Cybersecurity & Privacy

  • July 14, 2026

    States Will Get $18M From 23andMe Ch. 11 For Data Breach

    A week after a bankruptcy court approved a $46.75 million settlement between the DNA testing company 23andMe and data breach claimants, a coalition of more than 40 states announced Tuesday that they would share in an additional $18 million to resolve claims of unreasonable security practices.

  • July 13, 2026

    NJ Delays Registry Aspect Of Newly Enacted Data Broker Law

    New Jersey regulators won't immediately enforce a sweeping data broker law that took effect in June, announcing Friday covered businesses have to register and pay a potentially hefty registration fee until spring, and it would consider complaints about the law's lack of clarity in policing its sensitive data sales ban.

  • July 13, 2026

    7th Circ. Nixes Clearview AI Privacy Deal Over Class Rift

    The Seventh Circuit has vacated a novel biometric privacy settlement between Clearview AI and classes of individuals who claim the company misused their public photos, saying a nationwide class representative should have signaled their agreement before the district court approved a deal containing such comparatively "meager" benefits.

  • July 13, 2026

    WebAI Says Ex-Engineers Recast Firing As Fraud Claims

    WebAI Inc. has told a North Carolina federal court that a complaint by former engineers alleging an executive's conduct jeopardized huge deals is merely an attempt by disgruntled employees to conjure a multicount lawsuit from a lawful employment separation.

  • July 13, 2026

    4th Circ. Says Manual Cellphone Searches At Border Are Legal

    The Fourth Circuit has ruled that manual searches of a cellphone at the border are legal because they are considered routine and do not require individualized suspicion by a border agent about whether a crime has occurred.

  • July 13, 2026

    Blue Shield Of Calif. Beats Enrollee Data Privacy Suit, For Now

    A California federal judge dismissed a proposed class action accusing Blue Shield of California of violating the federal Wiretap Act by installing Google and Meta tracking tools on its website, saying plaintiffs failed to allege that the health plan provider intercepted their highly sensitive health-related electronic communications.

  • July 13, 2026

    23andMe Bankruptcy Plan Bars Data Breach Suit In Calif.

    A Missouri bankruptcy judge has told attorneys representing California the state can no longer press its data breach lawsuit against the reorganized 23andMe, finding the state court action is barred by the company's confirmed Chapter 11 plan.

  • July 13, 2026

    Casino Co. Moves To Toss Ex-Worker's Data Breach Suit

    A casino and entertainment company moved Monday to dismiss a former employee's proposed class action over a 2024 cyberattack, telling a Colorado federal court she lacks standing to sue and failed to show her alleged injuries were caused by the security incident.

  • July 13, 2026

    Families Cite Geofence Ruling In Newborn Blood Testing Case

    A group of parents suing the state of Michigan over the way newborn blood samples are collected and stored has asked a federal judge to revive its claims by citing recently decided U.S. Supreme Court precedent over the use of bulk cellphone data by police.

  • July 13, 2026

    Mass Tort Firms Hit With Suit Over AI Solicitation Calls

    A Michigan-based mass tort law firm and a pair of affiliate firms are violating federal and Texas state laws through an artificial intelligence-generated telemarketing campaign meant to solicit clients, according to a putative class action filed in Texas federal court.

  • July 13, 2026

    Trump-IRS Settlement Result Of Sham Suit, Judge Rules

    President Donald Trump's $10 billion suit against his own Internal Revenue Service and the resulting settlement deal lacked a legitimate controversy, given Trump's control over both the agency and the U.S. Department of Justice, a Florida district judge said Monday in an order barring Trump or others from citing the deal.

  • July 13, 2026

    Steptoe Adds Crowell & Moring Defense Pro As Cyber Lead

    Steptoe LLP announced Monday that it has hired a former government contracts and cybersecurity partner from Crowell & Moring LLP who has held senior procurement roles at the U.S. Department of Defense and the Department of Homeland Security to lead the firm's cybersecurity practice.

  • July 10, 2026

    Biggest Illinois Decisions Of 2026: Midyear Report

    One of the biggest decisions to come down in Illinois so far this year applies a 2-year-old Biometric Information Privacy Act amendment retroactively in an appellate ruling experts anticipate will deflate settlement values even though it came from a federal court.

  • July 10, 2026

    Healthcare Analytics Co. Beats Data Breach Suit, For Good

    Arbor Associates permanently beat patients' proposed negligence class action alleging their sensitive information was stolen following a 2025 data security incident that resulted in an uptick in spam calls, after a Michigan federal judge ruled those injuries are "nothing more than an 'unadorned, the-defendant-unlawfully-harmed-me accusation.'"

  • July 10, 2026

    WhatsApp Users Must Arbitrate Claims Over Private Messages

    A California federal judge has ordered WhatsApp users suing the messaging platform in a proposed class action over alleged privacy violations to arbitration, rejecting their argument that the underlying arbitration agreements improperly short-circuit certain of state law claims.

  • July 10, 2026

    House Duo Push Agencies To Tackle AI-Related Election Risks

    A bipartisan pair of members of the U.S. House of Representatives is calling on several federal agencies to coordinate efforts to ensure technologies fueled by artificial intelligence aren't operating in a way that undermines voters' ability to access "accurate, neutral and reliable" information about the upcoming midterm elections.

  • July 10, 2026

    Defense Contractor Accuses Rival Of Trade Secret Theft

    A defense technology contractor has accused a former employee of stealing its trade secrets to help a competing business build a similar product that allows the retrieval of data when a reliable internet connection is not available.

  • July 10, 2026

    Patient Says Data Suit Against Medical Pot Co. Should Go On

    A medical marijuana dispensary accused of clandestinely tracking and sharing online user health data with Google shouldn't be allowed to escape a proposed class action, a patient has told a Florida federal court, arguing that a disclaimer within its website's privacy policy doesn't automatically mean users consented to the conduct.

  • July 10, 2026

    DOJ Appeals Order Shielding Trans Youth Medical Records

    The U.S. Department of Justice asked the Ninth Circuit to review a California federal court's order blocking the government from trying to identify individuals who received gender-affirming care from a Stanford Medicine hospital as minors.

  • July 10, 2026

    Medical Device Co. Hit With Action Over Data Breach

    Pennsylvania-based medical device company AdaptHealth Corp. is facing a putative class action in federal court alleging the company was liable for a data breach last month that exposed the sensitive information of its customers.

  • July 10, 2026

    RentGrow To Pay $2.25M To End Fair Reporting Act Claims

    Tenant-screening report provider RentGrow Inc. will pay $2.25 million to settle allegations it violated the Fair Credit Reporting Act by not taking reasonable steps to ensure the accuracy of its reports or following up on disputed reports, according to the Federal Trade Commission.

  • July 10, 2026

    7th Circ. Revives BIPA Suit Over Virtual Try-On Tool

    The Seventh Circuit on Friday revived a proposed class action against an eyewear company accused of violating Illinois' biometric privacy law with its online "virtual try-on" tool, saying a lower court dismissed the case too early and more evidence is needed to see if the law's exemption for data collected for health care purposes bars the claims.

  • July 10, 2026

    FCC Floats $200K In Fines Over 'Covered List' Probes

    The Federal Communications Commission proposed fines Friday against eight companies for allegedly failing to answer letters inquiring about whether they sought to market devices in the U.S. that are restricted for national security reasons.

  • July 10, 2026

    EU Finds Meta's 'Addictive Design' Breaches Digital Rules

    The European Union said Friday that it has preliminarily found Meta Platforms Inc.'s Instagram and Facebook breach the bloc's landmark Digital Services Act because of design features they say encourage addictive use, particularly among children and vulnerable adults.

  • July 09, 2026

    Accellion Defeats Bid To Expand Classes In Data Breach Suit

    A California federal judge rejected a bid by plaintiffs suing software vendor Accellion over a sprawling data breach to broaden a previous order that limited class certification to allow only for the recovery of nominal damages, finding the introduction of a new damages expert wasn't enough to change the outcome.

Expert Analysis

  • Getting The Most Out Of Learning And Development Programs

    Excerpt from Practical Guidance
    Author Photo

    Junior associates can better develop the legal, business and interpersonal skills they need for long-term success by approaching their firms’ learning and development programs armed with five tips for getting the most out of these resources, says Lauren Hakala at Reed Smith.

  • AI And Threats To Privilege In Financial Sector Probes

    Author Photo

    The recent spotlight on the potential for artificial intelligence platforms to serve as a source for discoverable information is especially important for financial institutions to understand, as the industry navigates increasingly complex regulatory expectations and AI tools become embedded in investigative efforts, say attorneys at Jackson Lewis.

  • Del. Blackbaud Ruling Signals A New Era For Cyberinsurance

    Author Photo

    The recent Delaware Supreme Court ruling in Travelers v. Blackbaud shows that cyberinsurance is moving into a second maturity phase, in which insurers will increasingly attempt to recover their payments from vendors and insureds will face new pressure to justify cyber incident reimbursements, say Steven Teppler at Mandelbaum Barrett and Jade Davis at Shumaker.

  • How A High Court Music Piracy Ruling Shrinks ISP Liability

    Author Photo

    The U.S. Supreme Court's recent opinion in Cox Communications Inc. v. Sony Music Entertainment, which concerned the boundaries of contributory copyright infringement for internet service providers, dramatically lessens both the risk that an ISP will be held contributorily liable and, relatedly, the incentives an ISP may have to help combat online copyright infringement, say attorneys at Debevoise.

  • 'A-C-T' Agenda Signals New Regulatory Era At SEC Speaks

    Author Photo

    At this year's SEC Speaks, U.S. Securities and Exchange Commission Chairman Paul Atkins unveiled his ambitious A-C-T agenda — advance, clarify and transform — to align the federal securities regulatory regime with modern markets, illustrating that the conference was not merely a status update but an action plan, say attorneys at Perkins Coie.

  • Opinion

    AI Presents A Make-Or-Break Moment For Outside Counsel

    Author Photo

    The rapid adoption of artificial intelligence by corporate legal departments is forcing a long-overdue reset of the relationship between inside and outside counsel, and introducing a significant opportunity to shed frustrating inefficiencies and strengthen collaboration for firms willing to embrace the shift, says Intel Chief Legal Officer April Miller Boise.

  • 1st AI Acquisition Regulation Raises Contractor Concerns

    Author Photo

    The General Services Administration’s recently published contract clause addressing artificial intelligence systems is problematic in a number of ways, underscoring the complex legal and practical issues that will need to be addressed as AI becomes more widely deployed in federal contracting, say attorneys at Haynes Boone.

  • Series

    Watching Hallmark Movies Makes Me A Better Lawyer

    Author Photo

    I realize you may be judging me for watching, and actually enjoying, Hallmark Channel movies, but the escapism and storylines actually demonstrate qualities and actions that lead to an efficient, productive and positive legal practice, says Karen Ross at Tucker Ellis.

  • Reel Justice: 'Mercy' And Private Surveillance As Evidence

    Author Photo

    The near-future depicted in the film “Mercy” reminds attorneys that private surveillance networks are becoming central to the evidentiary ecosystem, shaping what prosecutors can obtain, what defendants must explain and what jurors may interpret as objective truth, says Veronica Finkelstein at Wilmington University.

  • How Iran War Might Reshape Proxy Contests This Year

    Author Photo

    The Iran war may function as a short-term poison pill for proxy contests, not because it strengthens corporate defenses, but because it increases the risks associated with activist commitments, say attorneys at Sidley.

  • When Trade Secret Litigation And Criminal Law Collide

    Author Photo

    An increasing convergence of trade secret litigation and white collar defense, especially with several recent criminal prosecutions from the Justice Department, should prompt businesses and counsel to adapt within the overlapping landscapes, says Kenneth Notter at MoloLamken.

  • How DOJ's New Corporate Crime Policy Will Work In Practice

    Author Photo

    The upshot of the Justice Department's new corporate crimes enforcement framework is uniformity for self-reporting companies, but there is uncertainty around how it will be applied in interaction with the Southern District of New York's more lenient, yet unpredictable, financial crimes enforcement program, say attorneys at Cahill Gordon.

  • 7 Employer Tips For Handling Calif. Privacy Risk Assessments

    Author Photo

    Recent changes to the California Consumer Privacy Act require certain employers to complete detailed risk assessments before handling workforce data in many routine ways, so employers should assess whether previous risk assessments can be reused or combined, assemble a team, and create a plan of action, among other steps, say attorneys at Littler.

  • Breaking Down State Legislative Efforts In Telecom Security

    Author Photo

    As the federal government has strengthened national security safeguards for the telecommunications ecosystem, states have also asserted a role in telecom security, with variations among these regimes risking regulatory fragmentation and complicating compliance strategies, say attorneys at Hogan Lovells.

  • Agentic AI Use May Trigger Existing Consumer Finance Laws

    Author Photo

    As artificial intelligence agents interact more and more with payment systems, financial institutions should be cognizant of how existing consumer protection laws like the Equal Credit Opportunity Act apply when transactions are executed by automated systems rather than individuals, noting authorization and liability gaps, say attorneys at Sheppard.

Want to publish in Law360?


Submit an idea

Have a news tip?


Contact us here
Can't find the article you're looking for? Click here to search the Cybersecurity & Privacy archive.