← Carolina Clear Tech

Legal & Privacy Brief

2026-03-02

Listen to this brief (20:10)

Download MP3
Show Notes

Show Notes - 2026-03-02

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - March 2, 2026

Today: Kenvue (Neutrogena's parent) agreed to a $4.7 million settlement under Illinois's Biometric Information Privacy Act for collecting facial geometry through its Skin360 app without proper consent, requiring destruction of all collected biometric images. The Pentagon designated AI company Anthropic as a supply chain risk after the company set limits on autonomous lethal decision-making and domestic mass surveillance, creating immediate compliance exposure for federal contractors using Anthropic products. The University of Hawaii Cancer Center confirmed that a 2025 ransomware attack leaked data on 1.2 million individuals, including Social Security numbers sourced from state transportation and voter registration records.


Enforcement Actions

Neutrogena Skin360 BIPA Settlement - Melzer, et al. v. Johnson & Johnson Consumer Inc. (Case No. 3:22-cv-03149, D.N.J.)

Kenvue Inc., formerly Johnson & Johnson Consumer Inc., agreed to a $4.7 million settlement resolving class action claims that its Neutrogena Skin360 app collected users' facial geometry without proper consent under the Illinois Biometric Information Privacy Act (BIPA), 740 ILCS 14/1 et seq. The settlement covers approximately 11,000 Illinois users who used the Skin360 skin assessment tool between December 2019 and May 2023, with individual payments estimated at $427 per class member. A federal judge denied Kenvue's motion to dismiss after the company failed to establish that a statutory BIPA exemption applied; Kenvue had argued that a third party developed the underlying technology and that a disclaimer added to the Skin360 website in 2023 was sufficient. Settlement terms require Kenvue to destroy all images collected through the Skin360 tool during the class period, in addition to the $4.7 million cash fund.

Eureka Casino Data Breach Settlement - In re: Eureka Casino Breach Litigation (Case No. 2:23-cv-00276-CDS-NJK, D. Nev.)

Eureka Casino agreed to a $1 million class action settlement for a data breach between November 9 and 13, 2022, that compromised names, Social Security numbers, financial account numbers, passport numbers, and driver's license numbers. Plaintiffs alleged the casino failed to implement reasonable cybersecurity measures and violated Nevada's data breach notification statutes. Class members can receive up to $5,000 for documented losses, with California residents eligible for an additional $100 statutory cash payment. Claim deadline is May 11, 2026; the final approval hearing is scheduled for June 10, 2026.

German Conviction - Milton Group Investment Fraud Network

The Bamberg Regional Court in Bavaria sentenced Mikheil Biniashvili to seven and a half years in prison for operating the Milton Group, a call-center fraud network that caused EUR 8 million ($9.4 million) in losses to victims primarily in German-speaking countries between 2017 and 2019. After leaving daily operations, Biniashvili continued selling his PumaTS customer management and trading platform to other criminal groups, which prosecutors attributed to an additional EUR 42 million ($49 million) in damages from copycat fraud operations. The court ordered confiscation of EUR 2.4 million ($2.8 million) in proceeds. Biniashvili was extradited from Armenia in 2024; the verdict is not yet final.


Litigation Updates

Betterment Dual Data Breach Class Actions - Tsou v. Betterment LLC, et al. (Case No. 1:26-cv-00444) and Huff, et al. v. Betterment (Case No. 1:26-cv-00364, S.D.N.Y.)

Two separate class action lawsuits were filed in January 2026 in the Southern District of New York against Betterment, a fintech company, following a January 9, 2026 breach. Attackers obtained access credentials through social engineering, used those credentials to access customer PII (names, email addresses, physical addresses, phone numbers, and dates of birth), and then exploited Betterment's own approved marketing and communication channels to send fraudulent sales solicitations to customers. A subsequent DDoS attack disrupted Betterment's website and app on January 13, 2026. Plaintiffs allege negligence, invasion of privacy, and breach of fiduciary duty.

Bumble Data Breach Class Action - Omirin v. Bumble Inc. (Case No. 1:26-cv-00398, W.D. Tex.)

A class action filed in the Western District of Texas alleges Bumble failed to implement adequate security measures to protect customer PII during a January 2026 breach. Plaintiff claims Bumble failed to follow required protocols for data encryption and did not properly secure servers. Claims include negligence, breach of implied contract, breach of the implied covenant of good faith and fair dealing, unjust enrichment, and violations of the Texas Deceptive Trade Practices Act. The plaintiff seeks declaratory and injunctive relief plus damages for a nationwide class and Texas subclass.

University of Hawaii Cancer Center Ransomware Breach - 1.2 Million Individuals Affected

The University of Hawaii Cancer Center disclosed that a ransomware attack discovered August 31, 2025, resulted in data exposure for approximately 1.2 million individuals. The breach affected epidemiology research servers containing Social Security numbers and driver's license numbers sourced from the Hawaii State Department of Transportation and City and County of Honolulu voter registration records dating back to 1998. Approximately 87,493 research study participants had data directly exfiltrated; the broader 1.15 million figure stems from historical government records retained on research infrastructure. The university paid a ransom and obtained an affirmation from the attackers that data was destroyed, though no independent verification of destruction was reported. The threat actor has not been publicly identified.

Joybird False Advertising Class Action - German, et al. v. Stitch Industries Inc. (Case No. 2:26-cv-01820, C.D. Cal.)

Three consumers filed a class action in the Central District of California alleging Joybird perpetually advertises 30-50% discounts taken from inflated reference prices that do not reflect any genuine regular price. Plaintiffs allege violations of California's Consumers Legal Remedies Act, False Advertising Law, and Unfair Competition Law. Joybird previously settled a related case for $7.15 million covering California, Oregon, and Washington consumers; this new action targets purchasers in other states.

Hunter v. United States - SCOTUS on Appellate Waiver Scope (Argument: March 3, 2026)

The Supreme Court is scheduled to hear oral argument March 3 in Hunter v. United States, addressing how broadly federal defendants can waive their right to appeal as part of a plea agreement and whether a district court's post-sentencing statement that a defendant "has a right to appeal" can override a previously executed appellate waiver. The 5th Circuit enforced the waiver and ruled the court's statement did not nullify it. The outcome will affect how prosecutors structure plea agreements and the enforceability of broad waiver language going forward.


Policy Changes

Pentagon Designates Anthropic as "Supply Chain Risk"

Defense Secretary Pete Hegseth designated Anthropic a "supply chain risk," effectively prohibiting entities with U.S. military contracts from maintaining commercial relationships with the company. The designation followed Anthropic's position that its AI should not make autonomous lethal decisions without human oversight and should not be used for domestic mass surveillance of U.S. citizens. This is the first known supply chain risk designation against a domestic AI company based on ethical use restrictions rather than foreign government ties or documented security vulnerabilities. Lawfare Research Director Alan Rozenshtein published legal analysis of the Defense Production Act questions raised by the designation; his analysis was cited in over 40 major outlets including CNN, Bloomberg, and the Financial Times.

UK NCSC Heightened Cyber Alert Following Middle East Strikes

The UK National Cyber Security Centre issued an advisory following U.S. and Israeli strikes on Iran that killed Supreme Leader Ayatollah Ali Khamenei. The NCSC assessed "likely no current significant change in the direct cyber threat from Iran to the UK" but warned of "a heightened risk of indirect cyber threat" for organizations with assets or supply chains in the Middle East. A suspected Iranian drone struck the RAF base in Cyprus; others were intercepted. The alert advised all organizations to review security guidance and directed critical national infrastructure operators to prepare for severe cyber threats.


Privacy Developments

LLM-Assisted De-anonymization at Scale

Published research demonstrates that LLM agents can identify individuals from anonymous online posts across Hacker News, Reddit, LinkedIn, and anonymized interview transcripts with high precision and at scale across tens of thousands of candidates. The research confirms that combining multiple contextual data points from posts enables identification even when no single attribute is uniquely identifying, undermining the practical assumptions underlying most current anonymization methods.

Prosper Data Breach - 17 Million Affected, Mass Arbitration Underway

Prosper, a peer-to-peer lending platform, confirmed a September 2025 cyberattack potentially affecting more than 17 million clients and applicants. The exposed database included Social Security numbers, government identification numbers, bank account numbers, tax information, passport numbers, and dates of birth. Prosper states customer accounts themselves were not accessed, but the underlying PII exposure is broad. A mass arbitration investigation is underway.

ECPA 40th Anniversary Event - March 6, 2026 (Free, Georgetown Law)

Georgetown Law's Institute for Technology Law & Policy and Center on Privacy & Technology are co-hosting a free half-day event March 6 marking the 40th anniversary of the Electronic Communications Privacy Act. Speakers include Susan Landau, Michael Dreeben, David Kris, Jennifer Daskal, and other privacy academics and former DOJ officials. The event is timely given ongoing executive branch and legislative pressure on electronic surveillance frameworks.


Compliance Takeaways