Get tomorrow's brief in your inbox
Today: Federal courts allow Cadence Bank's $5.25 million MOVEit breach settlement to proceed while Massachusetts dismisses a separate Wiretap Act claim against healthcare providers for pixel tracking. Spain's DPA fines BBVA €100,000 for debiting accounts without consent, and Russia-linked hackers deploy sophisticated iPhone exploits targeting Ukrainian sites. The Supreme Court hears election timing arguments that could affect mail-in ballot deadlines in 15 states.
$5.25M Cadence Bank data breach class action settlement (Case No. 1:23-md-03083-ADB-PGL, D. Mass.)
Cadence Bank agreed to pay $5.25 million to settle claims it failed to protect customers from a May 2023 MOVEit breach. Class members can claim up to $2,500 for ordinary losses (bank fees, four hours of lost time at $25/hour) or up to $10,000 for extraordinary losses (unreimbursed fraud, credit repair fees). Those without documented losses receive $100 plus two years of credit monitoring. The settlement covers individuals notified their personal information was compromised between May 28-31, 2023. Claims must be filed by June 4, 2026, with final approval scheduled for July 9, 2026.
Marquis Software bank vendor breach exposes 672,075 customers
Bank software vendor Marquis Software confirmed that an August 2024 breach exposed names, addresses, Social Security numbers, dates of birth, and financial account information of 672,075 individuals across at least 74 financial institutions. The breach occurred on August 14, 2024, affecting the company's customer relationship management platform used by banks to track accounts and marketing touchpoints. Community 1st Credit Union disclosed that Marquis Software paid a ransom to the attackers, though no ransomware gang claimed public credit. Multiple financial institutions sent breach notifications but several affected banks were not included in the official list of 74 institutions.
Eggland's Best must face class action over "cage free" eggs (Case No. 1:24-cv-06222, N.D. Ill.)
U.S. District Judge Franklin Valderrama ruled on February 27 that plaintiffs sufficiently alleged Eggland's Best misled consumers by claiming hens are "free to roam in a pleasant, natural environment" when they are confined to industrial facilities without outdoor access. The court rejected Eggland's Best's argument that the statement is puffery, finding it makes a verifiable promise about hen living conditions. Plaintiffs claim they paid a premium for cage-free eggs based on this representation. The court dismissed injunctive relief claims without prejudice, finding plaintiffs failed to show intent to purchase the products again. The case moves forward on damages claims.
Blue Buffalo class action sparks insurance coverage dispute (Case No. 3:26-cv-00328, D. Conn.)
Nationwide Agribusiness Insurance filed a declaratory judgment action seeking to determine which insurers must cover defense costs for an underlying class action alleging Blue Buffalo dog food caused heart problems in pets. The underlying case (Walsh v. Blue Buffalo, Case No. 1:25-cv-05808, N.D. Ill.) claims Blue Buffalo failed to disclose ingredients linked to dilated cardiomyopathy. Nationwide claims it is defending Blue Buffalo under a reservation of rights for policies issued between 2016-2018 but argues some alleged injuries occurred outside coverage periods. The insurer seeks proportional cost-sharing from Hartford and Blue Buffalo.
Massachusetts court dismisses Wiretap Act claims against healthcare providers (Progin v. UMass Mem'l Health Care, 2026 WL 632770, D. Mass.)
A Massachusetts federal court dismissed Wiretap Act claims against healthcare entities for embedding pixel tracking technologies that allegedly transmitted protected health information to third parties. The court applied the "heightened intent requirement" for the crime-tort exception, holding that plaintiffs failed to plead defendants purposefully committed HIPAA violations. The court explained that merely alleging defendants knowingly installed tracking tools or disclosed information is insufficient. Plaintiffs must show defendants purposefully committed the criminal or tortious act itself, not that violations were side effects.
Jehovah's Witnesses abuse DMCA subpoenas to unmask critics
The Electronic Frontier Foundation is defending an anonymous Jehovah's Witness member operating JWS Library, a research website that archives and analyzes the organization's historical documents. Watch Tower Bible and Tract Society sent DMCA subpoenas to Google and Cloudflare seeking to unmask the website operator, despite having no history of filing infringement lawsuits. EFF research shows Watch Tower filed 72 copyright subpoenas since 2017 but never used the information to file lawsuits. Instead, the organization initiates disfellowship proceedings to ostracize critics. The JWS Library content qualifies as transformative fair use for research and commentary purposes.
Spain's DPA fines BBVA €100,000 for unauthorized account debits (AEPD EXP202408496)
Spain's Data Protection Authority fined BBVA €100,000 (reduced to €80,000 after voluntary payment) for processing personal data without a legal basis under Article 6(1) GDPR. The bank redirected a SEPA direct debit mandate from a closed account to a new account without authorization. The DPA held that SEPA mandates are linked to specific IBANs and the bank needed new authorization to debit a different account. The DPA rejected BBVA's claims of implied consent, finding consent must be freely given, specific, informed, and unambiguous through clear affirmative action. The DPA also rejected alternative legal bases under Article 6(1)(b) (contract performance) and Article 6(1)(f) (legitimate interest), finding the bank failed to conduct required balancing tests.
Supreme Court hears election mail-in ballot timing case (Watson v. Republican National Committee)
The Supreme Court is hearing arguments on whether federal law requires mail-in ballots to be received by Election Day or only postmarked by that date. The case challenges Mississippi's 2020 law allowing ballots postmarked by Election Day to be counted if received within five business days. The 5th Circuit ruled federal law requires all ballots to be received by Election Day, reversing a district court decision. Mississippi argues that "election" refers to when voters cast ballots, not when officials receive them, citing the Court's 2020 ruling in Republican National Committee v. Democratic National Committee. A ruling requiring Election Day receipt could upend laws in more than a dozen states allowing post-election ballot arrival.
Federal court issues preliminary injunction against HHS vaccine schedule changes
U.S. District Judge Brian Murphy in Boston issued a preliminary injunction blocking HHS Secretary Robert F. Kennedy Jr.'s changes to CDC vaccine schedules and staying the appointment of 13 ACIP committee members. The court ruled Kennedy violated the Administrative Procedures Act by replacing the entire ACIP committee without following required procedures. The DOJ argued Kennedy's actions were "unreviewable," claiming he could advise the public to get measles instead of preventing it without judicial review. The court rejected this position. ACIP had issued controversial recommendations including advising against universal hepatitis B vaccination for newborns. The government plans to appeal.
Netherlands court upholds compulsory education exemption data processing (Rb. Noord-Holland HAA 25/1285)
A Dutch court held that municipalities lawfully process lists of objections to schools when reviewing compulsory education exemption requests under the Leerplichtwet 1969. The court rejected an Article 17 GDPR erasure request, finding the municipality must maintain detailed school-by-school objection lists to investigate exemption claims. The court held processing was necessary under Article 6(1) because the Compulsory Education Officers and courts must verify objections to all schools within a reasonable area. The Archival Act requires municipalities to retain exemption decisions. The court found processing proportional because the goal of verifying exemption claims cannot be achieved with less privacy-intrusive methods.
Russia-linked hackers deploy DarkSword iPhone exploit against Ukrainians
Russia-linked threat actor UNC6353 deployed DarkSword malware targeting Ukrainian users through watering hole attacks on compromised news sites and court websites. The malware exploits iPhone vulnerabilities patched by Apple in late 2025, allowing attackers to gain deep device access with minimal user interaction. DarkSword operates on a "hit-and-run" model, rapidly extracting emails, messages, photos, credentials, and cryptocurrency wallet data within minutes before self-deleting. The campaign targeted Coinbase, Binance, Kraken, MetaMask, and Ledger users. Lookout researchers noted the malware is professionally designed with modular architecture suggesting access to commercial surveillance tools. Google reported DarkSword was also deployed in Saudi Arabia, Turkey, and Malaysia by various threat actors.
University of Mississippi Medical Center recovers from nine-day ransomware attack
UMMC restored all clinics on March 2 following a ransomware attack detected February 19 that paralyzed the EPIC electronic medical records system. The attack forced closure of most outpatient clinics statewide and cancellation of elective surgeries. Staff used manual downtime procedures with pen and paper for nine days. UMMC confirmed communication with the attackers but has not disclosed their identity, ransom demands, or whether payment was made. The FBI, DHS, and CISA are assisting the investigation. UMMC is still determining whether patient data was compromised. The medical center is operating extended hours to address the appointment backlog. No statement confirmed data exfiltration.
Meta's AI glasses raise privacy concerns
Meta's new AI-enabled glasses are creating privacy concerns as wearers can capture photos and videos without clear indication to bystanders. A new Android app has been developed to detect smart glasses nearby, allowing individuals to identify when they may be recorded. The technology raises questions about consent and reasonable expectations of privacy in public spaces as camera-equipped wearables become more ubiquitous and harder to distinguish from regular eyewear.
CISA official reports no uptick in cyber threats amid Iran conflict
CISA Acting Director Nick Andersen stated the agency has not observed increased cyber threat activity from Iran since U.S. and Israeli strikes began in late February. CISA continues working with Stryker following a March 11 cyberattack by Iran-linked Handala group. Andersen raised concerns about AI-accelerated attacks creating a "velocity problem" for vulnerability disclosure, suggesting the current 1-2 week CVE publication timeline may be inadequate. CISA is studying whether to shorten required response windows for critical vulnerabilities.
DHS nominee Mullin declines to commit on CISA staffing restoration
Senator Markwayne Mullin, nominated as DHS Secretary, declined to commit to restoring CISA's budget or rehiring personnel cut by Secretary Noem. Under Noem, CISA lost one-third of its workforce and hundreds of millions in budget cuts. Mullin stated he would "recruit the right people" without specifying staffing levels. Senators warned that conflict with Iran will likely trigger cyberattacks requiring full CISA capabilities. The Michigan Stryker attack by Iranian actors was cited as evidence of escalating threats. CISA's previous acting director Gottumukkala was moved to a new role amid multiple controversies, with Congress calling for an investigation.
Intelligence community omits election threats from annual assessment
Director of National Intelligence Tulsi Gabbard defended excluding foreign election interference from the 2026 Annual Threat Assessment for the first time since 2017. Senator Mark Warner questioned whether foreign threats to midterm elections no longer exist. Previous assessments documented Iranian, Russian, and Chinese influence operations targeting elections. Warner stated "the intelligence community is no longer being allowed to speak honestly about it." Gabbard disclosed she observed the FBI's January raid on Georgia election records "at the request of the president" but did not participate in law enforcement activity. Senator Jon Ossoff questioned her presence given no evidence of foreign involvement in that investigation.
MOVEit settlements proceeding: Organizations affected by the May 2023 MOVEit breach should verify they have notified all impacted individuals and filed required state breach notifications. Review vendor contracts for indemnification clauses and coordinate with legal counsel if class actions are filed. Deadline for Cadence Bank settlement claims is June 4, 2026.
Wiretap Act heightened intent standard: Healthcare providers using website analytics must document that tracking pixel implementations were not intended to violate HIPAA. Conduct privacy impact assessments before deploying third-party analytics and maintain written policies prohibiting intentional disclosure of PHI to marketing platforms.
GDPR consent for payment redirects: Banks operating in EU jurisdictions must obtain explicit authorization before applying SEPA mandates to new accounts. Silence or absence of objection does not constitute valid consent under Article 6(1)(a). Document all consent with clear affirmative actions and conduct balancing tests before relying on legitimate interest.
Mobile device security amid nation-state exploits: Enforce 30-day patch windows for iOS devices accessing organizational data. The DarkSword campaign demonstrates sophisticated actors are deploying zero-day exploits against recently patched vulnerabilities. Block jailbroken devices and consider MDM solutions with jailbreak detection.
Reduced CISA capacity planning: Do not assume federal coordination will be available at historical levels. Critical infrastructure operators should establish direct peer-to-peer threat intelligence sharing and verify incident response plans can execute without CISA support. The one-third workforce reduction at CISA means longer response times for voluntary assistance requests.