PayPal reaches settlement with New York State over 2022 data breach

Monday, January 27, 2025
Under the settlement terms, PayPal must pay the fine within 10 days. The DFS confirmed no further action will be taken unless additional violations are uncovered.
“The NY DFS Cybersecurity Regulation (23 NYCRR Part 500) is probably one of the most detailed US state-level regulations related to cybersecurity and data protection, resembling to EU DORA by its comprehensive nature,” said Dr Ilia Kolochenko, CEO at ImmuniWeb and a Fellow at the British Computer Society (BCS). “This penalty is a clear reminder that cybersecurity is insufficient even if you implement all technical controls by implementing pricey solutions from the leading vendors, but fail to properly organize an ongoing and organization-wide training.” Read Full Article
SecurityWeek: Cyber Insights 2025: Cybersecurity Regulatory Mayhem
SiliconANGLE: FTC orders GoDaddy to strengthen security practices after years of data breaches