← Carolina Clear Tech

Legal & Privacy Brief

2026-03-24

Listen to this brief (20:07)

Download MP3
Show Notes

Show Notes - 2026-03-24

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - March 24, 2026

Today: Fidelity reaches $2.5 million settlement over 2024 data breach affecting 155,000 account holders. Kaplan reports breach exposing Social Security and driver's license numbers of 230,000 people. Federal court blocks Pentagon from credentialing journalists based on reporting content, restoring First Amendment protections.

Enforcement Actions

Fidelity $2.5M Data Breach Settlement (Case No. 1:24-cv-12601)

Fidelity Investments reached a proposed $2.5 million settlement with plaintiffs in Massachusetts federal court over allegations the company failed to protect personal and financial information during an August 2024 cybersecurity incident affecting more than 155,000 account holders. U.S. District Judge Leo T. Sorokin granted preliminary approval, finding the nationwide class presents common legal questions. According to the complaint, cybercriminals gained access to Fidelity's computer systems on August 17, 2024, and infiltrated the network to access sensitive data files containing financial account numbers and routing numbers. Plaintiffs argue Fidelity detected suspicious activity between August 17-19 but did not notify affected customers until October 10, leaving customers vulnerable to identity theft and fraud for nearly two months.

US Sentences Nigerian National to 7 Years in $6M Email Fraud Scheme

James Junior Aliyu, 31, received a 90-month prison sentence for conspiracy to commit wire fraud and money laundering as part of an international fraud ring that compromised business email accounts and stole approximately $6 million from American businesses and individuals. U.S. Immigration and Customs Enforcement announced the sentence, which also includes $1.2 million forfeiture and $2.4 million in restitution. The scheme dates back to at least 2017 and involved multiple co-conspirators gaining unauthorized access to email accounts and sending spoofed messages with fraudulent payment instructions. Aliyu, who used the online aliases "Old Soldier" and "Ghost," was arrested in Johannesburg in 2022 and extradited to the United States. Two other defendants have already pleaded guilty, with Kosi Goodness Simon-Ebo receiving 18 months and Henry Onyedikachi Echefu facing up to 20 years.

Trio-Tech International Reports Ransomware Attack to SEC

California-based semiconductor testing company Trio-Tech International disclosed to the Securities and Exchange Commission that its Singapore subsidiary suffered a ransomware attack discovered on March 11, 2026. Management initially determined the incident was not material, but on March 18 the incident escalated when unauthorized disclosure of company data occurred. The company took its network offline, hired cybersecurity experts, and notified Singapore law enforcement. Files within the subsidiary's network were encrypted, and the company is still working to restore systems. The subsidiary is notifying affected parties, though the specific data compromised has not been disclosed. Trio-Tech International reported more than $36 million in revenue last year with 94% of its customers located in Asia and approximately 600 employees.

Litigation Updates

Google Reaches $5M Settlement Over California Automatic Renewal Law Violations (Case No. 18-CV-328915)

Google agreed to a $5 million class action settlement resolving claims it violated California's automatic renewal law with Google Play subscriptions between May 30, 2014, and October 27, 2019. Plaintiffs claimed Google failed to follow California's automatic renewal law when selling subscriptions through the Google Play Store, resulting in consumers being charged for renewing subscriptions without proper notification. California residents who paid for at least one renewal term of a Google subscription through Google Play checkout are eligible, excluding Google Drive subscriptions, subscriptions canceled during free trials, and fully refunded subscriptions. No claim form is required. Class members will automatically receive estimated payments of $5.85 distributed as Google Play account credits, with Zelle or PayPal payments for those without active accounts. The exclusion and objection deadline is May 9, 2026, with final approval hearing scheduled for July 23, 2026.

Pennsylvania Federal Court Dismisses WESCA Suit Against Healthcare System (Case No. Muraski v. Penn Highlands Healthcare, 2026 WL 353041)

A Pennsylvania federal judge dismissed a suit challenging the use of third-party website analytics tools by Penn Highlands Healthcare, an integrated health system with eight hospitals in Pennsylvania. The Court concluded plaintiffs failed to plead the "specifics" of their interactions with defendant's website, which were "essential to convert [the] case" from a "law-school hypothetical to an actionable dispute" under the Pennsylvania Wiretapping and Electronic Surveillance Control Act (WESCA). The two plaintiffs asserted that Highlands Healthcare used a third-party analytics tool to collect data from their interactions with the website, including IP addresses, URLs, and information submitted through the search bar including medical diagnosis and symptoms. The Court found the exercise of subject-matter jurisdiction proper under the Class Action Fairness Act but dismissed the complaint for failure to state a claim. Following the Eastern District of Pennsylvania decision in Santoro v. Tower Health, the Court determined plaintiffs failed to allege a HIPAA violation with particularity, as they did not specify what medical condition was scheduled, how their inputted information related to their medical care, what protected health information was disclosed, or what confidential diagnoses were revealed.

District Courts Reject CAN-SPAM Preemption Challenges to Washington CEMA

Federal district courts have consistently rejected constitutional and federal preemption defenses in the wave of putative class actions under Washington's Commercial Electronic Mail Act (CEMA) following the Washington Supreme Court's decision in Brown v. Old Navy LLC. Retailers argued the federal CAN-SPAM Act preempts CEMA's subject line provision prohibiting "false or misleading information in the subject line," relying on the Ninth Circuit's decision in Gordon v. Virtumondo. However, recent district court decisions in Shahpur v. Ulta Salon (2026 WL 571122), Kempf v. Fullbeauty Brands (2026 WL 395677), Ma v. Nike (2026 WL 100731), and Harrington v. Vineyard Vines (2025 WL 3677479) distinguished Virtumondo on two grounds: the Ninth Circuit addressed a different CEMA subsection prohibiting use of third-party domain names, and Virtumondo arose in a different factual context involving technical aspects of email header information rather than promotional representations in subject lines. Courts also rejected dormant Commerce Clause challenges, relying on the Washington Supreme Court's decision in State v. Heckel, which upheld CEMA against similar challenges. Courts held that increased compliance costs such as tailoring subject lines or filtering recipient lists by state are insufficient to establish a substantial burden on interstate commerce.

Supreme Court Reverses Qualified Immunity Ruling in Police Excessive Force Case (Zorn v. Linton)

The Supreme Court reversed a 2nd Circuit decision that denied qualified immunity to Vermont detective Jacob Zorn in a lawsuit alleging he used excessive force when arresting Shela Linton during a 2015 demonstration inside the Vermont State House. The 2nd Circuit had reasoned that its 2004 decision in a case involving anti-abortion protesters "clearly establish[ed]" that the tactics Zorn used, such as a rear-wristlock on a protestor passively resisting arrest, constituted excessive force. The Supreme Court majority held that the 2004 case "did not clearly establish that Zorn's specific conduct violated the Fourth Amendment" because it "did not hold that any of" the police officers' actions in that case "violated the Fourth Amendment, let alone all of them," instead sending the case back to the lower court for a jury to consider the plaintiffs' claims. Justice Sotomayor, joined by Justices Kagan and Jackson, dissented, arguing the 2nd Circuit's decision was not so demonstrably wrong that it met the high bar necessary for summary reversal. Sotomayor characterized the ruling as a "resurgence and perpetuation of" the Court's "'one-sided approach to qualified immunity' that 'transforms the doctrine into an absolute shield for law enforcement officers, gutting the deterrent effect of the Fourth Amendment.'"

Meta Faces Class Action Over AI Glasses Privacy Claims (Case No. 3:26-cv-01897)

Meta Platforms is facing a class action lawsuit in California federal court alleging it failed to disclose that its AI smart glasses transmit videos to third-party contractors in Kenya for human review. Plaintiffs Gina Bartone and Mateo Canu filed the complaint on March 4, 2026, alleging violations of federal and state laws. The lawsuit claims Meta marketed the glasses as "designed for privacy, controlled by you," which was false and misleading because videos captured by the glasses are sent to Meta's servers and then to a subcontractor in Kenya where human workers manually view and label footage to train Meta's AI models. Workers in Kenya reportedly view highly sensitive moments such as people changing clothes or engaging in private activities. Plaintiffs claim they purchased the glasses relying on Meta's privacy assurances and would not have bought them had they known the truth. The class action accuses Meta of violating state consumer protection laws and seeks damages and restitution for anyone who purchased the Meta AI glasses in the United States.

Regulatory Guidance

Federal Court Blocks Pentagon Journalist Credentialing Based on Reporting Content

A federal court in Washington DC blocked the Department of Defense from selectively granting press credentials based on the content of journalists' reporting. The decision came in response to a lawsuit by the New York Times after the Defense Department under Secretary Pete Hegseth expelled NBC News, the New York Times, and NPR from the Pentagon press office while welcoming OAN, Newsmax, and Breitbart under new rules requiring journalists to pledge never to publish leaked documents. The court held that "a primary purpose of the First Amendment is to enable the press to publish what it will and the public to read what it chooses, free of any official proscription" and that "the nation's security requires a free press and an informed people" and "such security is endangered by governmental suppression of political speech." The court noted that reporters with decades of Pentagon experience "are not aware of the Department ever suspending, revoking, or not renewing a journalist's credentials due to concern over the safety or security of Department personnel or property or based on the content of their reporting." The court emphasized that decades of precedent matter, not the "vindictive whims" of current officials.

FBI Warns of Russian Phishing Campaign Targeting Signal and Other Messaging Platforms

The FBI and CISA issued a joint warning about a global campaign by Russia's intelligence services targeting commercial messaging applications like Signal, compromising thousands of accounts of current and former U.S. government officials, military personnel, political figures, and journalists. Russian actors are sending phishing messages designed to look like automated support notices, tricking victims into clicking links or providing verification codes and account PINs. If users perform the requested actions, they unwittingly provide attackers with unauthorized access either by adding the attacker's device as a linked device or through full account takeover. After compromising an account, malicious actors can view victims' messages and contact lists, send messages, and conduct additional phishing against other accounts. The advisory emphasizes there is no vulnerability with Signal or other messaging apps and the campaign is specifically designed to circumvent encryption by compromising the users themselves. The notice applies to any messaging app.

FBI Alerts on Iranian Malware Using Telegram for Command and Control

The FBI released a flash alert detailing how Iran's Ministry of Intelligence and Security (MOIS) is using Telegram as infrastructure to communicate with malware targeting Iranian dissidents, journalists, and others. The malware allows MOIS to steal information and monitor targeted individuals. Threat actors made the malware look like commonly used programs or services on Windows machines. Infected devices are connected to bots on Telegram "that enabled remote user access to exfiltrate screen captures or files from the victim devices." The FBI tied the use of Telegram directly to the alleged Iranian group known as Handala Hack, which recently took credit for an attack on medical device company Stryker. The malware was in some cases initially disguised as AI video generator Pictory.

Privacy Developments

Kaplan Data Breach Impacts 230,000+ Individuals

Educational services company Kaplan reported to state regulators that at least 230,000 people had Social Security and driver's license numbers leaked following a cybersecurity incident in fall 2025. The Florida-based company filed breach notification letters in at least seven states. Law enforcement was called after the incident was discovered, and an investigation revealed hackers had access to Kaplan servers from October 30 to November 18, 2025. The hackers "took certain files" containing names, Social Security numbers, and driver's license numbers. Disclosed state-level impacts include 19,075 people in Maine, 26,600 in South Carolina, 173,676 in Texas, and 11,600 in New Hampshire. No hacking group has taken credit for the incident. Kaplan serves about 1.2 million students through test prep services for high school exams like SAT and ACT, as well as graduate exams. The company has offices in 27 countries and works with more than 15,000 corporate clients on employee development programs. Several law firms have begun class action lawsuits related to the incident.

Austrian DPA Upholds CCTV Review Under Article 6(1)(f) GDPR (DSB 2025-0.861.933)

The Austrian Data Protection Authority rejected a complaint under Article 6(1)(f) GDPR, finding that a retail store controller lawfully reviewed CCTV footage to assess a reported coercion incident. A data subject visited a retail store on June 24, 2025, where staff refused card payment at a staffed till and directed the customer to self-service checkout. The data subject insisted on paying by card but ultimately paid cash. Following the incident, the data subject contacted the controller and alleged that the staff's conduct amounted to coercion. The controller operated a CCTV system for protecting property and preventing criminal offenses. After receiving the allegations, the controller reviewed relevant footage on June 26, 2025, to assess the situation, then deleted the footage and informed the data subject of the review. The DPA held that the evaluation of the footage complied with the purpose limitation principle under Article 5 GDPR because the data subject had explicitly alleged a criminal offense, entitling the controller to review the footage to verify this allegation. The DPA emphasized that such evaluation remained within the defined purpose of preventing and investigating potential criminal conduct. The controller limited processing to what was necessary by reviewing only relevant footage, deleting it afterwards, and informing the data subject.

Policy Changes

Congress Prepares Clean Extension of FISA Section 702 Without Reforms

Congress is poised to consider another extension of Section 702 of the Foreign Intelligence Surveillance Act without including necessary reforms. House Speaker Mike Johnson confirmed "the plan is to move a clean extension of FISA for at least 18 months." Two years ago, Congress passed the "Reforming Intelligence and Securing America" Act (RISAA) that included nominal reforms to Section 702 but extended authorities for only two years to allow Congress to continue work on negotiating a warrant requirement for Americans and other critical reforms. However, Congress did not continue this work. House Judiciary Chair Jim Jordan, who previously championed the warrant requirement and closing the data broker loophole, told press he would vote for a clean extension, claiming RISAA included enough reforms. Section 702 was previously misused to run improper queries on peaceful protesters, federal and state lawmakers, Congressional staff, thousands of campaign donors, journalists, and a judge reporting civil rights violations by local police. RISAA further expanded government authority by allowing it to compel a much larger group of people and providers into assisting with surveillance. Three reform bills are currently available for Congress to consider: SAFE, PLEWSA, and GSRA, all of which are significantly better than a clean extension.

Supreme Court Poised to Overturn Mississippi Mail-In Ballot Receipt Law

The Supreme Court appeared ready to overturn a Mississippi law allowing mail-in ballots to be counted as long as they are postmarked by and received within five business days of Election Day. After two hours of oral argument in Watson v. Republican National Committee, a majority of justices agreed with challengers that the Mississippi law conflicts with federal laws setting the Tuesday after the first Monday in November as "election day." More than a dozen states have similar laws. Mississippi passed the law in 2020 in response to the COVID-19 pandemic. The Republican National Committee, Mississippi Republican Party, a Mississippi voter, a county election official, and the Libertarian Party of Mississippi challenged the law. A 5th Circuit three-judge panel agreed that federal law requires all ballots to be received by Election Day. Mississippi Solicitor General Scott Stewart argued states have broad power over elections and laws like Mississippi's are consistent with federal law because voters make their final choices by Election Day. Challengers countered that when Congress initially passed the law establishing Election Day, the casting and receipt of ballots were "so inextricably intertwined" that a ballot is final when received by election officials. The court's ruling is expected by late June or early July and could have significant implications for federal elections beginning in November.

Compliance Takeaways