← Carolina Clear Tech

Legal & Privacy Brief

2026-04-01

Listen to this brief (21:58)

Download MP3
Show Notes

Show Notes - 2026-04-01

Stories Covered

CVEs Referenced

CVE-2025-5777, CVE-2026-3055

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - April 1, 2026

Today: Spain's data protection authority fined utility provider Gesternova €220,000 for processing customer data without consent through marketing contractors. Three Washington state class actions target Béis for deceptive email subject lines designed to mimic fraud alerts. Federal prosecutors indicted a Maryland man for stealing $54 million from cryptocurrency platform Uranium Finance through smart contract exploits.

Enforcement Actions

Spanish DPA Fines Utility €220,000 for Contractor Data Collection (AEPD Case EXP202307472)

Spain's data protection authority (AEPD) fined utilities company Gesternova €220,000 (€200,000 for Article 6(1) GDPR, €20,000 for Article 13 GDPR) after its marketing contractor collected customer personal data before a sales call without obtaining consent. The controller received an email containing a contract proposal with the data subject's full name, ID information, contact details, partial bank information, and energy supply data. Gesternova claimed the processor (Several) acted as a separate controller, but the AEPD ruled Gesternova determined the means and purposes of processing under Article 4(7) GDPR. The authority found Gesternova responsible for implementing mechanisms to verify lawfulness of contractor processing activities and cannot claim ignorance of processor operations. The controller also failed Article 13 GDPR transparency obligations by not informing the data subject about controller identity, processing purposes, legal bases, or data subject rights during the marketing call. AEPD ordered compliance within six months subject to additional fines.

Maryland Man Indicted for $54 Million Cryptocurrency Theft (US v. Spalletta)

Federal prosecutors indicted Jonathan Spalletta, 36, of Maryland on one count of computer fraud and one count of money laundering for allegedly stealing $54 million from cryptocurrency platform Uranium Finance in April 2021. Spalletta conducted a first attack on April 8, 2021, extracting $1.4 million by exploiting code errors. Uranium Finance negotiated a bug bounty allowing Spalletta to keep $386,000 in exchange for returning the rest and no prosecution. On April 28, 2021, Spalletta exploited a different vulnerability to steal $53.3 million, forcing Uranium Finance to shut down. He laundered the funds through Tornado Cash mixer before purchasing antique items. The Justice Department seized $31 million in cryptocurrency traced by TRM Labs and seized high-priced antiques purchased with stolen funds. Spalletta faces a maximum 30 years imprisonment. U.S. Attorney Jay Clayton stated the case demonstrates that stealing from cryptocurrency platforms is prosecuted as theft despite claims that crypto is different.

CISA Orders Federal Agencies to Patch Citrix NetScaler by Thursday (CVE-2026-3055)

The Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to patch CVE-2026-3055 by Thursday, April 3, 2026, after incident responders reported active exploitation over the weekend. The critical vulnerability (severity 9.3/10) affects Citrix NetScaler application delivery controllers (ADC) and NetScaler Gateway, enabling unauthenticated attackers to leak and read sensitive memory from deployments. Citrix disclosed and patched the bug on March 23, 2026. WatchTowr researchers reported exploitation on Sunday, March 30. The vulnerability has hallmarks of CitrixBleed (2023) and Citrix Bleed Two (CVE-2025-5777, summer 2025), both of which targeted critical infrastructure, hospitals, and government organizations. The original CitrixBleed in 2023 affected over 300 organizations according to CISA warnings and was exploited by ransomware gangs and nation-state actors. CVE-2025-5777 was allegedly used to target Pennsylvania's Attorney General Office and the Netherlands Public Prosecution Service.

Finland DPA Reprimands Credit Bureau for Access Request Violations (TSV/3375/2023)

Finland's data protection authority reprimanded a credit information controller for improperly handling access requests in violation of Articles 12(2), (3), (4), (5), and 15(4) GDPR. The controller responded to email access requests with standard messages directing data subjects to use the OmaData portal without taking further action or informing subjects whether it would act on requests. The DPA found this violated Article 12(2) facilitation requirements and Article 12(3) notification obligations. The controller's website stated access was free once within 12 months, charging €9.90 for subsequent requests concerning credit data. The DPA ruled this systematic fee violated Articles 12(5) and 15(4) because the controller did not assess on a case-by-case basis whether requests were repetitive, manifestly unfounded, excessive, or constituted new requests versus additional copies. The authority issued compliance orders for access request procedures.

Litigation Updates

Galderma Settles Differin Benzene Class Action for $990,000 (Williams v. Galderma, N.D. Ill.)

Galderma Laboratories agreed to a $990,000 class action settlement resolving claims that it misled consumers about possible benzene contamination in Differin acne products. The settlement covers purchasers of Differin Daily Deep Cleanser (5% benzoyl peroxide), Differin Acne Spot Treatment (10% benzoyl peroxide), and Differin Maximum Strength Acne Foaming Cleanser (10% benzoyl peroxide) between January 1, 2020, and February 19, 2026. The lawsuit alleged Differin failed to warn consumers about possible benzene contamination. Benzene is a known human carcinogen that can cause leukemia and other blood disorders. Class members can claim $9 per product with proof of purchase (unlimited claims) or $9 per product for up to three products without proof of purchase ($27 maximum). The final approval hearing is scheduled for June 30, 2026, in Case No. 1:24-cv-02222. Galderma has not admitted wrongdoing.

Three Washington Class Actions Target Béis for Deceptive Email Subject Lines

Three separate class action lawsuits were filed in Washington state courts against travel gear retailer Béis LLC alleging violations of the Washington Commercial Electronic Mail Act (CEMA) and Washington Consumer Protection Act (CPA) through deceptive email subject lines. Plaintiff Lilli Huong filed in King County (Case No. 25-2-37931-1 SEA) regarding a November 30, 2025, email with subject line "Action required: fraud alert" that advertised a 30% off sale extension. Plaintiff Kimberly Noble filed in Pierce County (Case No. 26-2-05533-1) regarding a December 1, 2025, email with the same subject line, where the email body stated "The fraud is us... sale now extended," proving intentional deception. Plaintiff Melinda Mott filed in Spokane County (Case No. 26-2-00036-32) alleging false time scarcity and dark patterns with misleading deadlines and countdowns creating false urgency for discounts that remained active. CEMA prohibits commercial emails to Washington residents containing false or misleading subject line information. Plaintiffs seek statutory damages of $500 per email or actual damages (whichever is greater), treble damages, attorneys' fees, and permanent injunctions.

Intuit Sued for Military Lending Act Violations on TurboTax Refund Loans (Bostick v. Intuit, C.D. Cal.)

Plaintiff Zachary Bostick filed a class action in California federal court alleging Intuit Inc. and subsidiaries (Intuit TT Offerings Inc., CK Progress Inc. d/b/a Credit Karma, MVB Bank Inc., First Century Bank N.A., Santa Barbara Tax Products Group LLC, Green Dot Bank) violated the Military Lending Act by charging excessive fees on TurboTax refund advance loans to covered borrowers. Bostick argues the loans are marketed as 0% interest but the Military Annual Percentage Rate (MAPR) calculation must include fees imposed as conditions of credit extension. The lawsuit claims defendants required borrowers to waive rights to seek court relief as a loan condition. Bostick seeks to represent a nationwide class of covered borrowers who obtained TurboTax refund advance loans and were required to authorize federal tax refund routing through temporary deposit accounts used for loan repayment and fee deduction. The complaint alleges standardized practices uniformly applied to all refund advance loan consumers.

Supreme Court Debates Federal Arbitration Award Jurisdiction (Jules v. Andre Balazs Properties)

The Supreme Court heard oral arguments on March 31, 2026, in a case examining whether federal courts can confirm arbitration awards when a case was pending in federal court prior to arbitration. The specific question follows from Badgerow v. Walters (2022), which held federal courts cannot entertain free-standing suits to confirm or vacate arbitration awards without independent jurisdiction. Justice Sonia Sotomayor suggested confirmation is merely a motion in an existing case, while Justice Elena Kagan (who authored Badgerow) rejected supplemental jurisdiction arguments, stating the arbitration confirmation involves different facts (such as arbitrator fraud) unrelated to underlying claims. Justices Clarence Thomas, Brett Kavanaugh, and Neil Gorsuch noted inconsistent results: federal question jurisdiction cases would move to state court for confirmation while diversity cases remain in federal court. Gorsuch stated he was "struggling to come up with a reason why Congress in the Federal Arbitration Act might have wanted diversity cases to remain in federal court for confirmation proceedings but federal question cases to go to state court."

Regulatory Guidance

North Korean Group Linked to Axios Supply Chain Attack (UNC1069)

Google Threat Intelligence Group (GTIG) attributed the axios npm package supply chain attack to North Korean threat actor UNC1069, a financially-motivated group with deep experience in supply chain attacks historically used to steal cryptocurrency. Two malicious axios versions were published to npm on Tuesday morning after attackers hijacked the lead maintainer's npm account. The malicious package deploys a multi-stage payload including a remote access trojan (RAT) capable of executing arbitrary commands, exfiltrating system data, and persisting on infected machines. The attack impacts Windows, macOS, and Linux. Axios is downloaded 100 million times per week and embedded across frontend frameworks, backend services, and enterprise applications. The backdoors resemble WAVESHAPER malware used by North Korean actors in a fake Zoom campaign targeting cryptocurrency companies. StepSecurity described this as among the most operationally sophisticated supply chain attacks ever documented against a top-10 npm package. The malware deletes itself after execution and replaces with a clean version to evade detection. Axios maintainers initially could not regain project control as the attacker's permissions exceeded collaborator access levels.

New Criminal Service Monetizes Ransomware-Stolen Data (Leak Bazaar)

A newly-proposed cybercrime service called Leak Bazaar is advertising across dark web criminal forums promising to process stolen data from ransomware attacks into structured, searchable intelligence for sale or extortion. Leak Bazaar positions itself as a data processing business rather than ransomware-as-a-service, taking vast datasets stolen in cyberattacks and converting them into actionable intelligence. Flare researcher Tammy Harper describes it as "effectively an e-discovery service for stolen data." The service represents attempts to monetize the enormous volume of personal information hoarded by ransomware groups that is typically unused except for initial extortion. Metropolitan Police Service cybercrime head Will Lyne noted that LockBit disruption proved groups do not delete data after promising to do so, indicating threat actors know stolen data has ongoing value. Risks include increased leverage to pressure ransom payments, enabling follow-on fraud and business email compromise, and direct extortion of individuals by threatening to publish sensitive data. However, experts note limited evidence of systematic personal data exploitation at scale, as personal extortion runs counter to current ransomware economics.

Privacy Developments

Supreme Court Hears Birthright Citizenship Case (Trump v. Barbara)

The Supreme Court heard oral arguments on April 1, 2026, in Trump v. Barbara, directly addressing the legality of President Trump's executive order limiting who is treated as a U.S. citizen at birth. Unlike the first trip to the Supreme Court (which focused on federal judges' power to block presidential directives nationwide), Barbara directly addresses citizenship law rather than immigration law. Historically, the Court has been less willing to let the president unilaterally set citizenship terms compared to immigration regulation. The Court has long given the executive branch remarkable flexibility to determine who can enter the United States under the plenary power doctrine, but the Court wrote in a 1977 case that "Congress regularly makes rules that would be unacceptable if applied to citizens" and citizenship "is regarded as the highest hope of civilized men." The executive order affects children of unauthorized parents as well as children born to parents lawfully present on student visas, work visas, and those awaiting green cards. Arguments focused on United States v. Wong Kim Ark (1898), which recognized citizenship of children born on American soil under the American flag. The Hintopoulos case (1957) recognized citizenship of children of illegal aliens. ACLU counsel Cecillia Wang argued the 14th Amendment phrase "subject to the jurisdiction thereof" focuses on persons born, not parents giving birth, and the executive order strips citizenship from countless children born to lawfully present parents.

Policy Changes

Pentagon Press Access Restrictions Face Compliance Hearing

A March 31, 2026, hearing examined whether the Department of Defense complied with an earlier ruling striking down Pentagon press access restrictions. The hearing focused on a dispute between the government and the New York Times over the Pentagon's revised policy. Cmdr. Tim Parlatore, special adviser to the Secretary of War, stated in a New York Times interview "We used more words to say the same thing and to foreclose creative misinterpretations." The Defense Department closed the Correspondents Corridor that served as workspace for credentialed journalists covering the military, physically tearing down signage. Reporters can no longer enter the main building unescorted and will conduct future business in an as-yet-unfinished annex. Judge Friedman presided over the hearing of the Times's motion to compel compliance. The government admitted contravening the judge's order to the entity that secured the original court order.

Meta Proactively Offered Content Removal to DOGE After Denouncing Government Censorship

Mark Zuckerberg texted Elon Musk on February 3, 2025, stating "Looks like DOGE is making progress. I've got our teams on alert to take down content doxxing or threatening the people on your team. Let me know if there's anything else I can do to help." This occurred 24 days after Zuckerberg's January 10, 2025, appearance on Joe Rogan's podcast denouncing Biden administration pressure to remove content. Zuckerberg's text offered to suppress information identifying federal employees working for the Department of Government Efficiency (DOGE), including truthful information like names of public servants. The Supreme Court found in Murthy v. Missouri that Biden administration communications Meta described as pressure were standard government speech happening "literally thousands of times a day in the federal government" and not coercion. Zuckerberg admitted on Rogan that Meta's response to Biden administration requests was to refuse: "We're not going to take down things that are true." The only documented specific Biden administration takedown request was flagging an account impersonating one of Biden's grandchildren. Zuckerberg framed identifying DOGE employees as "doxxing" while proactively volunteering content removal to a senior government official.

Compliance Takeaways