Last month, U.K.-based retailer FatFace made the news not for being the latest victim of ransomware, but instead for requesting that impacted customers not share details of the data breach with others.

Before detailing the security incident or the steps taken to resolve the matter, the clothing retail chain asked: "Please do keep this email and the information included within it strictly private and confidential," according to screenshots of the data breach notification.

Such confidentiality requests are last-ditch attempts from breached companies, lawyers said. While such requests likely spur further publicity of the incident, lawyers noted FatFace's efforts may be mirrored by other companies who seek to limit reputational risk. Still, they noted that confidentiality requests in breach notifications are not only unenforceable but could also rouse additional regulatory scrutiny.