By using this site, you agree to our Privacy Policy and our Terms of Use. Close

Forums - General - Judge: Not Having The Best Security Not Illegal; Defrauded Company Can't Blame Bank

source

An interesting ruling coming out of Maine. A judge has sided with a bank, in a case in which a company tried to blame its bank for not having better security, after it was hit by a trojan horse password stealer on one of its computers and subsequently had scammers transfer about $600k out of its account. The judge agreed that the bank did not have particularly good security, but also noted that there is no legal requirement that the bank have the absolutely best security. This is definitely the right decision, even if some may have a gut reaction the other way. To some extent, the company has to take some responsibility for its own actions, and on the flip-side, one would hope that market pressures would drive the banks to implement better security. For example, in this case, the bank itself -- Ocean Bank -- is getting a ton of bad publicity about its really poor security due to this lawsuit. So, even if it's won the lawsuit, that hardly means the bank comes out of it unscathed.

Both sides not having  good security...



Around the Network

I'm kind of confused. Was the breach on the side of the company (the trojan horse) or was it at the bank? If at the company I agree with the ruling. If it was the banks fault I would they would be held responible- just as if someone had physically robbed the bank.



You can have the best security in the world and still probably get hacked.



there is a difference between not having the best and having piss poor security. like a bank using a piece of cardboard to cover a vault than an actual door.



"I like my steaks how i like my women.  Bloody and all over my face"

"Its like sex, but with a winner!"

MrBubbles Review Threads: Bill Gates, Jak II, Kingdom Hearts II, The Strangers, Sly 2, Crackdown, Zohan, Quarantine, Klungo Sssavesss Teh World, MS@E3'08, WATCHMEN(movie), Shadow of the Colossus, The Saboteur

So this is not a Sony hate thread :( to bad



Bet reminder: I bet with Tboned51 that Splatoon won't reach the 1 million shipped mark by the end of 2015. I win if he loses and I lose if I lost.

Around the Network

In this case, the company is more at fault for having their system completely compromised that the hackers could use their credentials to take the money out of the bank.

I agree somewhat the bank don't have to reimburse the company but they at least should be required to do an audit for their banking system.

It's the same story everywhere. Companies try to cut cost and the place they cut first and most is the IT portion.



Galaki said:
In this case, the company is more at fault for having their system completely compromised that the hackers could use their credentials to take the money out of the bank.

I agree somewhat the bank don't have to reimburse the company but they at least should be required to do an audit for their banking system.

It's the same story everywhere. Companies try to cut cost and the place they cut first and most is the IT portion.

I don't see in anyway how the Bank is at fault except for letting some take money that according to them was the correct person, they had the correct passwords and credentials (okay stolen ones but the bank didn't know that). The bank would have to pay thousands for someone elses fault.

But then it might be sensible to do just that if it wasn't for the last part.



Hmm, pie.

These companies need to invest in some killer robots liker robocop to hunt down thieves/hackers. That's A+ security.



Anyone who's breaking the law is obvious a criminal.