Get tomorrow's brief in your inbox
Today: DOJ secures $150 million settlement from Adobe over deceptive subscription practices that buried cancellation fees in fine print and created deliberately convoluted cancellation processes. Meta and Google face $3 million in compensatory damages after a California jury finds them negligent for designing platforms to addict child users. EFF sues CMS over Medicare's WISeR AI program that uses algorithms to evaluate medical care requests with no public disclosure of training data, accuracy testing, or bias safeguards.
Adobe DOJ Settlement ($150M) - ROSCA Violations
Adobe will pay $150 million to resolve Department of Justice allegations that its subscription practices violated the Restore Online Shoppers' Confidence Act. The settlement includes $75 million in civil penalties to the U.S. Treasury and $75 million in free services to customers. DOJ alleged Adobe used fine print and inconspicuous hyperlinks to hide early termination fees and created deliberately complex cancellation processes with unnecessary steps, delays, and unsolicited offers. Adobe executives David Wadhwani and Maninder Sawhney allegedly oversaw these practices in their leadership roles. The settlement requires Adobe to clearly disclose any early termination fee and explain fee calculations before enrollment. For free trials exceeding seven days, Adobe must notify customers before conversion to paid plans that include termination fees. Adobe must also provide simple cancellation methods. Case: United States of America v. Adobe Inc., et al., Case No. 3:24-cv-05170, N.D. Cal.
Russian Botnet Operator Sentenced - Mario Kart Cybercrime Group
Russian national Ilya Angelov, 40, received a 24-month prison sentence and $100,000 fine for managing a botnet used by ransomware gangs. Angelov was one of the leaders of the Mario Kart cybercrime group (also tracked as TA-551, Shathak, Gold Cabin, Monster Libra) that distributed malware through massive phishing campaigns reaching up to 700,000 emails per day. The botnet compromised approximately 3,000 machines daily at peak operation. Angelov and co-managers monetized the botnet by selling access to individual compromised computers to ransomware operators. One customer distributed BitPaymer ransomware, which infected 72 U.S. networks between August 2018 and December 2019, generating over $14 million in ransom payments. Another group linked to IcedID malware paid approximately $1 million for botnet access in late 2019 or early 2020. Angelov operated under the aliases "milan" and "okart."
Amazon Unpaid Wages Class Action Settlement ($2M)
Amazon agreed to pay $2 million to resolve claims it failed to provide meal and rest breaks to hourly employees in Washington state. The settlement benefits individuals employed by Amazon Retail LLC in Washington in hourly positions between October 3, 2021, and October 27, 2025. Amazon has not admitted wrongdoing. Class members will receive cash payments varying by wages earned during the class period, with a guaranteed minimum of $50. Higher wage earners receive larger shares of the settlement fund. No claim form is required; class members automatically receive benefits unless they exclude themselves. Exclusion and objection deadline is April 30, 2026. Final approval hearing is scheduled for May 22, 2026. Case: Garner v. Amazon Retail LLC, Case No. 24-2-11344-0, Superior Court of Washington, Pierce County.
SoFi Data Breach Class Action - 38,000 Individuals Affected
Plaintiff Joshua Cook filed a class action against SoFi Technologies in California federal court alleging the company failed to protect customer personal information during a late 2025 data breach. The breach compromised names, dates of birth, addresses, email addresses, phone numbers, employment information, and education information of at least 38,049 individuals. Cook alleges SoFi failed to timely notify affected consumers, offer adequate assurances that personal information has been recovered or destroyed, or implement reasonable data security measures. Cook asserts claims for negligence, negligence per se, breach of contract, breach of implied contract, unjust enrichment, declaratory judgment, and violations of the Illinois Consumer Fraud and Deceptive Business Practices Act. The complaint alleges SoFi failed to comply with FTC guidelines and industry standards for data protection despite the substantial increase in cyberattacks targeting electronic records. Case: Cook v. SoFi Technologies Inc., Case No. 3:26-cv-01722, N.D. Cal., San Francisco Division.
Meta and Google Found Negligent in Social Media Addiction Case
A California jury found Meta and Google negligent for designing platforms to addict child users in a landmark social media case. The companies face $3 million in compensatory damages for pain and suffering plus additional financial penalties. This verdict represents one of the most significant social media trials addressing platform design practices targeting minors.
Amazon Prime Class Action Dismissed - CPA Claim Deficiencies
U.S. District Judge Kymberly K. Evanson dismissed a class action against Amazon filed by Prime subscribers who claimed they were unable to receive promised two-day shipping. The Prime subscribers alleged Amazon violated Washington's Consumer Protection Act by failing to disclose it had stopped using contractor-operated delivery vans in their zip codes. Judge Evanson found the plaintiffs failed to identify an unfair or deceptive practice and failed to plead facts supporting the causation element of their claims. The plaintiffs did not identify where or when Amazon promised or suggested Prime membership entitles subscribers to two-day delivery at a particular frequency, which was fatal to their CPA unfairness claim. The plaintiffs also failed to establish causation, with some continuing to subscribe to Prime despite awareness of slower delivery times. The court granted leave to amend the complaint by April 6, 2026. Case: King, et al. v. Amazon.com Services LLC, Case No. C24-2009-KKE, W.D. Wash.
Boston Red Sox Class Action - Drip Pricing Allegations
Plaintiffs Damon Campagna, Lily Rose Smith, and Patrick Spaulding filed a class action in Massachusetts federal court alleging the Boston Red Sox falsely advertised Fenway Park ticket prices using "drip pricing" and hidden fees. The plaintiffs claim the Red Sox advertised "illusorily low prices" only to add mandatory Per-Ticket Fees and Order Fees that could increase ticket costs by as much as 150%. The plaintiffs seek to represent a nationwide class of consumers who purchased Fenway Park tickets between January 16, 2022, and the present and paid additional fees not included in initial price advertisements. The plaintiffs allege violations of Mass. Gen. Laws ch. 93A and other state consumer protection laws, arguing drip pricing and junk fees misled ticket buyers and caused them to pay more than intended. They demand declaratory and injunctive relief and actual and treble damages. Case: Campagna, et al. v. Boston Red Sox Baseball Club L.P., et al., Case No. 1:26-cv-10182, D. Mass.
RealPage Rent Price Fixing Litigation Update
Multiple lawsuits, including a 2024 DOJ case, allege RealPage enabled landlords to coordinate rent pricing through its YieldStar algorithm instead of competing. The lawsuit claims the algorithm collected private data from competing property managers and recommended higher rent prices, allowing landlords to raise rents in sync. Estimates suggest renters paid 5% to 7% more than competitive market rates. November 2025: RealPage reached a settlement with DOJ requiring 3 years of monitoring and limitations on data collection and use. September 2025: Nevada AG reached settlement with RealPage. Landlords and property managers, including Greystar, agreed to settlements totaling over $140 million. January 2025: DOJ expanded its lawsuit to include six major property management companies. April 2023: RealPage lawsuits consolidated into MDL 3071. Individuals who signed leases after October 21, 2018, where property managers used RealPage software may be eligible for compensation.
Judge Denies Protective Order for DOGE Deposition Videos
U.S. District Judge Colleen McMahon denied the government's motion for a protective order seeking to suppress deposition videos of DOGE operatives Justin Fox and Nate Cavanaugh in the National Endowment for the Humanities lawsuit. The government argued the videos, which show the operatives struggling to explain how they used ChatGPT to decide which humanities grants to eliminate and failing to define "DEI" despite it being the basis for their work, led to harassment and death threats. Judge McMahon initially ordered plaintiffs to remove the videos from YouTube but reversed course after finding the government failed to show "good cause" for suppression. The videos are now publicly available. Judge McMahon criticized plaintiffs for procedural tactics in submitting videos on a thumb drive without filing them on the docket, but ultimately ruled the government's motion did not meet the legal standard for a protective order.
Bankrupt Debtor Judicial Estoppel Case
The Supreme Court heard oral argument in Keathley v. Buddy Ayers Construction, Case involving a bankrupt debtor who failed to disclose to the bankruptcy court a car accident that might produce additional assets for creditors. The lower court applied judicial estoppel to dismiss Keathley's lawsuit against the other driver's employer, reasoning that Keathley improperly benefited in bankruptcy by not disclosing the incident. Multiple justices expressed skepticism of the absolute standard applied by the lower court. Justice Neil Gorsuch suggested a "short and succinct" opinion finding that characterizing the omission as a "mistake" or "inadvertence" would be enough to excuse it. Justice Elena Kagan suggested complete inadvertence and absence of intention to mislead would weigh against barring the suit. Chief Justice John Roberts noted it seemed "a little much" that the party at fault gets off the hook, characterizing the ruling below as creating a windfall for the defendant. Justice Ketanji Brown Jackson called the ruling "harsh."
Supreme Court Venue Case - Federal Prosecution Location
The Supreme Court will hear oral argument Monday in Abouammo v. United States, considering whether federal prosecutors can try defendants not only in the district where the offense occurred but also where the crime's "contemplated effects" are felt. Ahmad Abouammo worked at Twitter's San Francisco headquarters from 2013 to 2015 as a media partnerships manager with access to tools that could pull users' private identifying data. Prosecutors say he passed information about Saudi dissidents to a Saudi royal court official in exchange for a luxury watch and $300,000 in wire transfers. One humanitarian worker's information was disclosed; he was detained in Saudi Arabia, held in solitary confinement, and tortured. Abouammo moved to Seattle in 2015. FBI agents from the San Francisco field office interviewed him in Seattle, where he fabricated a backdated invoice and emailed it to agents. A San Francisco grand jury indicted him for falsifying records under 18 U.S.C. section covering falsification "in relation to or contemplation of any such matter." The 9th Circuit held Abouammo could be prosecuted in San Francisco because the false document was directed at and received by agents working from the San Francisco field office. Abouammo argues Article III requires trial in the state where crimes were committed and that his only act of falsification occurred entirely in Seattle.
Supreme Court Arbitration Jurisdiction Case
The Supreme Court will hear argument in Jules v Andre Balazs Properties on whether a federal court that has a pending case over which it had jurisdiction to compel arbitration can use that jurisdiction to confirm the arbitration award. The case follows Badgerow v Walters (2022), which held federal courts do not have jurisdiction based on the Federal Arbitration Act to grant relief confirming arbitration awards. Adrian Jules filed suit in federal court raising employment discrimination claims. The court ordered arbitration and stayed the action pending results but did not dismiss. After Balazs prevailed in arbitration, it asked the federal court to confirm the award and dismiss Jules' claims. Lower courts granted relief, holding jurisdiction over the original action provided authority to confirm the award. Jules argues Badgerow establishes that once arbitration has been compelled, the FAA does not provide further jurisdiction to federal courts. Jules notes FAA Section 3 authorizes a stay "until arbitration has been had" and argues the stay necessarily ends when arbitration is complete, ending the court's jurisdiction. Balazs points to supplemental jurisdiction under 28 U.S.C. section 1367, which authorizes federal courts to adjudicate all "related" claims that are "part of the same case or controversy."
Voter Identification Laws - Crawford v. Marion County
SCOTUSblog analysis examines Supreme Court precedent on photo identification requirements for voting in light of the proposed SAVE Act. The SAVE Act would require individuals to provide documentary proof of citizenship when registering to vote and photo identification at voting. It would require photocopies of ID for absentee mail ballots, frequent voter roll reviews to remove noncitizens, states to share voter registration data with the federal government, and create personal criminal liability for election officials who violate the law. The bill passed the House in February 2026 and is stalled in the Senate by Democratic filibuster. The major Supreme Court precedent is Crawford v. Marion County Election Board (2008), which upheld Indiana's voter ID law without a majority opinion. Justice John Paul Stevens announced the judgment in an opinion joined by Chief Justice John Roberts and Justice Anthony Kennedy, applying Anderson v. Celebrezze balancing test for evenhanded restrictions protecting electoral integrity. Stevens found minimal burden because most people have picture identification and those without can cast provisional ballots. Justice Antonin Scalia concurred in an opinion joined by Justices Clarence Thomas and Samuel Alito, arguing strict scrutiny applies only when burdens are "severe."
FCC Foreign Router "Ban" - Covered List Expansion
FCC Chairman Brendan Carr announced the FCC will add all foreign-made routers to the agency's "covered list," effectively banning their sale in the United States unless manufacturers obtain "conditional approval" from the Trump administration via the Department of Defense or Department of Homeland Security. The policy requires manufacturers to pay application fees and obtain favors for approval. The FCC claims the action is necessary because malicious state and non-state cyber attackers have leveraged vulnerabilities in small and home office routers produced abroad to attack American civilians. Critics note the recent Salt Typhoon hack, involving Chinese state-sanctioned hackers compromising U.S. telecom networks, largely involved the broadly deregulated U.S. telecom sector failing to change default admin passwords and hiding evidence of intrusion for liability reasons. The Trump administration has gutted numerous government cybersecurity programs, dismantled the Cyber Safety Review Board, and eliminated oversight of domestic telecom privacy and security standards.
CISA Shutdown Impact on Cybersecurity
CISA Acting Director Nick Andersen testified before the House Homeland Security Committee that the Department of Homeland Security shutdown has led to risks "accumulating across the system." Approximately 60% of CISA's workforce is now furloughed. CISA currently has 1,000 vacancies and in a single day six members of a highly technical threat hunting and incident response team submitted resignations. Remaining personnel carry out mission essential functions without pay while facing increasing pressure from nation-state and criminal actors. CISA is largely limited to responding to imminent threats, protecting life and property, sharing critical vulnerability and incident information, and keeping its 24/7 operation center running. Delays in issuing binding operational directives, reduced coordination with industry partners, and constrained incident response capacity create openings for adversaries. CISA has been constrained in work with the private sector, state and local partners, and across the federal ecosystem. Risks are growing as CISA prepares for the heightened threat environment accompanying the America 250 celebration events and FIFA World Cup. Intelligence information sharing continues but capacity has become "exceedingly strained." Andersen warned the shutdown will create downstream impacts making it harder to recruit talent to DHS and CISA.
California Data Broker Registry - 33 Companies Selling Data to Foreign Actors
California released an updated registry of data brokers on March 24, identifying 33 companies in the business of collecting, inferring, aggregating, and selling people's data to foreign actors.
EFF Lawsuit - Medicare AI Program (WISeR)
The Electronic Frontier Foundation filed a FOIA lawsuit against the Centers for Medicare & Medicaid Services seeking records about the WISeR (Wasteful and Inappropriate Service Reduction) program, which uses AI to evaluate prior authorization requests from Medicare beneficiaries. Announced by CMS Administrator Dr. Mehmet Oz, WISeR was rolled out in six states in January, potentially affecting 6.4 million Medicare beneficiaries. There is little public information about how the AI algorithms work, including training data, safeguards against algorithmic bias, privacy violations, and wrongful denials of care. By design, WISeR incentivizes contracted companies to deny prior approval against the best interests of patients. Vendors are compensated in part on the volume of healthcare services they deny and are entitled to as much as 20% of associated savings. Hospitals and healthcare providers have reported delays in care approval, communication gaps, and administrative strain. EFF's FOIA request seeks agreements with software vendors participating in WISeR, records related to tests for accuracy, bias, or hallucinations in vendors' technology, and records related to audits, monitoring, or evaluation of WISeR. CMS has not provided any records to date.
Meta Ray-Bans Privacy Concerns
EFF's EFFector newsletter examines privacy implications of Meta Ray-Bans smartglasses with embedded cameras and microphones. The newsletter notes that sometimes it is not just the owners watching what these devices record. EFF Security and Privacy Activist Thorin Klosowski discussed smartglasses and privacy concerns on the EFFector podcast.
D.C. Personal Health Data Security Amendment Act
EPIC Senior Counsel Sara Geoghegan testified before the D.C. City Council's Committee on Health on March 23 in support of the Personal Health Data Security Amendment Act of 2025. The bill, introduced in December, would provide privacy protections for District residents' sensitive health data. It would prohibit geofencing around facilities that provide health services and require entities that handle personal health data to implement security safeguards.
Agent Washing Disclosure Risks
Debevoise Data Blog analysis examines "agent washing," where companies overstate AI tool capabilities by calling conventional automation "agentic" or overstating the degree of autonomy, reliability, or business impact of AI agents. Agent washing poses greater risk than general AI washing because the term "agent" is unusually elastic and can refer to anything from a chatbot executing one API call to a multi-step system that plans, reasons, retrieves data, uses tools, and takes actions across enterprise applications. Market pressure is increasing on companies to assert they have deployed AI agents producing measurable business outcomes, creating incentives to stretch terminology and market pilots as scaled production systems. Specific claims about agentic AI (such as "handles onboarding," "reviews contracts," "executes trades") are easier for regulators, plaintiffs, customers, whistleblowers, or journalists to test against actual functionality, failure rates, and human involvement.
Section 702 Surveillance Abuse Warning
Senator Ron Wyden delivered a Senate floor speech warning of another Section 702 abuse in the context of opposing Joshua Rudd's nomination to lead the NSA. Wyden protested Rudd being unwilling to agree to basic constitutional limitations on NSA surveillance. The speech serves as a jumping-off point ahead of Section 702's upcoming reauthorization deadline.
Government Asylum Violations
In testimony before Maryland federal Judge Stephanie Gallagher, U.S. Citizenship and Immigration Services asylum officer Kimberly Sicard testified that more than 100 asylum seekers covered by a settlement agreement have been removed in the past three to four weeks. The number is in the "low 100s." Sicard testified officials "queried systems" to identify the removals. The matter went to the office of chief counsel at USCIS three to four weeks ago. This represents violations of an existing court order and settlement agreement protecting asylum seekers from wrongful removal.
Fulton County Ballot Seizure
Lawfare analysis by Anna Bower examines the government's warrant to search and seize hundreds of boxes containing 2020 presidential election ballots from the Fulton County election office in Georgia. Bower argues the seizure omitted exculpatory evidence and rests on weak legal theories and fraud claims, raising broader concerns of institutional integrity. The affidavit supporting the warrant does not hold up under scrutiny. Its theory of probable cause relies on allegations that are legally uncertain, factually unsupported, or directly contradicted by prior investigations whose exculpatory findings it consistently omits. Judge Boulee is considering whether these deficiencies satisfy Rule 41(g)'s demanding "callous disregard" standard at an evidentiary hearing. A ruling returning the ballots would still leave unanswered how a warrant so fundamentally flawed cleared internal Justice Department review and received magistrate approval to authorize the extraordinary seizure of ballots from more than half a million voters in a state whose election the president had sought to overturn.
OMB AI Memo - Public Trust in AI
The Office of Management and Budget released a memo on public trust in artificial intelligence. Analysis by Merve Hickok unpacks the goals and shortcomings of the memo addressing biased AI in government.
Subscription Disclosures: Review all subscription agreements and cancellation workflows following the $150M Adobe DOJ settlement. Ensure material terms, including early termination fees and fee calculations, are disclosed clearly before enrollment. Implement simple cancellation mechanisms. ROSCA violations carry civil penalties and require free services to affected customers.
Data Breach Response: Document notification timelines and credit monitoring offerings following the SoFi class action. California law requires notification "without unreasonable delay." FTC and state AG guidance expects timely notification and remediation offers. Negligence claims succeed when plaintiffs show failure to implement reasonable security measures given foreseeable risks.
Pricing Transparency: Eliminate drip pricing practices following Boston Red Sox and other junk fee class actions. State consumer protection laws increasingly prohibit advertising prices that do not include all mandatory fees. Disclosed prices must match actual purchase prices.
AI System Disclosures: Substantiate all claims about AI agent capabilities, autonomy, and business impact. Document actual functionality, human involvement requirements, and performance metrics. Avoid agent washing by ensuring marketing claims are testable and verifiable. SEC disclosure rules and state consumer protection laws prohibit material misrepresentations about product capabilities.
Medicare Prior Authorization Appeals: Healthcare providers should document WISeR program delays and denials. Patients have appeal rights under 42 C.F.R. Part 405. Track denial patterns and patient harm for potential congressional oversight or litigation challenging the program's adequacy and bias safeguards.