Auto Finance News
  • Home
  • News
  • Features
  • Events
    • Auto Finance Summit East
    • Equipment Finance Connect
    • Auto Finance Summit
    • PowerSports Finance Summit
  • Webinar
    • Harnessing AI & Machine Learning to Address Vehicle Affordability Issues
    • Webinar Library
  • Podcast
  • Powersports
  • Big Wheels Data

No products in the cart.

Subscribe
  • Capital & Funding
  • Compliance
  • Risk
  • Technology
  • Best Practices
  • Compliance Monitor
Log In
No Result
View All Result
Auto Finance News
  • Home
  • News
  • Features
  • Events
    • Auto Finance Summit East
    • Equipment Finance Connect
    • Auto Finance Summit
    • PowerSports Finance Summit
  • Webinar
    • Harnessing AI & Machine Learning to Address Vehicle Affordability Issues
    • Webinar Library
  • Podcast
  • Powersports
  • Big Wheels Data
BIG Wheels
Log In
No Result
View All Result
Auto Finance News
No Result
View All Result

5 lessons to learn from software vendor data breach

Drew PattybyDrew Patty
August 9, 2019
in Compliance
Reading Time: 3 mins read
0

According to a June 12 settlement announced by the Federal Trade Commission, back in 2015 an employee of Iowa-based LightYear Dealer Technologies, the parent company of DealerBuilt, plugged a storage device into the company’s backup network to increase storage capacity. However, the employee failed to ensure that the device was securely configured, thereby providing an open, insecure port into the company network, which was open for 18 months.

Subsequently, a hacker penetrated the network and gained access to the company’s unencrypted backup data, including personal information — such as Social Security and drivers’ license numbers — of about 12.5 million consumers, and the entire backup directories of five dealerships. DealerBuilt failed to detect the breach until an auto dealer’s customer complained about personal information becoming public on the internet, and a reporter told the company about the security vulnerability.

The alleged insecure access enabled by the employee’s device installation, along with other poor data control and security practices allegedly ongoing at DealerBuilt, led the FTC to allege unfair practices and violation of the Gramm-Leach-Bliley Act’s Safeguards Rule (GLB) against DealerBuilt.

The FTC asserted that DealerBuilt met the definition of a “financial institution” for purposes of the Gramm-Leach-Bliley Act. (Under GLB, any institution engaged in certain “finance activities” may be considered a “financial institution.” Sufficient “finance activities” include those that are “financial in nature” or “incidental to financial activity,” as these terms are defined in 12 U.S.C. 1843(k) and by regulations promulgated by the Board of Governors of the Federal Reserve.) GLB further requires financial institutions to develop, implement and maintain a comprehensive information security program; identify reasonably foreseeable risks to the security, confidentiality and integrity of customer information; and implement basic safeguards and regularly test their effectiveness, all of which DealerBuilt failed to undertake, according to the FTC.

DealerBuilt’s data security practices, which were alleged to be lax at the time the FTC filed its complaint, included:

  • Storing information in clear text, without any access controls or authentication protections like passwords or tokens. Data transmitted between dealerships and DealerBuilt’s backup database also was in clear text.
  • No written information security policy.
  • No provision of reasonable data security training for employees or contractors.
  • No assessment of risks to the sensitive data on its network by conducting periodic risk assessments or performing vulnerability and penetration testing.
  • No use of readily available security measures to monitor – among other things – unauthorized attempts to transfer sensitive information.
  • No reasonable data access controls in place – for example, systems to limit inbound connections to known IP addresses or require authentication to access backup databases.
  • No reasonable process to select, install and secure devices with access to personal information.

In reporting the outcome of the case’s proposed settlement, the FTC noted the following key recommendations for those in possession of consumer personal information:

1) Train and supervise your employees to be security-centric.

2) Exercise care when installing devices with network access.

3) Note that Gramm-Leach-Bliley Act coverage is broad. Consider whether your business (or affiliates or service providers) could be a “financial institution” subject to the GLB Safeguards Rule (16 C.F.R. Part 314). All it takes is for a business to be “significantly engaged” in providing financial products or services.

4) If your company uses third-party software or providers, build security into your contracts with those providers.

5) Remember that service providers also are accountable for protecting the personal data they collect and store.

Drew Patty is a Member (Partner) in McGlinchey Stafford’s Baton Rouge office. He co-chairs the firm’s Cybersecurity and Data Privacy practice group and leads the firm’s Intellectual Property section. He regularly counsels clients regarding internet privacy and data privacy policies and procedures, as well as regulatory advice concerning compliance with data transfer regulations. He also guides clients in vendor management efforts in negotiating and drafting cloud services, software license, and other vendor contracts with appropriate data security, cyber insurance, and data management provisions. Drew can be reached at dpatty@mcglinchey.com or at (225) 382-3720.

Tags: complianceFederal ReserveFederal Trade Commission
Previous Post

Westlake likely to take over SNAAC servicing

Next Post

Aussie fintech to enter US auto market

Related Posts

A seal at the Consumer Financial Protection Bureau (CFPB) headquarters in Washington, D.C.
Compliance

CFPB priority shift won’t absolve lenders 

May 1, 2025
A Wells Fargo bank branch in New York
Compliance

Wells Fargo says CFPB ends consent order dating back to 2018

April 28, 2025
CFPB sues TransUnion
Compliance

CFPB seeks to withdraw from lawsuit against CACC 

April 25, 2025
Next Post
© Can Stock Photo / mybaitshop

Aussie fintech to enter US auto market

Please login to join discussion

Stay Informed with Our Newsletters

PowerSports Finance

The Roadmap Podcast

COLUMNS

cars lined up

Auto loan fraudsters punished with prison (Under the Hood)

May 6, 2025
Cars parked in a lot

Strike Acceptance takes aim at ABS market (Under the Hood)

April 15, 2025
Selection of new metallic blue and gray cars lined up in dealership parking lot.

Off the Lot: Rethinking lending in a post-tariff world 

April 8, 2025

TECHNOLOGY

Image by Upstart

Upstart auto originations surge 369%

May 8, 2025
(Courtesy/Canva)

9 companies compete for Best in Show at Auto Finance Summit East

April 29, 2025

SPONSORED

The Hidden Bottlenecks in Dealership Financing—And How to Fix Them Fast

April 28, 2025

Tax Refund Season is Here—Is Your Dealership Ready to Handle the Surge?

March 13, 2025

The Future of Dealer Commercial Lending: Mastering Inventory Risk Management

March 3, 2025

Resources

ABOUT US

HELP CENTER

ADVERTISE

PRIVACY TERMS

ADA COMPLIANCE

CODE OF JOURNALISM ETHICS

Manage Cookie Consent

Special Content

EXECUTIVES OF THE YEAR

AUTO FINANCE EXCELLENCE AWARDS

MAGAZINE ARCHIVE

INDUSTRY GLOSSARY

Follow Us

facebook linkedin twitter podcast podcast
© 2025 Royal Media
No Result
View All Result
  • Home
  • News
    • All News
    • Capital & Funding
    • EVs
    • Technology
    • Management
    • Powersports Finance News
    • Risk Management
    • Sales & Marketing
  • Events
    • Auto Finance Summit East
    • Equipment Finance Connect
    • Auto Finance Summit
    • PowerSports Finance Summit
  • Features
    • Latest Issue
    • Features
    • New Tracks
    • Car Culture
    • Staffing Shuffles
    • Under The Hood
    • Spotlight
    • Issue Archive
  • Webinar
  • Podcast
  • Big Wheels Data
  • SUBSCRIBE
  • Log In / Account

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • News
    • All News
    • Capital & Funding
    • EVs
    • Technology
    • Management
    • Powersports Finance News
    • Risk Management
    • Sales & Marketing
  • Events
    • Auto Finance Summit East
    • Equipment Finance Connect
    • Auto Finance Summit
    • PowerSports Finance Summit
  • Features
    • Latest Issue
    • Features
    • New Tracks
    • Car Culture
    • Staffing Shuffles
    • Under The Hood
    • Spotlight
    • Issue Archive
  • Webinar
  • Podcast
  • Big Wheels Data
  • SUBSCRIBE
  • Log In / Account

THIS WEBSITE USES COOKIES

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “I CONSENT”, you consent to the use of ALL the cookies.

Cookie settingsI CONSENT

Review our Cookie Policies
.
Manage Cookie Consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these cookies, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may have an effect on your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
34f6831605sessionGeneral purpose platform session cookie, used by sites written in JSP. Usually used to maintain an anonymous user session by the server.
a64cedc0bfsessionGeneral purpose platform session cookie, used by sites written in JSP. Usually used to maintain an anonymous user session by the server.
CookieConsentPolicy1 yearUsed to apply end-user cookie consent preferences set by our client-side utility.
cookielawinfo-checkbox-advertisement1 yearSet by the GDPR Cookie Consent plugin, this cookie is used to record the user consent for the cookies in the "Advertisement" category .
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
crmcsrsessionGeneral purpose platform session cookie, used by sites written in JSP. Usually used to maintain an anonymous user session by the server.
JSESSIONIDsessionThe JSESSIONID cookie is used by New Relic to store a session identifier so that New Relic can monitor session counts for an application.
LS_CSRF_TOKENsessionCloudflare sets this cookie to track users’ activities across multiple websites. It expires once the browser is closed.
LSKey-c$CookieConsentPolicy1 yearUsed to apply end-user cookie consent preferences set by our client-side utility.
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
CookieDurationDescription
__cf_bm30 minutesThis cookie, set by Cloudflare, is used to support Cloudflare Bot Management.
_zcsr_tmpsessionZoho sets this cookie for the login function on the website.
663a60c55dsessionThis cookie is related to Zoho (Customer Service) Chatbox
e188bc05fesessionThis cookie is set in relation to Zoho Campaigns
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
CookieDurationDescription
_ga2 yearsThe _ga cookie, installed by Google Analytics, calculates visitor, session and campaign data and also keeps track of site usage for the site's analytics report. The cookie stores information anonymously and assigns a randomly generated number to recognize unique visitors.
_gid1 dayInstalled by Google Analytics, _gid cookie stores information on how visitors use a website, while also creating an analytics report of the website's performance. Some of the data that are collected include the number of visitors, their source, and the pages they visit anonymously.
CONSENT2 yearsYouTube sets this cookie via embedded youtube-videos and registers anonymous statistical data.
vuid2 yearsVimeo installs this cookie to collect tracking information by setting a unique ID to embed videos to the website.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
CookieDurationDescription
__Host-GAPS2 yearsThis cookie allows the website to identify a user and provide enhanced functionality and personalisation.
_dc_gtm_UA-1038974-31 minuteUsed to help identify the visitors by either age, gender, or interests by DoubleClick - Google Tag Manager.
_fbp3 monthsThis cookie is set by Facebook to display advertisements when either on Facebook or on a digital platform powered by Facebook advertising, after visiting the website.
fr3 monthsFacebook sets this cookie to show relevant advertisements to users by tracking user behaviour across the web, on sites that have Facebook pixel or Facebook social plugin.
test_cookie15 minutesThe test_cookie is set by doubleclick.net and is used to determine if the user's browser supports cookies.
VISITOR_INFO1_LIVE5 months 27 daysA cookie set by YouTube to measure bandwidth that determines whether the user gets the new or old player interface.
YSCsessionYSC cookie is set by Youtube and is used to track the views of embedded videos on Youtube pages.
yt-remote-connected-devicesneverYouTube sets this cookie to store the video preferences of the user using embedded YouTube video.
yt-remote-device-idneverYouTube sets this cookie to store the video preferences of the user using embedded YouTube video.
yt.innertube::nextIdneverThis cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen.
yt.innertube::requestsneverThis cookie, set by YouTube, registers a unique ID to store data on what videos from YouTube the user has seen.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
CookieDurationDescription
caf_ipaddrsessionNo description available.
citysessionNo description available.
countrysessionNo description available.
gnt_eidsessionNo description available.
gnt_eu6 hoursNo description
iamcsrsessionZoho (Customer Support) sets this cookie and is used for tracking visitors (for performance purposes)
systemsessionNo description available.
traffic_targetsessionNo description available.
Save & Accept
Powered by CookieYes Logo