Cybersecurity & Privacy

  • March 24, 2026

    Fiserv, Credit Union Settle Payment Data Security Lawsuit

    Fiserv Solutions LLC and Cencap Federal Credit Union have "tentatively settled" a Connecticut federal lawsuit accusing the payment processor and fintech provider of operating an online banking platform that contained security flaws.

  • March 24, 2026

    Meta Owes $375M In NM Trial Over Harm To Teens

    A New Mexico jury said Tuesday that Meta must pay $375 million over the state attorney general's bellwether claims that the social media giant hid the full scope of mental health harm its apps were causing to underage users.

  • March 24, 2026

    AGs Seek Federal Help To Tackle Chinese App Drug Trade

    North Carolina Attorney General Jeff Jackson announced Monday that he's leading a bipartisan group of state enforcers in asking the federal government to act on drug traffickers' co-opting of Chinese-owned messaging app WeChat and its sister app Weixin to propagate the illegal drug trade. 

  • March 23, 2026

    Meta Ends WhatsApp Security Head's Retaliation Suit For Now

    A California federal judge dismissed, for now, a retaliation claim by a former Meta employee who claimed he was fired after reporting cybersecurity shortfalls concerning WhatsApp, finding the plaintiff's complaints aren't protected under the Sarbanes-Oxley Act since his cybersecurity violation reports don't relate to internal accounting controls.

  • March 23, 2026

    Anthropic Says DOD Security Risk Label Is Unconstitutional

    Anthropic PBC has doubled down on its push for an order blocking the Trump administration from labeling it a supply chain risk to national security, telling a California federal court the executive branch was punishing "a major company for the sin of expressing its views on a matter of profound public significance."

  • March 23, 2026

    SEC Must Give Video Of Elon Musk Interview To Oscar Winner

    The U.S. Securities and Exchange Commission must release a video interview of Elon Musk from its civil fraud investigation of the billionaire to a film company led by Oscar-winner Alex Gibney, a D.C. federal judge ruled Monday, saying the SEC already has publicized the interview's contents through a transcript.

  • March 23, 2026

    Social Media Jurors Say They Are Deadlocked On A Defendant

    A California jury considering claims Meta and Google harm children's mental health through their social media platforms reported Monday that it is deadlocked as to one of the defendants, but it wasn't clear if the jury is stuck on the question of liability or on potential punitive damages.

  • March 23, 2026

    FCC Urges Justices To Reject Repeal Of Penalty Power

    The Federal Communications Commission has urged the U.S. Supreme Court to keep the agency's monetary penalty powers intact, saying the agency's current practice does not deny targets of fines their right to a jury trial and is not binding until a court orders payment.

  • March 23, 2026

    FCC Adds Foreign Routers To Nat'l Security Risk List

    The Federal Communications Commission on Monday added foreign-made routers to a list of consumer electronics gear that cannot be sold on the U.S. market without specific authorization.

  • March 23, 2026

    FINRA Fines Stash Capital For AML, Identity Theft Controls

    The Financial Industry Regulatory Authority fined digital investing platform operator Stash Capital $450,000 for allegedly failing to properly review applications and detect suspicious account activity during a period of sharp customer growth.

  • March 23, 2026

    Novartis Faces Class Suit Over Patient Health Info Disclosure

    Drugmaker Novartis collected patients' personal and health information through pharmaceutical marketing websites and transmitted it to third parties including Google using "surreptitious online tracking tools" without patients' consent, a proposed class action in New Jersey federal court alleges.

  • March 23, 2026

    Md. Judge Rules Written Consent Not Needed Under TCPA

    Echoing a recent Fifth Circuit ruling, a Maryland federal judge has held that written consent to receive telemarketing calls is not required under the Telephone Consumer Protection Act, reversing a decision to certify a class of consumers against a dental plan marketer.

  • March 23, 2026

    Pediatric Data Breach Class Action Can Stay In NC Biz Court

    A consolidated class action alleging a pediatric medical practice failed to protect minor patients' data from hackers can remain in the North Carolina Business Court, a judge ruled in finding the lawsuits were properly designated to the state's specialized superior court for complex business matters.

  • March 23, 2026

    New Wash. Law Cuts Antispam Penalties Amid Multiple Suits

    Statutory penalties for emails sent in violation of Washington state's Commercial Electronic Mail Act, which bars messages with false or misleading subject lines, will fall from $500 per email to $100 under a measure signed into law by Gov. Bob Ferguson on Monday.

  • March 23, 2026

    Duke Health's $3.7M Pixel Privacy Deal Gets Initial OK

    Hundreds of thousands of Duke University Health System Inc. patients are one step closer to securing a share of a $3.7 million settlement stemming from a health data tracking suit involving Meta's Pixel, after a North Carolina federal court granted preliminary approval of the class action settlement.

  • March 23, 2026

    Ex-White Sox Star Thomas Sues Team, Nike Over Jersey Sales

    Former Chicago White Sox player Frank Thomas has sued his ex-team, Nike and Fanatics in Illinois state court, claiming they unlawfully sold jerseys bearing his name and number without his consent and without compensating him in any way.

  • March 23, 2026

    AbbVie Escapes Ill. Genetic Privacy Lawsuit

    An Illinois federal judge on Friday granted AbbVie summary judgment in a lawsuit claiming it violated the state's genetic privacy law, saying there was "no genuine dispute" that AbbVie never conditioned the plaintiff's employment on whether he disclosed genetic information in the physical exam he was required to undergo before starting work.

  • March 23, 2026

    Social Media Atty Sanctioned For 'Most Shameful Moment'

    A California judge on Monday sanctioned an attorney for the plaintiff in a bellwether trial alleging Meta Platforms and Google's social media platforms harm children's mental health, fining him $1,100 and keeping him off the plaintiffs' steering committee for violating court rules by twice filming inside the courthouse.

  • March 23, 2026

    Research Org. Seeks $530K In Fees After DOD Cap Ruling

    The Association of American Universities has asked a Massachusetts federal court for $530,000 in attorney fees after a judge ruled that the U.S. Department of Defense unlawfully capped the reimbursement for the institution's indirect research costs.

  • March 23, 2026

    Justices Reject Case Alleging Google-Apple Search Pact

    The U.S. Supreme Court refused Monday to review rulings from a California federal judge and the Ninth Circuit dismissing a lawsuit accusing Google of anticompetitively paying Apple not to produce its own search engine.

  • March 23, 2026

    Justices Won't Hear Fight Over 2020 Election Voting Machines

    The U.S. Supreme Court said Monday that it won't decide if two Pennsylvania county leaders had standing to sue Dominion Voting Systems over allegations that voting machines used during the 2020 election weren't secure.

  • March 20, 2026

    5th Circ. Wipes Out FTC's TurboTax 'Deceptive' Ad Ruling

    The Fifth Circuit on Friday vacated the Federal Trade Commission's cease-and-desist order imposed on Intuit Inc. for its TurboTax advertising that regulators say duped customers into thinking they could file their tax returns for free, saying the agency's in-house decision is unconstitutional, and the dispute must go to federal court.

  • March 20, 2026

    PowerSchool, Bain Can't Skirt MDL Over Student Data Breach

    A California federal judge has refused to toss multidistrict litigation seeking to hold PowerSchool and its majority stakeholder Bain Capital liable for a data breach that exposed roughly 50 million individuals' personal data, finding that Bain's involvement in the education technology provider's cybersecurity operations "went beyond what an ordinary investor would do."

  • March 20, 2026

    Feds Rip Ex-NFL Player's New Trial Bid Over Medicare Scheme

    The federal government opposed a new trial bid by Keith Gray, a former NFL player and Texas laboratory owner convicted in a $328 million scheme involving billing for unnecessary cardiovascular genetic testing for Medicare beneficiaries, arguing Thursday he lacks any valid basis to "disturb the jury's sound verdict."

  • March 20, 2026

    Jury Finds Tech Co. Data Analyst Guilty Of Extortion Scheme

    A data analyst contracted to work for a Washington, D.C.-based technology company was hit with a federal jury verdict finding him guilty of conducting a cyber extortion scheme that threatened to disclose employees and executives' personal information if they didn't pay him $2.5 million.

Expert Analysis

  • Cybersecurity Rule For DOD Contractors Creates New Risks

    Author Photo

    A rule locking in the Cybersecurity Maturity Model Certification system for defense contractors increases False Claims Act and criminal enforcement risks by narrowing a key exemption and mandating affirmations of past compliance, which may discourage new companies from entering the defense contracting market, say attorneys at Haynes Boone.

  • Compliance Steps To Take As FCRA Enforcement Widens

    Author Photo

    As the Fair Credit Reporting Act receives renewed focus from both federal and state enforcers, regulatory and litigation risk is most acute in several core areas, which companies can address by implementing purpose processes and quick remediation of consumer complaints, among other steps, say attorneys at Wiley.

  • Assessing The Future Of The HIPAA Reproductive Health Rule

    Author Photo

    In light of a Texas federal court's recent decision to strike down a U.S. Department of Health and Human Services rule aimed to protect the privacy of patients seeking abortions and gender-affirming care, entities are at least temporarily relieved from compliance obligations, but tensions are likely to continue for the foreseeable future, says Liz Heddleston at Woods Rogers.

  • Opinion

    Expert Reports Can't Replace Facts In Securities Fraud Cases

    Author Photo

    The Ninth Circuit's 2023 decision in Nvidia v. Ohman Fonder — and the U.S. Supreme Court's punt on the case in 2024 — could invite the meritless securities litigation the Private Securities Litigation Reform Act was designed to prevent by substituting expert opinions for facts to substantiate complaint assertions, say attorneys at A&O Shearman.

  • Glimmers Of Clarity Appear Amid Open Banking Disarray

    Author Photo

    The Consumer Financial Protection Bureau's vacillation over data rights rules has created uncertainty, but a recent proposal is a strong signal that open banking regulations are here to stay, making now the ideal time for entities to take action to decrease compliance risk, says Adam Maarec at McGlinchey Stafford.

  • Opinion

    High Court, Not A Single Justice, Should Decide On Recusal

    Author Photo

    As public trust in the U.S. Supreme Court continues to decline, the court should adopt a collegial framework in which all justices decide questions of recusal together — a reform that respects both judicial independence and due process for litigants, say Michael Broyde at Emory University and Hayden Hall at the U.S. Bankruptcy Court for the District of Delaware.

  • FTC's Consumer Finance Pivot Brings Industry Pros And Cons

    Author Photo

    An active Federal Trade Commission against the backdrop of a leashed Consumer Financial Protection Bureau will be welcomed by most in the consumer finance industry, but the incremental expansion of the FTC's authority via enforcement actions remains a risk, say attorneys at Hudson Cook.

  • How A New BIS Rule Greatly Expands Export Restrictions

    Author Photo

    The newly effective affiliates rule from the U.S. Department of Commerce's Bureau of Industry and Security restricts exports to foreign companies that are 50% or more owned by entities listed on the BIS entity list and the military end-user list — a major shift in U.S. export control enforcement, say attorneys at Simpson Thacher.

  • 3 New Cyberinsurance Rulings Aid In Policy Interpretation

    Author Photo

    Although the cyberinsurance market has exploded, there is no standardized cyber language or form and only a few court decisions thus far interpreting cyberinsurance policy language, making these three recent rulings key for guiding policyholders, insurers and brokers, say attorneys at Haynes Boone.

  • Series

    Traveling Solo Makes Me A Better Lawyer

    Author Photo

    Traveling by myself has taught me to assess risk, understand tone and stay calm in high-pressure situations, which are not only useful life skills, but the foundation of how I support my clients, says Lacey Gutierrez at Group Five Legal.

  • New Health AI Guidance Features A Provider-Centric Approach

    Author Photo

    New guidance from the Joint Commission and Coalition for Health AI regarding the responsible use of artificial intelligence in healthcare deviates from preexisting guidance by recommending a comprehensive framework for using AI tools, focusing on healthcare provider organizations rather than on AI developers, say attorneys at Ropes & Gray.

  • NY Zelle Suit Highlights Fraud Risks Of Electronic Payments

    Author Photo

    The New York attorney general's recent action against Zelle's parent company, filed several months after the Consumer Financial Protection Bureau abandoned a similar suit, demonstrates the fraud risks that electronic payment platforms can present and the need for providers to carefully balance accessibility and consumer protection, say attorneys at Weiner Brodsky.

  • Series

    Law School's Missed Lessons: Client Service

    Author Photo

    Law school teaches you how to interpret the law, but it doesn't teach you some of the key ways to keeping clients satisfied, lessons that I've learned in the most unexpected of places: a book on how to be a butler, says Gregory Ramos at Armstrong Teasdale.

  • How Financial Cos. Can Prep As NYDFS Cyber Changes Loom

    Author Photo

    Financial institutions supervised by the New York State Department of Financial Services can prepare for two critical cybersecurity requirements relating to multifactor authentication and asset inventories, effective Nov. 1, by conducting gap analyses and allocating resources to high-risk assets, among other steps, say attorneys at Pillsbury.

  • Series

    Adapting To Private Practice: 3 Tips On Finding The Right Job

    Author Photo

    After 23 years as a state and federal prosecutor, when I contemplated moving to a law firm, practicing solo or going in-house, I found there's a critical first step — deep self-reflection on what you truly want to do and where your strengths lie, says Rachael Jones at McKool Smith.

Want to publish in Law360?


Submit an idea

Have a news tip?


Contact us here
Can't find the article you're looking for? Click here to search the Cybersecurity & Privacy archive.