ARTICLE
31 August 2026

NYDFS Reaches Settlement With Money Transmitter Order Express Over Alleged Cyber Program Violations

SM
Sheppard, Mullin, Richter & Hampton LLP

Contributor

Businesses turn to Sheppard to deliver sophisticated counsel to help clients move ahead. With more than 1,200 lawyers located in 16 offices worldwide, our client-centered approach is grounded in nearly a century of building enduring relationships on trust and collaboration. Our broad and diversified practices serve global clients—from startups to Fortune 500 companies—at every stage of the business cycle, including high-stakes litigation, complex transactions, sophisticated financings and regulatory issues. With leading edge technologies and innovation behind our team, we pride ourselves on being a strategic partner to our clients.
The New York Department of Financial Services reached a $250,000 settlement with Order Express following a 2022 ransomware attack investigation. The case revealed inadequate risk assessments and software update policies that left the licensed money transmitter vulnerable to known security threats, highlighting what regulators expect from companies' cybersecurity measures.
United States New York Technology
Liisa M. Thomas’s articles from Sheppard, Mullin, Richter & Hampton LLP are most popular:
  • in European Union
Sheppard, Mullin, Richter & Hampton LLP are most popular:
  • within Strategy and Insolvency/Bankruptcy/Re-Structuring topic(s)

The New York Department of Financial Services recently reached a $250,000 settlement with Order Express, a licensed money transmitter. The case followed a 2022 ransomware attack that NYDFS investigated after the company reported it pursuant to requirements under the agency’s cybersecurity regulation.

In September 2022, Order Express found problems with its server connections and shut down its network to investigate. Two days later, it found a note stating that data had been encrypted and taken from its network. The company later determined that ransomware had encrypted just over half of its servers.

After notification, NYDFS reviewed the company’s security measures. It found that Order Express’s annual risk assessment was inadequate because it did not look at risks specific to the company. NYDFS found that the company’s policies for updating software covered only a small number of the third-party applications and software products it used. That left the company exposed to known weaknesses that threat actors could exploit.

Putting It Into Practice: This case is a reminder that regulators may look more broadly at a company’s security measures after a company reports a data incident. The settlement also outlines what steps NYDFS expects companies to take when assessing potential risks and taking steps to guard against them. These include having risk assessments address actual systems, data, threats, and controls. These are helpful reminders even for those not regulated by NYDFS.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

[View Source]

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More