Email Marketing Service Provider's Data Breach Likely to Affect Millions
Time 1 Minute Read
Categories: Security Breach

On April 1, 2011, Epsilon Data Management, LLC (“Epsilon”), a leading marketing services provider based in Irving, Texas, issued a press release announcing that its clients’ customer data had been “exposed by an unauthorized entry into Epsilon’s email system” that took place on March 30, 2011.  In the press release, Epsilon indicated that the information acquired as a result of the incident was limited to email addresses and customer names.  Several major retailers, credit card issuers, financial institutions and other companies that use Epsilon as a service provider have since notified their customers of the incident.  According to the various company statements and emails to customers distributed as a result of this incident, no other personal information (such as bank account information, credit card numbers or Social Security numbers) was compromised.  Potentially affected customers are being warned of possible “phishing” attacks that could be linked to the information acquired as a result of this incident.  Epsilon’s breach has the potential to be one of the largest in U.S. history.

You May Also Be Interested In

Time 5 Minute Read

Connecticut enacted SB 1295 in June, which added another round of amendments to the Connecticut Data Privacy Act. While most of the changes will take effect on July 1, 2026, impact assessment requirements will apply to processing activities created or generated on or after August 1, 2026.

Time 8 Minute Read

On April 22, 2025, the Federal Trade Commission published in the Federal Register final amendments to the Children’s Online Privacy Protection Act Rule, which will go into effect 60 days from publication, on or about June 21, 2025, with a compliance deadline of April 22, 2026.

Time 2 Minute Read

As part of the California Privacy Protection Agency’s investigative sweep of data broker registration compliance under California’s Delete Act, the CPPA recently announced an enforcement action against a Florida-based data broker and a settlement with a California-based data broker for failure to register as a data broker on the California Data Broker Registry, as required under the Delete Act.

Time 2 Minute Read

On January 23, 2025, the New York Department of Financial Services (“NYDFS”) announced a $2 million civil fine against PayPal, Inc. (“PayPal”) for alleged cybersecurity failures that resulted in the unauthorized exposure of customers’ personal information. 

Search

Subscribe Arrow

Recent Posts

Categories

Tags

Archives

Jump to Page