The issues and implications of a successful cyberattack on a business or organization have always received a fair amount of attention. Recently an event took place that received little attention even though it could significantly increase the total cost of a successful cyberattack resulting in a data breach for the victim organization. It wasn’t a new zero-day vulnerability or a new method of an attack; it was a court ruling decided on July 20, 2015.

The 7th Circuit Court of Appeals reinstated a class action suit against the retailer Neiman Marcus Group over a 2013 hack that potentially exposed the credit card information of 350,000 customers. Up until now companies have been successful at preventing such legal actions.

The ruling is causing corporate risk managers and cybersecurity professionals a severe case of heartburn. It makes it easier for individuals who had their information compromised in a breach to file a lawsuit claiming the breach resulted in injurythem being injured.

The plaintiffs of the Neiman case asserted they were injured by the breach in the following ways: 

  1. The victims will lose time and money resolving fraudulent actions resulting from the breach.
  2. The victims will lose time and money defending themselves against identity theft in the future.
  3. The victims have lost control over their personal information including the information’s value.

One cybersecurity professional believes that this could double the per victim cost of a cyber incident or breach. That is not the only impact of this ruling. Could this open the door for similar litigation resulting from the recent Office of Personnel Management breach? Looking down the road a ways, what if individuals working undercover have their cover blown because of this breach and results in their death? If that were to happen, could someone file a wrongful death case be filed? One thing is for sure, this is a long way from being over and we are likely to see many more twists and turns in the near future.