I have very fond memories of using a Eurail pass back in the day while backpacking through Europe as a student. I was saddened to see that Eurail was the victim of a data breach in December 2025 when attackers obtained access to travelers’ full names and contact information, including email addresses, passport details, ID
CNN Must Defend Privacy Suit Alleging Data Sharing with Microsoft and Adtech Firms
A federal judge has ruled that CNN must face a proposed class action alleging that its website shared consumers’ personal information with Microsoft and adtech firms without consent, in alleged violation of the California Invasion of Privacy Act (CIPA). The lawsuit challenges CNN’s alleged use of online tracking tools and the downstream sharing of data in the digital advertising ecosystem.
According…
Click to Join, Hard to Leave: FTC Reopens Negative Option Rulemaking
On March 11, 2026, the Federal Trade Commission (FTC) announced an Advance Notice of Proposed Rulemaking (ANPRM) highlighting its Rule Concerning the Use of Prenotification Negative Option Plans, seeking comment on whether the rule should be amended or supplemented to better address deceptive or unfair negative option practices.
The FTC describes negative options as marketing…
Social Engineering Schemes Target C-Suite Executives
March was a busy month for former Black Basta affiliates who are using old social engineering techniques to target executives in the manufacturing, professional, scientific, and technical services industries. According to Reliaquest, the activity of the threat actors indicates that these sectors “were likely direct targets.”
According to its report, “Attackers are using automation…
DOJ Announces First False Claims Act Settlement for “Illegal DEI Practices”
This post was co-authored by Government Enforcement + White-Collar Defense Team lawyers Seth B. Orkand and Danielle H. Tangorre and Litigation group lawyer Mallori D. Thompson. This post was originally published as a Legal Update.
On April 10, 2026, the Department of Justice (DOJ) announced a nearly $17.1 million settlement with IBM to…
Privacy Tip #486 – “Stolen Credentials Are a Major Threat”
According to Security Week’s recent article, “Stolen Logins Are Fueling Everything from Ransomware to Nation-State Cyberattacks,” cybersecurity firm Ontinue’s 2H 2025 Threat Intelligence Report, showcases that “Attackers aren’t breaking in anymore, they’re logging in.”
According to Ontinue’s Report, in the second half of 2025, “identity became the primary attack surface.” This means…
Vetting AI for Government: California’s Executive Order Sets New Expectations
California Governor Gavin Newsom issued a new executive order aimed at tightening California’s procurement rules for artificial intelligence (AI) vendors and “raising the bar” for companies that want to sell AI tools to the state. The administration says the goal is to ensure contractors meet strong standards and can demonstrate responsible policies that prevent misuse,…
Not Every Wiretap Claim Belongs in Federal Court: Federal Court Sends Pennsylvania Case Back to State Court
While California’s wiretapping statute, the California Invasion of Privacy Act (CIPA), tends to dominate the conversation about the recent rise in wiretapping litigation, plaintiffs are also turning to other states’ wiretapping laws to target web tracking and session-replay tools. The U.S. Court of Appeals for the Third Circuit recently held that a website visitor could…
Winona County Victim of Cyber Attack
Minnesota Governor Tim Walz issued an emergency executive order on April 7, 2026, dispatching the Minnesota National Guard after Winona County requested assistance following a cyber attack disrupting its “critical systems and digital services.” The attack occurred on April 6, 2026, and is “significantly impairing the county’s ability to deliver vital emergency and municipal services.”…
Water Treatment Facility Downed with Ransomware Attack
Critical infrastructure operators at the water treatment plant in Minot, North Dakota, were forced to resort to manual processes when its Supervisory Control and Data Acquisition (SCADA) system became inoperable as a result of a March 14, 2026, ransomware attack. The attackers are unidentified, but it comes in the wake of the war in Iran,…