Individual Project
.docx
keyboard_arrow_up
School
George Mason University *
*We aren’t endorsed by this school
Course
320
Subject
Information Systems
Date
Dec 6, 2023
Type
docx
Pages
12
Uploaded by KidPuppyMaster1919
The Case Study of Cash App Data Breach
Geraldine Arandid
Professor Chun-Lung Huang
MIS 320-001
May 5, 2023
1
Cash App
The simplest way to transfer, spend, save, and invest money is with the Cash App.
When
the Cash App was introduced in 2013, it offered consumers a practical way to transfer and receive
money without using a bank or wire service. Since then, it has broadened its range and currently
offers other services including Cash App-connected debit cards, direct deposit assistance, and an
investing platform. To compete with mobile payment applications like Venmo and PayPal, Block,
Inc., previously Square, Inc., also introduced the app in 2013. At the time, it was initially known
as Square Cash. Cash App has its customization of debit cards. Cash App is the US’s top
financial app. According to AppMagic estimates, it has had more than 36 million so far this year
which is across the App Store and Google Play. Customers may also take advantage of cashback
deals from establishments including McDonald’s, Walgreens, Walmart, and Whole Foods
(Freitas, 2022). Customers can pay other users who have linked a bank account, credit card, or
debit card, or request money from them via the platform. Although Cash App doesn’t have access
to transfer the balance to the prepaid card, it can use to add money to Cash App. Through partner
banks, the Federal Deposit Insurance Corporation insures the remaining balance in your account.
Cash App Investing LLC, a broker-dealer registered with the Securities and Exchange
Commission and a participant in the Financial Industry Regulation Authority, offers investing
services. In addition, the users of the investing tool can invest as little as $1 in equities.
This is
accomplished by purchasing a fractional share---a small component of a stock. Through the app,
users can also buy, sell, or transfer Bitcoin. Users also may file their taxes for free with Cash App
Taxes which used to be Credit Karma Tax. It is gradually becoming a one-stop shop for financial
services. Therefore, Cash App is convenient for all customers by using their phones to pay, send,
and transfers money.
2
Instruments
About 8.2 million current and former customers are being contacted via Cash App’s
Investing platform with information and resources related to the incident (Kost, 2023).
One of
the representatives of Cash App verified the data breach and mentioned that names and brokerage
account numbers were among the data in the disclosed reports. It also revealed the valuation,
holdings, and stock trading activity for certain investors’ brokerage portfolios for trading.
According to reports, the exposed data did not contain any personally identifying data such as
usernames, passwords, Social Security Numbers, credit card information, addresses, or banking
information (Cybertalks, 2022). They investigated that none of the security codes, access codes,
or passwords used to access Cash App accounts were impacted by the hack. In this incident, it
was an insider threat attack because, after the termination of that employee, he stole all the
information from the Cash App customers to hack it without asking permission, and he had the
advantage for that. Even though it had a data breach, Cash App is the most popular mobile
payment app in the US. It was developed by Square and has used a variety of various techniques
to expand the user base and boost service acceptance. Cash App company has a strategy which is
the social media marketing strategy. To drive app downloads, the business has been utilizing
innovative viral and influencer marketing methods. One of these tactics is to use sportsmen and
musicians in its advertisements and to work with hip-hop influencers and their followers. Cash
App has also advertised its commercials on social media apps like Instagram, Twitter, YouTube,
Snapchat, and Facebook. With that kind of strategy, Cash App used the 4Cs of successful brand
building which are community, collaborations, content, and curation. Overall, Cash App mastered
and became successful in its marketing strategy until now.
3
The Events
Despite of has a lot of benefits in Cash App for all customers and banks and becoming
popularity, it has some flaws or issues with that app. Cash App was likely affected and informed
by the breach, and it was about 8.2 million current and former Cash App customers (Kost, 2023).
The Securities Exchange Commission that Block owns the financial service company in the Cash
App, Block filed a report that the employee stole and downloaded all the information without
permission. These are the following information that the employee stole and downloaded: Full
Name, Brokerage Account Numbers, Portfolio Values and Holdings, and Stock trading activity
for one day of trading. According to the New York Times, Cowley interviewed Block, owner of
the Square Cash and Cash App, about why Cash App got hacked or data breached. It happened
around December 2021 and was made public when a former worker obtained business reports
after quitting the job. Also, when they interviewed the company, they explained that reports were
available for all employees to examine and download as part of their duties. According to Block,
the unidentified person was not prevented from promptly obtaining this information after the
employee stopped working for Cash App. With that incident, Block has taken this data extremely
seriously and is investigating with the assistance of the appropriate law enforcement and
regulatory agencies.
Outcomes
This incident happened in December 2021; most people think that hacking Cash App is
easy. It appears that the information required to access internal documents was given to a hacker
or hacking group by a former worker who is terminated or quit the company. To comply with the
regulations for publicly listed firms, the company acknowledged the security breach in a filing.
4
This was done to avoid a severe public reaction should the company have tried to ignore the
incident. With that, to protect confidential customers and internal information, the business may
use biometric authentication in conjunction with other security measures. Following the attack, a
digital forensic investigation revealed that an internal threat actor had downloaded reports
containing data on Block’s Cash App users residing in the US (Steven, 2022). With the
cooperation of law enforcement, a formal investigation into the data breach was carried out. In a
separate statement, Block said it will keep researching technical and managerial protections to
make sure clients could give the cryptocurrency corporation their sensitive personal data.
Ethics Analysis
Since inadequate security measures were in place, the Cash App data breach became
possible. Also, a new class action complaint claims that Cash App and Block breached in
December 2021 and neglected to protect the client data. According to the Cash App and Block
class action, the data breach was discovered after Block revealed that one of its former employees
had improperly obtained the private information of Cash App investors. Block alerted authorities
to the breach and, with the aid of a reputable forensics company that must remain nameless,
started an ongoing investigation into the event. It was about 8.2 million customers of Cash App
were affected by the breach, and they were informed. Sadly, the delay in sending this breach
notification which was sent four months after the incident increased the possibility of additional
cyberattacks against the affected customers (Kost, 2023).
The investigation continues when I research about Cash App data breach, which happened
recently. In 2021, after he left, the employee stole all the information such as the account name,
brokerage account number, portfolio values, and stock trading from 8.2 million customers of
5
Your preview ends here
Eager to read complete document? Join bartleby learn and gain access to the full version
- Access to all documents
- Unlimited textbook solutions
- 24/7 expert homework help