Cybersecurity & Privacy

  • September 29, 2026

    Geico Call Class Sunk After Plaintiff Tosses Phone In River

    A Maryland federal judge has refused to certify a class of thousands of insurance claimants who received allegedly unauthorized prerecorded medical appointment reminders from a scheduling vendor retained by Geico, finding that factors such as the plaintiff's decision to throw his cellphone into the Mississippi River made him an inadequate class representative.

  • September 29, 2026

    OpenAI Knew AI Was Rogue Before Hugging Face, Suit Says

    A public interest law nonprofit sued OpenAI in California state court Tuesday, seeking to hold the ChatGPT maker liable for a July cyberattack on Hugging Face, arguing OpenAI "straightforwardly violated California law" by failing to rein in hundreds of rogue AI agents that OpenAI knew were running amok without proper safeguards.

  • September 29, 2026

    7th Circ. Skeptical Of Reviving License Plate Surveillance Suit

    A Seventh Circuit panel seemed skeptical Tuesday that it should revive two Cook County residents' lawsuit claiming the Illinois State Police subject residents to unconstitutional searches through automatic license plate reading cameras whose data is saved for months.

  • September 29, 2026

    DC Circ. Anthropic Ruling Could Chill Contractor Speech

    The D.C. Circuit's decision backing the U.S. Department of Defense's removal of Anthropic from its supply chain was based on a broad reading of the Federal Acquisition Supply Chain Security Act, which could lead contractors to be more careful about publicizing disputes with the department.

  • September 29, 2026

    States' Temporary Aid Data-Sharing Injunction Bid Falls Short

    A D.C. federal judge declined to block a Trump administration policy allowing disclosures of temporary financial assistance recipients' sensitive personal information to federal authorities, saying that while it "seems plausible" this will chill participation in the program, Democratic-led states challenging the policy haven't provided "concrete evidence" of such harm.

  • September 29, 2026

    Ex-U. Of Mich. Coach Says Student's Hacking Suit Falls Short

    Former University of Michigan assistant football coach Matthew Weiss says a civil suit alleging he used his position in the athletic program to access personal photos and videos of thousands of young athletes is time-barred and hinges on expanding cybersecurity laws past precedent.

  • September 29, 2026

    Google Beats Suit Over 'Pig Butchering' App Scams, For Now

    A California federal judge tossed with leave to amend Monday a proposed class action alleging Google falsely advertised its Google Play Store as safe despite allowing swarms of "pig butchering" crypto-scam apps, finding that the claims are barred by Section 230 of the Communications Decency Act.

  • September 29, 2026

    Reed Smith Adds AI, Data And Cyber Partner In Chicago

    Reed Smith LLP announced Tuesday that an attorney specializing in cybersecurity and data privacy matters has moved her practice to the firm's Chicago office after more than two years with Neal Gerber & Eisenberg LLP.

  • September 29, 2026

    Fired Teacher Says AI Tainted Review And Arbitration

    A Massachusetts kindergarten teacher is suing to redo arbitration over her firing, saying the arbitrator who affirmed the school's decision used artificial intelligence to vet her claims that the principal relied on AI to prepare her final, negative performance evaluation.

  • September 29, 2026

    DOJ Puts FCA Target On Health Data Security Lapses

    Government contractors that fail to protect personal health information are on the radar of U.S. Department of Justice officials looking to leverage the False Claims Act, attorneys told attendees at a health law conference in Washington, D.C.

  • September 28, 2026

    Grok-Maker Can't Get Deepfake Suit Paused Or Transferred

    Elon Musk's artificial intelligence company must continue battling a proposed class action brought by women suing over Grok-generated deepfakes of them in sexual situations, a California federal judge ruled Monday, declining to pause or transfer the suit to Texas.

  • September 28, 2026

    Parler Wasn't Worth Much When CEO Was Fired, Jury Told

    A company valuation expert testified Monday in the trial over Parler's 2021 ouster of its CEO that the company had little value at the time and that insider estimates in the hundreds of millions of dollars were "speculation."

  • September 28, 2026

    CyberSec Pro Stole $53M In Uranium Finance Heist, Jury Told

    A prosecutor on Monday told a Manhattan federal jury that a Maryland cybersecurity consultant stole around $53 million in crypto by exploiting software bugs on the decentralized exchange Uranium Finance, while defense counsel argued that the government won't be able to show "whose fingers were on the keyboard."

  • September 28, 2026

    Calif. Governor Vetoes Broad Ban On Sensitive Data Sales

    California's governor has refused to sign off on legislation that would have made the state the latest to restrict the sale and sharing of consumers' geolocation, biometric and other sensitive information, saying the proposed "categorical ban" on these online data practices was "a step too far."

  • September 28, 2026

    CFPB Rips Bid To Ax $43M Debt-Relief Win As 'Frivolous'

    The Consumer Financial Protection Bureau has urged the Seventh Circuit to uphold a more than $43 million enforcement judgment against the former operator of a defunct debt relief provider, defending the agency's lower-court win in a case that has stretched across three presidential terms.

  • September 28, 2026

    Don't Overstep On Submarine Cable License Regs, FCC Told

    The Federal Communications Commission should shy away from implementing regulations for submarine cable landing licenses that would apply a uniform standard to all cable systems regardless of risk, says one of the country's biggest telecom trade groups.

  • September 28, 2026

    WordPress Parent Ducks Extortion But Not Antitrust Claims

    A California federal judge issued a mixed ruling last week in the two-way fight between WordPress parent Automattic and web hosting company WPEngine, dismissing digital extortion claims against Automattic while preserving WPEngine's antitrust allegations, and preserving Automattic counterclaims of trademark infringement but dismissing false advertising accusations.

  • September 28, 2026

    Atlanta Consulting Firm Sued Over May Data Breach

    Aprio Advisory Group LLC was hit with a proposed class action in Georgia federal court by a former employee who said its lax data security measures led to a data breach in May that exposed the personal information of hundreds, if not thousands, of people.

  • September 28, 2026

    Atty's Suit Over His Meme Coin Hack Sent To Arbitration

    A New York federal judge Monday ruled that a crypto-focused attorney must arbitrate his claims that wallet provider Phantom Technologies Inc. enabled the hack that stole half a million dollars from his dog-themed meme coin project.

  • September 28, 2026

    Al-Qaida, ISIS Victims Sue Ericsson Over Alleged Payoffs

    American victims of al-Qaida and Islamic State attacks and their families have sued telecommunications provider Ericsson and its CEO, Börje Ekholm, saying the company paid the groups protection money in Iraq and hid the payments from U.S. counterterrorism officials.

  • September 28, 2026

    Roblox, Epic Can't Force Arbitration In Gaming Addiction Suit

    A Pennsylvania federal judge won't let Roblox Corp., Epic Games Inc., Microsoft Corp. and Mojang AB compel arbitration in a suit by a minor alleging that they became addicted to video games, hurting their mental health.

  • September 28, 2026

    DOJ Wants DHS Free To Seek Driver Records Despite Block

    The U.S. Department of Justice asked a Virginia federal judge to clarify that an injunction barring the U.S. Department of Transportation from punishing states over withheld commercial driver's license data doesn't stop other agencies like the U.S. Department of Homeland Security from seeking the records through subpoenas or criminal investigations.

  • September 28, 2026

    Kirkland, White & Case Lead Defense Firm's $1.25B SPAC Deal

    REDLattice and blank check company Bold Eagle Acquisition Corp. said Monday they have agreed to merge in a deal that would take the cyber intelligence company public at a $1.25 billion premoney enterprise value.

  • September 25, 2026

    TikTok To Pay At Least $100M, Curb Teen Use In Alabama Deal

    TikTok agreed to pay at least $100 million and implement usage limits, age verification and other safety measures in a landmark settlement to resolve Alabama's claims the social media platform harmed children and misled users about its safety, the state's attorney general announced Friday.

  • September 25, 2026

    Astrana Health Reveals Spoofing Attack Targeting Private Data

    An Astrana Health unit was the target of a "series" of social engineering cyberattacks in which hackers impersonated the company's employees to gain access to systems that contained private and confidential information about patients and others, the healthcare provider disclosed in a recent regulatory filing. 

Expert Analysis

  • HPE-Juniper Settlement Teaches Key Tunney Act Lessons

    Author Photo

    A California federal court's recent approval of the U.S. Department of Justice's settlement with Hewlett Packard over its Juniper Networks acquisition offers legal practitioners some crucial lessons, including on unique tech-sector remedies for mergers and acquisitions and the continued viability of the Tunney Act, says Shubha Ghosh at Syracuse University College of Law.

  • Elder Fraud Risk And Pleading Lessons From Meta Cases

    Author Photo

    Michael Gilfix and Benjamin Gicqueau at Gilfix & La Poll discuss how a recent Meta youth settlement and an April decision involving social media harms to children may point to a broader pleading framework in cases of elder fraud, and offer practical measures for platforms and consumers seeking to reduce elder fraud risk.

  • Hugging Face Attack Is A Warning To The Securities Markets

    Author Photo

    The recent Hugging Face cyberattack, in which OpenAI's artificial intelligence agents hacked a third party without human instruction, raises questions about how regulators could respond to a similar incident in the securities markets and whether there's a substitute for scienter if no person is behind a financial crime, says Joseph A. Hall at Davis Polk.

  • Series

    Playing Bid Whist Makes Me A Better Lawyer

    Author Photo

    As a child, I viewed bid whist as a family tradition and a source of friendly card game competition, but as a lawyer, I see it as a tool that has helped me cultivate skills like communication, teamwork, risk assessment and composure, says Keyonn Pope at Riley Safer.

  • FCC Robotics Restrictions Raise AI Compliance Risks

    Author Photo

    A recent "covered list" update from the Federal Communications Commission places restrictions on foreign-produced advanced robotic devices’ ability to obtain new authorizations, creating a framework that is poorly suited to continuous artificial intelligence updates, and raising several transactional and contractual challenges, says Kim Larsen at Stinson.

  • What Greek Tragedy Teaches About Mediating AI Disputes

    Author Photo

    While ancient Greek writers could not have anticipated modern arbitration, their tragic plays illustrate new and familiar questions for mediators dealing with artificial intelligence disputes, including the functional differences between adjudication and resolution, says Giuseppe De Palo at JAMS.

  • Tracking Trends In State-Level Regulatory Enforcement

    Author Photo

    State-level enforcement now increasingly involves antitrust, artificial intelligence and data privacy issues, and the key for organizations to reducing risk is having the ability to respond across governance, public affairs, discovery and remediation in multiple states simultaneously, say consultants at FTI Consulting.

  • And Now A Word From The Panel: Accessing Key MDL Data

    Author Photo

    As the Judicial Panel on Multidistrict Litigation convenes for its September hearing session, it is useful to examine the treasure trove of historical and statistical information about MDLs past and present that the panel makes available to the public on its own website, says Alan Rothman at Sidley Austin.

  • Opinion

    Calif. Bill Goes Too Far In Trying To Regulate Attorney AI Use

    Author Photo

    California’s first-in-the-nation act regulating how attorneys and arbitrators use generative artificial intelligence will likely soon become law, but read broadly, the provisions may dissuade lawyers from employing AI at all, thereby depriving them of key work tools, says Joshua Wurtzel at Schlam Stone.

  • AI Rise In Healthcare Demands New Cybersecurity Strategies

    Author Photo

    As artificial intelligence-related capabilities are increasingly integrated into medical devices and healthcare operations, organizations must adapt their compliance playbook to address evolving cybersecurity needs and implement lifecycle-based risk assessment approaches, say attorneys at Covington.

  • Series

    Fintech Regulator Outlook: 5 Lessons From Minnesota

    Author Photo

    Minnesota's recent cryptocurrency kiosk ban and virtual currency custody rules hold several broad compliance lessons: Digital asset companies must map regulated activities, strengthen third-party oversight and engage regulators early to innovate responsibly, says Deputy Commissioner of Financial Institutions Mike Crow at the Minnesota Department of Commerce.

  • Hims & Hers Suit Spotlights Health Data-Sharing Privacy Risks

    Author Photo

    Regulators' complaint against telehealth company Hims & Hers alleging deceptive practices serves as a reminder that the privacy principles developed under consumer protection laws and predating omnibus statutes remain in force, and sensitive data governance continues to be a crucial component of compliance, say attorneys at Venable.

  • 4 Paths To AI Safety Coordination Amid Antitrust Debate

    Author Photo

    Frontier artificial intelligence companies have more room for collective safety work than the debate over an antitrust waiver suggests, with several existing avenues providing different degrees of protection and oversight, says Evan Miller at V&E.

  • How Calif. Privacy Bill Could Change CIPA Tracking Cases

    Author Photo

    If California Gov. Gavin Newsom signs S.B. 690, the bill could materially reduce the leverage behind a pen-register-only claim or demand, so California Invasion of Privacy Act website tracking claims should not be evaluated the same way they were six months ago, says Alexandra Samofalova at Spencer Fane.

  • How GCs Can Assess The Risks Of Emerging AI Laws

    Author Photo

    Amid a swirl of momentous legislative activity aimed at regulating artificial intelligence, general counsel must return to first principles when determining whether new laws will apply and whether the company’s use could cause regulators to subject it to additional regulation, say attorneys at WilmerHale.

Want to publish in Law360?


Submit an idea

Have a news tip?


Contact us here