Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

Snapchat finally apologizes for data breach – here’s what they should’ve done

By Anna Gallegos on January 10, 2014
Email this postTweet this postLike this postShare this post on LinkedIn

Snapchat, the photo-sharing app popular among millennials, apologized in an anonymous blog post for a data breach that exposed 4.6 million users’ phone numbers after downplaying the issue for several weeks.

Credit - Julie Schoenig
Credit – Julie Schoenig

The non-malicious hack was allegedly done to expose a security vulnerability in an feature that uses phone numbers to find users’ friends and to pressure the company to fix it. The hackers removed portions of telephone numbers but have offered the stolen information for download on their website.

While no other user data was leaked, the company has been skirting the technical flaw since August reports Reuters.

With Snapchat’s apology following the Target data breach, greater attention has been brought to what companies should do to protect consumer data both online and offline.

While no claims have been filed against Snapchat yet, numerous lawsuits were filed against Target the very day news broke about their data breach with some suits alleging that Target did not notify customers in a timely manner that their credit card numbers were stolen.

According to Al Saikali, partner at Shook, Hardy & Bacon and author of Data Security Law Journal, the steps that companies take before notifying customers can be time consuming.

First, you need to identify and understand the nature of the compromise, and you have to be reasonably sure that the compromise has been contained and remediated so it is no longer a threat.  This step alone can take days or weeks to complete depending on the level of sophistication of the attack.  Further complicating this step is the coordination with law enforcement, who may be concerned that acting too quickly will inhibit their ability to identify the perpetrators.  After the integrity of your system has been restored, you need to identify what information was affected by the breach.  If you learn that personal information was potentially compromised as a result of the breach, you need to know whose information was affected so you can quickly inform them and regulatory authorities in compliance with applicable legal requirements.  Undertaking this entire process can often take weeks.

46 states have laws that require a timely notification of a data breach, but Congress is pushing for legislation and hearings to protect consumers against future hacks, write attorneys at Covington & Burling‘s InsidePrivacy.

While the hackings for both of these companies were done by third parties, Target and Snapchat have both come under fire for not adequately protecting their users.

In the case of Snapchat, CEO Evan Spiegal said “I believe at the time we thought we had done enough” about preventing the data leak. Seems that’s certainly not the case. TechCrunch’s Natasha Lomas had this to say on the breach:

Beyond Spiegel’s earlier ‘not going to cry over spilt milk’ attitude to user data leaks, the breach has been hugely embarrassing for Snapchat because it ignored (and even scoffed at) warnings about how its systems could be exploited — only for the exploit to subsequently be carried out. Oops.

Let that be a lesson to app makers everywhere to care a lot more about user data security. And to underestimate hackers at your peril.

That last line is key.

In these situations, companies are likely to be targets of ire regardless of who is responsible for the lost data, said Jason Weinstein, a former cybercrime prosecutor at the Department of Justice and now a partner at Steptoe & Johnson, in a interview this week on LXBN TV discussing the Target breach.

“These companies … find themselves victimized by hackers are then victimized again as the public and the courts and regulators seem to blame them for not having done more to prevent the breach,” said Weinstein. “It’s almost like a bank manager being blamed for allowing his bank to be robbed.”

After the damage is done, companies cannot hack the hackers because, according to Weinstein, the Computer Fraud and Abuse Acts prohibits that even if companies have the resources to go after their stolen data, leaving businesses to rely on law enforcement.

Saikali suggests that companies be more proactive about how they secure their proprietary data and customer information. His recommendations include identifying an indemnification clause with parties that store data, identifying what servers are required to do to protect data and prepare a legal plan of action in case there is a breach.

Instead of waiting for a data disaster, mobile apps, like Snapchat, need a well-written privacy policy to protect them from legal action and keep users on what is happening to their information.

  • Posted in:
    Privacy and Cybersecurity, Technology and AI
  • Organization:
    LexBlog

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo