A $250,000 penalty and a vendor that went dark
Free weekly email
This went to subscribers on August 11. Get the next one.
One email every Tuesday: what changed in security and compliance that week, and what it means if you sell to enterprise buyers.
Free. Unsubscribe in one click, and replies reach Jacob directly. Read the latest issue or browse the archive.
This is the first issue of a weekly note on what actually moved for Canadian SaaS companies selling into the United States. I read the same feeds you do not have time for, and I keep the items that change how a US security review or a vendor contract goes. Five stories this week, all with a consequence attached.
New York fined a money transmitter for a weak program, not a breach
Source: DataBreaches.net
The New York Department of Financial Services announced that Order Express, a licensed money transmitter, will pay a $250,000 penalty for violations of the DFS cybersecurity regulation, 23 NYCRR Part 500. DFS investigators identified deficiencies in the company's cybersecurity program. The settlement was announced on August 5.
For fintech readers this is the enforcement pattern that matters most, because the penalty attached to program gaps rather than to a headline incident. When your customer is covered by Part 500, its obligations arrive on your desk as contract language about access controls, risk assessments and notification windows, and their examiners are the reason they will not negotiate on those clauses. If you are in a deal with a New York regulated institution, read Part 500 once yourself instead of relying on your counsel's summary of the security exhibit.
LexisNexis pulled products offline over a third-party vendor incident
Source: BleepingComputer
LexisNexis took several services offline, including Diligence and the Metabase API, in response to unusual activity on servers hosted and managed by a third-party vendor it has not named. The company treated the shutdown as part of its incident response.
Taking the service down was the right call, and it is also the version of vendor risk that most SaaS companies have never modelled. Your subprocessor list probably names the screening or data provider, and almost certainly says nothing about who runs their infrastructure, so an outage two layers out becomes your degraded onboarding flow and your customer notification. I would spend an hour this week deciding what your product does if a KYC or enrichment provider is unavailable for three days, and write that down before a US reviewer asks.
The Snowflake extortion case ends with a guilty plea in Kitchener
Source: Krebs on Security
Connor Riley Moucka of Kitchener, Ontario, pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used Snowflake. He also admitted to stealing call and text history records of more than 100 million AT&T customers. He was described as one of the most consequential threat actors of 2024.
My read has not changed since that campaign broke: the platform held and the tenants did not, and every question you now get about enforced SSO, MFA on service accounts and contractor access to production data traces back to it. If you run a warehouse with customer data in it, assume a US buyer's security team already knows this case and is looking for the control that would have stopped it in your environment. The Canadian angle is only atmosphere, though it does mean your reviewers have read a story with Ontario in the headline.
Gunra ransomware is getting in through firewalls, per a joint advisory
Source: The Hacker News
US and South Korean agencies issued a joint advisory on Gunra, a ransomware-as-a-service operation that has been breaching organizations by exploiting vulnerabilities in Fortinet and Schneider Electric products. Named targets span critical infrastructure, healthcare, financial services and government. The group uses double extortion, encrypting data and threatening to publish what it exfiltrates.
Nothing in this advisory is novel, which is the uncomfortable part. Internet-facing appliances remain the cheapest way in, and most companies I test have a documented patch SLA for servers and an informal one for the firewall and the VPN concentrator. Pick the number you can actually meet for edge devices, put it in your policy, and then produce evidence that you met it, because the alternative is writing a slower number into an audit finding later.
Hidden prompt injection is showing up in "Ask AI" buttons on marketing pages
Source: The Hacker News
Researchers observed production websites embedding hidden prompt injection payloads inside pre-filled deep links behind "Ask AI" buttons, including on marketing and competitor comparison pages. The technique needs no malware, no stolen credentials and no zero-day, because it abuses a normal feature of major AI assistants. The payloads can influence what an assistant later tells the user.
This one sits on your marketing site rather than in your product, which means the people shipping it do not report to your head of engineering. If you have added an AI assistant handoff to your site, someone should be reviewing what those links actually carry and where the text comes from. I expect the questionnaire version of this within a year, phrased as some awkward question about how you validate untrusted input to LLM features, so having an answer early is cheap.
That is the week. If a story you expected is missing, it is because I could not find a consequence in it for a company in your position.
Jacob
Free weekly email
Get the next issue on Tuesday
One email a week from Jacob Masse: the security and compliance stories that changed something that week, and what each one means if you sell software to enterprise buyers. Five stories, a take on each, five minutes to read.
Free. Unsubscribe in one click, and replies reach Jacob directly.