Yazılar

Block Wins Dismissal of Shareholder Lawsuit Over 2021 Cash App Breach

Block (XYZ.N), the fintech company led by Jack Dorsey, has defeated a shareholder lawsuit tied to a 2021 Cash App data breach that exposed information from about 8.2 million users.

The Case

  • Shareholders accused Block of:

    • Inflating its stock price by failing to disclose weak data security before the breach.

    • Delaying disclosure until April 2022, nearly four months after the incident.

    • Misleading Afterpay shareholders ahead of its $29 billion acquisition of the BNPL firm in January 2022.

Court’s Ruling

  • U.S. District Judge Margaret Garnett in Manhattan dismissed the case.

  • She ruled there was no evidence Block intended to defraud investors.

  • General statements about data security risks were not guarantees of system safety.

  • Shareholders also failed to prove:

    • A unique link between alleged misstatements and the Afterpay deal.

    • That Block executives had a specific motive or benefit from the alleged omissions.

Context

  • Block has faced regulatory pressure over Cash App:

    • $80M settlement with 48 U.S. state regulators (Jan 2024).

    • $40M settlement with New York (Apr 2024).

  • Despite these issues, Cash App processed $283B in inflows in 2024 and had 57M monthly active users by year-end.

What’s Next

  • The case (In re Block Inc Securities Litigation, No. 22-08636) is now dismissed, though investors could still pursue an appeal.

  • For Block, the ruling removes a major legal overhang as it continues to scale Cash App and integrate Afterpay.

UnitedHealth Tech Unit Hack Affected 192.7 Million People

A cyberattack on UnitedHealth Group’s (UNH.N) technology unit, Change Healthcare, last year affected 192.7 million people, according to the U.S. Department of Health and Human Services (HHS). The company had previously estimated the breach impacted 190 million individuals.

Disclosed in February 2024, the attack—identified as the largest healthcare data breach in U.S. history—was carried out by hackers claiming to be part of the “Blackcat” ransomware group. The breach caused widespread disruptions in claims processing and affected patients and healthcare providers nationwide.

A UnitedHealth spokesperson confirmed, “The final total number of individuals impacted by the Change Healthcare cyberattack is approximately 192.7 million,” noting that state-by-state figures may vary.

Compromised data is believed to include health insurance member IDs, patient diagnoses, treatment records, social security numbers, and provider billing codes. The breach is now listed in HHS’s official database of healthcare data breaches maintained by its Office for Civil Rights.

Australia’s Privacy Regulator Sues Optus Over Massive 2022 Data Breach

Australia’s privacy regulator, the Australian Information Commissioner (AIC), has filed a lawsuit against Optus, the Singapore Telecommunications-owned carrier, alleging violations of the Privacy Act 1988 related to a 2022 cyberattack that compromised personal data of nearly 9.5 million customers.

The lawsuit names both Singtel Optus Pty Ltd and Optus Systems Pty Ltd as defendants. The AIC claims a separate breach for each affected customer, with potential fines up to A$2.2 million per breach. However, the regulator has not disclosed the total fine amount sought. Optus is currently reviewing the claims but has not yet assessed the financial impact.

The September 2022 cyberattack is considered one of the worst data breaches in Australia’s history, exposing sensitive information including home addresses, passport details, and phone numbers. Around 10 million Australians—about 40% of the population—were affected, and many experienced a significant disruption to mobile, broadband, and landline services.

The breach sparked calls from Prime Minister Anthony Albanese for stronger privacy laws and faster breach notifications, especially to banks. Optus has also faced ongoing criticism due to a 12-hour nationwide network outage in 2023, leading to the resignation of then-CEO Kelly Bayer Rosmarin.

In addition to this legal action, Optus was taken to court by Australia’s domestic media regulator earlier in 2024 over the same cyberattack.