DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Another lawsuit filed against Maricopa County Community College District over massive breach

Posted on April 21, 2014 by Dissent

Jamie Ross of Courthouse News reports that another lawsuit has been filed against Maricopa County Community College District (MCCCD) following a data breach it disclosed in November 2013 (search MCCCD for all previous coverage on this blog).

This latest lawsuit was reportedly filed by Jason Liebich, a current student at Phoenix College. It was filed in in Maricopa County Court by his lawyer, Robert Carey of Hagens Berman Sobol Shapiro in Phoenix.

Ross reports:

According to the lawsuit, MCCCD is now “falsely advising class members that no data breach had occurred, including current students who were never informed (in writing or otherwise) that a data incursion had occurred.”

Liebich reportedly seeks class certification, compensatory damages, credit monitoring, credit restoration, and punitive damages for breach of contract and negligence. 

So far, all of the lawsuits have been filed within the state. Given that some of those whose information was involved resided out-of-state at the time MCCCD acquired their personal information and/or now reside out-of-state, I’m waiting to see lawsuits filed in other jurisdictions with a possible move to consolidate in a federal court. But time will tell.

I continue to believe that this breach is not only an epic #FAIL on infosecurity, but also highlights why we need more data security enforcement and accountability in the education sector. When colleges amass tremendous amounts of personal information but fail to adequately secure it, who steps in and investigates? Not the U.S. Department of Education. Not the FTC, who has no authority over the education sector and non-profits, and likely not state attorneys general – particularly if the educational institution is a state agency.  It shouldn’t require lawsuits by breach victims to hold educational entities accountable for data security.

For another example of a security fail involving an educational institution, see my post about the University of Virginia hack, here.


Related:

  • The day after XSS.is forum was seized, it struggles to come back online -- but is it really them?
  • Korea imposes 343 million won penalty on HAESUNG DS for data breach of 70,000 shareholders
  • Paying cyberattackers is wrong, right? Should Taos County's incident be an exception? (1)
  • IVF provider Genea notifies patients about the cyberattack earlier this year.
  • Clorox Files $380M Suit Alleging Cognizant Gave Hackers Passwords in Catastrophic 2023 Cyberattack
  • Legal Silence and Chilling Effects: Injunctions Against the Press in Cybersecurity
Category: Breach IncidentsCommentaries and AnalysesEducation SectorU.S.

Post navigation

← Court Ventures/U.S. InfoSearch/Experian breach resulted in ID theft – Krebs
Unconscious Patient Says Doctors Mocked Him →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Connex Credit Union notifies 172,000 members of hacking incident
  • Federal judiciary says it is boosting security after cyberattack; researcher finds new leaks (CORRECTED)
  • Bank of America Refused To Reimburse Georgia Customer After Hackers Hit Account. Then a News Station Showed Up.
  • NCERT Issues Advisory on “Blue Locker” Ransomware Targeting Pakistan’s Key Institutions
  • Scattered Spider has a new Telegram channel to list its attacks
  • SC: Spartanburg County hit by cyberattack, some online services disrupted
  • Pakistan Petroleum thwarts ransomware attempt, says no critical data compromised
  • ShinyHunters sent Google an extortion demand; Shiny comments on current activities
  • Air France and KLM alert customers to data breach on external platform
  • Samourai CEO Keonne Rodriguez and Samourai CTO William Lonergan Hill Pled Guilty to Operating a Money Transmitting Business, Samourai Wallet, That Transmitted Over $200 Million in Criminal Proceeds

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Germany’s top court holds that police can only use spyware to investigate serious crimes
  • Flightradar24 receives reprimand for violating aircraft data privacy rights
  • Nebraska Attorney General Sues GM and OnStar Over Alleged Privacy Violations
  • Federal Court Allows Privacy Related Claims to Proceed in a Proposed Class Action Lawsuit Against Motorola
  • Italian Garante Adopts Statement on Health Data and AI
  • Trump administration is launching a new private health tracking system with Big Tech’s help
  • Attorney General James Takes Action to Protect Sensitive Personal Information of Tens of Millions of People

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.