Cybersecurity & Privacy

  • November 07, 2025

    Financial Advising Firms Face Class Action Over Data Breach

    Two financial advising companies are facing a proposed class action in Colorado state court that alleges the firms failed to take steps to prevent a data breach that compromised customers' private information, including names and Social Security numbers.

  • November 07, 2025

    Seattle Pot Shop Slapped With Site Tracking Pixel Privacy Suit

    A Seattle cannabis dispensary has been hit with a proposed class action in Washington federal court by a customer who claims the retailer shared his private information about medical marijuana appointments and pot purchases with Google and other third parties by using online browser tracking tools on its website.

  • November 07, 2025

    Texas AG Defends App Store Law Against Free Speech Claims

    Texas Attorney General Ken Paxton has pushed back on efforts to block the state's new App Store Accountability Act, telling a federal court that the measure's parental-consent and age-verification rules don't restrict speech but simply help parents oversee what apps their kids can download.

  • November 06, 2025

    Retailer Can't Force Arbitration Of False Pricing Class Claims

    A California federal judge Thursday rejected a bid by women's fashion brand Maggy London to arbitrate a proposed class action accusing it of advertising "phantom" price discounts on products sold on its website, finding that merely providing a link to the arbitration terms during the checkout process wasn't enough to form a binding agreement. 

  • November 06, 2025

    NetChoice Gets Judge To Halt Colo. Social Media Warning Law

    A Colorado federal judge Thursday temporarily blocked a state law that would require social media platforms to provide social media health warnings to minors, saying the law likely didn't meet the highest standard of review for First Amendment challenges.

  • November 06, 2025

    Conduent Pummeled With Suits Over Monthslong Data Breach

    Conduent Business Services LLC has been hit with a barrage of class action lawsuits in New Jersey federal court alleging it failed to adequately protect sensitive personal and health information of more than 10.5 million individuals that were compromised in a major data breach.

  • November 06, 2025

    Atty Ordered Detained After Harassment Of BigLaw Attys

    A Texas federal judge on Thursday ordered U.S. marshals to put an attorney accused of cyberstalking other attorneys at BigLaw firms in jail until trial, saying the attorney has continued to make harassing online posts while on pretrial release and didn't attend mandatory mental health treatment.

  • November 06, 2025

    Debt Collectors Sue Over Colo.'s Medical Debt Reporting Ban

    A major debt collection trade group sued to block a Colorado law banning medical debt from credit reports, arguing it conflicts with a federal law that the Consumer Financial Protection Bureau recently said doesn't let states regulate credit report content.

  • November 06, 2025

    UMich 'Did Nothing' To Stop Ex-Coach Hacking, Students Say

    Student-athletes who had their personal accounts hacked by a former University of Michigan assistant football coach have said the university and athletic leadership are not immune from Title IX claims, arguing that the school knew about the coach's behavior and still allowed him to coach in a playoff game.

  • November 06, 2025

    Pa. Statehouse Catchup: Cannabis Quality, 'Deepfake' Fines

    Even as the Pennsylvania General Assembly has struggled to agree to a state budget since the summer deadline passed, legislators have introduced and advanced bills dealing with perennial topics like cannabis legalization or responding to newer concerns like AI-fueled fraud.

  • November 06, 2025

    Education Tech Co. Inks $5.1M Data Breach Deal With 3 AGs

    Technology company Illuminate Education Inc. will pay a total of $5.1 million to California, Connecticut and New York and strengthen its data security efforts after a breach in late 2021 and early 2022 exposed the information of millions of students to online hackers, the attorneys general of the three states announced Thursday.

  • November 06, 2025

    Social Media Apps Must Face Jury After Section 230 Loss

    A California state judge refused Wednesday to grant social media companies summary judgment on claims their platforms harm young users' mental health, again rejecting arguments that Section 230 of the Communications Decency Act shields them from liability, and sent three cases to bellwether trials, with the first to begin Jan. 27.

  • November 06, 2025

    CFPB Frees TransUnion From Biden-Era Enforcement Order

    The Consumer Financial Protection Bureau has freed TransUnion LLC from compliance monitoring and reporting provisions in a deal stemming from allegations the credit reporting bureau took years to place requested security freezes for consumers, according to a recent filing.

  • November 06, 2025

    Apple Denies Blame For Gift Card Scammers' Actions

    Apple told a California federal judge a proposed class action accusing it of selling gift cards that scammers can drain before customers get a chance to use them doesn't identify any design flaw or deceptive statement that would make the tech giant liable for criminals' conduct.

  • November 06, 2025

    Health Cos. Sent Google Private Patient Data, Suit Says

    A group of Georgia healthcare facilities has been hit with a proposed class action in federal court accusing the providers of disclosing patients' confidential health information to Google without consent through website tracking and data collection tools.

  • November 06, 2025

    Calif. Judge OKs $1.3M Deal Over Houser LLP Data Breach

    A California federal judge on Oct. 31 signed off on final approval of a $1.3 million settlement and $351,000 in attorney fees in a class action against business litigation firm Houser LLP over a 2023 data breach.

  • November 06, 2025

    Samourai Wallet Exec Gets 5 Years In Crypto Laundering Case

    A Manhattan federal judge sentenced the CEO of crypto mixer Samourai Wallet to five years in prison Thursday after he admitted that his business facilitated big-dollar transfers derived from criminal activity including narcotics trafficking and extortion.

  • November 05, 2025

    DOJ Clears Google's $32B Deal To Buy Cybersecurity Co. Wiz

    Google's plan to acquire Wiz for $32 billion and integrate the growing cloud security platform into Google Cloud has cleared the U.S. Department of Justice's antitrust review, the tech giant confirmed Wednesday.

  • November 05, 2025

    4 Firms Fueling Website Tracking Claims, Cyber Insurer Says

    A quartet of California-headquartered consumer law firms were behind nearly three-quarters of the website tracking and data privacy claims that both large and small businesses have reported to cyber insurer Coalition Inc. in recent years, according to a new report released Wednesday. 

  • November 05, 2025

    Paramount Hit With Privacy Class Action Over Children's Data

    Paramount Skydance Corp. illegally disclosed to Google and Microsoft the personally identifiable information of children who viewed streaming content on their families' personal electronic devices, the kids' parents have claimed in a proposed class action in California federal court.

  • November 05, 2025

    Microsoft Wants To Weigh In On Google Search Fixes, Too

    Microsoft is urging a D.C. federal court to make sure that the limits imposed on Google in the U.S. Department of Justice's search monopolization case prevent the search giant from inking multiyear default agreements and that they reach new types of generative artificial intelligence products.

  • November 05, 2025

    Mamdani Taps Ex-FTC Chief Lina Khan For NYC Transition

    New York City Mayor-elect Zohran Mamdani on Wednesday named an all-woman transition team, including former Federal Trade Commission Chair Lina Khan, who attracted the ire of tech giants and corporations by spearheading the Biden administration's aggressive antitrust enforcement.

  • November 05, 2025

    Jones Day Hires Ex-Coinbase Associate GC In San Diego

    Jones Day has added to its San Diego cybersecurity practice a former member of Coinbase's commercial litigation team, the firm announced.

  • November 05, 2025

    11th Circ. Says Not Feds' Fault If $345M Crypto Key Was Lost

    The Eleventh Circuit has ruled that a man convicted of identity theft cannot sue the government for $345 million he claims he lost because federal investigators wiped a hard drive containing access codes to several thousand bitcoins, noting the man didn't tell investigators about the cryptocurrency.

  • November 05, 2025

    Docs Show IRS Improperly Shared Data With ICE, Groups Say

    Documents submitted by the U.S. government to a D.C. federal court show the IRS violated taxpayer privacy laws by sharing individuals' addresses with ICE despite its requests lacking required information and by accepting an unreasonable explanation about why the information was requested, several groups said.

Expert Analysis

  • Series

    Law School's Missed Lessons: Educating Your Community

    Author Photo

    Nearly two decades prosecuting scammers and elder fraud taught me that proactively educating the public about the risks they face and the rights they possess is essential to building trust within our communities, empowering otherwise vulnerable citizens and preventing wrongdoers from gaining a foothold, says Roger Handberg at GrayRobinson.

  • Strategies For Merchants As Payment Processing Costs Rise

    Author Photo

    As current economic pressures and rising card processing costs threaten to decrease margins for businesses, retail merchants should consider restructuring how payments are made and who processes them within the evolving legal framework, says Tom Witherspoon at Stinson.

  • Shifting Crypto Landscape Complicates Tornado Cash Verdict

    Author Photo

    Amid shifts in the decentralized finance regulatory landscape, the mixed verdict in the prosecution of Tornado Cash’s founder may represent the high-water mark in a cryptocurrency enforcement strategy from which the U.S. Department of Justice has begun to retreat, say attorneys at Venable.

  • 5 Crisis Lawyering Skills For An Age Of Uncertainty

    Author Photo

    As attorneys increasingly face unprecedented and pervasive situations — from prosecutions of law enforcement officials to executive orders targeting law firms — they must develop several essential competencies of effective crisis lawyering, says Ray Brescia at Albany Law School.

  • Compliance Tips Amid Rising FTC Scrutiny Of Minors' Privacy

    Author Photo

    The Federal Trade Commission has recently rolled out multiple enforcement actions related to children's privacy, highlighting a renewed focus on federal regulation of minors' personal information and the evolving challenges of establishing effective, privacy-protective age assurance solutions, say attorneys at Nelson Mullins.

  • Opinion

    It's Time For The Judiciary To Fix Its Cybersecurity Problem

    Author Photo

    After recent reports that hackers have once again infiltrated federal courts’ electronic case management systems, the judiciary should strengthen its cybersecurity practices in line with executive branch standards, outlining clear roles and responsibilities for execution, says Ilona Cohen at HackerOne.

  • Prepping For Website Automatic Opt-Out Signal Mandates

    Author Photo

    Maryland's Online Data Privacy Act, which, along with a growing number of U.S. states, requires businesses to offer mechanisms in their privacy policies or online interfaces to allow individuals to opt out of data collection, marks a new frontier in consumer privacy, raising both technical and legal risks, say attorneys at Baker Donelson.

  • Tips For Cos. Crafting Enforceable Online Arbitration Clauses

    Author Photo

    Recent rulings from the Ninth Circuit and the U.S. District Court for the Southern District of California indicate that courts are carefully examining the enforceability of online arbitration clauses, so businesses should review the design of their websites and consider specific language next to the "purchase" button, say attorneys at DTO Law.

  • 7 Lessons From The Tractor Supply CCPA Enforcement Action

    Author Photo

    The California Privacy Protection Agency's recent enforcement action targeting Tractor Supply for alleged violations of the California Consumer Privacy Act provides critical insights into the compliance areas that remain a priority for the California regulator, including businesses with significant consumer interactions, say attorneys at Troutman.

  • Series

    Writing Novels Makes Me A Better Lawyer

    Author Photo

    Writing my debut novel taught me to appreciate the value of critique and to never give up, no matter how long or tedious the journey, providing me with valuable skills that I now emphasize in my practice, says Daniel Buzzetta at BakerHostetler.

  • SDNY OpenAI Order Clarifies Preservation Standards For AI

    Author Photo

    The Southern District of New York’s recent order in the OpenAI copyright infringement litigation, denying discovery of The New York Times' artificial intelligence technology use, clarifies that traditional preservation benchmarks apply to AI content, relieving organizations from using a “keep everything” approach, says Philip Favro at Favro Law.

  • Addressing Legal Risks Of AI In The Homebuilding Industry

    Author Photo

    Artificial intelligence is transforming the homebuilding industry, but the legal challenges posed by its adoption spread across many areas, including contractual liability and intellectual property issues, so builders should adopt strategies to mitigate the risks and position themselves for success, says Philip Stein at Bilzin Sumberg.

  • Cybersecurity Rule For DOD Contractors Creates New Risks

    Author Photo

    A rule locking in the Cybersecurity Maturity Model Certification system for defense contractors increases False Claims Act and criminal enforcement risks by narrowing a key exemption and mandating affirmations of past compliance, which may discourage new companies from entering the defense contracting market, say attorneys at Haynes Boone.

  • Compliance Steps To Take As FCRA Enforcement Widens

    Author Photo

    As the Fair Credit Reporting Act receives renewed focus from both federal and state enforcers, regulatory and litigation risk is most acute in several core areas, which companies can address by implementing purpose processes and quick remediation of consumer complaints, among other steps, say attorneys at Wiley.

  • Assessing The Future Of The HIPAA Reproductive Health Rule

    Author Photo

    In light of a Texas federal court's recent decision to strike down a U.S. Department of Health and Human Services rule aimed to protect the privacy of patients seeking abortions and gender-affirming care, entities are at least temporarily relieved from compliance obligations, but tensions are likely to continue for the foreseeable future, says Liz Heddleston at Woods Rogers.

Want to publish in Law360?


Submit an idea

Have a news tip?


Contact us here
Can't find the article you're looking for? Click here to search the Cybersecurity & Privacy archive.