NEW YORK – New York Attorney General Letitia James and a bipartisan coalition of 45 other attorneys general today secured $45 million from Block, Inc. (Block), the company behind the popular peer-to-peer payments app Cash App, for misleading its users and failing to protect them from scams and fraud. Attorney General James and the coalition allege that Block failed to help users when they were scammed, misled consumers about the safety of Cash App, and failed to provide the fraud protection and resolution that it promised and was required to provide by law. As part of the settlement with Attorney General James and the coalition, Block must implement changes to protect users from fraud, ensure users have access to live customer service agents, and stop all misleading marketing. Block must also pay $1.6 million in penalties to New York.
“New Yorkers were promised that Cash App was a…
IT & DATA SECURITY (MITIGATING THE “INSIDER THREAT”)
As seen in the TD Bank case, an employee with too much “access” can sell your customer data to syndicates.
- Principle of Least Privilege (PoLP): Employees should only have access to the specific folders and databases required for their current task.
- Access Revocation: Have a “Termination Checklist” that ensures all digital access (Email, VPN, Banking) is revoked within 60 minutes of an employee resigning or being dismissed.
- System Logs & Audit Trails: Enable “Read/Write Logging” on your server. If a customer’s data is leaked, you need to know exactly which login accessed that record and at what time.
- Encryption at Rest: Ensure that sensitive files (like your customer ID numbers or payroll spreadsheets) are encrypted so that if a staff member copies them to a USB, they cannot be read.
