Cybersecurity, Privacy, & AI

Trending Now
5 Structural Barriers Breaking Your Cybersecurity Compliance Framework • Everyone’s Building AI Agents. Almost Nobody’s Ready for What They Do to Identity. • GAO Identifies Shortfalls in DCSA Industrial Data Security Oversight • Disclosed Government AI Use Increased by 70% in 2025, per OMB • Congress Tries Again on National Preemptive Data Privacy Law

CFTC Brings Cybersecurity Enforcement Action

The U.S. Commodity Futures Trading Commission has reached a $100,000 settlement with a registered futures merchant, which it charged with failing to diligently supervise an IT provider’s implementation of provisions in the merchant’s written IT security program. This is a rare case of an CFTC enforcement action premised on a cybersecurity failure at a registered entity.

The case involved a defective network-attached storage device installed by the vendor, which exposed unencrypted customer records for 10 months, resulting in them being accessed. The vendor failed to detect the problem in subsequent risk assessments, even though the hacker had blogged about exploiting this vulnerability elsewhere. The merchant only learned about the breach when the hacker contacted them.

The CFTC charged the merchant under Regulation 166.3, which requires that every CFTC registrant “diligently supervise the handling [of confidential information] by its partners, officers, employees and agents,” and Regulation 160.30, which requires them to “adopt policies and procedures that address administrative, technical and physical safeguards for the protection of customer records and information.”

Stay compliant and protected with daily updates on cybersecurity, data privacy, and federal oversight with our Cyber & Privacy newsletter, delivering up-to-the-minute intelligence Monday–SaturdaySubscribe here.