Scarinci Hollenbeck, LLC, LLCScarinci Hollenbeck, LLC, LLC

Firm Insights

Companies Who Fail to Patch Log4j Vulnerability Could Face FTC Enforcement

Author: Scarinci Hollenbeck, LLC

Date: February 14, 2022

Key Contacts

Back
Companies Who Fail to Patch Log4j Vulnerability Could Face FTC Enforcement

The FTC is advising companies to work quickly to remediate the Log4j security vulnerability...

The Federal Trade Commission (FTC) is advising companies to work quickly to remediate the Log4j security vulnerability. Failure to act could result in an FTC enforcement action under applicable laws such as the Federal Trade Commission Act and the Gramm Leach Bliley Act. 

Cyber Risks Posed by Log4j Vulnerability

Log4j is very broadly used in a variety of consumer and enterprise services, websites, and applications—as well as in operational technology products—to log security and performance information. In December, a critical security flaw was discovered, which could be exploited by an unauthenticated remote actor to take control of an affected system. 

On January 3, 2022, Microsoft warned that the vulnerabilities in Apache Log4j 2, referred to as “Log4Shell”, remain a “complex and high-risk” situation for companies. It further advised that due to the “many software and services that are impacted and given the pace of updates, this is expected to have a long tail for remediation, requiring ongoing, sustainable vigilance.”

In light of the severity of the vulnerabilities and the likelihood of exploitation by sophisticated cyber threat actors, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) urges vendors and users to immediately identify, mitigate, and update affected products using Log4j to the latest version. It also recommends that companies conduct a security review to determine if there is a security concern or compromise.

FTC Warning

On January 4, 2022, the FTC issued an alert regarding the Log4j security vulnerability, noting that it poses a severe risk to millions of consumer products to enterprise software and web applications. The FTC encouraged companies to update their Log4j software package to the most current version found and follow guidance issued by CISA.

The FTC also advised companies to ensure remedial steps are taken to avoid legal repercussions, emphasizing that the failure to identify and patch instances of the software may violate the Federal Trade Commission Act (FTC Act). 

“When vulnerabilities are discovered and exploited, it risks a loss or breach of personal information, financial loss and other irreversible harms,” the agency wrote. “The duty to take reasonable steps to mitigate known software vulnerabilities implicates laws including, among others, the Federal Trade Commission Act and the Gramm Leach Bliley Act. It is critical that companies and their vendors relying on Log4j act now, in order to reduce the likelihood of harm to consumers, and to avoid FTC legal action.”

The FTC alert also cited its enforcement action against Equifax, which involved the  company’s failure to patch a known vulnerability and the disclosure of the personal information of 147 million consumers. Equifax agreed to pay $700 million to settle actions by the FTC, the Consumer Financial Protection Bureau, and all fifty states. According to the FTC, it intends to use its “full legal authority” to pursue companies that fail to take reasonable steps to protect consumer data from exposure as a result of Log4j, or similar known vulnerabilities in the future. 

If you have questions, please contact us

If you have any questions or if you would like to discuss the matter further, please contact me, Maryam Meseha, or the Scarinci Hollenbeck attorney with whom you work, at 201-896-4100.

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Scarinci Hollenbeck, LLC, LLC

Related Posts

See all
Breaking Down New Jersey’s “Mansion” Tax: What Buyers and Sellers Need to Know post image

Breaking Down New Jersey’s “Mansion” Tax: What Buyers and Sellers Need to Know

For many years, the New Jersey Mansion Tax has been a significant consideration in high-value real estate transactions. Recent legislative changes, however, have substantially altered how the tax operates, including who is responsible for paying it and the amount owed in certain transactions. Whether you are purchasing, selling, or investing in New Jersey real estate, […]

Author: George McGowan

Link to post with title - "Breaking Down New Jersey’s “Mansion” Tax: What Buyers and Sellers Need to Know"
Estate Planning for Digital Assets Under New Jersey Law post image

Estate Planning for Digital Assets Under New Jersey Law

As our personal and financial lives increasingly move online, estate planning must evolve to address a new category of property: digital assets. From email accounts and social media profiles to cryptocurrency and cloud-stored business records, these assets often carry both financial and sentimental value. Yet, without proper planning, they can become inaccessible—or even lost—upon incapacity […]

Author: Marc J. Comer

Link to post with title - "Estate Planning for Digital Assets Under New Jersey Law"
The Role of Representation and Warranty Insurance in M&A Transactions post image

The Role of Representation and Warranty Insurance in M&A Transactions

In today’s mergers and acquisitions market, representation and warranty (R&W) insurance has become a common feature of deal negotiations. Once used primarily in larger transactions, R&W insurance is now frequently incorporated into middle-market deals as buyers and sellers look for efficient ways to allocate risk and close deals. When structured properly, R&W insurance can help […]

Author: George McGowan

Link to post with title - "The Role of Representation and Warranty Insurance in M&A Transactions"
You Just Received a Federal Grand Jury Subpoena in New Jersey: Now What? post image

You Just Received a Federal Grand Jury Subpoena in New Jersey: Now What?

Receiving a federal grand jury subpoena is not something most businesses or individuals anticipate. While it can be concerning, a federal grand jury subpoena does not necessarily mean that you are being accused of wrongdoing. It does, however, mean that a federal criminal investigation is underway and that federal prosecutors believe you may possess information […]

Author: George McGowan

Link to post with title - "You Just Received a Federal Grand Jury Subpoena in New Jersey: Now What?"
Why Every Business Should Conduct an Annual Insurance Coverage Review post image

Why Every Business Should Conduct an Annual Insurance Coverage Review

Most New Jersey business owners purchase insurance policies, file them away, and assume they are protected if a claim arises. Without a regular insurance coverage review, many companies discover gaps only after a lawsuit, cyberattack, property loss, or other significant event occurs. An annual insurance coverage review can help businesses identify potential risks, ensure their […]

Author: George McGowan

Link to post with title - "Why Every Business Should Conduct an Annual Insurance Coverage Review"
Demand Letters & Cease and Desist Letters: When to Send One (and When Not To) post image

Demand Letters & Cease and Desist Letters: When to Send One (and When Not To)

Businesses and individuals often encounter situations where another party breaches a contract, fails to pay a debt, or continues harmful conduct. In many such disputes, a precisely drafted demand letter or cease-and-desist letter serves as a powerful legal tool. It can frequently resolve the dispute and avoid litigation. While demand or cease-and-desist letters can resolve […]

Author: George McGowan

Link to post with title - "Demand Letters & Cease and Desist Letters: When to Send One (and When Not To)"

No Aspect of the advertisement has been approved by the Supreme Court. Results may vary depending on your particular facts and legal circumstances.

Sign up to get the latest from our attorneys!

Explore What Matters Most to You.

Consider subscribing to our Firm Insights mailing list by clicking the button below so you can keep up to date with the firm`s latest articles covering various legal topics.

Stay informed and inspired with the latest updates, insights, and events from Scarinci Hollenbeck. Our resource library provides valuable content across a range of categories to keep you connected and ahead of the curve.

Let`s get in touch!

* The use of the Internet or this form for communication with the firm or any individual member of the firm does not establish an attorney-client relationship. Confidential or time-sensitive information should not be sent through this form. By providing a telephone number and submitting this form you are consenting to be contacted by SMS text message. Message & data rates may apply. Message frequency may vary. You can reply STOP to opt-out of further messaging.
“If you would like to submit a file, please email it directly to info@sh-law.com.

Sign up to get the latest from the Scarinci Hollenbeck, LLC attorneys!