CVE-2025-10035, CVE-2026-23760
Get tomorrow's brief in your inbox
Today: Google settles $135 million Android data transfer class action while Nike faces litigation over a January 2026 data breach that exposed customer payment data. Tech companies pledge to continue CSAM scanning in Europe despite the expiration of legal protections, and Congress reintroduces legislation to grant copyright protection to building codes and safety standards incorporated into law.
FBI Reports $17.6 Billion in Cyber Fraud Losses for 2025
The FBI's Internet Crime Complaint Center reported that cyber-enabled fraud accounted for 85% of all losses in 2025, totaling $17.6 billion across over 1 million complaints. Investment fraud led all categories at $8.6 billion, followed by business email compromise scams at $3 billion and tech support fraud at $2.1 billion. Ransomware complaints increased to 3,611 incidents with over $32 million in reported losses, up from 3,156 complaints and $12 million in 2024. The FBI is currently investigating over 200 ransomware variants and identified 63 new variants last year. Fourteen of the sixteen U.S. critical infrastructure sectors were victims of ransomware attacks in 2025.
German Authorities Identify Two REvil Ransomware Suspects
Germany's Federal Criminal Police Office identified two suspects linked to the REvil and GandCrab ransomware gangs. Mikhail Shchukin, a 31-year-old Russian national using the alias UNKN, and Anatoly Kravchuk, a 43-year-old Ukraine-born Russian citizen, are wanted internationally for approximately two dozen ransomware attacks that generated nearly $2.3 million in extorted payments and caused over $40 million in economic damage. Both suspects are believed to be in Russia. REvil operated under a ransomware-as-a-service model and targeted high-profile victims including Lady Gaga's law firm, President Trump, and software provider Kaseya before being dismantled in 2021.
First Stalkerware Manufacturer Convicted Since 2014 Receives No Jail Time
Bryan Fleming, founder of pcTattletale, was sentenced to a $5,000 fine and no prison time beyond one day already served after pleading guilty in January to one count of manufacturing, distributing, possessing and advertising wire, oral or electronic communication intercepting devices. Fleming's Michigan-based stalkerware company sold surveillance products marketed for spying on spouses and others without consent. The prosecution resulted from a Homeland Security Investigations probe that began in June 2021 and covered more than 100 stalkerware companies. Fleming promoted the product on YouTube showing how users could install it on Android phones where "they won't be able to see it" and view "a movie of everything they've done."
$135 Million Google Android Data Transfer Settlement (Case No. 5:20-cv-07956-VKD)
Google agreed to a $135 million class action settlement to resolve claims that Android devices transferred information to Google without user permission over cellular data networks. The lawsuit, Taylor, et al. v. Google LLC, in the U.S. District Court for the Northern District of California, alleges that Google's Android operating system caused devices to transfer information in the background even when idle, using cellular data instead of Wi-Fi connections. The settlement benefits approximately 100 million class members who used Android devices with cellular data plans to access the internet since November 12, 2017. Each class member is expected to receive an equal payment from the settlement fund, though exact amounts are not yet available. Google also agreed to update its Google Play Terms of Service, Help Center documentation, and device setup screens to disclose the conduct and request user consent. The deadline for exclusion and objection is May 29, 2026, and the final approval hearing is scheduled for June 23, 2026.
Nike Data Breach Class Action Filed in Oregon (Case No. 6:26-cv-00564-AP)
Plaintiff Maria Gomez filed a class action lawsuit against Nike in Oregon federal court alleging the company failed to safeguard customer personally identifiable information during a January 2026 data breach. The lawsuit claims Nike's network was infiltrated by cybercriminals who accessed names, email addresses, billing addresses, phone numbers, transaction information and payment card details. Nike allegedly discovered the breach on January 21, 2026, but did not begin notifying victims until February 25, 2026, more than a month later. Media reports indicated a ransomware group published 1.4 terabytes of Nike data on its website. The complaint alleges negligence, breach of implied contract, and unjust enrichment, claiming customers are now at imminent risk of identity theft and fraud.
State Farm Total Loss Claims Settlement Receives Preliminary Approval (Case No. 4:21-cv-01161)
A federal judge granted preliminary approval to a $15.58 million class action settlement resolving claims State Farm underpaid policyholders for total loss vehicle claims in Arkansas. Plaintiff Rose Chadwick filed the lawsuit in November 2021 alleging State Farm systematically underpaid insureds by basing compensation on Audatex valuation reports that applied improper "typical negotiation adjustments." The settlement covers persons who made first-party claims on policies issued to Arkansas residents between November 29, 2016, and October 18, 2021, where vehicles were declared total losses with payouts based on Audatex reports applying typical negotiation adjustments. Class members are eligible for payments of 68% of estimated TNA amounts, with an average recovery of approximately $489 per claim. The deadline to opt out is June 25, 2026, the deadline to object is June 15, 2026, and the final approval hearing is scheduled for July 15, 2026.
Federal Circuit Affirms Approval of Class Representative Incentive Awards
In National Veterans Legal Services Program v. United States, the Federal Circuit joined the clear majority of circuit courts in holding that district courts are permitted to approve incentive awards for class representatives. The case involved a class action settlement regarding overcharging of fees for the judiciary's PACER system. The district court approved $10,000 incentive awards to each of three nonprofit organizations that served as class representatives. The Federal Circuit rejected objections to the awards, relying on the history of Rule 23 and rejecting comparisons of incentive awards to "salaries" or "bounties." The court found that incentive awards permissibly recognize the "meaningful burden, including facing reputational risks and expending time and effort" that class representatives undertake. The decision deepens the circuit split with the Eleventh Circuit, which stands alone in finding incentive awards per se unlawful since its 2022 decision in Johnson v. NPAS Solutions, LLC.
Supreme Court Sends Steve Bannon Case Back to Lower Court
The Supreme Court sent the case of Stephen Bannon, convicted of contempt of Congress for refusing to comply with a House January 6 Committee subpoena, back to the lower court where the Department of Justice filed a motion to dismiss his indictment. Bannon was convicted of violating a federal law that makes it a crime to "willfully" fail to respond to a congressional subpoena and served four months in prison. The U.S. Court of Appeals for the D.C. Circuit upheld his sentence and rejected his argument that his failure to comply was not "willful" because he acted on his attorney's advice. The Trump administration urged the Supreme Court to invalidate the D.C. Circuit's ruling and remand the case so the district court could grant the government's motion to dismiss.
Microsoft Reports Medusa Ransomware Exploiting Zero-Days Within 24 Hours
Microsoft published research showing that the Medusa ransomware operation is increasingly exploiting new vulnerabilities days before public disclosure, with multiple cases where the group moves from initial access to data exfiltration and ransomware deployment within 24 hours. Microsoft cited two recent examples: CVE-2026-23760 in SmarterMail and CVE-2025-10035 in GoAnywhere Managed File Transfer, which Medusa actors exploited one week before public disclosure. CISA previously confirmed both CVEs have been used in ransomware attacks. The group targets vulnerable web-facing systems during the window between vulnerability disclosure and widespread patch adoption. Recent victims include healthcare organizations, education institutions, professional services firms, and finance sector entities in Australia, the United Kingdom, and the United States, including Mississippi's largest hospital and Passaic County, New Jersey.
Tech Companies Vow to Continue CSAM Scanning Despite Expiration of EU Legal Protections
A European Union law allowing tech companies to scan communications for child sexual abuse materials expired on April 5, 2026, but Microsoft, Google, Meta and Snapchat released a statement pledging to continue voluntary scanning despite potential legal risk. European Commission spokesperson Guillaume Mercier cautioned that "without a legal basis, companies are no longer allowed to proactively detect child sexual abuse in private communications." The decision to let the law expire was contested, with critics arguing the scanning allowed indiscriminate surveillance and violated privacy rights, while law enforcement officials and several European commissioners supported maintaining legal protections for the scans. Lawmakers have been negotiating to find a permanent solution since November 2023 but have been unable to agree on terms.
Hong Kong Police Granted Authority to Demand Encryption Keys
Hong Kong authorities changed the rules governing enforcement of the National Security Law on March 23, 2026, granting police the authority to require individuals to provide passwords or other assistance to access personal electronic devices, including cellphones and laptops. According to a U.S. Consulate General security alert dated March 26, refusal to comply is now a criminal offense. Authorities also have expanded powers to seize and retain personal electronic devices as evidence if they claim the devices are linked to national security offenses. The requirements apply to individuals transiting through Hong Kong's airport.
New Mexico Meta Ruling Creates Precedent for Design Liability and Encryption
A New Mexico court ruling against Meta has created implications for end-to-end encryption and security features after the state attorney general used Meta's 2023 decision to add end-to-end encryption to Facebook Messenger as evidence against the company. The state argued that predators used Messenger to groom minors and exchange child sexual abuse material, and that encryption made it harder for law enforcement to access evidence of crimes. The state is now seeking court-mandated changes including "protecting minors from encrypted communications that shield bad actors." The ruling establishes a "design liability" framework where product improvements that protect the majority of users can be held against companies if a small fraction of bad actors exploit them.
Congress Reintroduces Pro Codes Act to Grant Copyright Protection to Incorporated Standards
Senators Coons, Cornyn, Hirono, and Tillis reintroduced the Pro Codes Act, legislation that would grant copyright protection to standards that have been incorporated by reference into law. The bill would make building codes, fire safety codes, electrical codes, and accessibility guidelines the copyrighted property of private standards development organizations that wrote them, despite multiple federal courts, including the Supreme Court, the Fifth Circuit, the D.C. Circuit, and the First Circuit, ruling that no one can own the law. The bill includes a provision requiring incorporated standards be made "publicly accessible online" but specifies this access must be provided "in a manner that does not substantially disrupt the ability of those organizations to earn revenue." Organizations providing free public access to incorporated standards, including Public.Resource.Org and UpCodes, would face copyright liability under the bill.
UK Advances Social Media Ban Enabling Secretary of State to Restrict Internet Access for Under-18s
The UK House of Commons proposed an amendment to the Children's Wellbeing and Schools Bill enabling the Secretary of State to require providers to prevent access by children under age 18 to specified internet services or features, replacing a House of Lords amendment that would have banned under-16s from all regulated user-to-user services. The Commons proposal transfers power from Parliament and Ofcom to the Secretary of State for Science, Innovation and Technology, who can restrict internet access for young people, determine harmful content, limit VPN use for under-18s, restrict access to addictive features, and change the age of digital consent without demonstrating specific harms. The process contains no accountability mechanisms and does not require ministers to assess online services according to established risk frameworks.
Patch web-facing systems within 24-48 hours of vulnerability disclosure. Microsoft's Medusa research demonstrates ransomware groups are exploiting vulnerabilities within one week of disclosure and completing full attack chains within 24 hours of initial access. The traditional 30-day patch window is inadequate for internet-exposed assets.
Review data breach notification procedures to ensure compliance with state statutory timelines. Nike's one-month delay between breach discovery and victim notification creates additional liability exposure. Most states require notification within 30-60 days of discovery.
Establish travel security policies for employees transiting Hong Kong. Hong Kong authorities can now demand encryption keys and seize devices from individuals transiting the airport. Organizations should provide travel-specific devices with minimal sensitive data for employees traveling to or through Hong Kong.
Monitor the Pro Codes Act legislative progress and budget for potential compliance costs. If enacted, the legislation would restrict free access to building codes, fire safety codes, and electrical standards incorporated into law, potentially requiring paid subscriptions to access compliance requirements.
Document product security and privacy decisions carefully. The New Mexico Meta ruling demonstrates that internal risk assessments and safety deliberations can become evidence in design liability cases. Legal counsel should review documentation retention policies for security implementation discussions to balance transparency with litigation exposure.