Cybersecurity & Privacy

  • August 15, 2025

    Judge Tosses GitLab Investors' AI Hype Suit

    Software development collaboration platform GitLab has escaped a lawsuit accusing it of overhyping its artificial intelligence technology, but the California federal judge in charge of the case has given shareholders another chance to demonstrate just how the technology allegedly was not up to snuff.

  • August 15, 2025

    Production Co.'s Subpoena Over Pirated Film Fails At 9th Circ.

    The film production company behind the 2022 film "Fall" on Friday lost its fight at the Ninth Circuit to force Cox Communications to hand over the names of a group of subscribers who allegedly were pirating copies of the film.

  • August 15, 2025

    NY Fines Insurer Healthplex $2M Over Cybersecurity Failures

    A dental insurance provider has agreed to pay a $2 million penalty and undergo an audit of its multifactor authentication controls in order to resolve the New York financial regulator's claims that its failure to implement robust cybersecurity safeguards led to an email phishing attack that exposed customers' sensitive data.

  • August 15, 2025

    AT&T Seeks Approval To Halt Copper Service After Thefts

    AT&T is asking the Federal Communications Commission for emergency authorization to suspend its copper-based phone legacy service for 22 customers outside Dallas, claiming that service outages were caused by a series of copper thefts from its facilities in June.

  • August 15, 2025

    3rd Circ. Won't Rehear Pa. County's Dominion Contract Suit

    The Third Circuit has declined to revisit a ruling that a Pennsylvania county's commissioners lacked standing to sue Dominion Voting Systems over alleged security flaws during the 2020 election.

  • August 15, 2025

    Google Asks 9th Circ. To Rethink Play Store Antitrust Ruling

    Google urged the Ninth Circuit to reconsider a panel's decision to affirm a jury's findings that it monopolized the Android app market, saying the panel made several missteps when evaluating the claims and contended the injunction issued as a result of the verdict goes too far.

  • August 14, 2025

    Banks Ask To Halt 'Unfair' Clock On CFPB Open Banking Rule

    Bank trade groups are asking a Kentucky federal judge to freeze looming compliance deadlines for the Consumer Financial Protection Bureau's contested open banking rule as the agency revamps the measure, while opposing fintech groups called on the White House to block banks from charging them fees for the kind of data-sharing the rule mandates.

  • August 14, 2025

    Fla. Judge Won't Require Snap To Heed Teen Social Media Law

    A Florida federal judge has rejected the state attorney general's bid to force Snap Inc. to comply with a new law that would limit the ability of teens to access the platform, holding that the state's challenge was unlikely to succeed in light of his prior ruling in a related case finding the measure to likely be unconstitutional. 

  • August 14, 2025

    6th Circ. Upholds FCC's Telecom Data Breach Rules

    The Sixth Circuit on Wednesday upheld the Federal Communications Commission's expanded data breach notification rules for telecommunications carriers, rejecting challenges from industry groups who said the 2024 changes were too similar to a 2016 FCC order that Congress rejected under the Congressional Review Act early the following year.

  • August 14, 2025

    2nd Circ. Backs Convictions In ATM-Skimming Ploy

    The Second Circuit on Thursday affirmed the convictions of two men involved in a major ATM card-skimming ring, but said a district court should clarify one defendant's restitution payment schedule.

  • August 14, 2025

    Grindr Says Section 230 Shields It From Teen Death Suit

    Dating app Grindr told a Florida federal judge Wednesday that Section 230 of the Communications Decency Act shields it from claims it negligently allowed a 16-year-old to access the platform and caused her to be matched with a 35-year-old man who is accused of murdering her.

  • August 14, 2025

    Truist Settles Class Claims Over Third-Party Data Trackers

    Truist Financial Corp. has settled a proposed class action accusing the company of embedding third-party trackers on its website for companies like Meta and Google to use to monetize user data through advertising, according to a joint settlement notice filed Thursday in California federal court.

  • August 14, 2025

    AGs Urge Meta To 'Prioritize Safety' With Location Feature

    A bipartisan coalition of more than three dozen state attorneys general is calling on Meta Platforms Inc. to strengthen the privacy and security safeguards for a new location tracking feature that recently debuted on Instagram, arguing that the social media giant has a duty "to prioritize user safety over product novelty."

  • August 14, 2025

    Rumble's Ad Boycott Suit Tossed For Now

    A Texas federal court tossed Rumble's antitrust case against the World Federation of Advertisers and others after finding the claims about a boycott of the video-sharing site, after it refused to follow safety standards, have no connection to the state.

  • August 14, 2025

    Dental Clinic Privacy Breach Claims Not Covered, Insurer Says

    A dental practice's insurer told an Illinois federal court it should owe no coverage in an underlying proposed class action accusing the practice of transmitting patients' sensitive personal information to Alphabet Inc. via the business's online scheduling platform, arguing an exclusion concerning "personal information" applies.

  • August 14, 2025

    FCC Member Sees Special Authority As Key To Defense Tech

    The Federal Communications Commission could increasingly use its legal authority to temporarily authorize radio licenses as a way to test new wireless networks that bolster national security, an agency member said.

  • August 14, 2025

    US Targets Russia-Linked Crypto Exchanges Over Illicit Flows

    The Trump administration on Thursday renewed sanctions on Russian cryptocurrency exchange Garantex and moved against its successor, Grinex, accusing the platforms of helping launder illicit transactions and shifting business to dodge earlier penalties.

  • August 14, 2025

    Conn. Credit Union Hit With Suit Over Data Breach

    A North Haven, Connecticut-based credit union is facing a proposed class action over allegations that it failed to properly safeguard customers' personal information in a June data breach and violated state law by delaying notification to victims.

  • August 14, 2025

    Mullen Coughlin Strengthens Cyber Practice With New Partner

    Cybersecurity boutique Mullen Coughlin LLC has expanded its incident response resources at its office in the Philadelphia suburbs with the addition of an attorney specializing in data protection.

  • August 14, 2025

    What To Watch As FAA Preps Beyond-Line-Of-Sight Drone Ops

    With drones poised to fly as yet forbidden skies — beyond the sight line of their operators — under long-awaited potential new rules from the Federal Aviation Administration, the anticipated boon for commercial ventures will hinge on how to safeguard the wider airspace.

  • August 14, 2025

    Justices Allow Mississippi's Social Media Age Verification Law

    The U.S. Supreme Court said Thursday that social media giants like Facebook, X, YouTube and Reddit must comply with a Mississippi law that requires platforms to verify users' ages and obtain parental consent before minors can create accounts, while the companies challenge its constitutionality.

  • August 14, 2025

    DiDi Investors Get Partial Cert. In Ride-Hailing App IPO Suit

    A New York federal judge adopted a magistrate judge's recommendation to partially grant class certification in an investor suit alleging DiDi Global Inc., a ride-hailing business based in China, hid enterprise-threatening regulatory risks during its initial public offering in 2021.

  • August 13, 2025

    DC Circ. Upholds Toss Of Video Privacy Suit Against Paper

    The D.C. Circuit has refused to revive a proposed class action accusing the Washington Examiner of illegally sharing website visitors' video-viewing information with Meta, finding that the plaintiff had failed to show that she "subscribed" to the content that she accessed online rather than through her newsletter subscription.

  • August 13, 2025

    Whoop's Health Tracker Accused Of Sharing Users' Data

    Health and wellness company Whoop Inc., whose wearable devices track and collect users' heart rate, movement, blood pressure and other health metrics, is secretly sharing that data and other user information with an undisclosed third party, according to a proposed class action filed Wednesday in California federal court.

  • August 13, 2025

    Trump Admin Bid To Kill SSA Data Suit Ruled Premature

    The Trump administration can't fight an injunction in Maryland federal court and the Fourth Circuit simultaneously, a Maryland federal judge said Wednesday, tabling the administration's dismissal bid while the Fourth Circuit considers whether to lift a ban on the Department of Government Efficiency accessing unredacted Social Security data.

Expert Analysis

  • How DOJ's New Data Security Rules Leave HIPAA In The Dust

    Author Photo

    The U.S. Department of Justice's recently effective data security requirements carry profound implications for how healthcare providers collect, store, share and use data — and approach vendor oversight — that go far beyond the Health Insurance Portability and Accountability Act, say attorneys at Nelson Mullins.

  • Opinion

    Section 1983 Has Promise After End Of Nationwide Injunctions

    Author Photo

    After the U.S. Supreme Court recently struck down the practice of nationwide injunctions in Trump v. Casa, Section 1983 civil rights suits can provide a better pathway to hold the government accountable — but this will require reforms to qualified immunity, says Marc Levin at the Council on Criminal Justice.

  • Courts Redefining Software As Product Generates New Risks

    Author Photo

    A recent wave of litigation against social media platforms, chatbot developers and ride-hailing companies has some courts straying from the traditional view of software as a service to redefining software as a product, with significant implications for strict liability exposure, say attorneys at Reed Smith.

  • Now Is The Time To Prep For SEC's New Data Breach Regs

    Author Photo

    Recent remarks from the U.S. Securities and Exchange Commission’s acting director of the Division of Examinations suggest that the commission will support exams for compliance with its new data breach detection and reporting regulations, and a looming deadline means investment advisers and broker-dealers must act now to update their processes, say attorneys at McGuireWoods.

  • How Banks Can Harness New Customer ID Rule's Flexibility

    Author Photo

    Banking regulators' update to the customer identification process, allowing banks to collect some information from third parties rather than directly from customers, helps modernize anti-money laundering compliance and carries advantages for financial institutions that embrace the new approach, say attorneys at Bradley Arant.

  • Series

    Playing Soccer Makes Me A Better Lawyer

    Author Photo

    Soccer has become a key contributor to how I approach my work, and the lessons I’ve learned on the pitch about leadership, adaptability, resilience and communication make me better at what I do every day in my legal career, says Whitney O’Byrne at MoFo.

  • How Trump Cybersecurity EO Narrows Biden-Era Standards

    Author Photo

    President Donald Trump recently signed Executive Order No. 14306, which significantly narrows the scope and ambition of a Biden executive order focused on raising federal cybersecurity standards among federal vendors, say attorneys at Jenner & Block.

  • Opinion

    The SEC Should Embrace Tokenized Equity, Not Strangle It

    Author Photo

    The U.S. Securities and Exchange Commission should grant no-action relief to firms ready to pilot tokenized equity trading, not delay innovation by heeding protectionist industry arguments, says J.W. Verret at George Mason University.

  • And Now A Word From The Panel: Back In Action

    Author Photo

    A lack of new petitions at the May hearing session of the Judicial Panel on Multidistrict Litigation caught many observers' attention — but a rapid uptick in petitions scheduled to be heard at this week's session illustrates how panel activity always ebbs and flows, says Alan Rothman at Sidley.

  • Compliance Changes On Deck For Banks Under Texas AI Law

    Author Photo

    Financial services companies, including banks and fintechs, should evaluate their artificial intelligence usage to prepare for Texas' newly passed law regulating AI governance, noting that the enforcement provisions provide for an affirmative defense to liability, say attorneys at Mitchell Sandler.

  • Series

    Law School's Missed Lessons: Learning From Failure

    Author Photo

    While law school often focuses on the importance of precision, correctness and perfection, mistakes are inevitable in real-world practice — but failure is not the opposite of progress, and real talent comes from the ability to recover, rethink and reshape, says Brooke Pauley at Tucker Ellis.

  • 23andMe Fine Signals ICO's New GDPR Enforcement Focus

    Author Photo

    Many of the cybersecurity failures identified by the Information Commissioner’s Office in its investigation of 23andMe, recently resulting in a £2.3 million fine, were basic lapses, but the ICO's focus on several new U.K. General Data Protection Regulation considerations will likely carry into the future, say lawyers at Womble Bond.

  • Midyear Rewind: How Courts Are Reshaping VPPA Standards

    Author Photo

    The first half of 2025 saw a series of cases interpreting the Video Privacy Protection Act as applied to website tracking technologies, including three appellate rulings deepening circuit splits on what qualifies as personally identifiable information and who qualifies as a consumer under the statute, say attorneys at Perkins Coie.

  • How The Healthline Privacy Settlement Redefines Ad Tech Use

    Author Photo

    The Healthline settlement is the first time California has drawn a clear line in the sand around how website tracking must function in practice, so if your site uses tracking technologies, especially around sensitive content like health or finance, regulators are inspecting your website's back end, not just its banner, say attorneys at Baker Donelson.

  • Series

    Adapting To Private Practice: From ATF Director To BigLaw

    Author Photo

    As a two-time boomerang partner, returning to BigLaw after stints as a U.S. attorney and the director of the Bureau of Alcohol, Tobacco, Firearms and Explosives, people ask me how I know when to move on, but there’s no single answer — just clearly set your priorities, says Steven Dettelbach at BakerHostetler.

Want to publish in Law360?


Submit an idea

Have a news tip?


Contact us here
Can't find the article you're looking for? Click here to search the Cybersecurity & Privacy archive.