1、CRS Legal Sidebar Prepared for Members and Committees of Congress Legal SidebarLegal Sidebari i What Legal Obligations do Internet Companies Have to Prevent and Respond to a Data Breach? October 25, 2018 Recently, large Internet companiesi.e., companies that do most of their business on the Internet
2、, such as social media platforms or search engineshave made headlines after failing to secure their users personal information. For example, on September 28, 2018, Facebook announced a security breach affecting tens of millions of user accounts. According to Facebook, hackers exploited a vulnerabili
3、ty in its code that allowed them to steal “access tokens,” which are the “equivalent of digital keys” that “keep people logged in to Facebook.” Facebook later disclosed that, of the affected accounts, hackers accessed the names and contact details of 15 million users and the biographical information
4、 of another 14 million users. Just over a week after Facebooks breach, on October 8, 2018, Google, in announcing the end of its social network Google+, disclosed that a software glitch exposed the personal data associated with up to 500,000 Google+ accounts. Google explained that it discovered and r