Data Breaches in New York Hit Record High in 2013, State Attorney General Says
Last year was a record-setting one for the state of New York — and not in a good way. — Public and private institutions in New York experienced more than 900 data breaches in 2013, according to a report released …
Context & Ripple Effects
The New York Attorney General's tally is the first statewide, official count of its kind in this corpus, and it lands on an arc that has been running for years: Computerworld flagged deteriorating data safety back in 2007, and Pew's April 2014 survey found the share of online Americans who had important personal information stolen had climbed from 11% to 18% year over year.
What makes the report matter is who compiled it — a state law-enforcement office rather than a security vendor — turning what was previously vendor-estimated risk into an officially counted problem across both public and private institutions. The pickup by security-trade outlets Tech Times and We Live Security signals the number resonated with practitioners even without broader consumer-press spread.
First-order effects
- More than 900 affected New York institutions — public agencies and private companies alike — face notification duties and exposure to Attorney General scrutiny, since the office that counted the breaches is positioned to enforce against them.
- Consumers whose records were exposed gain a documented, official basis for credit monitoring and identity-theft claims rather than relying on company disclosures alone.
Second-order effects
- Other state attorneys general have a template to copy: annual breach tallies convert scattered incident reports into a public scoreboard, raising the political cost of weak institutional security.
- Security vendors and cyber-insurance sellers gain an official demand driver — a government-published record number makes breach preparedness an easier boardroom sell.
Third-order effects
- If states keep publishing these counts, breach disclosure hardens into a standing regulatory regime with attorneys general acting as de facto privacy enforcers, independent of any federal standard.
- Institutions shift security from an IT cost center to a compliance function, because an official annual tally makes every incident publicly attributable by name and sector.
The trend: Data-breach reporting is moving from voluntary corporate disclosure to mandated state-level accounting, with attorneys general emerging as the primary public counters of institutional security failure.