Get tomorrow's brief in your inbox
Today: Spain's data protection authority fined Hyundai €2 million after a breach exposed data of over 1 million customers due to unpatched software vulnerabilities and lack of encryption. The FBI coordinated a 13-country operation to dismantle Leakbase, a cybercrime marketplace with 142,000 members trading stolen credentials. The FTC issued a policy statement declining to enforce COPPA against age verification technologies, despite acknowledging they collect children's personal data without parental consent in violation of the law.
AEPD (Spain) Fines Hyundai €2,000,000 for Data Breach (EXP202306835)
Spain's data protection authority fined Hyundai Motor España €2 million after a January 2023 data breach exposed personal information of 1,012,730 customers and potential customers. An attacker exploited an unpatched software vulnerability in a server managed by Hyundai's processor, Hyundai AutoEver Europe GmbH, and exfiltrated 5.4 GB of data including names, dates of birth, telephone numbers, email addresses, and vehicle identification numbers. The authority found Hyundai violated Article 5(1)(f) GDPR by failing to ensure appropriate security measures, specifically noting that security updates addressing the exploited vulnerability were available before the attack but had not been installed. The authority also cited the absence of encryption for the database containing personal information of over one million individuals as increasing risk to data subjects once the attacker gained access. Hyundai conducted a risk analysis only after the incident occurred, failing to assess risks proactively as required by GDPR.
FBI Dismantles Leakbase Cybercrime Forum in 13-Country Operation
The FBI and European law enforcement agencies executed Operation Leak, a coordinated takedown of Leakbase, a subscription-based cybercrime marketplace operating since 2021. The operation resulted in 13 arrests, 32 searches, 33 suspect interviews, and seizure of the forum's entire database across more than a dozen countries. Leakbase had grown to 142,000 registered members trading stolen credentials, personally identifiable information, and software exploits, with over 33,000 forum threads and 215,000 messages. The forum operated on a subscription model with premium access costing a few hundred dollars. Much of the compromised data was obtained through SQL injection attacks against unpatched web applications targeting government systems and U.S. businesses. The FBI's Salt Lake City field office led the multi-year investigation, which included shutting down hosting infrastructure from the Netherlands to Malaysia and seizing and redirecting the forum's domains to bureau-controlled servers.
Taiwan Indicts 62 Over Prince Group Cyber Scam Operations
Taipei prosecutors indicted 62 people and 13 companies for involvement in cyber scam operations organized by Prince Group throughout Asia. Prosecutors allege those associated with Prince Group laundered at least $339 million into Taiwan and used stolen funds to purchase 24 properties, 35 vehicles, and other assets totaling approximately $1.7 million. Taiwan seized about $174 million in cash and assets. Prince Group effectively controlled 250 offshore companies in 18 countries with 453 domestic and international financial accounts, creating fictitious transaction contracts between offshore companies to launder money through foreign exchange channels. Nine defendants were detained and face charges including organized crime, money laundering, and human trafficking violations. Prince Group ran hundreds of compounds in Cambodia where workers and trafficking victims were forced to conduct cyberscams stealing billions from victims in the U.S., Europe, and China. Founder Chen Zhi was previously indicted by U.S. prosecutors on money laundering charges and extradited to China after his arrest in Cambodia.
$3.85M Los Angeles Times Website Trackers Class Action Settlement (Mirmalek v. Los Angeles Times, Case No. 3:24-cv-01797-CRB)
The Los Angeles Times agreed to pay $3.85 million to resolve claims that it violated California's Invasion of Privacy Act (CIPA) by using trackers to collect information from website visitors without consent. The settlement benefits California residents who accessed the Los Angeles Times online via website or mobile app between January 31, 2023, and December 19, 2025. The plaintiff alleged the Los Angeles Times used three website trackers (TripleLift Tracker, GumGum Tracker, and Audiencerate Tracker) to collect information from website visitors without their consent. Class members can receive a pro rata cash payment, with exact amounts varying depending on the number of claims filed. The deadline for exclusion and objection is April 22, 2026. The final approval hearing is scheduled for June 26, 2026, in U.S. District Court for the Northern District of California. To receive a settlement payment, class members must submit a valid claim form by May 20, 2026.
Trump Administration Abandons Defense of Law Firm Sanctions
The Justice Department plans to abandon its appeals of four trial court rulings that struck down executive orders sanctioning Perkins Coie, Jenner & Block, WilmerHale, and Susman Godfrey for representing clients opposed to the Trump administration. An ideological mix of judges ruled against the administration, with Judge Richard Leon (appointed by President George W. Bush) stating that blocking the sanctions was necessary to preserve an "independent bar willing to tackle unpopular cases." Judge Beryl Howell (appointed by President Barack Obama) compared the administration's actions to Shakespeare's phrase "The first thing we do, let's kill all the lawyers." Nine large law firms, led by Paul Weiss, chose to cut deals with the administration rather than challenge the executive orders, promising nearly $1 billion in pro bono work for administration-favored causes. The firms that fought the sanctions in court achieved complete victory, with the executive orders now dead.
Supreme Court Sides with Government in Immigration Asylum Standard (Urias-Orellana v. Bondi)
The Supreme Court unanimously held that federal courts of appeals must use the deferential substantial-evidence standard when reviewing Board of Immigration Appeals determinations that asylum seekers did not experience persecution qualifying for asylum protections. Justice Ketanji Brown Jackson wrote that reversal of the BIA's decision is warranted only "if, in reviewing the record as a whole, any reasonable adjudicator would be compelled to conclude to the contrary." The case involved Douglas Humberto Urias-Orellana and his family, who fled El Salvador after facing threats from a hit man. An immigration judge ruled their experiences did not meet the persecution threshold because they had successfully avoided danger by relocating within El Salvador. The Court resolved a disagreement between federal circuits over the appropriate standard of review, reaffirming its 1992 holding in INS v. Elias-Zacarias that asylum applicants must show evidence was "so compelling that no reasonable factfinder could fail to find the requisite fear of persecution."
New Jersey Federal Court Threatens DHS and DOJ with Contempt Sanctions
A New Jersey federal court issued an order stating the government's handling of immigration detention is "emblematic of its approach to immigration enforcement in this state" and that "on the merits, its detentions are illegal." The court noted the U.S. Attorney for New Jersey conceded to "violating 72 orders" issued in immigration cases in that jurisdiction alone. The court rejected the U.S. Attorney's claim that violations were "unintentional," stating the government's continued actions after being called to task "can now only be deemed intentional." The judge threatened that any further arrests or detentions in violation of the order will result in mandatory testimony under oath by DHS and DOJ officials, if not actual sanctions. The court wrote that the credibility once attached to the U.S. Attorney's Office "has been sadly eroded."
T-Mobile Class Action Alleges Failure to Honor $200 Gift Card Promotion (Ghrabeti v. T-Mobile USA Inc., Case No. 5:25-cv-03031)
Plaintiff Purya Ghrabeti filed a class action lawsuit against T-Mobile USA Inc. in California state court, alleging the company failed to provide $200 promotional gift cards as promised to customers who purchased new phone lines. Ghrabeti claims he was induced to purchase additional phone lines based on T-Mobile's promise of $200 gift cards per line but was informed after making the purchase that the promotion did not exist and the company would not provide the promised gift cards. The lawsuit alleges T-Mobile engaged in false advertising and deceptive business practices under California consumer protection laws. Ghrabeti seeks to represent a class of California consumers who purchased new phone lines or devices from T-Mobile based on a promotional offer promising a gift card or other financial incentive and who did not receive the promised incentive. He demands a jury trial and seeks restitution, equitable relief, and injunctive relief.
Hyundai Class Action Alleges Defective Automatic Emergency Braking Systems (Sperling v. Hyundai Motor America, Case No. 8:26-cv-00410)
Plaintiff Dennis Sperling filed a class action lawsuit in California federal court alleging Hyundai sold 2025 Tucson SUVs with defective automatic emergency braking systems that falsely engage randomly, causing sudden, unintended braking. Sperling claims the AEB systems detect obstacles that are not actually present, automatically triggering the brakes and causing vehicles to abruptly slow down or stop, sometimes in the middle of traffic. He alleges the defect can startle and distract drivers by activating sudden, blaring visual and audible alerts even when no obstacles are present. Sperling contends both Hyundai and the National Highway Traffic Safety Administration received numerous complaints about sudden unintended braking and that Hyundai knew about the problem before bringing vehicles to market. He seeks certification of a nationwide class and an order requiring Hyundai to implement a service campaign to deactivate the AEB system or replace it with a safe alternative, publicize its knowledge about the defect, reform its warranty to ensure free repairs, and award damages and restitution.
My Medic Class Action Alleges Deceptive Email Marketing (Cerkezoglu v. SLED Distribution LLC, Case No. 25-2-00678-14)
Plaintiff Deborah Cerkezoglu filed a class action lawsuit in Washington state court alleging Sled Distribution LLC, doing business as My Medic, violated Washington's Commercial Electronic Mail Act (CEMA) and Consumer Protection Act by sending deceptive marketing emails that created a false sense of urgency. Cerkezoglu claims My Medic used subject lines and email content designed to pressure consumers into making immediate purchases out of fear of missing out. The lawsuit alleges the emails flood consumers' inboxes with repeated notifications falsely suggesting the time to act is short, steering consumers away from shopping for better deals. Cerkezoglu seeks to represent a class of Washington consumers who received My Medic's allegedly deceptive commercial emails and requests injunctive relief to stop the email marketing practices and all relief available under Washington law.
FTC Declines to Enforce COPPA Against Age Verification Technologies
The Federal Trade Commission issued a policy statement announcing it will not bring enforcement actions under the Children's Online Privacy Protection Rule (COPPA Rule) against website and online service operators that collect, use, and disclose personal information solely for determining a user's age via age verification technologies. The statement explicitly acknowledges that age verification technologies "may require the collection of personal information from children, prompting questions about whether such activities could violate the COPPA Rule." The FTC creates an enforcement carve-out for operators who collect children's personal data for age verification purposes, provided they promise to use the data only to check age, delete it afterward, and keep it secure. Christopher Mufarrige, Director of the FTC's Bureau of Consumer Protection, called age verification technologies "some of the most child-protective technologies to emerge in decades" and stated the policy "incentivizes operators to use these innovative tools, empowering parents to protect their children online."
Austrian DPA: Real Estate Drone Photos Violated Privacy Rights (DSB 2024-0.917.161)
Austria's Data Protection Authority held that a real estate agency infringed a data subject's right to secrecy by publishing unpixelated drone images of her home in an online property advertisement. The authority found the data subject's home was identifiable from the published drone images and location information, making the photographs personal data under Article 4 GDPR and Section 1 of Austria's Data Protection Act. The publication violated her right to secrecy because it was unnecessary for the marketing purpose of the advertisement. While marketing the property could be a legitimate interest under Article 6(1)(f) GDPR, the agency could have achieved this goal using pixelated or anonymized images. The data subject's complaint was granted.
ACIP to Discuss COVID Vaccine Injuries Outside Its Mandate
The CDC's Advisory Committee on Immunization Practices (ACIP) will include COVID vaccine injuries on the agenda for its meeting next month, despite vaccine injury discussions falling outside the committee's mandates. Vaccine policy expert Dorit Reiss noted that "vaccine injuries are not a direct part of the committee's mandates" and that while ACIP should consider vaccine risks when making recommendations, discussing the prevalence and validity of vaccine injury claims is not within ACIP's purview. The CDC's own webpage describing ACIP's purpose and program contains no reference to vaccine injury, nor does the ACIP charter. Michael Osterholm, director of the Center for Infectious Disease Research and Policy at the University of Minnesota, stated "some committee members have made repeated claims about COVID vaccine harms that were either unsupported by verifiable data or reflected clear mischaracterizations of the existing scientific literature."
High-Ranking Federal Election Officials Attended Summit of Election Deniers
Several high-ranking federal election officials attended a summit last week at which prominent figures who worked to overturn Donald Trump's 2020 election loss pressed the president to declare a national emergency to take over this year's midterms. Participants included Kurt Olsen, a White House lawyer charged with reinvestigating the 2020 election, and Heather Honey, the Department of Homeland Security official in charge of election integrity. The event was convened by Michael Flynn, Trump's former national security adviser, and attended by Cleta Mitchell, who directs the Election Integrity Network. The Washington Post reported that activists associated with those at the summit have been circulating a draft executive order that would ban mail-in ballots and eliminate voting machines as part of a federal takeover. A White House official stated federal officials' attendance at the gathering should not be construed as support for a national emergency declaration and that it was "common practice" for staffers to communicate with outside advocates who want to share policy ideas.
Patch Management: The Hyundai Spain enforcement demonstrates that failure to apply available security patches before a breach can result in multi-million euro fines. Establish patch management policies requiring security updates within 30 days for all systems processing personal data, with 7-day windows for critical vulnerabilities on internet-facing systems.
Encryption Requirements: Spanish and Austrian regulators both emphasized encryption as a fundamental technical safeguard. Implement encryption at rest for all databases containing personally identifiable information, regardless of whether your jurisdiction has specific encryption mandates.
Website Tracking Compliance: The $3.85 million Los Angeles Times settlement reinforces that California's Invasion of Privacy Act applies to website trackers. Audit all third-party tracking technologies and ensure cookie consent mechanisms are functional before any tracking occurs for California visitors.
Age Verification Documentation: If implementing age verification technologies following the FTC's new policy, document your data minimization practices in writing. The carve-out requires that personal information be collected solely for age verification, deleted immediately after determination, and secured with appropriate technical safeguards. Failure to comply with these narrow conditions could result in COPPA enforcement.
Processor Oversight: Controllers remain responsible for ensuring processors implement adequate security measures under GDPR Article 5(1)(f). Document processor security controls in data processing agreements, verify compliance quarterly through audits or certifications, and conduct your own risk assessments before engaging processors.