Are you storing sensitive data on a shared network drive? If so, your organization could be at serious risk of a data breach or privacy lawsuit. Shared drives, like the common “S:\ drive,” are often used to store documents, spreadsheets, customer information, financial records, and even scanned IDs. But here’s the problem: these network shares are rarely encrypted, lack clear data governance policies, and are accessible to dozens—or even hundreds—of employees across different departments. Without proper oversight, unsecured network drives become a data security nightmare.

Don’t let poor information governance put your business at risk; take the time to learn why securing sensitive data on shared drives is critical for avoiding data breaches, maintaining compliance with privacy laws, and safeguarding your company’s reputation.

In today’s environment of rapidly expanding state consumer privacy laws and data breach notification statutes, companies that fail to control where sensitive data lives are sitting on serious legal and reputational risk. Here’s what you need to know—and why unsecured network shares are no longer just an IT headache. It’s a legal liability.

The Rise of State Privacy Laws: More Than Just California

Most people know about California’s Consumer Privacy Act/Consumer Privacy Rights Act, but it’s far from alone. As of 2025, over a dozen states have passed their own consumer privacy laws—including Colorado, Connecticut, Utah, Virginia, Texas, Florida, Oregon, and others. Here’s what these state privacy laws typically grant consumers:

  • The right to know what personal data companies collect.
  • The right to access or delete their personal data.
  • The right to opt-out of data sales or targeted advertising.
  • The expectation that their data will be securely protected.

“Reasonably protected” sounds vague, but it’s increasingly being interpreted to mean basic security practices—like encryption, access controls, and data governance. Storing Social Security numbers or financial info in an unprotected shared drive with no audit trail? That’s not going to fly.

Data Breach Notification Laws: 50 States, 50 Triggers

Every U.S. state has its own data breach notification law, and many have recently updated them. These laws require businesses to notify affected consumers—and sometimes regulators—when certain types of personal information are accessed or acquired without authorization.

The trigger? Often, it’s exposure of unencrypted data such as:

  • Social Security numbers
  • Driver’s license numbers;
  • Financial account or credit card numbers; and
  • Health records.

Why Network Shares are High-Risk

If that data lives on an unsecured network share, accessible by anyone on the network—or worse, breached by an outsider—you may have a legal duty to notify, and fast.

Shared network drives are a leftover from a simpler time. They often:

  • Lack encryption, either at rest or in transit.
  • Have overly broad access (e.g., “Everyone in Finance” means everyone).
  • Are unmanaged—no one monitors what’s stored, for how long, or by whom.
  • Become digital junk drawers: you name it, someone’s dumped it there.

In short, they’re a soft target for internal mishandling or external breaches.

Even if no breach has occurred yet, regulators may still view careless storage as a failure to implement reasonable security measures, something required by many state laws (and by the FTC under its enforcement of Section 5 for unfair practices).

Real World Risk: Enforcement and Lawsuits

Let’s connect the dots:

  • A former employee downloads a folder full of unencrypted spreadsheets with customer data from a shared drive and walks out the door.
  • A ransomware attacker gains access to your network and hits a file share containing years’ worth of sensitive HR or payroll data.
  • A privacy audit reveals that your network share is a free-for-all and your company never implemented access logs or retention policies.

In each case, you’re potentially looking at:

  • Mandatory breach notifications;
  • Fines from state attorneys general;
  • Consumer lawsuits, including class actions; and
  • Reputational damage, especially if the exposure goes public.

What You Can Do Now

The good news? Much of this risk is preventable. Here are some practical steps:

  1. Encrypt sensitive data at rest and in transit. Don’t assume your internal network is a safe zone.
  2. Limit access based on role or need-to-know. Broad group permissions are a red flag.
  3. Inventory your data. You can’t protect what you don’t know you have.
  4. Establish a governance policy. Set clear rules about what data can be stored, where, and for how long.
  5. Clean up legacy shares. Archive or securely delete outdated files, especially ones with sensitive info.
  6. Train employees. They need to know that dumping sensitive info into a shared folder is no longer acceptable.

State privacy laws are becoming more aggressive, and regulators are increasingly focused on where and how companies store consumer data, not just how they use it. An old network share with no encryption, no oversight, and no purpose may seem like low-hanging fruit from a compliance perspective, but it’s exactly the kind of vulnerability that can turn into a legal firestorm.

If your organization hasn’t taken a hard look at its shared storage practices lately, now is the time. Because in the age of modern data privacy laws, “we didn’t know it was there” is no longer a defense.

Identity theft will continue to rise in 2025. According to the Better Business Bureau of Missouri (BBB), it received over 16,000 identity theft complaints in the past three years. Scammers are “increasingly using advanced tactics such as artificial intelligence to exploit victims.”

The BBB notes that threat actors are taking over social media accounts to solicit money and “impersonating individuals to rent apartments or open credit cards.”

According to Which?, fraud prevention service Cifas reports the continuing rise of identity theft and fraud, and artificial intelligence (AI) is “fuelling [the] identity fraud increase.” Cases of account takeover “drastically increased by 76% in 2024.” Over half of these cases involved threat actors hijacking mobile telephone accounts, and SIM swap fraud increased by a whopping 1,055%. Threat actors use AI more frequently in cases of false applications, where it assists “with the speed, sophistication and scale of false documentation, as well as aiding the ability to pass verification checks.”

Identity theft will continue to rise, so preventative measures, such as those outlined by the BBB, Identitytheft.org, and the FTC, will hopefully prevent victimization. If you become a victim, the FTC has free helpful resources to consider.

On March 31, 2025, President Trump signed an executive order (EO 14254) titled “Combating Unfair Practices in the Live Entertainment Market.” EO 14254 directs the Federal Trade Commission (FTC) to, amongst other provisions, rigorously enforce the Better Online Ticket Sales Act (BOTS Act or the Act) and address unfair ticket scalping practices.

Overview of the BOTS Act

Enacted in 2016, the BOTS Act aims to prevent ticket brokers from buying large numbers of event tickets and reselling them at inflated prices. The Act applies to tickets for public concerts, theater performances, sporting events, and similar activities at venues that seat over 200 and prohibits an entity from circumventing access controls or security measures used by online ticket sellers (such as Ticketmaster) to enforce ticket-purchasing limits. It also prevents the resale of tickets obtained by knowingly circumventing access controls. Violations of the Act are considered violations of Section 5 of the FTC Act, which prohibits unfair or deceptive practices. Violators are subject to fines of up to $53,088 per violation.

Under the Act, the circumvention of access controls or security measures is construed broadly and applies to automated ticket bots and certain human actions. A ticket bot is a software program designed to rapidly purchase large quantities of tickets the moment they become available. Scalper bots specifically automate tasks like filling out forms, refreshing web pages, and completing the checkout process. Since scalper bots can complete the checkout process much faster than human users, they can buy thousands of limited-edition tickets as soon as they go on sale. Scalped tickets are then resold for higher profit because they are no longer available from the original ticket seller – this practice is known as ticket scalping.

Sellers often set limits on the number of tickets each buyer can purchase. Bots can bypass this limit by rapidly purchasing tickets across multiple accounts or using fake online profiles and IP addresses. Bots may bypass CAPTCHA and other security measures or manage multiple browser sessions simultaneously to purchase large volumes of tickets simultaneously. These tactics may run afoul of the BOTS Act if the seller has access controls or security measures to prevent such activity. The BOTS Act is not only limited to bot activity, though. A person who buys tickets by creating multiple accounts or using proxies and VPNs to disguise their IP address may also be circumventing a seller’s security measures, which may also violate the Act.

Enforcement Action Under the BOTS Act

In January 2021, the FTC filed complaints against three ticket brokers for allegedly using bots to buy tens of thousands of event tickets and then resell them at inflated prices. The FTC alleged that the defendants violated the Act in multiple ways, including using bots to search for and automatically reserve tickets, using software to conceal their IP addresses, and using bots to bypass CAPTCHA security measures. The complaint also alleged that the defendants had created hundreds of Ticketmaster accounts in the names of friends, family, and fictitious individuals and used hundreds of credit cards to bypass ticket limits. In total, the brokers were subject to a judgment of over $31 million, but due to their inability to pay, they were ultimately liable for $3.7 million in civil penalties.

The BOTS Act also empowers state attorneys general to enforce the Act if they determine that their states’ residents have been threatened or adversely affected by violations of the Act. Though there has been little notable state enforcement action to date, senators from both political parties have introduced bills to enable stronger enforcement of the Act. For instance, in May 2024, the Democratic governor of Arizona, Katie Hobbs, signed and passed a state law often referred to as the “Taylor Swift bill” to authorize the state’s attorney general to investigate unlawful uses of bots to purchase multiple event tickets or circumvent waiting periods and presale codes.

Looking Forward

The executive order instructs the FTC to “rigorously enforce” the BOTS Act and to provide state attorneys general and consumer protection officers with information and evidence to further this directive. The EO also directs the FTC to take additional actions, such as proposing regulations and enforcing against unfair methods of competition and unfair or deceptive acts and practices.

EO 14254 follows on the heels of a December 2024 FTC Rule – the Junk Fees Rule – banning junk ticket and hotel fees, which goes into effect on May 10, 2025. Under the Junk Fees Rule, businesses must clearly and conspicuously disclose the total price, including all mandatory fees, whenever they offer, display, or advertise any price of live-event tickets or short-term lodging. According to the FTC, the Junk Fees Rule enables the agency to “rigorously pursue” bait-and-switch pricing tactics, such as drip pricing and misleading fees.

Following the release of EO 14254 on April 8, 2025, two members of Congress, Diana Harshbarger (R-TN) and Troy Carter (D-LA) co-sponsored a bill in the House titled the “Mitigating Automated Internet Networks for [MAIN] Event Ticketing Act.” This bill is a companion bill to the one initially introduced in the Senate by Marsha Blackburn (R-TN) and Ben Ray Luján (D-NM). The bill would create reporting requirements for online ticket sellers to report successful bot attacks to the FTC. The proposed legislation would also create a complaint database for consumers to share their experiences with the FTC, who would, in turn, be required to share the information with state attorneys general. According to Congresswoman Harshbarger’s press release, the legislation aims to build on the BOTS Act and codify EO 14254. There is strong bipartisan support for live-event industry regulation. In light of EO 14254, the FTC’s Junk Fee Rule, and the MAIN Event Ticketing Act introduction, it is safe to say that both state and federal authorities are focused on regulating the live entertainment industry, particularly in the ticket sale context. BOTS Act enforcement may increase in the coming years, and ticket scalpers should beware.

The Stram Center for Integrative Medicine in New York recently reported a security incident where an employee misused a patient’s payment card information. Although only one patient’s card was directly misused, a subsequent breach report to the U.S. Department of Health and Human Services Office for Civil Rights indicates that the incident potentially compromised the information of 15,263 patients. The employee involved has been arrested and terminated. The Stram Center states that Social Security numbers were not affected and is offering complimentary credit monitoring and identity protection services to those impacted.

When we hear “data breach,” we’re likely to think of ransomware incidents, business email compromises, and other cyberattacks from external threats. However, according to a Cybersecurity Insiders report, 83% of organizations reported at least one insider attack in 2024. According to IBM’s 2024 Cost of a Data Breach report, data breaches resulting from insider threats were the costliest, at $4.99 million on average. While insider threats may not make headlines as frequently, organizations should take measures to mitigate risks surrounding insider data incidents. Insider threats include unintentional errors, such as emailing personal information to the wrong recipient, misplacing documents, and speaking about personal information among those without authorized access. Insider threats also include malicious insider threats, such as disgruntled employees.

Organizations should monitor for several signs that may signal a malicious insider threat:

  • Timing of access – Malicious insiders may access the network and systems at unusual times. If an employee typically only works night shifts but the user’s access logs suddenly reflect daytime activity, this could indicate potential malicious activity.
  • Unexpected spikes in network traffic – Atypical spikes in network traffic might reflect that a user is downloading or copying large volumes of data.
  • Unusual requests – If a user is requesting access to applications or information that are beyond the scope of their role or unusual for team members in similar roles, this could signal malicious intent.

Several security practices can help organizations reduce the risk of insider attacks:

  • Endpoint monitoring – Constant endpoint monitoring can help organizations analyze user and entity behavior, scan networks, and detect potential early signs of insider activity.
  • Role-based access – Employees should only have access to the information that they need to fulfill their job responsibilities. Providing employees access on a least-privilege basis helps minimize the risk of unauthorized access and misuse.
  • Culture of awareness – Regular cybersecurity training, including on best practices such as locking one’s computer and maintaining proper password hygiene, can help minimize unauthorized insider access.

Since malicious insiders often already have some level of existing access to an organization’s systems and knowledge of business practices and organization policies, such threats can cause significant harm. Insider threat prevention should be an integral component of all organizations’ overall cybersecurity posture.

The Trump administration has systematically fired federal privacy- and security-focused employees since taking office.

Three members of the bipartisan, independent agency, the Privacy and Civil Liberties Oversight Board (which was established by Congress in 2004 “to ensure that the federal government’s efforts to prevent terrorism are balanced with the need to protect privacy and civil liberties”) were fired on January 27, 2025.   

The administration has also fired multiple members of the privacy team and employees who oversee Freedom of Information Act (FOIA) requests from the Office of Personnel Management (OPM), which is the equivalent of the federal government’s human resources department. The firings were discovered when CNN filed a FOIA request with OPM seeking information about the security clearances of Elon Musk and “anyone from the Department of Government Efficiency (DOGE) who has been granted access to sensitive or classified government networks.”

OPM’s response to CNN’s FOIA request, as reported by CNN, was, “Good luck with that they just got rid of the entire privacy team.” In addition to the privacy team and the FOIA response team, the administration fired other members of OPM’s communications staff. Although an OPM official told CNN that the agency did not lay off the entire privacy team, and some of the firings are not effective until April 15, these actions call into question whether OPM can still “ensur[e] the agency’s data privacy practices meet legal requirements and protect the trust of the public” with the sensitive data housed within OPM.

Jonathan Kamens, Information Security Lead at the Department of Veterans Affairs, was also fired. The Associated Press reports that, according to Kamens, sensitive health data of millions of veterans stored on a benefits website is at risk of compromise. Kamens oversaw security for the VA.gov website and was responsible for “securing private health and financial information including bank account numbers and credit card numbers.” According to Kamens, millions use the VA.gov website monthly: “VA.gov has access to a huge number of databases within VA in order to provide all of those benefits and services to veterans, so if that information can’t be kept secure, then all of that information is at risk and could be compromised by a bad actor.” Kamens questioned whether DOGE workers were background-checked to access the data, alleging that “[t]hey’re not confirmed to be trustworthy.”

More recently, 21 DOGE staffers resigned on February 25, 2025, stating that they would not use their “skills as technologists to compromise core government systems, jeopardize Americans’ sensitive data, or dismantle critical public services…We will not lend our expertise to carry out or legitimize DOGE’s actions.” According to the joint resignation letter, the staffers (who had previously been part of the U.S. Digital Service, which was assimilated into DOGE after the inauguration) wrote, “We swore to serve the American people and uphold our oath to the Constitution across presidential administrations. However, it has become clear that we can no longer honor those commitments.”

Earlier in February, about 40 staffers from the Digital Service had been laid off. The resignation letter claimed that “[t]hese highly skilled civil servants were working to modernize Social Security, veterans’ services, tax filing, health care, disaster relief, student aid, and other critical services. Their removal endangers millions of Americans who rely on these services every day. The sudden loss of their technology expertise makes critical systems and American’s data less safe.”

The resigning staffers also alleged that they were interviewed by individuals wearing White House visitors’ badges (some of whom would not identify themselves) about their politics after the inauguration. According to the staffers, these individuals appeared to have “limited technical ability,” and the process “created significant security risks.”  

Federal employees focused on privacy and security are tasked with ensuring that all of our data is accessed, used, and disclosed lawfully and that our data is protected and secured using established protocols. It is very uncertain at this time whether these laws and protocols are being followed when so many of these employees have been fired. It is crucial to stay abreast of the impacts these firings will have on the protection of our data and to be able to obtain assurances that proper measures are being taken by DOGE employees who have access to the data. We will continue to update our readers on these issues as they unfold.

Last year, the Illinois Judicial Conference Task Force on Artificial Intelligence (IJC) was created to develop recommendations for how the Illinois Judicial Branch should regulate and use artificial intelligence (AI) in the court system. The IJC made recommendations to the Illinois Supreme Court, which adopted a policy on AI effective January 1, 2025.

The policy is consistent with the American Bar Association’s AI Policy. The policy states that “the Illinois Courts will be vigilant against AI technologies that jeopardize due process, equal protection, or access to justice. Unsubstantiated or deliberately misleading AI generated content that perpetuates bias, prejudices litigants, or obscures truth-finding and decision-making will not be tolerated.” In addition, the Illinois Supreme Court reiterated that “The Rules of Professional Conduct and the Code of Judicial Conduct apply fully to the use of AI technologies. Attorneys, judges, and self-represented litigants are accountable for their final work product. All users must thoroughly review AI-generated content before submitting it in any court proceeding to ensure accuracy and compliance with legal and ethical obligations. Prior to employing any technology, including generative AI applications, users must understand both general AI capabilities and the specific tools being utilized.”

Simultaneously, the Illinois Supreme Court published a judicial reference sheet that explains what AI and generative AI are, and what judges should watch for if litigants are using AI technology, including hallucinations, deepfakes, and extended reality. We anticipate more state courts will develop and adopt policies for AI use in the court system. Judges, lawyers, and pro se litigants should stay apprised of the court rules in the states in which they are active.

This week, I received a fake text message (a smish) saying my E-ZPass account was overdue and that I urgently needed to pay it. That’s a new one and, apparently, quite effective. Luckily, I knew it was a scam, but others were victimized.

According to the website Krebs on Security, security researchers “say the surge in SMS spam coincides with new features added to a popular commercial phishing kit sold in China that makes it simple to set up convincing lures spoofing toll road operators in multiple U.S. states.”

Residents in multiple states have been targeted, to the point where the Massachusetts Department of Transportation issued a warning about the smishing scheme using its EZDriveMA electronic tolling program. Others targeted by the scam include California, Colorado, Connecticut, Florida, Minnesota, Rhode Island, Texas, and Washington residents.

According to a reported conversation with a security researcher at SecAlliance, these smishing attacks increased after the New Year, when “at least one Chinese cybercriminal group known for selling sophisticated SMS phishing kits began offering new phishing pages designed to spoof toll operators in various U.S. states.” The purpose is to get consumers’ credit card information.

It has been such a problem that the Federal Trade Commission issued a consumer alert about it last week. If you receive a smish purporting to be from a toll road operator, delete it. Do not click the link or visit the site it directs you to.

As we outlined in our previous blog article, California recently became the second state to enact a law safeguarding consumer brain data, following a similar law passed by Colorado in April. Both state laws prevent the sale or unauthorized sharing of data generated by consumer neurotechnology products. Under these new state privacy laws, companies must disclose the types of brain data they collect and their uses and disclosures of it.

The amendment adds brain data (i.e., neural data) neural data to the definition of personal information and will take effect on January 1, 2025. Neural data is information derived from an individual’s brain, spinal cord, or nervous system, which is collected and interpreted by a device. Neurotechnology includes any device designed to understand brain activity or visualize brain processes. These products, which are becoming more accessible to consumers, can be beneficial as they can improve or repair brain functions. Additionally, these products have the ability to observe and record brain data, which could, in turn, be used to determine consumers’ emotions and preferences and infer thoughts, all of which raise privacy concerns.

These technologies are not novel; they have been used to diagnose and treat neurological disorders and alleviate systems of neurological diseases such as epilepsy. The novelty lies in the use of neurotechnology outside of the clinical setting by consumers on the free market.

Consumers can purchase headbands to help them meditate and earbuds to monitor stress levels and other brain activity. Without appropriate regulation of this data and its use, companies could misuse the data for behavioral advertising, profiling, and/or discrimination. Further, if not secured properly, this type of data could be sought after by cybercriminals due to its sensitive, valuable nature. Similar to biometric data, brain data is uniquely tied to an individual’s identity. If an individual’s brain data is compromised, it cannot be replaced or updated in the same way that a credit card account number can be canceled and reissued.

We’ll continue to monitor the regulatory landscape for additional state amendments that are likely to come.

This week, Marriott International, Inc. and its subsidiary Starwood Hotels & Resorts Worldwide LLC (collectively, Marriott) agreed to settle on the terms of a settlement order with the Federal Trade Commission (FTC) for its alleged failures to implement reasonable security measures which in turn led to three data breaches between 2014 and 2020, affecting over 344 million consumers across the globe. The type of data affected included names, passport information, payment card numbers, loyalty numbers, dates of birth, email addresses, and other types of personal information. Specifically, the FTC alleged that Marriott failed to implement appropriate password controls, access controls, firewall controls, or network segmentation; patch outdated software and systems; adequately log and monitor network environments; or deploy adequate multifactor authentication.

Pursuant to the Order, Marriott will:

  • Provide all U.S. consumers with a means to request deletion of their personal information;
  • Allow all U.S. consumers to review loyalty rewards accounts upon request and reinstate loyalty points if such points were stolen as a result of the breach(es);
  • Clearly and transparently disclose to consumers how Marriott collects, maintains, uses, deletes, and discloses consumers’ personal information;
  • Minimize the retention of personal information only for as long as such information is needed to fulfill the purpose for which it was collected;
  • Implement and maintain a comprehensive information security program and certify compliance to the FTC annually for 20 years; and,
  • Undergo an independent, third-party security risk assessment every two years;

The FTC does not have legal authority to require Marriott to pay civil penalties in this matter. Additionally, this week, Marriott agreed to pay a $52 million penalty to 49 states and the District of Columbia to resolve similar data security allegations made by state regulators.

A 34-page class action was filed against Blackhawk Network for a data breach that occurred on MyPrepaidCenter.com in September of this year. The plaintiffs allege that Blackhawk Network’s failure to prevent or detect this incident was “particularly egregious” since it operates a website where consumers can activate and manage prepaid gift cards, which requires collection of lots of sensitive and high-risk data.

The incident involved unencrypted and unredacted names, email addresses, telephone numbers, and payment card data (such as card numbers, expiration dates, and CVV codes). The complaint states that Blackhawk had “blocked” the impacted prepaid cards, but did not address the data involved in the breach.

The plaintiffs further allege that as a result of this incident and Blackhawk’s failure to prevent or detect the incident, MyPrepaidCenter.com users have and will incur “real and imminent harm” such as unauthorized credit card charges, theft of their personal information, loss of use and access to financial accounts, loss of time, and future risks related to the unauthorized access to their data by cybercriminals.

This incident comes shortly after Blackhawk Network announced a similar breach in August 2020, when it detected suspicious activity on GiftCards.com. The action identifies the class as all users who were impacted by the September 2022 breach, including all individuals who received notification from Blackhawk.