Get tomorrow's brief in your inbox
Today: Google accelerates its post-quantum encryption deadline to 2029 citing advances in quantum computing that threaten current encryption standards. Amazon attempts to use the Computer Fraud and Abuse Act to block AI-powered price comparison tools that steer customers to competitors. Federal agencies receive authorization to deploy Microsoft's Government Community Cloud High despite security reviewers warning of inadequate documentation and expressing lack of confidence in the system's security posture.
ANSPDCP Fine Against Blue Projects SRL (Romania)
Romanian DPA fined Blue Projects SRL RON 12,734 (€2,500) for failing to implement appropriate security measures following a cyberattack that led to unauthorized access to employee, business partner, and correspondence recipient data. The investigation began after the company submitted a GDPR Article 33 data breach notification. DPA found the controller violated Article 32(1)(b), Article 32(1)(d), and Article 32(2) GDPR by not ensuring adequate security measures, including failing to maintain confidentiality of processing systems and lacking processes for testing and evaluating security measure effectiveness.
FTC Robocall Enforcement and Proposed Penalties
FTC proposed fining voice service provider Voxbeam Telecommunications $4.5 million for allegedly accepting call traffic from an unauthorized foreign provider, facilitating financial impersonation robocalls to American consumers using non-compliant accounts. FTC also proposed new rulemaking to strengthen know-your-customer (KYC) rules for voice service providers, including switching to per-call penalties to correlate fines with the volume of illegal calls made. Proposed requirements include collecting name, physical address, government ID numbers, and alternative phone numbers before allowing service use, with high-volume customers required to disclose intended use and IP addresses. Providers would be required to maintain records for at least four years after customer relationships end.
FTC Refund Programs (March 2026)
FTC distributed over $58 million in refunds to consumers across five enforcement actions in March 2026. Financial Education Services settlement resulted in $10.9 million to 443,048 consumers who paid the credit repair operation between May 2019 and May 2022 for services not delivered. Invitation Homes settlement distributed $47.2 million to 444,131 consumers for undisclosed fees and deceptive charges between January 2021 and September 2024. WealthPress distributed $177,000 in second-round payments to consumers who paid $2,500 or more for investment advice sold under false earnings claims. Restoro-Reimage sent refund checks to consumers who did not accept March 2025 PayPal payments for computer repair services sold through misleading ads and fake Windows pop-ups. Pyrex sent PayPal payments to consumers who did not cash October 2024 refund checks related to measuring cups advertised as made in USA but imported from China.
Bitcoin Depot Cyberattack Disclosure
Cryptocurrency ATM company Bitcoin Depot reported to SEC that a March 23, 2026 cyberattack resulted in the theft of approximately $3.6 million (50.903 Bitcoin) after threat actors gained access to systems and obtained credentials for the company's digital asset settlement accounts. Bitcoin Depot stated the incident was contained to corporate environment and did not affect customer platforms, systems, data, or environments. Investigation is ongoing with outside cybersecurity experts and law enforcement notified.
Excelsior Orthopaedics $2.4M Data Breach Settlement
Excelsior Orthopaedics and Buffalo Surgery Center agreed to $2.4 million class action settlement (Case No. 812753/2024, Supreme Court of New York, County of Erie) to resolve claims from June 2024 data breach affecting personal information. Settlement provides up to $5,000 for documented losses including bank fees, communication charges, credit expenses, and travel costs with documentation required. Class members without documentation eligible for pro rata cash payments. Two years of free credit monitoring services included. Claim deadline is June 11, 2026. Exclusion and objection deadline is May 17, 2026. Final approval hearing scheduled for July 8, 2026.
Empire Hotel Drip Pricing Class Action
Plaintiff Dylan Bittlingmaier filed class action lawsuit (Case No. 1:26-cv-01209, S.D.N.Y.) against Empire Hotel alleging violation of FTC's Rule on Unfair or Deceptive Fees effective May 12, 2025. Complaint claims hotel engages in drip pricing by listing room rates on search pages excluding taxes and fees, only revealing full price at checkout after consumers navigate multiple pages. Plaintiff asserts claims for unjust enrichment, fraud, and violations of New York General Business Law. FTC warned hotel industry about drip pricing in 2012 and directly prohibited the practice in 2025 rule.
Pepperdine University v. Netflix Trademark Dismissal
U.S. District Judge Cynthia Valenzuela dismissed Pepperdine University's trademark infringement lawsuit against Netflix and Warner Bros. over the show "Running Point." Court held that fictional Los Angeles Waves basketball team in the show did not violate Pepperdine's rights because the "Waves" name and logo were not used as trademarks or source identifiers. Court applied Rogers test, finding the use was artistically relevant to the fictional narrative and not used to identify the source of the series. Pepperdine given leave to amend complaint.
Higbee & Associates Copyright Demand Withdrawn
Higbee & Associates, representing Agence France-Presse, withdrew copyright demand against May First Movement Technology after EFF represented the nonprofit web hosting provider. Demand letter alleged May First infringed AFP photograph, but May First merely provided hosting infrastructure for member organization that posted the image and promptly ensured removal upon notification. EFF explained May First lacked volitional conduct required for direct infringement and acted appropriately under DMCA safe harbor provisions by facilitating content removal.
Maghoney v. Dotdash - Standing Dismissed Under Popa
Southern District of California (Case No. 2026 WL 497402) granted Dotdash Meredith's motion to dismiss for lack of Article III standing. Plaintiff alleged Dotdash disclosed sensitive health-related search terms (genital warts, STI treatment) along with IP address and device information to third-party advertisers. Court applied Ninth Circuit's Popa v. Microsoft precedent, holding that mere disclosure of sensitive search terms without indication they were tied to plaintiff's personal medical history fails to establish concrete injury. Court rejected theories of invasion of privacy, informational injury, emotional distress, and future harm as insufficient to establish standing.
Amazon v. Perplexity - CFAA Ruling on Price Comparison Tools
Federal district court ruled that Perplexity's AI-enabled web browser Comet violated Computer Fraud and Abuse Act by building a tool that helps users access information on Amazon and compare prices across competitors. Court relied on Ninth Circuit's Facebook v. Power Ventures decision. Perplexity appealed to Ninth Circuit. EFF filed amicus brief arguing the ruling could undermine research, security, competition, and innovation by allowing companies to criminalize legitimate research and price comparison tools through cease-and-desist letters.
Google Accelerates Post-Quantum Encryption Deadline to 2029
Google moved estimated deadline for quantum preparedness in cryptography to 2029 (33 months from now) based on two new papers showing significant advances in quantum computing technology. Timeline acceleration addresses two attack vectors: future quantum computers will be able to insert malware into core systems and fake authentication by observing network traffic, and quantum computers will decrypt years of captured encrypted messages sent before platforms upgraded to quantum-proof encryption. Engineers should upgrade key agreement systems immediately due to store-now-decrypt-later attacks and prepare authentication systems for signature forgery attacks. Symmetric encryption remains quantum-resistant. NGINX on Ubuntu 26.04 released necessary security settings for key agreement upgrades.
Treasury Department Crypto Industry Threat Sharing Initiative
Treasury's Office of Cybersecurity and Critical Infrastructure Protection (OCCIP) announced initiative to share cyber threat intelligence with cryptocurrency industry following multiple major thefts totaling over $3.4 billion in 2025. Eligible U.S. digital asset firms and industry organizations meeting Treasury criteria can receive, at no cost, the same actionable cybersecurity information Treasury shares with traditional financial institutions. Initiative aims to help firms identify, prevent, and respond to cyber threats targeting customers and networks. Announcement follows $280 million theft from Drift platform attributed to North Korean hackers and comes amid broader administration cuts to CISA external engagement programs.
ProPublica Report on Microsoft GCC High Authorization
Federal Risk and Authorization Management Program (FedRAMP) authorized Microsoft's Government Community Cloud High for federal use despite internal government report showing reviewers lacked confidence in the system's overall security posture. Reviewers cited Microsoft's lack of proper detailed security documentation and inability to fully explain how it protects sensitive information as it moves between servers. FedRAMP authorization included buyer-beware notice to federal agencies but allowed Microsoft to expand government business worth billions. ProPublica obtained internal government report showing one team member called the security package "a pile of shit."
Russia Detains Former Radio Free Europe Journalist for Alleged Cyberattack Aid
Russian Federal Security Service (FSB) detained former Radio Free Europe freelance journalist Alexander Andreyev (65) on treason charges, accusing him of passing information to Ukraine via Telegram channel controlled by Security Service of Ukraine. FSB claims information about local print publication and critical infrastructure facility was used to assist cyberattacks. Suspect placed in pre-trial detention. Radio Free Europe designated "foreign agent" in 2020 and "undesirable organization" in 2025, effectively banned in Russia. Case follows pattern of Russian criminal investigations tied to Telegram activity, including cases involving Telegram Stars virtual currency allegedly funding banned organizations and criticism of government anti-cybercrime legislation.
EFF Announces Departure from X Platform
Electronic Frontier Foundation announced withdrawal from X (formerly Twitter) after nearly 20 years on the platform, citing declining reach (3% of 2018 impression levels) and platform changes under Elon Musk ownership. EFF criticized elimination of human rights team, mass layoffs of staff who fought censorship demands in repressive regimes, lack of transparent content moderation, absence of genuine end-to-end encryption for DMs, and insufficient user control. EFF will maintain presence on Facebook, Instagram, YouTube, TikTok, Bluesky, Mastodon, and LinkedIn to reach communities embedded in mainstream platforms, including marginalized groups using these platforms for mutual aid, political organizing, and community care.
Supreme Court Decision in Chiles v. Salazar - Conversion Therapy Law
Supreme Court issued 8-1 decision in Chiles v. Salazar declaring unconstitutional Colorado law prohibiting talk therapy to change minors' sexual orientation or gender identity. SCOTUSblog analysis warns decision continues pattern of inconsistent rulings on government regulation of professional speech, potentially endangering countless regulations of professional advice. Decision contrasts with court's approach in Planned Parenthood v. Casey (upholding compelled doctor speech about abortion) and NIFLA v. Becerra (striking down required reproductive health facility notices). Justice Clarence Thomas previously stated in NIFLA that court has not recognized "professional speech" as separate category. SCOTUSblog notes inconsistency except that both abortion-related cases favored opponents of abortion rights.
Supreme Court Legislative History Analysis
SCOTUSblog analysis reveals Supreme Court justices continue consulting legislative history despite textualist claims to ignore congressional intent. D.C. Circuit Judge Gregory Katsas admitted in Federalist Society panel that he cited Supreme Court case (Yates v. United States) that itself relied on legislative history, rather than directly citing legislative history, to avoid "creating a side show" in "edgy case" involving January 6 prosecutions. Katsas joked he "got away with it." Pattern suggests textualist judges secretly rely on legislative purpose and history while avoiding direct citation to maintain textualist credentials.
Fourth Amendment Dog Sniff Case - Johnson v. United States
Supreme Court will consider petition in Johnson v. United States addressing whether Fourth Amendment requires warrant for drug-detection dog sniff at apartment door. Case involves 2019 narcotics investigation where Maryland police brought drug-detection dog to area outside Apartment 201 with building management permission. Dog alerted to drugs at door seam, police obtained warrant, search uncovered heroin-fentanyl, handgun, ammunition, and drug-dealing evidence. Fourth Circuit held dog sniffs are different than thermal imaging and apartment hallways are different than front porches under Florida v. Jardines. Petition argues Fourth Circuit ruling deepens circuit split and threatens to deprive Americans in multi-unit dwellings (approximately 25% of population) of Fourth Amendment rights.
Prepare for post-quantum cryptography transition. Inventory all cryptographic systems and upgrade key agreement protocols immediately. The 2029 deadline is tight and some systems (particularly hardware-based trusted execution environments) may not make it. Prioritize systems handling sensitive long-term data vulnerable to store-now-decrypt-later attacks.
Review data security measures following Romanian DPA ruling. Implement monitoring systems for data flows at technical and procedural levels. Establish regular testing and evaluation processes for security measure effectiveness. Document all security assessments and maintain evidence of GDPR Article 32 compliance.
Cryptocurrency firms should enroll in Treasury threat sharing program. Contact Treasury OCCIP to determine eligibility and obtain access to threat intelligence feeds. Given $3.4 billion in 2025 losses and ongoing North Korean targeting, actionable government intelligence is critical for defense planning.
VoIP and voice service providers must prepare for enhanced FCC KYC requirements. Review customer verification processes and establish four-year record retention policies. Monitor FCC public comment period for proposed rulemaking on per-call penalty structure and enhanced verification requirements including government ID, physical address, and IP address collection.
Hotels and online platforms must eliminate drip pricing practices. Display total price including all mandatory fees upfront on search and listing pages to comply with FTC's May 12, 2025 rule. First enforcement actions and class action litigation are already underway under both federal and state consumer protection statutes.