Robinson Cole LLP
High Contrast Mode
March 20, 2025 - R+C Newsletter

Data Privacy + Cybersecurity Insider

Share this page:

CYBERSECURITY

Joint Alert Warns of Medusa Ransomware

On March 12, 2025, a joint cybersecurity advisory was issued by the Cybersecurity and Infrastructure Security Agency, the Federal Bureau of Investigation, and the Multi-State Information Sharing and Analysis Center to advise companies about the tactics, techniques and procedures (TTPs), and indicators of compromise (IOCs) to protect themselves against Medusa ransomware. Read More


DATA PRIVACY

CPPA Settles Alleged CCPA Violations with Honda

Last week, the California Privacy Protection Agency (CPPA) settled its first non-data broker enforcement action against American Honda Motor Co. for a $632,500 fine and the implementation of certain remedial actions. Read More


DATA SECURITY

Insider Threats: Potential Signs and Security Tips

The Stram Center for Integrative Medicine in New York recently reported a security incident where an employee misused a patient's payment card information. Although only one patient's card was directly misused, a subsequent breach report to the U.S. Department of Health and Human Services Office for Civil Rights indicates that the incident potentially compromised the information of 15,263 patients. The employee involved has been arrested and terminated. The Stram Center states that Social Security numbers were not affected and is offering complimentary credit monitoring and identity protection services to those impacted. Read More


ARTIFICIAL INTELLIGENCE

AI Governance: The Problem of Shadow AI

If you hang out with CISOs like I do, shadow IT has always been a difficult problem. Shadow IT refers to refers to “information technology (IT) systems deployed by departments other than the central IT department, to bypass limitations and restrictions that have been imposed by central information systems. While it can promote innovation and productivity, shadow IT introduces security risks and compliance concerns, especially when such systems are not aligned with corporate governance.” Read More


PRIVACY TIP #436

Microsoft Warns of Crypto Wallet Scanning Malware StilachiRAT

A Microsoft blog post reported that incident response researchers uncovered a remote access trojan in November 2024 (dubbed StilachiRAT) that “demonstrates sophisticated techniques to evade detection, persist in the target environment, and exfiltrate sensitive data.” Read More