← Carolina Clear Tech

Legal & Privacy Brief

2026-04-08

Listen to this brief (19:39)

Download MP3
Show Notes

Show Notes - 2026-04-08

Stories Covered

CVEs Referenced

CVE-2021-22681

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - April 8, 2026

Today: The Supreme Court limited platform secondary liability in Cox v. Sony, protecting ISPs from copyright infringement claims for user actions. Lakeview Loan Servicing agreed to a $26 million settlement for a 2021 data breach affecting mortgage servicing customers. Iranian-affiliated hacking groups escalated attacks on U.S. operational technology systems in water, energy, and municipal sectors, exploiting vulnerabilities in Rockwell PLCs.

Enforcement Actions

Iranian APT Groups Target U.S. Critical Infrastructure OT Systems

The FBI, NSA, and Defense Department issued a joint advisory warning that Iranian-affiliated hacking groups are attacking internet-facing operational technology devices across U.S. water, energy, and municipal government sectors. Since at least March 2026, Iranian actors have targeted Rockwell Automation and Allen-Bradley programmable logic controllers (PLCs), exploiting CVE-2021-22681 to cause operational disruptions and financial losses. The attacks involve malicious manipulation of project files and SCADA displays, with at least 75 devices compromised in similar 2023-2024 campaigns linked to Iran's Islamic Revolutionary Guard Corps. Federal agencies assess the escalation is in response to current U.S.-Iran military conflict.

Russian GRU Unit 26165 Hijacks Home Routers for Espionage

UK National Cyber Security Centre exposed Russian military intelligence Unit 26165 (APT28, Fancy Bear) exploiting vulnerable TP-Link and other home and small office routers to redirect internet traffic through adversary-controlled servers. The group exploits Simple Network Management Protocol (SNMP) with default or weak credentials, particularly SNMP version 2 which lacks encryption. Attackers modify DNS settings to intercept credentials, authentication tokens, and redirect users to fraudulent sites in adversary-in-the-middle attacks. The campaign targets organizations supporting Ukraine and appears opportunistic initially before focusing on intelligence priorities.

Italian Physiotherapy Clinic Reprimanded for Email Misdirection Data Breach

Italy's Garante per la protezione dei dati personali reprimanded a physiotherapy clinic (Case No. 10210247) after it sent a patient's clinical report containing health data, name, date of birth, and tax identification number to an incorrect email address due to a software bug. The controller failed to implement email address validation procedures required by Italian DPA guidelines for healthcare providers, violating Articles 5(1)(f), 9, and 32 GDPR. The DPA classified the incident as a minor infringement under Recital 148 GDPR and issued a reprimand rather than a fine due to the isolated nature, lack of intent, cooperation, and corrective measures implemented.

German Telecommunications Company Ordered to Pay Damages for Unlawful Direct Marketing

The LG Düsseldorf (Case No. 38 O 243/23) prohibited a telecommunications company from sending personalized direct marketing to data subjects without consent and ordered €243.51 in damages. The controller obtained names, addresses, and landline numbers from a mailing list vendor and sent contract offers without consent, violating Articles 5(1)(a), 6(1), 12(1), 12(3), 12(5), 14(1), 14(2)(a)-(c), 14(2)(e)-(f), and 15 GDPR. The court rejected the controller's reliance on legitimate interests under Article 6(1)(f), ruling that Recital 47 GDPR does not automatically make direct marketing lawful and that the controller failed to provide required information about data sources and objection rights under Article 21 GDPR.

Trump DOJ Drops 23,000 Criminal Investigations to Focus on Immigration

The Department of Justice closed more than 23,000 criminal cases in the first six months of the Trump administration, abandoning investigations into terrorism, white-collar crime, fraud, and other offenses as it shifted resources to immigration enforcement. In February 2025 alone, nearly 11,000 cases were declined, the highest monthly total since at least 2004. Closed cases included investigations into a Virginia nursing home patient abuse case, New Jersey labor union fraud including embezzlement allegations, and cryptocurrency investor fraud. The DOJ prosecuted 32,000 new immigration cases in the same period, triple the Biden administration rate, while pursuing fewer prosecutions of nearly every other crime type than new administrations dating back to 2009.

Litigation Updates

Lakeview Loan Servicing $26M Data Breach Settlement (Case No. 1:22-cv-20955)

Lakeview Loan Servicing, the second largest mortgage servicer in the U.S., agreed to a $26 million class action settlement to resolve claims it failed to prevent an October 11, 2021 data breach that compromised Social Security numbers, loan numbers, and personal identifiers. The settlement covers individuals who received breach notifications from Lakeview. Class members can recover up to $5,000 for out-of-pocket expenses including identity theft damages, credit expenses, and up to two hours of lost time at $20 per hour, subject to pro rata reduction if claims exceed $5 million. California subclass members are eligible for additional payments under the California Consumer Privacy Act. All class members receive one year of free credit monitoring regardless of documented losses.

Patelco Credit Union $7.25M Data Breach Settlement (Case No. 24CV082095)

Patelco Credit Union agreed to a $7.25 million settlement for a June 2024 data breach affecting California members. Class members who experienced losses can recover up to $5,000 in reimbursement for fraudulent charges, identity theft, and credit monitoring costs with documentation. Class members without losses receive between $100 and $200 in cash payments, with exact amounts varying based on claims filed. The settlement covers individuals whose personally identifiable information was potentially involved in the breach discovered in June 2024.

Supreme Court Limits Platform Secondary Liability in Cox v. Sony

The Supreme Court ruled in Cox Communications v. Sony Music Entertainment that broadband providers cannot be held liable for copyright infringements committed by their users under secondary liability theories. The Court held that the Copyright Act only provides for direct liability, and any secondary liability must be inferred using traditional common law principles with appropriate restraints. The decision limits contributory and vicarious liability doctrines, protecting internet platforms from expansive liability for user actions. The ruling builds on Sony v. Universal Music (1984) and narrows the expansion of secondary liability that began with MGM Studios v. Grokster (2005).

WhatsApp Class Action Alleges Meta Intercepted Private Messages (Case No. 3:26-cv-02615)

Plaintiffs Brian Y. Shirazi and Nida Samson filed a class action in the Northern District of California alleging WhatsApp, Meta Platforms, Accenture PLC, and Accenture LLP wrongfully intercepted and shared private WhatsApp messages with third parties despite marketing claims of end-to-end encryption. The complaint cites whistleblower reports that Meta employees and third-party contractors had broad access to encrypted messages. The suit alleges violations of California privacy laws, Pennsylvania Wiretapping and Electronic Surveillance Act, fraud, false advertising law, unfair competition, breach of contract, and common law intrusion upon seclusion. Plaintiffs seek to represent a nationwide class of WhatsApp users who sent or received communications between April 5, 2016 and present.

Seventh Circuit Limits BIPA Damages to Per-Person Basis in Clay v. Union Pacific

The Seventh Circuit held that a 2024 amendment to the Illinois Biometric Information Privacy Act (BIPA) limiting damages to a per-person basis applies retroactively to cases pending when the amendment was enacted. The ruling in Clay v. Union Pacific Railroad Company significantly limits potential statutory damages plaintiffs may obtain in pending BIPA cases, applying the amendment to violations that occurred before the statutory change.

Third Circuit Dismisses Harriet Carter Gifts Wiretapping Case on Standing (Case No. 25-1760)

The Third Circuit vacated a district court judgment and remanded Popa v. Harriet Carter Gifts to state court after finding the plaintiff lacked Article III standing under Cook v. GameStop (2025). The plaintiff alleged defendants tracked her browsing activity while shopping for pet stairs in violation of the Pennsylvania Wiretapping and Electronic Surveillance Control Act, but did not input sensitive or personal information. The court held that interacting with a website without inputting personal data does not constitute a sufficiently concrete injury-in-fact for federal jurisdiction. The decision demonstrates that Article III standing is not static and intervening precedent can strip federal courts of jurisdiction even deep into litigation.

Ruggable Faces TCPA Class Action for Early Morning Marketing Texts (Case No. 2:26-cv-02279)

Plaintiff Kaitlyn Guthre filed a class action in the Central District of California alleging Ruggable sent marketing text messages at 6:01 a.m. and 6:02 a.m. between October 2 and October 12, 2025, violating the Telephone Consumer Protection Act's prohibition on telemarketing between 9 p.m. and 8 a.m. The proposed class includes U.S. consumers who received more than one marketing text from Ruggable within any 12-month period initiated before 8 a.m. or after 9 p.m. The TCPA provides penalties up to $500 per violation and up to $1,500 for willful or knowing violations.

Costco Class Action Alleges Untimely Membership Renewal Notices (Case No. 3:26-cv-02369)

Plaintiff Russel George filed a class action in the Northern District of California alleging Costco violates California's Automatic Renewal Law (ARL) by sending membership renewal notices 60 days before automatically charging credit cards, outside the required 45-day window. The complaint alleges renewal notices fail to include statutorily required information including renewal length, terms, amount charged, and cancellation methods. George claims violations of California ARL, False Advertising Law, Consumers Legal Remedies Act, and Unfair Competition Law after being charged $65 for automatic Gold Star membership renewal in January 2026.

Privacy Developments

Figure Technology Data Breach Affects 967,000 Users

Figure Technology confirmed a data breach affecting nearly 1 million users following a January social engineering attack on an employee. ShinyHunters hacking group claimed responsibility, asserting they stole 2.5 gigabytes of data containing approximately 967,000 records including names, dates of birth, and addresses. The group leaked the data on a dark web forum after Figure Technology allegedly refused ransom negotiations. Figure is offering complimentary TransUnion credit monitoring services to affected individuals, with enrollment required by May 31, 2026. A dedicated call center is available at 1-855-522-6935.

EU Parliament Blocks Extension of e-Privacy Derogation for Mass Chat Scanning

The European Parliament voted against prolonging the interim e-Privacy derogation that allowed service providers to voluntarily scan private communications for child abuse material. The derogation has expired, making general and indiscriminate scanning of messages potentially illegal under EU law without specific legal basis. Google, Meta, Microsoft, and Snap issued a joint statement indicating intent to "continue to take voluntary action on our relevant Interpersonal Communication Services," raising questions about compliance with EU privacy rules. The Chat Control proposal remains under negotiation with focus shifted toward risk mitigation measures including age verification and voluntary activities.

Austrian Court Rules GDPR Cross-Border Cooperation Suspends Decision Deadlines (Case No. W137 2324046-1)

The Austrian Federal Administrative Court held that decision deadlines under national law are automatically suspended during GDPR cross-border cooperation procedures under Articles 56 and 60 GDPR. In a case where a data subject complained about an incomplete Article 15 access request response from a controller in another Member State, the court ruled the suspension applies from the moment a complaint is filed, not only after formal cooperation is initiated. The decision clarifies that lead authority competence under Article 56 GDPR automatically triggers timeline suspension for concerned authorities during the cooperation mechanism.

Massachusetts Hospital Forced to Divert Ambulances After Cyberattack

Signature Healthcare and Signature Healthcare Brockton Hospital activated incident response protocols and moved to down-time procedures after a cyberattack impacted information systems. The hospital is turning away ambulances while maintaining walk-in emergency services and scheduled surgeries, but cancelled chemotherapy infusion services for cancer patients on Tuesday. No hacking group has claimed responsibility. Health ISAC reports sustained high levels of malicious activity targeting healthcare sector with multiple significant incidents affecting hospitals, payers, pharmaceutical companies, and medical device manufacturers, primarily from Iranian nation-state actors and financially motivated cybercriminals conducting ransomware and data extortion attacks.

Northern Ireland School Network Cyberattack Affects 300,000 Students

The Northern Ireland Education Authority's C2K centralized school IT system suffered a cyberattack affecting around 300,000 pupils and 20,000 teachers. The EA shut down system access to contain the breach and is working with service provider Capita and incident response teams to restore services. The investigation has not yet confirmed whether personal data was compromised. Recovery is prioritizing students at critical academic points, particularly those sitting examinations. Officials report no evidence of data corruption or data leaving the system, though the investigation remains active.

Policy Changes

National Security Veterans Urge Clean FISA Section 702 Reauthorization

Approximately 50 former national security officials including former DNI James Clapper and former FBI Director Christopher Wray sent a letter to Congress urging clean renewal of FISA Section 702 before the April 20 expiration. The letter warns against entangling reauthorization with unrelated policy debates including voting rights bills and concerns about government purchasing data from data brokers. The officials cite a Privacy and Civil Liberties Oversight Board staff report endorsing current Section 702 usage, though the report faces criticism because Trump fired Democratic panelists. President Trump has publicly called for a tweak-free renewal with support from his national security team.

Trump Office of Legal Counsel Claims Presidential Records Act Does Not Bind Trump

The DOJ Office of Legal Counsel issued an opinion stating Trump is not obligated to turn over presidential records to the National Archives and Records Administration (NARA) following his second term. The opinion, written by Assistant Attorney General T. Elliot Gaiser (formerly legal counsel for Trump's 2020 campaign and involved in post-election litigation), claims Supreme Court precedent Nixon v. Administrator was "wrong" in concluding the Presidential Records Act does not violate separation of powers. The memo contradicts nearly 50 years of established law requiring presidents to preserve and transfer records to NARA.

EFF Report: Arab Spring Digital Tools Enabled Global Surveillance Boom

EFF published analysis tracing how the 2011 Arab Spring uprisings fueled expansion of global surveillance infrastructure. After 2011, MENA governments invested heavily in internet monitoring, deep packet inspection, and interception systems from Western vendors. Security agencies built permanent monitoring centers to track social media at scale, monitor activist pages, and preemptively control digital organizing. The research shows tactics refined in MENA now shape digital authoritarianism worldwide through cybercrime laws, mercenary spyware markets, biometrics, facial recognition, and smart city AI-driven surveillance systems.

Compliance Takeaways