Cybersecurity & Privacy

  • November 21, 2025

    Ruger's $1.5M Data Breach Deal Heads For Final OK

    A proposed class of data breach victims has asked a federal judge to issue final approval of a $1.5 million settlement with Connecticut-based gunmaker Sturm, Ruger & Co. and a New Jersey web developer, along with $500,000 in fees to attorneys with four firms including Siri & Glimstad LLP.

  • November 21, 2025

    Rothman Orthopaedics Hit With Pa. Wiretapping Lawsuit

    Rothman Orthopaedics has been hit with a proposed class action in Pennsylvania alleging the company violated state wiretapping laws by intercepting private healthcare information on its website using a third-party tracking pixel.

  • November 21, 2025

    Mich. Atty Fights Defamation Suit From Election Investigator

    A Michigan attorney has said any statements that a cybersecurity firm claims she made to scuttle its president's job prospects with the Pennsylvania Legislature are protected speech on a matter of public concern, urging a federal judge to dismiss a suit the firm brought after it told her it found no evidence of fraud in the 2020 presidential election.

  • November 21, 2025

    Mich. Mortgage Co. Hit With Data Breach Class Actions

    A Michigan mortgage lender was hit with several proposed data breach class actions that alleged in Michigan federal court that the lender failed to do enough to protect consumers' personally identifiable information, such as their Social Security numbers, from a June data breach.

  • November 21, 2025

    DOJ Will Speed Some Classified Discovery In Bolton Case

    Federal prosecutors agreed Friday to accelerate their classified discovery timeline in the prosecution of John Bolton, as a Maryland federal judge pressed them to move faster.

  • November 21, 2025

    SEC, Virtu To Settle Customer Data Suit For $2.5M

    Virtu Financial Inc. has agreed to pay the U.S. Securities and Exchange Commission $2.5 million for allegedly failing to safeguard customer information, according to a Friday proposed final order that would end the regulator's two-year-old suit against the broker-dealer.

  • November 21, 2025

    1st Circ. Clears IT Co. In Suit Over Zoll Patient Data Breach

    An information technology company cannot be held liable for a data breach exposing the health information of patients of a unit of medical device maker Zoll Medical Corp, the First Circuit ruled, because the two companies did not have a business relationship permitting them to hold one responsible for another's conduct.

  • November 20, 2025

    Renewed Federal Push To Block State AI Laws Faces Backlash

    The Trump administration is pushing to revive a failed effort to stop states from regulating artificial intelligence systems, drawing opposition from California's data privacy regulator, consumer advocates and others that argue it's crucial for states to retain their ability to put guardrails on the emerging technology in the wake of continued federal inaction.

  • November 20, 2025

    Meta Will Pay $190M, Change Policies To End $8B Privacy Suit

    Meta Platforms Inc. has agreed to pay $190 million, as well as enhance its whistleblower program and implement a new code of conduct and insider trading policy, as part of a proposed settlement in an $8 billion privacy suit tied to the Cambridge Analytica scandal, according to several new filings Thursday.

  • November 20, 2025

    Roblox Can't Get Teen Grooming Suit Arbitrated

    A California state judge said Roblox couldn't compel a minor to arbitrate his claims that he was targeted and exploited by a sexual predator on the online gaming platform, saying that a recent federal law aimed at ending forced arbitration in sexual assault and harassment cases isn't limited to workplaces.

  • November 20, 2025

    Journalist Jailed For Contempt, Fined For Stealing Court Mug

    A Texas federal judge ordered U.S. marshals Thursday to haul a onetime conservative journalist to a nearby jail for contempt of court and separately fined him $1,000 for stealing a court coffee mug, saying he had had it with the defendant's "shenanigans."

  • November 20, 2025

    1st Circ. Tosses Challenge To Maine Lobster Boat Tracking

    The First Circuit has declined to revive a case brought by several Maine lobstermen who said their privacy rights were violated by the state's tracking of their vessels, ruling that the tracking devices were part of administrative searches of a closely regulated industry and do not violate the Fourth Amendment.

  • November 20, 2025

    Data Breach Suit Against Circle K Franchisee Wraps Up

    A group of ex-workers who sued a franchisee of gas and convenience store chain Circle K over a May 2024 data breach have agreed to end their proposed class action, according to a Georgia federal court filing. 

  • November 20, 2025

    Ill. Justices Back Walgreens In Receipt Class Standing Fight

    A Walgreens customer looking to hold the company liable for allegedly printing too much financial information on consumers' receipts should not have won class certification in her case because she lacked standing to bring her claims, the Illinois Supreme Court said Thursday.

  • November 20, 2025

    Adidas Must Face Claim It Shared Info With Microsoft, TikTok

    A California federal judge has denied a motion from Adidas to toss a proposed class action alleging the apparel company violated a California privacy statute by placing tracking pixels from TikTok Pixel and Microsoft Bing on its website, finding the trackers plausibly constitute a "pen register" under state law. 

  • November 20, 2025

    FCC Rescinds Contested Biden-Era Cybersecurity Ruling

    The Federal Communications Commission on Thursday reversed a ruling made late in the Biden administration that required new steps from telecoms to beef up cybersecurity, even as an FCC Democrat decried the move as gutting the agency's response to the Salt Typhoon cyberattack.

  • November 20, 2025

    Fed. Circ. Shoots Down Bot Patent Claim In Google Challenge

    The Federal Circuit on Thursday reversed the Patent Trial and Appeal Board's finding that upheld one of the claims in a Nobots LLC's bot-detecting patent challenged by Google, finding that the PTAB incorrectly interpreted the claim.

  • November 20, 2025

    SEC Walks Away From SolarWinds Data Breach Case

    The U.S. Securities and Exchange Commission announced Thursday that it was voluntarily dismissing a lawsuit accusing software developer SolarWinds Corp. and its chief information security officer of failing to warn investors about lax cybersecurity standards prior to suffering a massive data breach.

  • November 20, 2025

    Cybersecurity Co. Axonius Names 1st GC From Azra Games

    Cybersecurity company Axonius Inc. has found its first general counsel in a veteran legal leader who has worked at software and technology companies including Azra Games and Iterable as it prepares for an initial public offering.

  • November 20, 2025

    Ex-SDNY Chief Rejects Claim Of Broken FTX Plea Promise

    Former interim Manhattan U.S. Attorney Danielle Sassoon told a federal judge Thursday that she never promised crypto lobbyist Michelle Bond any kind of no-prosecute deal as the government negotiated a guilty plea with Bond's husband, former FTX executive Ryan Salame.

  • November 19, 2025

    29 AGs Want Social Media Addiction Fight Decided In 1 Trial

    A coalition of 29 state attorneys general Wednesday urged a California federal judge presiding over social-media addiction multidistrict litigation to consolidate state law claims into a single jury trial, while Meta's counsel argued that there's no case law precedent for such a single trial and it would be prejudicial.

  • November 19, 2025

    Calif. Privacy Agency Targets Data Brokers With 'Strike Force'

    The California Privacy Protection Agency is stepping up its oversight of the data broker industry, revealing Wednesday that it is establishing a dedicated "strike force" within its enforcement division to monitor whether these companies are meeting registration requirements and properly handling consumers' personal data.

  • November 19, 2025

    Amazon Alexa Users Win Cert. Of 1.2M-Member BIPA Class

    An Illinois federal judge has certified a class of roughly 1.2 million users of Amazon's Alexa in litigation accusing the e-commerce giant of unlawfully collecting their biometric voice data, allowing two people to serve as representatives for those in the state for whom Amazon allegedly created voiceprints.

  • November 19, 2025

    DaVita Reaches Tentative Deal In Patients' Data Breach Suit

    DaVita Inc. has reached a settlement in principle with current and former patients of the healthcare company who alleged in Colorado federal court that it did not adequately protect their personal information, resulting in an April data breach.

  • November 19, 2025

    Mich. Judge Questions AG's Role In Roku Privacy Suit

    A Michigan federal judge on Wednesday questioned the state attorney general's authority to pursue privacy violation claims against Roku Inc. on behalf of residents and children, saying that such allegations can also be brought as a private class action.

Expert Analysis

  • AI Product Safety Insights May Expand Foreseeability

    Author Photo

    Product liability law has long held that companies are responsible for risks they knew about or should have known about — and with AI systems now able to assess and predict hazards during the design process, companies should expect that courts will likely treat such hazards as foreseeable, says Donald Fountain at Clark Fountain.

  • Series

    Law School's Missed Lessons: Educating Your Community

    Author Photo

    Nearly two decades prosecuting scammers and elder fraud taught me that proactively educating the public about the risks they face and the rights they possess is essential to building trust within our communities, empowering otherwise vulnerable citizens and preventing wrongdoers from gaining a foothold, says Roger Handberg at GrayRobinson.

  • Strategies For Merchants As Payment Processing Costs Rise

    Author Photo

    As current economic pressures and rising card processing costs threaten to decrease margins for businesses, retail merchants should consider restructuring how payments are made and who processes them within the evolving legal framework, says Tom Witherspoon at Stinson.

  • Shifting Crypto Landscape Complicates Tornado Cash Verdict

    Author Photo

    Amid shifts in the decentralized finance regulatory landscape, the mixed verdict in the prosecution of Tornado Cash’s founder may represent the high-water mark in a cryptocurrency enforcement strategy from which the U.S. Department of Justice has begun to retreat, say attorneys at Venable.

  • 5 Crisis Lawyering Skills For An Age Of Uncertainty

    Author Photo

    As attorneys increasingly face unprecedented and pervasive situations — from prosecutions of law enforcement officials to executive orders targeting law firms — they must develop several essential competencies of effective crisis lawyering, says Ray Brescia at Albany Law School.

  • Compliance Tips Amid Rising FTC Scrutiny Of Minors' Privacy

    Author Photo

    The Federal Trade Commission has recently rolled out multiple enforcement actions related to children's privacy, highlighting a renewed focus on federal regulation of minors' personal information and the evolving challenges of establishing effective, privacy-protective age assurance solutions, say attorneys at Nelson Mullins.

  • Opinion

    It's Time For The Judiciary To Fix Its Cybersecurity Problem

    Author Photo

    After recent reports that hackers have once again infiltrated federal courts’ electronic case management systems, the judiciary should strengthen its cybersecurity practices in line with executive branch standards, outlining clear roles and responsibilities for execution, says Ilona Cohen at HackerOne.

  • Prepping For Website Automatic Opt-Out Signal Mandates

    Author Photo

    Maryland's Online Data Privacy Act, which, along with a growing number of U.S. states, requires businesses to offer mechanisms in their privacy policies or online interfaces to allow individuals to opt out of data collection, marks a new frontier in consumer privacy, raising both technical and legal risks, say attorneys at Baker Donelson.

  • Tips For Cos. Crafting Enforceable Online Arbitration Clauses

    Author Photo

    Recent rulings from the Ninth Circuit and the U.S. District Court for the Southern District of California indicate that courts are carefully examining the enforceability of online arbitration clauses, so businesses should review the design of their websites and consider specific language next to the "purchase" button, say attorneys at DTO Law.

  • 7 Lessons From The Tractor Supply CCPA Enforcement Action

    Author Photo

    The California Privacy Protection Agency's recent enforcement action targeting Tractor Supply for alleged violations of the California Consumer Privacy Act provides critical insights into the compliance areas that remain a priority for the California regulator, including businesses with significant consumer interactions, say attorneys at Troutman.

  • Series

    Writing Novels Makes Me A Better Lawyer

    Author Photo

    Writing my debut novel taught me to appreciate the value of critique and to never give up, no matter how long or tedious the journey, providing me with valuable skills that I now emphasize in my practice, says Daniel Buzzetta at BakerHostetler.

  • SDNY OpenAI Order Clarifies Preservation Standards For AI

    Author Photo

    The Southern District of New York’s recent order in the OpenAI copyright infringement litigation, denying discovery of The New York Times' artificial intelligence technology use, clarifies that traditional preservation benchmarks apply to AI content, relieving organizations from using a “keep everything” approach, says Philip Favro at Favro Law.

  • Addressing Legal Risks Of AI In The Homebuilding Industry

    Author Photo

    Artificial intelligence is transforming the homebuilding industry, but the legal challenges posed by its adoption spread across many areas, including contractual liability and intellectual property issues, so builders should adopt strategies to mitigate the risks and position themselves for success, says Philip Stein at Bilzin Sumberg.

  • Cybersecurity Rule For DOD Contractors Creates New Risks

    Author Photo

    A rule locking in the Cybersecurity Maturity Model Certification system for defense contractors increases False Claims Act and criminal enforcement risks by narrowing a key exemption and mandating affirmations of past compliance, which may discourage new companies from entering the defense contracting market, say attorneys at Haynes Boone.

  • Compliance Steps To Take As FCRA Enforcement Widens

    Author Photo

    As the Fair Credit Reporting Act receives renewed focus from both federal and state enforcers, regulatory and litigation risk is most acute in several core areas, which companies can address by implementing purpose processes and quick remediation of consumer complaints, among other steps, say attorneys at Wiley.

Want to publish in Law360?


Submit an idea

Have a news tip?


Contact us here
Can't find the article you're looking for? Click here to search the Cybersecurity & Privacy archive.