"He's one of the most knowledgeable and service-oriented attorneys I have ever worked with in my long career. He is able not only to speak to the legal team but our technicians too – a superstar."
Chambers USA 2021
"Antony has a strong practice."
Chambers USA 2024
"Tony is very talented and has technical expertise."
Chambers USA 2023
"He's very knowledgeable."
Chambers USA 2023
"Deeply knowledgeable on the technical and legal side. A strong advocate and excellent at working with different stakeholders."
Chambers USA 2022
"He is a great privacy attorney, and we like his mix of real technical expertise in the craft, as well as a sense of urgency that helps us identify solutions."
Chambers USA 2022
"He offers deep knowledge in financial services and project finance transactions, particularly in the oil and gas and power sectors."
Chambers Asia-Pacific 2022
Profile
Tony Kim represents clients across the full spectrum of advisory and enforcement matters implicating cybersecurity, data privacy, and consumer protection issues.
Tony helps companies navigate crises to avoid legal, risk, and reputational landmines. He also defends clients in regulatory investigations and enforcement actions by the Federal Trade Commission (FTC), State Attorney General Offices (AGOs), the Securities & Exchange Commission (SEC), and various sector regulators, as well as in litigation matters, involving the following areas:
Cybersecurity resiliency and incident response
Privacy implications of innovative data use-cases
Consumer protection issues, including in sales and marketing and advertising contexts with a particular focus on global e-commerce, fintech, and platform businesses
In each of these areas, Tony partners with stakeholders in legal, IT/infoSec, product, growth, engineering, marketing, investor relations, communications, the c-suite, and the board/audit committee across governance, compliance, and crisis management contexts.
Accolades
Recognized as a leading lawyer, Tony has been ranked in Chambers USA, The Legal 500 US, Benchmark Litigation, The Cybersecurity Docket, and Super Lawyers D.C. Rising Stars. He’s been consistently named to The Cybersecurity Docket’s “Incident Response 30” list of the top IR professionals in the United States since the inception of that recognition. Clients endorse Tony, telling Chambers “He’s fantastic,” “He takes the time to tend to companies’ needs and understands clients’ objectives.”
Experience
Cyber / Incident Response
In the cybersecurity space, Tony has deep experience handling both preparedness efforts and incident response involving:
APT (Advanced Persistent Threat) attackers emanating from nation state-sponsored actors
Ransomware variants and threat actor groups, and other cyber extortion and disruptive attacks
Business Email Compromises (BEC) and “spoofing” conduct
Malicious insider threats
Supply chain and service provider vulnerabilities and cyberattacks
Un-exploited vulnerabilities in software and on-prem/cloud infrastructure
B2B and B2C product and service vulnerabilities and exploits
“Bug bounty” program and “security researcher” (white/grey hat) interactions
In live incidents, Tony collaborates with client teams to coordinate outside advisors and mission-critical workflows, such as:
Directing forensic investigations (including ransom negotiations) and engaging with law enforcement and global regulatory agencies
Facilitating governance and escalation processes, such as reporting to c-suite, board/audit committee, and outside auditors and SEC disclosures counsel
Executing on multi-jurisdictional notifications and disclosures, and guiding IR/PR communications
Managing regulatory inquiries and contractual engagement (e.g., customers; PCI/card brands)
Coordinating with insurance brokers and carriers
Regulatory Enforcement
Tony has defended clients in federal and state regulatory investigations and enforcement actions. Highlights include representing a(n):
Large publicly-traded multi-nationals (across industries such as telecom, manufacturing, healthcare, energy/oil/gas, semiconductors, cloud infrastructure, and e-commerce), in cybersecurity inquiries and investigations before the SEC
Global security company in relation to an FTC investigation regarding allegedly unlawful data collection and use practices related to "browsing data"
Global independent sales organizations (ISOs) and payment processers in FTC investigations related to Section 5 and the Telemarketing Sales Rule (TSR)
Major global technology company in an FTC investigation involving COPPA and disclosures in the context of online apps/games
E-commerce platform in connection with FTC and state AG regulatory investigations involving COVID-19 time-frame sales and marketing practices*
Global e-commerce platform in connection with state AG investigations into credential stuffing and account takeovers*
National ticketing and events company in FTC and 25 state AG investigations in the aftermath of a major cybersecurity incident*
Consumer financing company in an FTC investigation related to marketing of unique consumer financing product*
Bank marketing subsidiary in an FTC investigation alleging violations of a prior consent decree requiring privacy disclosures and cyber assessments in relation to digital marketing tools*
Fintech lender in an FTC investigation involving claims-substantiation in the B2C advertising context*
Loan modification entity in an FTC investigation and litigation involving credit repair services*
National mortgage provider in an FTC investigation relating to a major cybersecurity incident and data breach*
Consumer lender in an FTC investigation involving Gramm Leach Act and Fair Credit Reporting Act claims*
National mobility device maker in FTC and four state AG investigations involving Telemarketing Sales Rules, Do-Not-Call Rules, and state analogs*
Professional networking service in an FTC investigation into collection, sharing, and use of personal information*
Social gaming network in an FTC investigation involving a data breach that implicated the Children’s Online Privacy Protection Act (COPPA)*
Online background check service in an FTC investigation related to collection, sharing, and use of personal information*
Global retailer in one of the FTC’s first data privacy investigations regarding online behaviorally targeted advertising*
Consumer Litigation
Tony has litigated an array of class action matters focused on data/tech issues, including for a(n):
Leading sports and achievement e-commerce company in a payment card breach allegedly involving over 1.1 million individuals (Southern District of Indiana)
Leading global online dating platform in a data breach allegedly involving over 30 million individuals (Northern District of California)*
On-demand gaming platform in a Telephone Consumer Protection Act (TCPA) action related to alleged text message–based solicitations (Northern District of Illinois)*
National ticketing and events management platform in a payment card breach allegedly involving over 10 million individuals (Cal. Superior Court, Santa Clara)*
Social network company in a TCPA case related to alleged SMS-based solicitations by affiliate marketers (Southern District of Florida)*
Boutique fashion retailer against a Fair and Accurate Credit Transactions Act (FACTA) claim related to allegedly non-compliant point-of-sale receipts (Southern District of Florida)*
Online dating network against deceptive ad claims related to the company’s subscription-based services (Maryland state court)*
Catalog-based shopping club against Fair Credit Reporting Act claims related to “firm offers” of credit and alleged violations of the Credit Repair Organizations Act (Northern District of Illinois)*
Merchant card provider against allegations of abusive telemarketing and deceptive practices (Alabama state court)*
Tony also has substantial experience in the antitrust and competition space, including mergers and acquisitions and conduct investigations before the Department of Justice (DOJ), Antitrust Division and Federal Trade Commission Bureau of Competition, class action and IP-related antitrust litigation, as well as criminal cartel investigations and enforcement actions before the DOJ and international regulators.
*Matter handled prior to joining Latham
Qualifications
Bar Qualification
District of Columbia
New York
Education
JD, Georgetown University Law Center, 2003
BA in Ethics, Politics & Economics, Yale University, 1998 cum laude
Firm honored by Law360 for advising startups, financial institutions, VCs, digital asset and Web3 participants, and corporations on their most innovative and complex transactions, investigations, litigation, and regulatory matters.
Notice: We appreciate your interest in Latham & Watkins. If your inquiry relates to a legal matter and you are not already a current client of the firm, please do not transmit any confidential information to us. Before taking on a representation, we must determine whether we are in a position to assist you and agree on the terms and conditions of engagement with you. Until we have completed such steps, we will not be deemed to have a lawyer-client relationship with you, and will have no duty to keep confidential the information we receive from you. Thank you for your understanding.