OUT-LAW NEWS

Businesses must brace for mass claims as cyber attacks on rise

Cyber attack

Hackers are increasingly targeting customers and users’ personal data. Photo: Bill Hinton/Getty Images


A recent spate of cyber attacks in Germany has underscored the need for both public sector organisations and the private sector to develop a prompt and coordinated response to such incidents to ward off potential mass claims, experts have said.

Dr. Janett Bachmann and Johanna Weißbach of Pinsent Masons were commenting in the wake of several high-profile attacks on institutions and businesses in Germany where hackers appear to have gained unauthorised access to and, in some cases, went on to comprise customers' personal data.

In August, data from the Berlin Senate Administration was leaked after a federal government employee interacted with a phishing email. After the government refused to pay a €2 million ransom, the ransomware group went on to publish 1.4 million files on the dark web, which included employees’ personnel files, timesheets and telephone numbers, as well as official and sensitive documents.

In early September, an attack on the IT system of a German university compromised data records of around 600,000 current and former students. The university says it has taken steps to shut down and isolate the system that was breached but maintains there are no indications to date that students’ personal data has been published or misused.

In late September, an attack on Berlin-based food delivery service Flink allowed a group of hackers to gain access to customers' personal data and demanded a €10 ransom from each customer. Flink said it had notified customers in Germany and the Netherlands, reassured them that their passwords were not at risk and urged them not to pay the ransom.

The latest attacks highlight the growing efforts by hackers to gain unauthorised access to private businesses and government servers and their potential to put sensitive personal data at risk. In some incidents, data is exfiltrated by the attackers and subsequently offered for sale on the dark web, thereby creating numerous opportunities for misuse.

Earlier this year, a data breach at Booking.com gave hackers access to names, email addresses, phone numbers of customers and details about their past and present bookings. The online travel operator is already facing a Europe-wide mass class action over allegations that its use of ‘price parity’ clauses unfairly restricts accommodation providers.

Under the GDPR, cyber attacks could give rise to other potential mass claims for compensation, said Janett Bachmann. “Companies and institutions targeted by cyber attacks are frequently confronted, within a very short period of time, with a large number of judicial and extrajudicial claims asserted by the affected data subjects,” she said.

In light of the rising number of sophisticated attacks on businesses and public sector institutions, Bachmann said it is critical for organisations to be prepared, not only before the incidents, but in the worst-case scenario that data does become compromised. “Once a data breach becomes public knowledge, specialised law firms typically move quickly to market and pursue the rights of affected individuals,” she said. “As a result, the affected companies may, within a very short period of time, find themselves confronted with a large number of judicial and extrajudicial claims, requiring a prompt and coordinated response based on a consistent defence strategy.”

Johanna Weißbach, a mass litigation defence expert at Pinsent Masons, said the burden of proof remains on those affected to prove they have suffered a form of damage justifying any potential financial redress. However, she stressed that organisations must have processes and a documentation trail in place to prepare themselves in the event of a mass claim.

“In particular, the simultaneous filing of claims before courts across the country creates a significant administrative burden,” she said. “This applies both to the overall management of the proceedings and to the preparation of pleadings and attendance at court hearings. In such circumstances, it is essential to develop strategies that are both efficient and resource-conscious while ensuring a consistent and robust defence approach.”

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.