Active extortion or breach? Call +1 212 457 9797 · Beware impersonation — we e-mail only from @dilendorf.com

Cyber Breach Lawyer: Board Risks After June 22, 2026

Cyber Breach Lawyer: Board Risks After June 22, 2026

On June 22, 2026, the National Security Agency (NSA) warned that artificial intelligence is accelerating cyber threats and creating new cybersecurity risks. (NSA, Five Eyes Cyber Security Agencies Statement, June 22, 2026).

Every board should take note of two sentences from the NSA’s statement this quarter. The first warns that “cyber risk assumptions can become outdated in months, not years” (NSA statement, We must act now).

The second is shorter: “Breaches will occur” (NSA statement, Key Actions for Leaders). That sentence reframes the governance question: not whether the organization bought security, but whether it was prepared to respond.

This article explains what that shift means for boards, family offices, and executives. It also discusses when a cyber breach lawyer should be brought in to help manage the response and legal risks.

What six national agencies told leaders

“Breaches will occur. Preparedness helps you contain them quickly and prevent escalation into major operational and financial crises.”

“It is not enough to have controls. Leaders must be confident those controls will perform during a real incident.”

Actions the agencies called urgent

  • Limit unnecessary system access/external connectivity.
  • Accelerate patching; AI shortens the time between disclosure and exploitation.
  • Replace unsupported legacy systems.
  • Strengthen identity & access controls and review permissions.
  • Test response plans and assume breaches will occur.

Source: National Security Agency, Five Eyes Cyber Security Agencies Statement (June 22, 2026), https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/

The duty is no longer abstract

A New York director must act in good faith and with “that degree of care which an ordinarily prudent person in a like position would use under similar circumstances” (N.Y. Bus. Corp. Law § 717(a)).

“A trustee shall exercise reasonable care, skill and caution” in managing trust property (N.Y. EPTL § 11-2.3(b)(2)).

Entities regulated by the New York Department of Financial Services (“NYDFS”) certify material compliance with Part 500 every year. The certification must be signed by the highest-ranking executive and the chief information security officer (23 NYCRR 500.17(b)(2)).

The SHIELD Act requires any business holding private information of New York residents to maintain “reasonable safeguards” (N.Y. Gen. Bus. Law § 899-bb(2)(a)). The statute lists examples of administrative, technical, and physical safeguards, but it does not define the word reasonable (N.Y. Gen. Bus. Law § 899-bb(2)(b)).

The critical question is how reasonableness will be measured after a cyber incident. Regulators and courts often evaluate that question with the benefit of hindsight and by examining the organization’s own records, policies, and risk assessments.

The benchmark has now shifted. A risk assessment prepared before the June 22 NSA statement may be viewed differently once federal cybersecurity authorities have publicly warned that traditional assumptions about cyber risk are no longer sufficient.

Where losses occur

Business email compromise remains one of the costliest forms of cyber theft. The FBI received 24,768 complaints in 2025, with reported losses above $3.04 billion (FBI IC3, 2025 Internet Crime Report, pp. 7–8).

An attacker gains access to an email thread and sends revised wire instructions. The funds leave in minutes.

The dispute that follows is rarely with the criminal. It is with the counterparty, over whose system was compromised, and the answer depends on forensic evidence that is often retained for only a limited period.

Server compromise follows a similar pattern. In September 2025, CISA reported that attackers exploited a public-facing server 11 days after the vulnerability was disclosed, and that the activity “remained undetected for three weeks” (CISA, Advisory AA25-266A, Sept. 23, 2025).

The victim had an incident response plan. It had never been tested, and it contained no procedure for granting outside responders access to the security tools (CISA, Advisory AA25-266A, Lessons Learned).

Ransomware adds sanctions exposure. The Office of Foreign Assets Control may impose civil penalties “based on strict liability,” even where the payer did not know the recipient was sanctioned (OFAC, Updated Ransomware Advisory, Sept. 21, 2021, p. 4).

Regulated financial entities must also notify the Department of Financial Services within 24 hours of an extortion payment and explain it in writing within 30 days (23 NYCRR 500.17(c)).

Insurance denial is where sophisticated organizations are most often surprised. A policy may carry a large limit and a small sublimit for social engineering and funds transfer fraud, which is where business email compromise losses fall.

War and state-actor exclusions have become standard wording, and attribution is contestable (GAO-22-104256, Cyber Insurance). In family office structures, the policy may name the management company while the loss falls on a trust.

LOSS 1

Business email compromise

Revised wire instructions from a compromised mailbox. 24,768 complaints and more than $3.04 billion in reported losses in 2025. The dispute is with the counterparty, not the criminal.

LOSS 2

Server compromise

Exploited 11 days after disclosure and undetected for three weeks in a CISA engagement. The response plan had never been tested and had no procedure for outside access.

LOSS 3

Ransomware and extortion

Strict liability sanctions exposure for payments, a 24-hour notice to the Department of Financial Services, and a 30-day written explanation. Decisions made under pressure by people who have not made them before.

LOSS 4

Insurance denial

Small sublimits for the funds transfer loss, war and state-actor exclusions, and policies that name the management company while the loss falls on a trust.

Sources: FBI IC3, 2025 Internet Crime Report, pp. 7–8, https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf; CISA, Advisory AA25-266A, https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-266a; OFAC, Updated Ransomware Advisory (2021), https://ofac.treasury.gov/media/912981/download?inline; 23 NYCRR 500.17(c), https://www.law.cornell.edu/regulations/new-york/23-NYCRR-500.17; GAO-22-104256, https://www.gao.gov/products/gao-22-104256

Five Regulatory Deadlines at Discovery

Discovery starts a series of independent regulatory deadlines, many of which expire before the forensic findings are finalized.

DeadlineTimeWho and what
Insurer noticeAs the policy statesEvery policy that may respond, in the manner the policy requires. Late notice is a common ground for denial.
FinCEN Rapid Response Program72 hoursFraudulent wires reported to law enforcement within 72 hours are the most likely to be interdicted (FinCEN RRP Fact Sheet, Apr. 15, 2026, p. 2).
Department of Financial Services72 hoursCovered entities notify the superintendent after determining that a cybersecurity incident occurred (23 NYCRR 500.17(a)(1)).
SEC Form 8-K, Item 1.054 business daysPublic companies disclose after determining that an incident is material (SEC, Small Entity Compliance Guide, Item 1.05).
SHIELD Act notice30 daysNotice to affected New York residents within 30 days after discovery, subject to a law enforcement delay (N.Y. Gen. Bus. Law § 899-aa(2)).

Sources: FinCEN, https://www.fincen.gov/system/files/2026-04/RRPFactSheet.pdf; 23 NYCRR 500.17, https://www.law.cornell.edu/regulations/new-york/23-NYCRR-500.17; SEC, https://www.sec.gov/resources-small-businesses/small-business-compliance-guides/cybersecurity-risk-management-strategy-governance-incident-disclosure; N.Y. Gen. Bus. Law § 899-aa, https://www.nysenate.gov/legislation/laws/GBS/899-AA

The first 72 hours

A cyber breach lawyer will ask about these five steps first.

  1. Preserve the evidence. Instruct every provider to retain email, authentication, and access logs. Do not wipe or rebuild affected devices until the examiners have imaged them.
  2. Contact the bank and the FBI. Request a recall of the funds from the sending bank and file a complaint at IC3.gov (FBI IC3, 2025 Internet Crime Report, p. 17).
  3. Give notice to every insurer. Send notice under each insurance policy. Keep a copy of the transmittal.
  4. Assign responsibility for each regulatory deadline. Name the officer responsible for the Department of Financial Services, SHIELD Act, and securities deadlines. Record the discovery date and time.
  5. Avoid rushed decisions. Engage counsel immediately. A self-initiated and complete report to law enforcement is a significant mitigating factor in any sanctions review of a ransom payment (OFAC, Updated Ransomware Advisory, p. 5).

How Dilendorf Law Firm helps

Dilendorf Law Firm represents high-net-worth individuals, family offices, trustees, and closely held businesses across the full arc of a cyber loss. The firm serves as cyber breach lawyer before, during, and after an incident.

Before an incident, the firm conducts loss-allocation reviews of the documents that decide who pays. Those documents include trust instruments, custodian and banking agreements, exchange terms, managing agent contracts, and cyber liability policies.

During an incident, the firm directs the response. It preserves evidence, coordinates forensic examiners, and manages notification deadlines under the SHIELD Act and Part 500.

The firm also works with former cybercrime law enforcement professionals and government agencies to pursue emergency measures that could freeze fraudulent transfers while the funds remain recoverable. That window is typically 24 to 72 hours.

After a loss, the firm pursues recovery against banks, exchanges, payment processors, and counterparties. It also contests denied insurance claims.

The firm works together with forensic examiners and investigators with federal law enforcement backgrounds, retained as independent experts. The technical work establishes what happened, and the legal work determines who pays for it.

If your risk assessment predates June 22, 2026, or if an incident is under way, contact Dilendorf Law Firm at +1 212 457 9797 or info@dilendorf.com.

The window

The Five Eyes statement said months, not years. It was published in June.

The question for any board, trustee, or principal is direct. When was the risk assessment last updated, and would it withstand review by someone building a case against the organization?

Contact Us

Dilendorf Law Firm PLLC, 115 Broadway, 5th Floor, New York, NY 10006. Telephone +1 212 457 9797. Email info@dilendorf.com.

This article is for general informational purposes only and does not constitute legal advice. Reading it does not create an attorney-client relationship with Dilendorf Law Firm. Attorney Advertising.

Frequently asked questions

What does a cyber breach lawyer do?

A cyber breach lawyer directs the legal side of an incident from the first hour. Counsel engages forensic examiners so that their work is protected, preserves evidence, and gives notice to insurers, regulators, and law enforcement.

Counsel also decides which notice clocks apply under the SHIELD Act, Part 500, and the federal securities rules (N.Y. Gen. Bus. Law § 899-aa(2)). After containment, the same lawyer pursues recovery and contests any insurance denial.

The goal is to keep the technical response and the legal position aligned from the start.

Is a business email compromise a breach under New York law?

It may be, depending on what the attacker reached. New York defines a breach as unauthorized access to or acquisition of computerized data that compromises the security of private information (N.Y. Gen. Bus. Law § 899-aa(1)(c)).

Private information includes a user name or email address together with a password that permits access to an online account (N.Y. Gen. Bus. Law § 899-aa(1)(b)(ii)). A compromised mailbox that holds client account details may therefore trigger notice duties.

The forensic findings decide the answer, which is one reason to preserve logs immediately.

How quickly must we give notice after a breach in New York?

The deadlines differ by regulator. Affected New York residents must be notified in the most expedient time possible and within 30 days after the breach is discovered (N.Y. Gen. Bus. Law § 899-aa(2)).

Entities regulated by the Department of Financial Services must notify the superintendent within 72 hours of determining that a cybersecurity incident occurred (23 NYCRR 500.17(a)(1)). A public company must file a Form 8-K within four business days of determining that an incident is material (SEC, Small Entity Compliance Guide, Item 1.05).

Each clock should be assigned to a named officer.

Can we lawfully pay a ransomware demand?

Payment may be lawful, but it carries sanctions risk that must be reviewed first. The Office of Foreign Assets Control may impose civil penalties on a strict liability basis, even where the payer did not know the recipient was sanctioned (OFAC, Updated Ransomware Advisory, Sept. 21, 2021, p. 4).

The United States government strongly discourages payment of ransom or extortion demands (OFAC advisory, p. 1). A Department of Financial Services covered entity must also report any extortion payment within 24 hours and explain it within 30 days (23 NYCRR 500.17(c)).

Counsel should document the alternatives considered before any decision.

Can a fraudulent wire transfer be recovered?

Sometimes, if the report is fast. FinCEN states that it is most likely to interdict or recover funds when a fraudulently induced wire is reported to law enforcement within 72 hours of the transaction (FinCEN, Rapid Response Program Fact Sheet, Apr. 15, 2026, p. 2).

Since 2015 that program has facilitated the interdiction of $1.8 billion on behalf of United States victims (FinCEN RRP Fact Sheet, p. 1). In 2025 the FBI’s Recovery Asset Team froze $679 million of $1.16 billion in attempted theft, a 58 percent success rate (FBI IC3, 2025 Internet Crime Report, p. 17).

The bank recall and the IC3 complaint should be filed the same day.

Who bears the loss when wire instructions were changed by email?

It depends on the facts, and the central fact is whose system was compromised. The parties to the transaction usually dispute that question, because the criminal is rarely available to pay.

The answer turns on email and access logs from both sides, and those records may be retained for only a limited period. Contract terms, account agreements, and the parties’ verification practices also matter.

A cyber breach lawyer should demand preservation from every provider before the evidence is gone.

Can customers sue us under the SHIELD Act?

The SHIELD Act itself does not permit a private lawsuit. The statute states that nothing in the data security section creates a private right of action (N.Y. Gen. Bus. Law § 899-bb(2)(e)).

Enforcement belongs to the Attorney General, who may seek injunctions and civil penalties (N.Y. Gen. Bus. Law § 899-bb(2)(d)). Customers and counterparties may still bring claims under contract or other law, depending on the facts.

The organization’s own risk assessment often becomes the central exhibit in those disputes.

Does our cyber insurance policy cover a fraudulent wire?

Often only in part. Stolen funds are usually claimed under a crime policy or a social engineering endorsement, and those sections may carry a low sublimit.

Insurers have argued that a wire released by the insured’s own employee is not a direct loss from computer fraud (American Tooling Center v. Travelers, slip op. at 7). Some federal appellate courts have rejected that argument under particular policy wording (Ernst & Haas v. Hiscox, slip op. at 16–17).

The result depends on the exact definitions in the policy, so counsel should review them before the claim is submitted.

What should the board record after the June 22, 2026 statement?

Record that the board considered the statement and directed a refreshed risk assessment. The Five Eyes agencies asked leaders to understand and assess risk, readiness, and accountability (NSA, Five Eyes Cyber Security Agencies Statement).

They also wrote that it is not enough to have controls and that leaders must be confident the controls will perform during a real incident (NSA statement, whole-of-organization response). A dated minute that names the responsible officer and the deadline is evidence that oversight occurred.

It is also the document a director will want to have when the records are later reviewed.

Sources

[1] National Security Agency, Five Eyes Cyber Security Agencies Statement (June 22, 2026). https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/4523810/five-eyes-cyber-security-agencies-statement/

[2] Cybersecurity and Infrastructure Security Agency, Cybersecurity Advisory AA25-266A, CISA Shares Lessons Learned from an Incident Response Engagement (Sept. 23, 2025). https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-266a

[3] N.Y. Business Corporation Law § 717, Duty of directors (New York State Senate). https://www.nysenate.gov/legislation/laws/BSC/717

[4] N.Y. Estates, Powers and Trusts Law § 11-2.3, Prudent investor act (New York State Senate). https://www.nysenate.gov/legislation/laws/EPT/11-2.3

[5] N.Y. General Business Law § 899-aa, Notification; person without valid authorization has acquired private information (New York State Senate). https://www.nysenate.gov/legislation/laws/GBS/899-AA

[6] N.Y. General Business Law § 899-bb, Data security protections (New York State Senate). https://www.nysenate.gov/legislation/laws/GBS/899-BB

[7] 23 NYCRR § 500.17, Notices to superintendent (Legal Information Institute, Cornell Law School). https://www.law.cornell.edu/regulations/new-york/23-NYCRR-500.17

[8] U.S. Department of the Treasury, Office of Foreign Assets Control, Updated Advisory on Potential Sanctions Risks for Facilitating Ransomware Payments (Sept. 21, 2021). https://ofac.treasury.gov/media/912981/download?inline

[9] U.S. Department of the Treasury, Financial Crimes Enforcement Network, Rapid Response Program Fact Sheet (Apr. 15, 2026). https://www.fincen.gov/system/files/2026-04/RRPFactSheet.pdf

[10] Federal Bureau of Investigation, Internet Crime Complaint Center, 2025 Internet Crime Report. https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf

[11] U.S. Securities and Exchange Commission, Cybersecurity Risk Management, Strategy, Governance, and Incident Disclosure: A Small Entity Compliance Guide (Aug. 30, 2023). https://www.sec.gov/resources-small-businesses/small-business-compliance-guides/cybersecurity-risk-management-strategy-governance-incident-disclosure

[12] U.S. Government Accountability Office, GAO-22-104256, Cyber Insurance: Action Needed to Assess Potential Federal Response to Catastrophic Attacks (June 21, 2022). https://www.gao.gov/products/gao-22-104256

[13] American Tooling Center, Inc. v. Travelers Casualty and Surety Co. of America, No. 17-2014 (6th Cir. July 13, 2018). https://www.opn.ca6.uscourts.gov/opinions.pdf/18a0138p-06.pdf

[14] Ernst and Haas Management Company, Inc. v. Hiscox, Inc., No. 20-56212 (9th Cir. Jan. 26, 2022). https://cdn.ca9.uscourts.gov/datastore/opinions/2022/01/26/20-56212.pdf

Discuss Your Matter

Confidential consultations by appointment.

Call us now Request consultation