Major data breach involving 2 Maine firms headed to court (2024)

BerryDunn, a Portland accounting firm, and Reliable Networks of Biddeford are trading blame about who is responsible for the breach that resulted in the theft of personal information ranging from Social Security numbers to medical data of more than a million people.

Posted

Updated

Major data breach involving 2 Maine firms headed to court (1)
Penelope OvertonPress Herald
Major data breach involving 2 Maine firms headed to court (2)
Hannah LaClaireStaff Writer

3 min read

Major data breach involving 2 Maine firms headed to court (3)Font size +

  • Facebook
  • Reddit
  • Linkedin
  • Email

Two Maine companies are pointing fingers at each other over who is to blame for a cybersecurity breach last fall that resulted in the theft of personal information ranging from Social Security numbers to medical data of more than a million people.

BerryDunn, a prominent Portland accounting firm, says one of its vendors, Reliable Networks of Biddeford, got hacked. Reliable Networks says it was hired to manage BerryDunn’s health care data, not secure it, and that it spotted the hack of BerryDunn’s network.

“The investigation found that an unauthorized actor gained limited access to the vendor’s network and took some data,” BerryDunn said on its website.

Reliable fired back on its website: “BerryDunn’s own network and system were breached by a third party, through no fault of Reliable Networks.”

The company blasted BerryDunn for its “baseless allegations” and said it was confident that once forensic analysis was complete, its claims would be found “devoid of any merit whatsoever.”

A spokesperson for BerryDunn said the company was addressing Reliable’s accusations with “the utmost seriousness” and that it is working with outside legal counsel to respond.

Advertisem*nt

“As is common in security incidents like these, claims are made despite a thorough forensics analysis,” the company said. “We always aim to work through issues, even complex and unfortunate ones, in a professional manner.”

Regardless of who is to blame, the companies agree that some combination of individuals’ names, addresses, birthdates, Social Security numbers, health insurance policy numbers, state or governmental ID numbers, passport numbers and medical information was stolen.

The dispute is likely to be hashed out in the U.S. District Court of Maine now that eight customers of BerryDunn came forward this week to accuse the company of negligence, unjust enrichment, and breach of fiduciary duty because of the September data theft.

According to BerryDunn, there is no evidence the stolen information has been misused. The company is offering credit monitoring and identity protection services from a third-party cybersecurity company to impacted individuals at no cost.

“We respect the privacy and security of information within our control, and sincerely apologize for any concern or inconvenience this may cause,” the company says in a message on its website. BerryDunn has 800 employees and is headquartered on outer Congress Street.

The plaintiffs, who hail from as far away as West Virginia and seek a jury trial and damages, say online thieves sometimes wait years to use stolen data. Social Security numbers are valuable because they can be used to fraudulently obtain credit cards, driver’s licenses and unemployment benefits.

Advertisem*nt

Martin Walter, senior director at cybersecurity firm RedSeal, described the high value of this kind of data in a 2015 edition of IT World magazine, “Compared to credit card information, personally identifiable information and Social Security numbers are worth more than 10x on the black market.”

Some of the plaintiffs note the high value of the medical information stolen.

A 2010 study by credit ratings company Experian found that the average cost of medical identity theft is “about $20,000” per incident and that most victims of medical identity theft were forced to pay out-of-pocket costs for health care they did not receive to restore coverage.

Almost half of medical identity theft victims lost their health care coverage as a result, the plaintiffs noted.

The plaintiffs, who hope to form a class-action lawsuit, complained about the seven-month delay between the discovery of the theft and their notification letters. If they had known about the hack, they say they would have kept a closer watch over their finances during that time.

The hack occurred in September. BerryDunn posted an initial notification of a data breach on its website in November but waited until a hired cybersecurity expert could tell them what data had been stolen, and from whom before it sent out customer notification letters in April.

“As soon as BerryDunn learned of the suspicious activity, it began an investigation,” BerryDunn wrote in a Frequently Asked Questions guide sent to impacted customers. “This process took time to complete due to the size and complexity of the data that had to be reviewed.”

To guard against possible identity theft or fraud, BerryDunn urged impacted individuals to review bank accounts, financial statements and credit reports for suspicious activity. Incidents of suspected identity theft should be reported to law enforcement or the attorney general.

Invalid username/password.

Success. Please wait for the page to reload. If the page does not reload within 5 seconds, please refresh the page.

Enter your email and password to access comments.

Hi, to comment on stories you must . This profile is in addition to your subscription and website login.
Already have a commenting profile? .

Invalid username/password.

Please check your email to confirm and complete your registration.

Only subscribers are eligible to post comments. Please subscribe or login first for digital access. Here’s why.

Use the form below to reset your password. When you've submitted your account email, we will send an email with a reset code.

Send questions/comments to the editors.

« Previous

College graduations begin in Maine even as protests disrupt ceremonies around the U.S.

Next »

Massachusetts man charged with assaulting infant in Wells

filed under:

health care, identity theft, Maine business

Related Stories

Major data breach involving 2 Maine firms headed to court (4)

Latest Articles

Major data breach involving 2 Maine firms headed to court (2024)

References

Top Articles
Latest Posts
Article information

Author: Arline Emard IV

Last Updated:

Views: 6502

Rating: 4.1 / 5 (52 voted)

Reviews: 83% of readers found this page helpful

Author information

Name: Arline Emard IV

Birthday: 1996-07-10

Address: 8912 Hintz Shore, West Louie, AZ 69363-0747

Phone: +13454700762376

Job: Administration Technician

Hobby: Paintball, Horseback riding, Cycling, Running, Macrame, Playing musical instruments, Soapmaking

Introduction: My name is Arline Emard IV, I am a cheerful, gorgeous, colorful, joyous, excited, super, inquisitive person who loves writing and wants to share my knowledge and understanding with you.