Cybersecurity & Privacy

  • September 28, 2026

    WordPress Parent Ducks Extortion But Not Antitrust Claims

    A California federal judge issued a mixed ruling last week in the two-way fight between WordPress parent Automattic and web hosting company WPEngine, dismissing digital extortion claims against Automattic while preserving WPEngine's antitrust allegations, and preserving Automattic counterclaims of trademark infringement but dismissing false advertising accusations.

  • September 28, 2026

    Atlanta Consulting Firm Sued Over May Data Breach

    Aprio Advisory Group LLC was hit with a proposed class action in Georgia federal court by a former employee who said its lax data security measures led to a data breach in May that exposed the personal information of hundreds, if not thousands, of people.

  • September 28, 2026

    Atty's Suit Over His Meme Coin Hack Sent To Arbitration

    A New York federal judge Monday ruled that a crypto-focused attorney must arbitrate his claims that wallet provider Phantom Technologies Inc. enabled the hack that stole half a million dollars from his dog-themed meme coin project.

  • September 28, 2026

    Al-Qaida, ISIS Victims Sue Ericsson Over Alleged Payoffs

    American victims of al-Qaida and Islamic State attacks and their families have sued telecommunications provider Ericsson and its CEO, Börje Ekholm, saying the company paid the groups protection money in Iraq and hid the payments from U.S. counterterrorism officials.

  • September 28, 2026

    Roblox, Epic Can't Force Arbitration In Gaming Addiction Suit

    A Pennsylvania federal judge won't let Roblox Corp., Epic Games Inc., Microsoft Corp. and Mojang AB compel arbitration in a suit by a minor alleging that they became addicted to video games, hurting their mental health.

  • September 28, 2026

    DOJ Wants DHS Free To Seek Driver Records Despite Block

    The U.S. Department of Justice asked a Virginia federal judge to clarify that an injunction barring the U.S. Department of Transportation from punishing states over withheld commercial driver's license data doesn't stop other agencies like the U.S. Department of Homeland Security from seeking the records through subpoenas or criminal investigations.

  • September 28, 2026

    Kirkland, White & Case Lead Defense Firm's $1.25B SPAC Deal

    REDLattice and blank check company Bold Eagle Acquisition Corp. said Monday they have agreed to merge in a deal that would take the cyber intelligence company public at a $1.25 billion premoney enterprise value.

  • September 25, 2026

    TikTok To Pay At Least $100M, Curb Teen Use In Alabama Deal

    TikTok agreed to pay at least $100 million and implement usage limits, age verification and other safety measures in a landmark settlement to resolve Alabama's claims the social media platform harmed children and misled users about its safety, the state's attorney general announced Friday.

  • September 25, 2026

    Astrana Health Reveals Spoofing Attack Targeting Private Data

    An Astrana Health unit was the target of a "series" of social engineering cyberattacks in which hackers impersonated the company's employees to gain access to systems that contained private and confidential information about patients and others, the healthcare provider disclosed in a recent regulatory filing. 

  • September 25, 2026

    Ex-Soldier Gets 70-Month Sentence For Telecom Hack Scheme

    A Washington federal judge on Friday sentenced a former U.S. Army soldier to 70 months in prison and ordered him to pay nearly $300,000 in restitution for his role in extorting telecommunication companies by hacking their systems and holding sensitive data hostage for ransom.  

  • September 25, 2026

    Judge Moves Sen. Scott's Tax Info Leak Case To DC Court

    A Florida federal court transferred U.S. Sen. Rick Scott's suit against a former employee of federal contractor Booz Allen Hamilton Inc. for leaking his personal tax returns to D.C. federal court Friday, saying the employee's conduct didn't happen in Florida.

  • September 25, 2026

    9th Circ. OKs Class Cert. In Classmates.com Name Use Case

    The Ninth Circuit has approved a lower court's certification of a class of Californians suing over their names appearing in the yearbooks platform Classmates.com, rejecting a number of challenges from the website's operator, including that the lead plaintiff couldn't adequately represent the class.

  • September 25, 2026

    Cox Can't Recoup $15M In DMCA Suit Costs From Insurers

    A Georgia federal judge backed two insurers in a lawsuit by Cox Enterprises that alleged it was wrongly denied coverage for more than $15 million it racked up in separate litigation with a music publisher, saying the claims were not covered under Cox's policies.

  • September 25, 2026

    Nvidia Wins Stay In AI Voice Data Class Action

    An Illinois federal judge granted Nvidia's motion to stay discovery pending his ruling on its bid to dismiss a suit claiming it used journalists' and voice actors' voices to train its artificial intelligence models without permission, saying the plaintiffs could have sought emergency relief if continued dissemination of the models was an urgent concern.

  • September 25, 2026

    Tarter Krinsky Faces Suit After Disclosing Data Breach

    Tarter Krinsky & Drogin LLP maintained "intentional opacity" about a recently disclosed cybersecurity attack last year that may have compromised protected health information, a proposed class action alleged in New York federal court.

  • September 25, 2026

    Meta Lied About Data Privacy, New Mexico Jury Finds

    A New Mexico jury said Friday that Meta lied willfully on 26 different occasions regarding data privacy, hate speech, misinformation and Facebook's outside investigation of third-party app developers after the Cambridge Analytica scandal.

  • September 25, 2026

    Cold Storage Co. To Pay $5.25M To Settle Data Breach Lawsuit

    Americold Logistics LLC agreed to pay $5.25 million to settle a pair of proposed class actions alleging that lax cybersecurity at the cold storage giant led to two separate data breaches that impacted nearly 225,000 workers.

  • September 25, 2026

    Supreme Court Revives DHS Voter Citizenship Database

    The Trump administration can reinstate the U.S. Department of Homeland Security's upgraded citizenship verification database ahead of this year's midterm elections, the U.S. Supreme Court ruled Friday.

  • September 25, 2026

    DC Circ. Denies Anthropic's Security Risk Suit Against DOD

    A divided D.C. Circuit panel ruled Friday the Pentagon was justified in citing national security concerns to exclude Anthropic's suite of Claude artificial intelligence models from its supply chain.

  • September 25, 2026

    Prediction Market Regulators, Bad Actors In AI Arms Race

    Artificial intelligence is playing an increasingly important role in policing prediction markets, and attorneys say that regulators and investigators are starting to effectively use the same technology that would-be bad actors have leveraged to try to score big with their bets.

  • September 25, 2026

    US Backs Elon Musk In €120M EU Digital Transparency Case

    The U.S. has announced it will join Elon Musk in a bid to overturn a €120 million ($137 million) fine imposed by the European Commission on social media platform X for breaching the bloc's digital transparency rules.

  • September 24, 2026

    Ex-Google CEO's Rape Accuser Can't Undo $12M Arb. Loss

    A California judge on Thursday told a woman who accused former Google CEO Eric Schmidt of sexual assault that he will not vacate a $12 million arbitration award in Schmidt's favor, saying she appeared to have ignored the arbitrator's orders just like she disregarded his own, and asking, "Why did you do that?"

  • September 24, 2026

    Calif. Bill Deals Blow, But Not Knockout, To Tracking Suits

    A California bill awaiting the governor's signature is poised to reduce the swell of litigation under the California Invasion of Privacy Act, but the narrow scope of the pending lawsuit ban leaves open other avenues for plaintiffs to target the widespread use of website tracking technologies.

  • September 24, 2026

    Seyfarth Failed To Guard Client Data From Hack, Suit Alleges

    Seyfarth Shaw LLP on Thursday was hit with a proposed class action in Illinois federal court accusing it of failing to protect its current and former clients' personal information after the Chicago-based law firm this month disclosed a recent data breach.

  • September 24, 2026

    TikTok Loses Bid To Trim Kids' Data Privacy Suit In Calif.

    A California federal judge on Thursday refused TikTok's bid to trim claims from a proposed class action alleging that the platform exploits the private information of users under 13, saying at a hearing that the question of whether previous TikTok settlements bar the plaintiffs' claims should be saved for later.

Expert Analysis

  • Series

    Going To Hardcore Shows Makes Me A Better Lawyer

    Author Photo

    While government contracts law and the hardcore scene may seem entirely unrelated, in my experience, both are about community, focus, being prepared for the unexpected and managing chaos, says Isaac Natter at Fluet.

  • Brace For Expanding Scrutiny Of Dark Patterns In Healthcare

    Author Photo

    Recent reporting and regulatory developments highlight growing concern surrounding so-called dark patterns in healthcare — user interface designs that improperly influence consumer decision-making — and represent an important evolution of how healthcare professionals should evaluate consent processes, say attorneys at Clark Hill.

  • How Data Broker Laws Are Reaching Consumer-Facing Cos.

    Author Photo

    As states, most recently New Jersey, expand the scope of data broker laws to cover some customer data sharing, consumer-facing companies should reassess advertising, vendor and partner arrangements to determine whether they trigger registration, contracting and governance obligations, says Sam Castic at Hintze Law.

  • What Regulatory 'Reputation Risk' Purge Means For Banks

    Author Photo

    Banks should expect closer scrutiny of account closures and service denials after federal regulators recently stripped "reputation risk" from supervisory guidance, and should tie customer decisions to documented, objective legal and financial criteria to protect against debanking-related enforcement, say attorneys at Troutman.

  • How New Counter-Drone Rule Will Reshape Event Security

    Author Photo

    A new interim final rule on counter-unmanned aircraft systems creates one of the most structured regulatory frameworks yet adopted for mitigating unauthorized drone activity, with implications for law enforcement, airport and stadium operators, drone companies, and public event organizers, say attorneys at Morgan Lewis.

  • Justices' FTC Ruling Weakens Qui Tam's Constitutional Base

    Author Photo

    The U.S. Supreme Court’s holding in Trump v. Slaughter, expanding presidential control over those exercising executive power, suggests that courts may be receptive to arguments challenging the constitutional foundations of the False Claims Act’s qui tam mechanism, says Daniel Passeser at Wiggin.

  • FTC-Deere Deal Tells Cautionary Tale On Repair Access Limits

    Author Photo

    A recent proposed Federal Trade Commission antitrust settlement in Illinois federal court requires Deere & Co. to provide access to repair services previously available only to authorized dealers, and companies that limit access to aftermarket resources should ensure they can substantiate the reasoning behind any restrictions, say attorneys at Freshfields.

  • Series

    Being A Sommelier Makes Me A Better Lawyer

    Author Photo

    Being a sommelier has quietly shaped how I practice law by changing the way I think, communicate and connect with people, and offers a constant reminder that expertise is about making your knowledge useful and accessible to others, says Kara Du at Sheppard.

  • Deposit Contracts Do Heavy Lifting As Fraud Moves Upstream

    Author Photo

    As courts increasingly find that upstream parties are best positioned to detect red flags in fraud disputes, most recently in Yangtze v. Ohio Valley Trackwork, companies should tighten treasury and deposit agreement verification protocols, indemnity terms, and insurance coordination to reduce exposure, says Nadine Dorsht at Stinson.

  • DOJ's FCA Push Creates Risks For Construction Contractors

    Author Photo

    The construction industry may be uniquely vulnerable to a new generation of False Claims Act enforcement driven by the U.S. Department of Justice's increasing usage of the FCA to target a much broader category of conduct than it has in decades past, specifically compliance certifications and regulatory representations, say attorneys at Cozen O'Connor.

  • 3 Private Suits Test Influencer Ads As FTC Stays On Sidelines

    Author Photo

    Three lawsuits filed so far this year illustrate how influencer campaigns are facing growing scrutiny from private plaintiffs, despite the Federal Trade Commission not bringing an influencer marketing enforcement action since revising its endorsement guides to address the topic in 2023, but brands can take concrete steps to reduce the risks, says Gonzalo Mon at Kelley Drye.

  • CIPA Tech Tracking Suits Highlight Uncertain Legal Ground

    Author Photo

    Alexandra Samofalova at Spencer Fane discusses the state of California Invasion of Privacy Act website tracking litigation, why credible defendants choose to settle and how the businesses best positioned to face this uncertain legal landscape are the ones treating data practices as a legal compliance matter to address today.

  • Where Is The Line On Actionable Comms In Securities Cases?

    Author Photo

    Recent securities cases demonstrate the difficulty in discerning a clear difference between statements made in connection with the purchase or sale of securities and those that aren't, with that line more likely attributable to individualized factual situations than to any doctrinal differences of opinion between various courts, says Samuel Groner at Fried Frank.

  • House-Passed KIDS Act Spurs Child Data Practices Audit

    Author Photo

    Graham Dean, Brian Roper-Nelson and Will Quick at Brooks Pierce discuss the noteworthy sections of the U.S. House of Representatives' recently passed Kids Internet and Digital Safety Act, the potential revisions as the law moves through the U.S. Senate and the significant business changes that the House law would require.

  • FTC Focus: Enforcing Vertically Integrated Operating Systems

    Author Photo

    As digital platforms increasingly pair operating systems with commerce, advertising, content and data, antitrust scrutiny will turn on whether those integrations create private bottlenecks that foreclose rivals through access, ranking, interoperability or defaults, pushing courts and enforcement agencies to adapt traditional utility and merger frameworks more aggressively, say attorneys at Proskauer.

Want to publish in Law360?


Submit an idea

Have a news tip?


Contact us here
Can't find the article you're looking for? Click here to search the Cybersecurity & Privacy archive.