2021 (2)
  • June 2021 (4)
  • May 2021 (3)
  • April 2021 (2)
  • March 2021 (2)
  • February 2021 (3)
  • January 2021 (2)
  • December 2020 (2)
  • November 2020 (2)
  • October 2020 (4)
  • September 2020 (2)
  • August 2020 (3)
  • July 2020 (2)
  • June 2020 (3)
  • May 2020 (2)
  • April 2020 (3)
  • March 2020 (3)
  • February 2020 (3)
  • January 2020 (4)
  • December 2019 (3)
  • November 2019 (2)
  • October 2019 (4)
  • September 2019 (3)
  • August 2019 (4)
  • July 2019 (2)
  • June 2019 (3)
  • May 2019 (3)
  • April 2019 (3)
  • March 2019 (3)
  • February 2019 (3)
  • January 2019 (4)
  • December 2018 (3)
  • November 2018 (4)
  • October 2018 (3)
  • September 2018 (2)
  • August 2018 (3)
  • July 2018 (3)
  • June 2018 (3)
  • May 2018 (2)
  • April 2018 (3)
  • March 2018 (3)
  • February 2018 (3)
  • January 2018 (3)
  • December 2017 (3)
  • November 2017 (4)
  • October 2017 (3)
  • September 2017 (4)
  • August 2017 (4)
  • July 2017 (4)
  • June 2017 (3)
  • May 2017 (5)
  • April 2017 (4)
  • March 2017 (4)
  • February 2017 (5)
  • January 2017 (4)
  • December 2016 (3)
  • November 2016 (4)
  • October 2016 (4)
  • September 2016 (4)
  • August 2016 (5)
  • July 2016 (4)
  • June 2016 (5)
  • May 2016 (3)
  • April 2016 (4)
  • March 2016 (4)
  • February 2016 (3)
  • January 2016 (3)
  • December 2015 (4)
  • November 2015 (4)
  • October 2015 (3)
  • September 2015 (3)
  • August 2015 (3)
  • July 2015 (3)
  • June 2015 (5)
  • May 2015 (4)
  • April 2015 (6)
  • March 2015 (4)
  • February 2015 (2)
  • January 2015 (5)
  • December 2014 (4)
  • November 2014 (3)
  • October 2014 (8)
  • September 2014 (5)
  • August 2014 (2)
  • July 2014 (3)
  • June 2014 (6)
  • May 2014 (3)
  • April 2014 (6)
  • March 2014 (5)
  • February 2014 (3)
  • January 2014 (5)
  • December 2013 (4)
  • November 2013 (4)
  • October 2013 (6)
  • September 2013 (3)
  • August 2013 (5)
  • July 2013 (6)
  • June 2013 (4)
  • May 2013 (3)
  • April 2013 (4)
  • March 2013 (4)
  • February 2013 (3)
  • January 2013 (5)
  • December 2012 (4)
  • November 2012 (5)
  • October 2012 (5)
  • September 2012 (6)
  • August 2012 (6)
  • July 2012 (6)
  • June 2012 (3)
  • May 2012 (7)
  • April 2012 (6)
  • March 2012 (10)
  • February 2012 (6)
  • January 2012 (5)
  • December 2011 (7)
  • November 2011 (9)
  • October 2011 (4)
  • September 2011 (4)
  • August 2011 (11)
  • July 2011 (14)
  • June 2011 (4)
  • May 2011 (11)
  • April 2011 (8)
  • March 2011 (11)
  • February 2011 (11)
  • January 2011 (21)
  • December 2010 (10)
  • November 2010 (10)
  • October 2010 (8)
  • September 2010 (10)
  • August 2010 (12)
  • July 2010 (8)
  • June 2010 (9)
  • May 2010 (8)
  • April 2010 (7)
  • March 2010 (10)
  • February 2010 (8)
  • January 2010 (6)
  • December 2009 (7)
  • November 2009 (13)
  • October 2009 (11)
  • September 2009 (16)
  • August 2009 (13)
  • July 2009 (16)
  • June 2009 (18)
  • May 2009 (16)