Cybersecurity & Privacy

  • September 29, 2025

    Ill. Judge Trims Suit Over Chicago Children's Hospital Hack

    Patients and patrons of Lurie Children's Hospital in Chicago whose personal information was allegedly compromised in a hack can pursue their claim that the hospital's negligent data security practices led to the exposure, but an Illinois federal judge dismissed most of their other claims.

  • September 29, 2025

    MyPillow CEO Defamed Smartmatic, Minn. Judge Rules

    MyPillow CEO Mike Lindell defamed Smartmatic when he accused the voting systems company of rigging votes in the 2020 election to favor President Joe Biden, a Minnesota federal judge ruled, but issues of damages and whether the statements were made with malice will need to be worked out by a jury.

  • September 29, 2025

    TikTok Can't Use Section 230 To End NJ AG's Harm Suit

    A New Jersey state court judge has rejected TikTok's bid to use an internet safety law carveout that shields publishers of third-party information to end Attorney General Matthew Platkin's lawsuit over the exploitation of children, reasoning that the alleged harm stems from the social media app's design rather than what users view.

  • September 29, 2025

    NY's Top Financial Services Regulator Is Stepping Down

    The head of the New York State Department of Financial Services is stepping down next month and will be replaced on an interim basis by the chief of its fintech-focused innovation division, New York Gov. Kathy Hochul said Monday.

  • September 26, 2025

    Meta Set To Appeal Flo Privacy Verdict As Users Seek Billions

    Meta is gearing up to appeal a California federal jury verdict that found it liable for using a data analytics tool to illegally retrieve sensitive health data from users of the popular menstrual tracking app Flo, the company disclosed in a posttrial filing in which the plaintiffs separately asked the court to award statutory damages that could reach the billions.

  • September 26, 2025

    Trump Demands Microsoft Fire Ex-Biden Deputy AG Monaco

    President Donald Trump on Friday demanded that Microsoft fire its new President of Global Affairs Lisa Monaco, deputy attorney general in the Biden administration and homeland security adviser in the Obama administration, in what seems to be the president's latest effort to exact revenge on his perceived political enemies.

  • September 26, 2025

    Ad Tech Judge Told Google Shouldn't Control Auctions

    The head of an industry consortium that could have an important role in breaking up Google's advertising placement technology business told a Virginia federal judge Friday that the Justice Department should be able to take away Google's control over the processes that pick where ads are placed.

  • September 26, 2025

    Google Asks High Court To Pause Epic Play Store Order

    Google has asked the U.S. Supreme Court to pause parts of the order won by Epic Games in its antitrust case targeting the tech giant's app store policies, saying the sweeping injunction threatens to create security and privacy concerns for millions of users.

  • September 26, 2025

    Conn. Psych Facility Faces Class Claims Over Data Breach

    A residential psychiatric treatment facility in Connecticut fell victim to a cyberattack that exposed the personal information of more than 5,000 current and former patients and employees, according to a putative class action that alleges The Children's Center of Hamden Inc. was negligent with its data security.

  • September 26, 2025

    Fla. Urges 11th Circ. To Remand Snap Inc. Suit To State Court

    The Florida Office of the Attorney General urged the Eleventh Circuit to undo an order blocking enforcement of a law that requires Snap Inc. to limit teens' access to the platform, arguing the case belongs in state court. 

  • September 26, 2025

    Oldies.com Class Claims Over Video-Buying Info Kept Alive

    A Pennsylvania federal judge has ruled that online video seller oldies.com must face a customer's proposed class action claiming it unlawfully disclosed his personal viewing information, finding he adequately showed the website violated the Video Privacy Protection Act.

  • September 26, 2025

    FCC Rejects More Equipment Labs Tied To Adversaries

    The Federal Communications Commission said Friday it had blocked more labs tied to foreign adversaries from its equipment authorization program.

  • September 26, 2025

    Texas' Eastern District Tightens Sealed-Document Procedures

    Chief U.S. District Judge Amos L. Mazzant III of the Eastern District of Texas issued new protocols Wednesday for filing sealed documents that will prohibit electronic access effective immediately, a move that comes amid escalating cyberattacks on the federal judiciary's case management system.

  • September 26, 2025

    Commerce Opens 2 New Section 232 Investigations

    The U.S. Department of Commerce recently self-initiated investigations into imports of medical devices and personal protective equipment as well as robotics to determine whether they pose a national security threat requiring tariff actions under Section 232 of the Trade Expansion Act of 1962, according to two notices published Friday.

  • September 25, 2025

    DOJ Unveils New 'Affirmative Litigation' Civil Division Branch

    The U.S. Department of Justice Thursday announced its newly created "Enforcement & Affirmative Litigation Branch," part of which will be dedicated to going after states, municipalities and private entities that impede federal immigration enforcement or profit from "false and misleading claims" about gender transition.

  • September 25, 2025

    Trump Blesses Deal To Transfer TikTok To $14B US Co.

    President Donald Trump Thursday signed an executive order greenlighting a proposed deal that transfers the majority of TikTok's U.S. operations to a new U.S.-based joint venture, saying that the divestiture adequately addresses national security concerns.

  • September 25, 2025

    Google VP Says Ad Tech Breakup Is 'Possible'

    The Google executive responsible for its advertising placement technology business told a Virginia federal judge Thursday that the company previously determined that a breakup was doable, even as he argued that the U.S. Department of Justice is mischaracterizing recent considerations of what that would look like.

  • September 25, 2025

    Senate Dems Float Bill To Shield Neural Data From Misuse

    A trio of Senate Democrats proposed legislation Wednesday that would establish a federal framework for how companies and the government collect and use data derived from measuring brain activity, arguing that the current lack of protections for such neural data leaves consumers open to manipulation and other serious harms.

  • September 25, 2025

    Textron Shakes Privacy Suit Over Data Sharing With Google

    A California federal judge has tossed a proposed class action accusing Textron Inc. of illegally sharing information about website visitors' search activities with Google LLC, finding that the plaintiff failed to allege that the aviation and defense products manufacturer had expressly targeted residents of the Golden State.

  • September 25, 2025

    Wash. Judge Weighs Audible Bid To Toss Privacy Class Action

    A Seattle federal judge on Thursday questioned whether a proposed class action accusing Amazon-owned Audible of violating customers' privacy should proceed under California law, as the plaintiffs argue, or Washington law, as Audible insists — a decision that could determine the lawsuit's fate.

  • September 25, 2025

    Hagens Berman Not Very Contrite About AI Errors, Judge Says

    A California federal judge chided attorneys from Hagens Berman on Thursday over what he called a lack of contrition after submitting briefs that contained errors lifted from ChatGPT in a proposed class action against the online platform OnlyFans, saying the attorneys seemed more interested in excuses.

  • September 25, 2025

    UFCW Faces Negligence Suit Over Data Breach Affecting 55K

    A United Food and Commercial Workers local was hit with a putative class action in Colorado federal court Thursday looking to hold it liable for allegedly failing to protect more than 55,000 individuals' personal information from a cybersecurity attack and waiting more than nine months to inform the victims.

  • September 24, 2025

    Google Ad Tech Judge Ponders If Order Without Sale Is Enough

    A Virginia federal judge wondered aloud Wednesday if it's necessary to break up Google LLC's advertising placement technology business, or if she can address the monopolies targeted by the U.S. Department of Justice through a "strict set of requirements."

  • September 24, 2025

    Robocall Recipients Get Class Cert. Against Ill. Bank

    Consumers who allegedly received unwanted robocalls from Illinois-based Federal Savings Bank will secure certification of a nationwide class of nearly 2.3 million consumers in a proposed Telephone Consumer Protection Act class action, an Illinois federal judge has decided.

  • September 24, 2025

    UnitedHealth Fights Investor Suit Over DOJ's Merger Probe

    UnitedHealth and its executives have asked a Minnesota federal judge to toss a proposed securities class action accusing it of, among many things, not disclosing that the U.S. Department of Justice had reopened an antitrust investigation into the health insurer, saying the complaint consists of unsupported "scattershot allegations."

Expert Analysis

  • And Now A Word From The Panel: Back In Action

    Author Photo

    A lack of new petitions at the May hearing session of the Judicial Panel on Multidistrict Litigation caught many observers' attention — but a rapid uptick in petitions scheduled to be heard at this week's session illustrates how panel activity always ebbs and flows, says Alan Rothman at Sidley.

  • Compliance Changes On Deck For Banks Under Texas AI Law

    Author Photo

    Financial services companies, including banks and fintechs, should evaluate their artificial intelligence usage to prepare for Texas' newly passed law regulating AI governance, noting that the enforcement provisions provide for an affirmative defense to liability, say attorneys at Mitchell Sandler.

  • Series

    Law School's Missed Lessons: Learning From Failure

    Author Photo

    While law school often focuses on the importance of precision, correctness and perfection, mistakes are inevitable in real-world practice — but failure is not the opposite of progress, and real talent comes from the ability to recover, rethink and reshape, says Brooke Pauley at Tucker Ellis.

  • 23andMe Fine Signals ICO's New GDPR Enforcement Focus

    Author Photo

    Many of the cybersecurity failures identified by the Information Commissioner’s Office in its investigation of 23andMe, recently resulting in a £2.3 million fine, were basic lapses, but the ICO's focus on several new U.K. General Data Protection Regulation considerations will likely carry into the future, say lawyers at Womble Bond.

  • Midyear Rewind: How Courts Are Reshaping VPPA Standards

    Author Photo

    The first half of 2025 saw a series of cases interpreting the Video Privacy Protection Act as applied to website tracking technologies, including three appellate rulings deepening circuit splits on what qualifies as personally identifiable information and who qualifies as a consumer under the statute, say attorneys at Perkins Coie.

  • How The Healthline Privacy Settlement Redefines Ad Tech Use

    Author Photo

    The Healthline settlement is the first time California has drawn a clear line in the sand around how website tracking must function in practice, so if your site uses tracking technologies, especially around sensitive content like health or finance, regulators are inspecting your website's back end, not just its banner, say attorneys at Baker Donelson.

  • Series

    Adapting To Private Practice: From ATF Director To BigLaw

    Author Photo

    As a two-time boomerang partner, returning to BigLaw after stints as a U.S. attorney and the director of the Bureau of Alcohol, Tobacco, Firearms and Explosives, people ask me how I know when to move on, but there’s no single answer — just clearly set your priorities, says Steven Dettelbach at BakerHostetler.

  • New DOJ Penalty Policy Could Spell Trouble For Cos.

    Author Photo

    In light of the U.S. Department of Justice’s recently published guidance making victim relief a core condition of coordinated resolution crediting, companies facing parallel investigations must carefully calibrate their negotiation strategies to minimize the risk of duplicative penalties, say attorneys at Debevoise.

  • 5 Consumer Protection Compliance Issues In NY State Budget

    Author Photo

    Companies that engage with New York consumers should promptly familiarize themselves with new state budget provisions that require finance and retail companies to make certain business practices more transparent and easier for customers to execute, say attorneys at Mintz.

  • Balancing The Promises And Perils Of Tokenizing Securities

    Author Photo

    Tokenizing listed securities offers the promise of greater efficiency, accessibility and innovation, but a recent U.S. Securities and Exchange Commission statement makes clear that the federal securities laws continue to apply to tokenized securities, so financial institutions and technology developers must work together to create clear rules, say attorneys at Orrick.

  • High Court Cert Spotlights Varying Tests For Federal Removal

    Author Photo

    A recent decision by the U.S. Supreme Court to review Chevron v. Plaquemines Parish, a case involving the federal officer removal statute, highlights three other recent circuit court decisions raising federal removal questions, and serves as a reminder that defendants are the masters of removal actions, says Varun Aery at Hollingsworth.

  • How Cos. In China Can Tailor Compliance Amid FCPA Shifts

    Author Photo

    The U.S. Department of Justice’s recently updated Foreign Corrupt Practices Act enforcement guidelines create a fluid business environment for companies operating in China that will require a customized compliance approach to navigate both countries’ corporate and legal systems, say attorneys at Dickinson Wright.

  • Open Banking Is On Ice As CFPB Seeks To Toss Its Own Rule

    Author Photo

    Even as the Consumer Financial Protection Bureau's efforts to toss its open banking rule play out in Kentucky federal court, it remains statutorily required to effectuate consumer access to data, raising questions about how it would replace the previously finalized standard, say attorneys at Cooley.

  • Series

    Playing Baseball Makes Me A Better Lawyer

    Author Photo

    Playing baseball in college, and now Wiffle ball in a local league, has taught me that teamwork, mental endurance and emotional intelligence are not only important to success in the sport, but also to success as a trial attorney, says Kevan Dorsey at Swift Currie.

  • How US Cos. Should Prep For Brazil's Int'l Data Transfer Rules

    Author Photo

    Brazil's National Data Protection Authority's new rules concerning the processing and storing of Brazilians' personal data carry significant reputational risks for the e-commerce, financial services, education and health sectors, so U.S. companies with business in Brazil should prepare ahead of the Aug. 23 compliance date, says Juliane Chaves Ferreira at Guimarães & Vieira de Mello.

Want to publish in Law360?


Submit an idea

Have a news tip?


Contact us here
Can't find the article you're looking for? Click here to search the Cybersecurity & Privacy archive.