CVE-2025-0282, CVE-2025-21590
Get tomorrow's brief in your inbox
Today: Nissan North America agreed to pay $1.5 million to settle claims over a November 2023 data breach affecting 50,000 employees. The Supreme Court ruled unanimously that New Jersey Transit can be sued in other states, rejecting sovereign immunity claims. Multiple data breach class actions target Total Wireless, Veriff, Norway Savings Bank, and Brightspeed over failures to protect customer PII.
University of Limerick Data Breach (Ireland DPC IN-19-7-1)
The Irish Data Protection Commission fined the University of Limerick €98,000 following six phishing-related data breaches between November 2018 and January 2020. The DPC found the university failed to implement appropriate technical and organizational security measures under Article 5(1)(f) and Article 32(1) GDPR when unauthorized users accessed staff email accounts through phishing attacks and set up forwarding rules. The compromised accounts contained PPS numbers, bank information, medical and legal documentation, and staff disciplinary records. The DPC also found the university violated Article 30(1) GDPR by failing to maintain adequate records of processing activities, Article 33(1) GDPR by delaying breach notifications to the DPA, and Article 34(1) GDPR by failing to notify 100 data subjects without undue delay.
UK ICO Prosecutes Data Theft Ring (Christopher Munro and William Chipoma)
The UK Information Commissioner's Office secured convictions against two men who deliberately sought employment at claims management and insurance companies to steal and sell personal data. Christopher Munro accessed thousands of records without authority between 2015 and 2016, receiving £16,000 in payments, while William Chipoma received £70,550 for similar activities between 2015 and 2017. The case, described as the ICO's largest nuisance call investigation, involved data stolen from more than 400 garages, claims management firms, and insurance companies. Both men pleaded guilty to four offenses under Section 55 of the Data Protection Act 1998 and the Computer Misuse Act 1990. Munro received a 32-week suspended sentence and 150 hours of unpaid work, while Chipoma received a 10-month suspended sentence and 240 hours of unpaid work. The ICO is pursuing financial recovery under the Proceeds of Crime Act 2002.
Altex România Fined €8,000 for Non-Cooperation (Romania ANSPDCP)
The Romanian Data Protection Authority fined electronics retailer Altex România S.R.L. RON 40,768 (€8,000) under Article 83(5)(e) GDPR for failing to respond to the DPA's inquiries during an investigation launched after multiple complaints. Data subjects alleged the company failed to respond to access requests, a data rectification request, an erasure request, and a customer account closure request. The investigation was triggered by the controller's non-responsiveness to complainants, and the fine was imposed specifically for failure to cooperate with the supervisory authority under Article 58(1)(a) and (e) GDPR.
Greek DPA Fines Tutoring Center €4,000 for Access Request Violations
The Hellenic Data Protection Authority fined a private tutoring center €4,000 (€2,000 per violation) for refusing to fulfill a father's access request on behalf of his two minor children and for failing to cooperate with the DPA during the investigation. The controller told the father to obtain tax receipts from the children's mother instead of providing them directly, violating Article 15(1) GDPR in conjunction with Article 12(3) and (4) GDPR. The controller also failed to respond to multiple emails and registered letters from the DPA, which had to serve the complaint through police. The decision confirms Greek case law that parents exercising parental responsibility may exercise access rights on behalf of minor children unless a court decision provides otherwise.
Croatian School Fined €2,000 for Unlawful Payroll Disclosure
The Croatian Data Protection Authority fined a primary school €2,000 for disclosing payroll slips of 18 employees to a city audit office without a legal basis under Article 6(1) GDPR. The school transmitted the payroll slips (containing names, addresses, personal identification numbers, salary details, deductions, credit obligations, and family information) to the city on March 6, 2024, claiming the city needed them to audit municipal funding. AZOP rejected this argument, finding that the city's internal audit office had no legal competence to supervise state budget funds, which financed most school salaries. The Ministry of Finance confirmed the city lacked authority to review the payroll data. The disclosure violated Article 5(1)(a) GDPR (lawful processing) and Article 6 GDPR (legal basis requirement).
Phobos Ransomware Leader Pleads Guilty, Faces 20 Years
Russian national Evgenii Ptitsyn, 43, pleaded guilty to wire fraud charges on Wednesday after prosecutors accused him of being the key developer behind the Phobos ransomware operation. Ptitsyn faces a maximum penalty of 20 years in prison at sentencing on July 15, 2026. He began operating Phobos in November 2020, offering it to criminal affiliates in a ransomware-as-a-service model. The operation attacked more than 1,000 organizations worldwide, including the California public school system (which paid a $300,000 ransom in 2023) and multiple healthcare organizations. U.S. prosecutors stated that Phobos and the related 8Base strain collected upwards of $16 million from victims from 2019 through 2024. Ptitsyn was arrested in South Korea and extradited in November 2024.
$1.5M Nissan North America Data Breach Settlement (Case No. 25-0975-BC)
Nissan North America agreed to pay $1.5 million to resolve claims over a November 2023 data breach affecting more than 50,000 employees. The breach resulted from a phishing attack that plaintiffs argue could have been prevented through reasonable cybersecurity measures. Under the settlement terms, class members can receive up to $4,500 for extraordinary losses (fraudulent charges, identity theft) supported by documentation, up to $450 for ordinary losses (bank fees, postage, notary fees), or an alternative cash payment of up to $100 for those without documented losses. All class members are eligible for two years of free credit monitoring with one-bureau monitoring and up to $1 million in identity theft insurance. The claims deadline is May 26, 2026, with final approval hearing scheduled for June 1, 2026.
Total Wireless and Veriff Face Three Class Actions Over Data Breach
Three separate class action lawsuits filed in New York federal court allege that Total Wireless and identity verification provider Veriff OU failed to protect customer PII from a data breach. Unauthorized access occurred around November 18, 2025, and was detected on December 10, 2025. Total Wireless filed a notice with the Maine Attorney General on January 9, 2026. The complaints allege the companies left PII unencrypted and unredacted, exposing customers to identity theft and fraud risks. The cases are Stockton v. Veriff OU, et al. (Case No. 1:26-cv-00520), Reed v. Veriff OU, et al. (Case No. 1:26-cv-00465), and McLaughlin v. Veriff OU, et al. (Case No. 1:26-cv-00566), all in the U.S. District Court for the Southern District of New York.
Norway Savings Bank Data Breach Litigation (Three Texas Cases)
Three class action lawsuits filed in Texas federal court allege that Marquis Software Solutions and Norway Savings Bank failed to protect customer PII from an August 2025 data breach affecting tens or hundreds of thousands of individuals. The breach exposed names, addresses, dates of birth, account numbers, Social Security numbers, tax ID numbers, and financial account information. Plaintiffs claim Norway Savings Bank delayed notification to affected individuals for months after the breach occurred and negligently entrusted customer data to Marquis, which failed to implement adequate security measures. The cases are Hart v. Marquis Software Solutions, Inc., et al. (Case No. 4:25-cv-01285), Simmering v. Norway Savings Bank, et al. (Case No. 4:25-cv-01281-SDJ), and Boutot v. Norway Savings Bank, et al. (Case No. 4:25-cv-01321), all in the Eastern District of Texas, Sherman Division.
Brightspeed Data Breach Class Actions (Four Federal Courts)
Four class action lawsuits filed in North Carolina, Ohio, Virginia, and Texas allege that telecommunications provider Brightspeed (Connect Holding II LLC) failed to protect customer data compromised in a January 2026 breach. A hacker known as "Crimson Collective" posted on Telegram around January 4, 2026, claiming to have stolen data belonging to more than 1 million residential customers, including names, emails, phone numbers, addresses, account numbers, payment histories, and partial credit card numbers and bank identification numbers. Plaintiffs claim Brightspeed failed to implement adequate security measures, encrypt data, and follow appropriate protocols. The cases are Arter v. Connect Holding II, LLC (Case No. 3:26-cv-00045, W.D.N.C.), Polner v. Connect Holding II, LLC (Case No. 1:26-cv-00067, S.D. Ohio), Riggs v. Connect Holding II, LLC (Case No. 3:26-cv-00058), and Smith v. Connect Holding II, LLC.
Supreme Court: New Jersey Transit Can Be Sued in Other States (Galette v. New Jersey Transit)
The Supreme Court ruled unanimously in Galette v. New Jersey Transit Corporation that New Jersey Transit is not an extension of the state of New Jersey and therefore does not share the state's sovereign immunity from lawsuits in other states' courts. The decision allows Jeffrey Colt, who was hit by a New Jersey Transit bus in Manhattan in 2017, and Cedric Galette, whose car was hit by a bus in Pennsylvania in 2018, to pursue their lawsuits. Justice Sonia Sotomayor wrote that the court examines "whether the State structured the entity as a legally separate entity liable for its own judgments" and found that New Jersey created the transit agency as a corporation with traditional corporate powers to sue, be sued, hold property, make contracts, and incur debt. State law explicitly states that New Jersey cannot be held liable for the transit agency's debts.
Austrian Court: Confirmed Deletion That Never Happened Violates GDPR (BVwG W254 2313142-1)
The Austrian Federal Administrative Court held that a network operator unlawfully processed a data subject's email address by continuing to store and use it after falsely confirming deletion. The controller confirmed deletion in March 2022 but sent a meter-reading notification to the same email address on January 26, 2024. The court found the processing violated Article 5(1)(a) GDPR (lawfulness), Article 5(1)(b) and (c) GDPR (purpose limitation and data minimization), Article 6(1) GDPR (no valid legal basis), and Article 5(2) GDPR (accountability) when the controller initially claimed deletion occurred but later admitted the email remained stored until April 2, 2024. However, the court dismissed the Article 17 GDPR erasure claim as inadmissible because the data subject did not submit a new deletion request after discovering the continued processing.
Belgian DPA Dismisses Complaint Over Email Access Method (APD/GBA 44/2026)
The Belgian Data Protection Authority dismissed an employee's complaint that his employer failed to comply with an access request by providing reproductions of email content rather than full email extracts. The employee requested access to personal data including an overview of recipients, all reports and notifications about him, and a copy of his personnel file. The controller provided personal data from emails through reproduction rather than extraction. The DPA held that the controller complied sufficiently with Article 15(1) and Article 15(3) GDPR, finding that an in-depth investigation would not be proportionate and that disclosure through reproduction rather than extraction satisfied the access obligation.
Supreme Court Hears Federal Preemption Case on Freight Broker Liability (Montgomery v. Caribe Transport II)
The Supreme Court heard oral argument on whether federal law preempts state negligent hiring claims against freight brokers. Shawn Montgomery suffered severe injuries in an Illinois highway accident involving a driver employed by motor carrier Caribe Transport II, whose shipment was arranged by freight broker C.H. Robinson under the Federal Aviation Administration Authorization Act of 1994. The 7th Circuit held that Section 14501(c)(1) preempts state claims against brokers for negligently hiring motor carriers, creating a circuit split with the 9th Circuit. During arguments, justices questioned whether the safety exception in Section 14501(c)(2)(A) applies to broker selection claims and whether "with respect to motor vehicles" language limits the exception's scope. Amicus briefs were filed by Amazon, the U.S. Chamber of Commerce, and the federal government.
House Committee Advances KIDS Act Over Democrat Opposition
The House Energy and Commerce Committee advanced the Kids Internet and Digital Safety (KIDS) Act in a party-line vote on Thursday, with Democrats criticizing the legislation as toothless regulation that could preempt stronger state laws. Democrats attacked the bill's weak knowledge standard, which they said allows tech companies to escape accountability by claiming ignorance that kids are using their platforms. The bill lacks a duty of care provision that would compel platforms to proactively mitigate severe harms posed by social media. Democrats also expressed alarm that the preemption language could block state attorneys general from suing platforms like Meta and Roblox and could undercut existing lawsuits. Parents for Safe Online Spaces thanked Republicans for improvements including mandating that platforms turn off recommendation algorithms for children and teens by default, but expressed disappointment that the House abandoned core tenets of the Senate's Kids Online Safety Act (KOSA), which has 75 bipartisan cosponsors.
FCC Approves Cox-Charter Merger With DEI Elimination Conditions
The Federal Communications Commission approved the merger of Cox and Charter Communications, creating the largest cable company in the United States, on condition that the companies eliminate diversity, equity, and inclusion programs. The FCC described the conditions as "safeguards to protect against DEI discrimination" and commitments to recruit, hire, and promote based on "skills, qualifications, and experience." The decision continues the Trump FCC's pattern of rubber-stamping telecom mergers without meaningful review. Critics note that four decades of evidence show such consolidation consistently results in higher prices, worse service, and mass layoffs, with debt from mergers typically paid through workforce reductions and price increases.
EPIC Urges Virginia Governor to Sign Geolocation Data Sales Ban (S.B. 338)
EPIC sent a letter to Virginia Governor Abigail Spanberger urging her to sign S.B. 338, which bans the sale of precise geolocation data. The bill addresses the practice of data brokers collecting and selling location information from smartphones, which federal law enforcement agencies including Customs and Border Protection, ICE, and the FBI have purchased for surveillance purposes.
EPIC Testifies on Maryland Tech Policy Bills
EPIC testified in support of three Maryland bills that would establish commonsense safeguards on chatbots, prohibit surveillance pricing in grocery stores, and establish a data broker registry. The testimony supports state-level privacy legislation addressing AI transparency, price discrimination based on consumer surveillance, and data broker accountability.
EPIC Testifies in Support of Michigan Kids Code
EPIC testified before Michigan lawmakers in support of the Michigan Kids Code, explaining why the model is the right approach to mitigate harms children face online. The testimony supports state legislation establishing protections for minors using digital platforms.
CBP Confirms Location Data Purchases From Real-Time Bidding (RTB) Ad Auctions
A document obtained by 404 Media reveals that Customs and Border Protection acknowledged purchasing location data sourced from the real-time bidding system that powers online advertising. The document states "RTB-sourced location data is recorded when an advertisement is served." This is the first time CBP has confirmed that location data it buys for surveillance is partially sourced from the ad tech ecosystem. The agency used the data in a 2019-2021 pilot program and has continued purchasing commercially obtained location data since then. ICE recently requested information on "Ad Tech" tools for investigations. Location data can be collected from apps through software development kits (SDKs) or indirectly through RTB when apps request location permissions.
SCOTUS to Hear Video Privacy Protection Act Case (Salazar v. Paramount Global)
The Supreme Court granted certiorari on January 26, 2026, in Salazar v. Paramount Global to address the proper scope of the Video Privacy Protection Act (VPPA) in the digital age. The VPPA, enacted in 1988 after a Supreme Court nominee's video rental history was published, prohibits video service providers from disclosing consumers' sensitive personal information. The case will determine how the 1988 law applies to modern streaming platforms and digital video services.
EPIC Files Amicus Brief on Geofence Warrants (Chatrie v. United States)
EPIC filed an amicus brief on behalf of 14 law and technology and Fourth Amendment scholars in Chatrie v. United States, arguing that geofence searches require a warrant with particularized probable cause. Geofence warrants request location data from tech companies for all devices within a specific geographic area during a specific time period, raising Fourth Amendment concerns about dragnet searches lacking individualized suspicion.
Google Reports 90 Zero-Days Exploited in 2025, Commercial Vendors Lead
Google Threat Intelligence Group tracked 90 zero-day vulnerabilities exploited in 2025, up from 78 in 2024. Of the 42 zero-days with attribution, 18 were used by commercial surveillance vendors and 15 by state-sponsored espionage groups from China, Russia, and the UAE. Commercial vendors primarily targeted mobile devices and browsers to sell surveillance tools, while state-sponsored groups prioritized edge devices like routers and firewalls. Chinese groups remained the most prolific users of zero-days, targeting security appliances to maintain persistent access. Microsoft had the largest number of zero-days followed by Google and Apple. Key examples included Juniper Networks CVE-2025-21590 and Ivanti CVE-2025-0282.
Spanish Police Bust Gambling Fraud Ring Exploiting Ukrainian Refugees
Europol announced the arrest of 12 suspects in a criminal network that exploited dozens of Ukrainian women fleeing the war to carry out a $5.5 million gambling fraud scheme. The network recruited Ukrainian women from war-affected regions, brought them to Spain under promises of assistance, then took them to banks to open accounts and obtain credit cards. The criminals took control of the accounts, used them to move money through online betting platforms via automated bots, and transferred government refugee subsidies. Police identified 55 Ukrainian women used in the operation and seized more than 5,000 stolen identities from 17 nationalities and at least 3,000 compromised credit cards.
Syrian Nationals Challenge TPS Termination at Supreme Court
Syrian nationals urged the Supreme Court to leave in place a ruling allowing them to remain in the United States under Temporary Protected Status (TPS) despite Trump administration efforts to end the program. U.S. District Judge Katherine Polk Failla issued an injunction on November 18, 2025, blocking DHS Secretary Kristi Noem's September 2025 decision to terminate Syria's TPS designation effective November 21, 2025. Judge Failla found that Noem's heavy reliance on "national interest" divorced from country conditions rendered the termination unlawful under the statute governing TPS, which only allows DHS to consider conditions in the designated country. The statute was created in 1990 to allow DHS to authorize nationals to stay and work when they cannot return home due to natural disaster, armed conflict, or other extraordinary conditions. Syria has had TPS designation since 2012 when Janet Napolitano cited Bashar al-Assad's brutal crackdown. The 2nd Circuit declined to pause the injunction, prompting Solicitor General D. John Sauer to ask the Supreme Court to allow termination while litigation continues.
Attorney General Bondi Allegedly Misled Congress on Lewandowski Contract Authority
ProPublica reported that DHS Secretary Kristi Noem misled Congress about top aide Corey Lewandowski's role in approving contracts. At a Senate Judiciary Committee hearing on March 3, 2026, Noem told Senator Richard Blumenthal that Lewandowski has no role in approving contracts, but internal DHS records show Lewandowski personally approved a multimillion-dollar equipment contract and routinely signs off on large contracts before they reach Noem under a routing sheet system. Noem imposed a policy requiring her approval for all contracts above $100,000, with Lewandowski's signature typically appearing last before hers on the approval checklist. Lewandowski is classified as a "special government employee," a designation allowing limited government service without disclosing outside income sources. Under federal law, knowingly and willfully making false statements to Congress is a crime, though rarely prosecuted.
OpenAI Amends Defense Department Contract to Address Surveillance Concerns
OpenAI announced on March 3, 2026, that it amended its Department of War agreement to add explicit language prohibiting domestic surveillance of U.S. persons and nationals. The new language states: "Consistent with applicable laws, including the Fourth Amendment to the United States Constitution, National Security Act of 1947, FISA Act of 1978, the AI system shall not be intentionally used for domestic surveillance of U.S. persons and nationals." The amendment prohibits "deliberate tracking, surveillance, or monitoring of U.S. persons or nationals, including through the procurement or use of commercially acquired personal or identifiable information." OpenAI CEO Sam Altman also stated the Defense Department affirmed that services will not be used by intelligence agencies like NSA without a follow-on contract modification. Anthropic CEO Dario Amodei criticized the amendment as "safety theater" and "straight up lies" in a leaked memo to staff.
Minnesota Federal Judge Rebukes AG Bondi for Violating Protective Orders
U.S. District Judge Dulce Foster issued an order criticizing Attorney General Pam Bondi for posting on X about arrests in Minnesota immigration enforcement cases while a court seal was in effect. On January 28, 2026, at 12:53 PM, Bondi publicly posted that defendant Ms. Flores and 15 others were arrested as "rioters" who "have been resisting and impeding our law enforcement officers," violating a sealing order that was not lifted until later that day after initial appearances. Judge Foster wrote that the government's claimed concern about victim and agent "dignity and privacy" and the risk of doxxing is "eyebrow-raising, to say the least" when the government itself publicly identified the defendant to a national audience while seeking protective orders to prevent public identification of federal officers.
Phishing defense audit: Review email security configurations following the €98,000 University of Limerick fine. Implement monitoring for unauthorized forwarding rule changes and ensure multi-factor authentication protects administrative email accounts. The DPC found standard security measures insufficient when sophisticated phishing attacks compromised six separate accounts over 14 months.
Vendor security assessments: The Total Wireless/Veriff breach and Norway Savings Bank/Marquis Software incidents demonstrate third-party risk. Before engaging identity verification providers, claims processors, or software vendors with PII access, verify encryption requirements, breach notification SLAs, and security audit rights are contractually binding. The Marquis incident shows that banks can face negligent entrustment claims when vendor security fails.
Data subject rights response procedures: Three enforcement actions (Greek tutoring center, Romanian retailer Altex, Belgian employer) involved failures to respond to access, rectification, and erasure requests. Establish documented workflows with deadline tracking for GDPR Article 15-17 requests. Train staff that parents exercising parental responsibility may exercise rights on behalf of minor children. Budget for potential €2,000-€4,000 fines per violation when controllers ignore supervisory authority inquiries.
Deletion request verification: The Austrian network operator case demonstrates the compliance risk of confirming deletion that never occurred. Implement automated deletion verification before sending confirmation notices. Maintain deletion logs with timestamps and responsible parties. Note that courts may require new deletion requests if data subjects discover continued processing after a confirmed deletion.
State privacy law tracking: Monitor Virginia S.B. 338 (geolocation sales ban), Maryland bills (chatbot safeguards, surveillance pricing prohibition, data broker registry), and Michigan Kids Code. If the KIDS Act passes with preemption language, state AG enforcement against platforms may be restricted. The CBP/RTB disclosure confirms that commercially available location data purchased from ad tech systems enables warrantless government surveillance, increasing pressure for state-level sales restrictions.