Get tomorrow's brief in your inbox
Today: Disney settles $50 million class action over ESPN bundling driving up streaming prices. PHH Mortgage reaches $1.5 million settlement over misleading foreclosure threats. Federal judge strikes down most of California's Age Appropriate Design Code on First Amendment grounds. DOJ drops Ticketmaster breakup in favor of weak settlement that leaves monopoly intact.
IRS Violated Federal Law 42,695 Times Sharing Taxpayer Addresses with ICE
U.S. District Judge Colleen Kollar-Kotelly found the IRS violated 26 U.S.C. § 6103 over 42,000 times when it handed taxpayer addresses to ICE without verifying that ICE had provided valid addresses for the individuals they were seeking. The IRS used a "TIN Matching" process that only checked whether the address field contained a five-digit or nine-digit number resembling a zip code. No actual address verification occurred. The court found the IRS would have accepted requests with addresses like "Don't Care 12345" or "00000" and still disclosed confidential taxpayer information. Of 47,289 taxpayer addresses shared with ICE, 90.3% went through this deficient verification process. ICE submitted requests with addresses marked "Failed to Provide," "Unknown Address," "NA NA," or missing street names and numbers entirely.
Ransomware Negotiator Charged with Feeding Client Information to BlackCat Gang
The Justice Department charged Angelo Martino, a ransomware negotiator at DigitalMint, with conspiracy to interfere with interstate commerce by extortion. Prosecutors allege Martino provided confidential negotiation information to ALPHV/BlackCat cybercriminals while representing victims, helping maximize ransom payments in exchange for kickbacks. Court documents identify five incidents in 2023 where Martino allegedly fed intelligence to attackers, including negotiations reaching $26 million, $25 million, $16 million, and $6 million. Martino worked alongside Ryan Goldberg (Sygnia) and Kevin Martin (DigitalMint), who pleaded guilty in December to conspiracy charges and face up to 20 years. The three earned approximately $1.2 million from an attack on a Florida medical company. DigitalMint terminated both Martino and Martin, cooperated with the investigation, and implemented mandatory cloud-based negotiation platforms with audit logging and founder oversight of all ransom negotiations.
Disney Agrees to $50 Million Class Action Settlement Over ESPN Bundling (Biddle v. Disney, Case No. 5:22-cv-07317)
The Walt Disney Co. agreed to a proposed $50 million settlement with YouTube TV and DirecTV Stream subscribers who alleged Disney used anticompetitive carriage agreements to inflate streaming prices. Plaintiffs claimed Disney forced streaming platforms to carry expensive ESPN networks as a condition of offering Disney programming, preventing platforms from offering lower-cost packages without sports content. The settlement class includes subscribers from April 1, 2019, through preliminary approval. The settlement includes three-year injunctive relief requiring Disney to consider proposals from streaming providers for packages with fewer Disney networks, potentially excluding ESPN. The case is pending preliminary approval in the U.S. District Court for the Northern District of California.
PHH Mortgage Settles FDCPA Violations for $1.5 Million (Williams v. PHH Mortgage, Case No. 3:25-cv-00144-KDB-UMJ)
PHH Mortgage Corp. agreed to a $1.5 million settlement over allegations it violated the Fair Debt Collection Practices Act and state debt collection laws by sending misleading default notices to borrowers. Plaintiffs alleged the notices contained false threats of immediate loan acceleration and foreclosure if borrowers did not cure defaults by specified deadlines, when PHH could not legally accelerate or foreclose until loans were at least 120 days delinquent. The settlement covers three classes: FDCPA class (U.S. borrowers sent notices Dec. 18, 2022, to Dec. 15, 2025), California class (same period), and North Carolina class (Jan. 14, 2021, to Dec. 15, 2025). Payments vary based on number of loans and delinquency status when PHH began servicing. No claim form required. Final approval hearing scheduled June 9, 2026, in the U.S. District Court for the Western District of North Carolina.
Sprouts Farmers Market Settles FACTA Violations for $5 Million
Sprouts Farmers Market agreed to a $5 million settlement over claims it violated the Fair and Accurate Credit Transactions Act (15 U.S.C. § 1681c) by printing more than the last five digits of customer payment card numbers on receipts. The settlement covers credit/debit card users from Aug. 16, 2020, to Oct. 31, 2022, and EBT card users from March 15, 2021, to April 15, 2023. Class members who received a notice with claim ID submit a short-form claim; others must submit long-form claim with receipt or card statement. Claim deadline is May 8, 2026 (extended from earlier deadline). Sprouts agreed to implement FACTA-compliant receipt truncation policy. Final approval hearing is Nov. 19, 2026, in Los Angeles County Superior Court (Tran v. Sprouts, Case No. 22STCV26572, and Cohen v. Sprouts, Case No. 23STCV08339).
Ninth Circuit Strikes Down California Age Appropriate Design Code Provisions
The Ninth Circuit Court of Appeals upheld most of a preliminary injunction against California's Age Appropriate Design Code, finding key provisions unconstitutional on vagueness grounds. The court struck down requirements prohibiting use of children's personal information in ways that harm their "well-being," are not in their "best interests," or are "materially detrimental" to them. The court found these standards created unacceptable risk of subjective enforcement, particularly because the provisions must be assessed individually for each child. The ruling sends the case back to district court for further proceedings following Supreme Court precedent in Moody v. NetChoice, which requires challenging laws "as applied" rather than facially. The court left intact procedural and ministerial provisions but eliminated all substantive speech-regulating requirements.
Apple Carbon Neutrality Class Action Dismissed for Failure to State Claim (Dib v. Apple, Case No. 25-cv-02043-NW)
U.S. District Judge Noel Wise dismissed with leave to amend a class action alleging Apple made false carbon neutrality claims about Apple Watches. Plaintiffs alleged Apple's marketing of certain watches as "carbon neutral" was deceptive because Apple's carbon offset purchases were insufficient. The court found plaintiffs' complaint relied on their own unsupported analysis of Apple's carbon credits without validation from experts or objective sources. Judge Wise held that Apple's reliance on carbon credits certified by Verra, a globally recognized nonprofit administering voluntary carbon offset programs, was reasonable and shielded Apple from liability absent evidence that reliance was unreasonable. Plaintiffs may file amended complaint addressing identified deficiencies. The case is pending in the U.S. District Court for the Northern District of California.
Hims & Hers Faces Class Action Over Compounded Semaglutide Claims (Donoho v. Hims & Hers, Case No. 1:26-cv-01954)
Consumers filed a class action in Illinois federal court alleging Hims & Hers Health Inc. falsely advertises its compounded semaglutide GLP-1 products as equivalent to FDA-approved Ozempic and Wegovy. Plaintiffs claim the compounded products contain different active ingredients than the semaglutide found in brand-name drugs, use different manufacturing processes, and have not been evaluated by the FDA for safety or effectiveness. The complaint alleges the manufacturing differences can cause immunogenicity and other health consequences. The FDA issued a warning letter to Hims & Hers in September 2025 over claims about its compounded GLP-1 product. Plaintiffs assert violations of the Illinois Consumer Fraud and Deceptive Trade Practices Act and similar state statutes, plus unjust enrichment claims. The case is pending in the U.S. District Court for the Northern District of Illinois.
New York Mandates Cybersecurity Standards for Water Systems Effective 2027
New York approved cybersecurity regulations requiring water and wastewater utilities to comply with baseline security standards by the end of 2027. The rules apply to community water systems serving more than 3,300 people, with additional requirements for systems serving over 50,000 people. Regulated entities must provide mandatory cybersecurity training for certified operators, implement incident response plans, establish reporting requirements, and designate a cyber lead for larger utilities. All systems must create and test response and recovery plans ensuring continued operations during cyberattacks. The state created a $2.5 million grant program offering $50,000 for cybersecurity assessments and up to $100,000 for upgrades. Technical assistance is available at no cost. The regulations align with EPA and CISA guidance and avoid duplicating existing federal requirements.
European Council Proposes Ban on AI Nudification Tools in AI Act Amendment
The European Council released its proposal for amending the EU AI Act, adding a prohibition on AI practices involving generation of non-consensual sexual or intimate content and child sexual abuse material. The amendment also reinstates strict necessity standards for processing special categories of personal data for bias detection and correction purposes. The Council proposal includes requirements that AI providers register high-risk systems in an EU database even when claiming exemption from high-risk rules. The proposal follows the European Parliament's Wednesday approval of a similar nudification ban. Both bodies must negotiate final terms. The amendments respond to the Grok chatbot generating millions of nonconsensual intimate images shared globally starting December 2025. The European Commission opened a formal investigation of X and its Grok feature in January 2026.
DOJ Settles with Ticketmaster, Abandons Breakup Effort
The Trump DOJ struck a settlement with Live Nation and Ticketmaster requiring $280 million in civil penalties and a 15 percent cap on service fees for Live Nation amphitheaters, but backing away from pursuing a breakup of the companies. The settlement was negotiated behind closed doors without informing the 27 states (including Republican-led states) currently litigating against Ticketmaster. The Biden DOJ and states sued Live Nation in 2024 alleging monopolization of live music delivery in the United States. States filed a motion for mistrial, arguing the DOJ's sudden withdrawal gives the jury the incorrect impression that antitrust violations have been cured or that state claims lack merit. The presiding judge in the Southern District of New York stated the manner of settlement announcement was "absolutely unacceptable." States are continuing litigation independently.
EFF Sues CPSC to Force Release of Incorporated Safety Standards
The Electronic Frontier Foundation filed a lawsuit against the Consumer Product Safety Commission demanding the agency release copies of legally binding safety codes for children's products. Public.Resource.Org submitted FOIA requests for the codes, but CPSC refused release, claiming the private standards organizations that drafted the codes retain copyright even after adoption into federal law. The Fifth Circuit previously held that safety codes lose copyright protection when incorporated into law. The D.C. Circuit (in a case EFF previously defended) held that even if standards retain copyright after incorporation, making them fully accessible online constitutes fair use. EFF and Harvard Law School's Cyberlaw Clinic argue copyright cannot restrict public access to binding legal requirements. The lawsuit challenges CPSC's position that private organizations control who can read and share mandatory safety rules.
Supreme Court Analysis: Justice Alito Signals Section 2 VRA May Be Unconstitutional
Justice Samuel Alito's solo concurring opinion in Malliotakis v. Williams suggests he may vote to declare Section 2 of the Voting Rights Act unconstitutional or severely limit its application to vote dilution claims. Section 2 prohibits voting practices that give minority voters less opportunity than others to participate in the political process and elect representatives of their choice, based on totality of circumstances. Compliance with Section 2 requires consideration of race in redistricting, creating tension with equal protection strict scrutiny standards. The Supreme Court has long assumed without deciding that Section 2 compliance is a compelling government interest. Louisiana v. Callais, argued in October and still pending, presents a vehicle for the Court to rule on Section 2's constitutionality. Alito's concurrence in Malliotakis (a New York state constitutional case, not a VRA case) previews potential arguments against Section 2.
Supreme Court Opinions Scheduled for March 20
The Supreme Court will potentially release opinions in argued cases from the current term on Friday, March 20, 2026. Ten cases were argued in October; eight have been decided, leaving Louisiana v. Callais and one other case pending.
Supreme Court May Revive Legislative History in Statutory Interpretation
Justice Ketanji Brown Jackson's concurrence in Learning Resources v. Trump argues courts should consult legislative history to determine congressional intent, potentially signaling a shift from strict textualism. The five-page concurrence stands alone among nearly 170 pages of opinions in the tariffs case. Jackson's position could gain traction following Loper Bright v. Raimondo, which eliminated Chevron deference. Without deference to agency interpretations of ambiguous statutes, courts may turn to legislative reports and floor debates for interpretive guidance. Justice Scalia categorically opposed legislative history use, while Justice Kagan in 2015 described it as "extra icing on a cake already frosted" and suggested the Court had largely abandoned it. The post-Chevron environment may create renewed debate over legislative history's proper role in statutory construction.
Verify data disclosure controls: Tax-exempt organizations and entities sharing confidential information with government agencies must implement technical controls preventing disclosure when required verification fields are incomplete or contain placeholder values. The IRS-ICE case demonstrates systemic failure when verification relies solely on format checks rather than substantive validation.
Audit incident response vendor relationships: Organizations using third-party ransomware negotiators or incident response firms must require all negotiations occur on cloud-based platforms with audit logging, implement dual-control procedures for sensitive communications, conduct background checks on negotiators, and include anti-collusion clauses in service agreements. The DigitalMint case shows insider threats can compromise ransom negotiations.
Review FACTA compliance for retail receipts: All retailers accepting payment cards must verify point-of-sale systems print only the last five digits of card numbers on customer receipts. The $5 million Sprouts settlement demonstrates ongoing FACTA liability for non-compliant receipt configurations. Test all terminals and update payment processor settings immediately if violations found.
Monitor Voting Rights Act litigation: Jurisdictions subject to Section 2 vote dilution claims should closely monitor Louisiana v. Callais for potential Supreme Court ruling limiting or invalidating Section 2. Justice Alito's Malliotakis concurrence suggests at least one vote to restrict Section 2's application to redistricting. Prepare contingency plans for redistricting processes if Section 2 protections are curtailed.
Prepare for EU AI Act nudification ban: AI developers with EU operations or users must immediately discontinue any features generating non-consensual intimate images or deepfakes. The European Council and Parliament are both advancing prohibitions in response to the Grok scandal. Strict liability and significant penalties will likely attach when amendments take effect.