FREE LIVE WEBINAR  •  Sept 23, 1:00 PM EDT   You Don’t Have to Be an AI Expert: 5 Client Conversations MSPs Can Lead
d :
h :
m

FREE LIVE WEBINAR  •  Sept 23, 1:00 PM EDT 

d :
h :
m
fcc logo black on white

FCC fines Cox Communication $595,000 over data breach

fcc logo black on white
According to an article over at The Register, the FCC has fined Cox Communication $595,000 over a 2014 data breach.

Hacker disguised as IT support

The breach in question occurred in August of 2014 when, the FCC says, a hacker called “eviljordie” phoned Cox customer service claiming to be an employee in the company’s IT department. After tricking the call-center staffer into visiting a fake support website and entering their username and password, the hacker used the login details to access Cox’s customer database.

FCC accuses Cox of weak security

The regulator said Cox failed to provide adequate security for its customer database, and then failed to notify the commission when the intrusion was discovered.

“Cable companies have a wealth of sensitive information about us, from our credit card numbers to our pay-per-view selections,” said Travis LeBlanc, FCC enforcement bureau chief.

FCC Penalties

In addition to paying the FCC nearly $600,000, Cox has agreed to implement a stricter security program including regular testing, audits, and monitoring of customer data. The cable giant will also notify all customers whose details were exposed in the breach and pay for a year of credit monitoring.

Need for employee education

One thing that was not mentioned by the FCC is the need for employee security training. If the Cox Communication’s employee was aware of the potential for this type of phone scam they may have been unwilling to give out network credentials. Test, audits and monitoring are needed but ensuring that employees are trained is just as important.

 

Are you providing Security Training to your Clients?

badge w light burst white (1)
Exclusively for Our MSP Partners

Now Available: Gen AI Certification From BSN

Lead Strategic AI Conversations with Confidence

Breach Secure Now’s Generative AI Certification helps MSPs simplify the AI conversation, enabling clients to unlock the value of gen AI for their business, build trust, and drive growth – positioning you as a leader in the AI space.

More on blogs

AI Training First: Why the People Come Before the Platform

Employees are already using AI, whether organizations have formal licenses, automations, or a complete AI strategy in place. An AI Training First approach helps businesses

OpenAI Announces Unlimited ChatGPT Access. Is Your Organization Ready for the Shadow AI Risk?

As generative AI becomes easier to access and more deeply embedded in daily work, organizations face growing Shadow AI, data privacy, and governance challenges. Learn

Breach Secure Now Integrates with Bumblebee for MSP Automation

Breach Secure Now now integrates with Bumblebee, giving MSPs access to employee security, phishing, dark web, and training data inside an AI automation platform built
Take the First Step

Experience Training That Makes a Difference

during the demo you’ll:

Take the First Step

Experience Training That Makes a Difference

During the demo you’ll: