Get tomorrow's brief in your inbox
April 14, 2026
Today: The Massachusetts Supreme Judicial Court created a new legal framework for bypassing Section 230 immunity by distinguishing between content and content presentation, threatening every platform that makes editorial decisions. Multiple data breach settlements topped $1.5 million as SouthState Bank, Crunchyroll, and Staples face class actions over compromised customer and employee data. The Trump administration's nationwide drone flight restriction blocking surveillance of ICE operations faces First and Fifth Amendment challenges from EFF and major news organizations.
FBI and Indonesia Disrupt W3LL Phishing Platform
The FBI's Atlanta office and Indonesian National Police took down W3LL, a phishing-as-a-service platform that enabled over $20 million in attempted fraud. The platform sold custom phishing kits for $500 that created fake login portals to harvest credentials and bypass multifactor authentication. Between 2019 and 2023, the marketplace advertised over 25,000 compromised accounts for sale, serving at least 500 threat actors. Group IB identified that W3LL's tools targeted over 56,000 corporate Microsoft 365 accounts in the US, UK, Australia, and Europe between October 2022 and July 2023. Indonesian police arrested the alleged developer G.L., who personally collected and resold access to compromised accounts. The W3LLSTORE shut down in 2023 but continued operating through encrypted messaging platforms, and from 2023 to 2024 the tools were used in attacks on 17,000 victims globally.
$1.5M SouthState Bank Data Breach Settlement (Case No. CACE-2024CA-002530)
SouthState Bank agreed to a $1.5 million class action settlement to resolve claims it failed to prevent a February 7, 2024 data breach that compromised Social Security numbers and other sensitive information. Class members can receive up to $3,500 for documented losses including bank fees, credit monitoring charges, credit freeze costs, professional fees, replacement costs, and fraudulent charges. All class members are eligible for one year of free credit monitoring and $1 million of identity theft insurance. The claim form deadline is June 15, 2026, with the final approval hearing scheduled for June 22, 2026 in the Circuit Court of the Tenth Judicial Circuit in Polk County, Florida. The bank has not admitted wrongdoing.
Staples Employee Data Breach Class Action (Case No. 1:26-cv-11336)
Plaintiff Eric Carroll filed a class action in Massachusetts federal court alleging Staples failed to protect the personally identifiable information of current and former employees during a data breach discovered on or around March 11, 2026. The breach exposed names, Social Security numbers, financial account information, health insurance information, and driver's license information. Carroll claims Staples has not yet notified those affected by the breach, leaving employees unaware their private information was compromised. The complaint alleges Staples failed to adequately train employees on cybersecurity and maintain reasonable security safeguards. Carroll seeks declaratory relief, injunctive relief, and compensatory, exemplary, punitive, and statutory damages on behalf of all affected current and former employees.
Crunchyroll Data Breach Exposes 6.8M Users (Case No. 3:26-cv-02553)
Plaintiff Max Agress filed a class action in California federal court alleging Crunchyroll failed to protect the personally identifiable information of 6.8 million users in a March 12, 2026 data breach. The breach occurred when a Telus employee in India executed malware on his system, giving a threat actor access to Crunchyroll's environment for 24 hours. The hacker downloaded 8 million support ticket records from Crunchyroll's Zendesk instance, containing 6.8 million unique email addresses, full names, usernames, IP addresses, approximate location data, and the text of user support exchanges. The breach did not expose full payment card data, but partial card details shared voluntarily in tickets may have been compromised. Crunchyroll did not disclose the breach until March 22, 2026, ten days after it occurred. Agress alleges violations of Section 5 of the Federal Trade Commission Act, the California Consumer Privacy Act, and California's Consumer Records Act and Unfair Competition Law.
3 Day Blinds Spam Email Class Action (Case No. 3:26-cv-00973)
Plaintiffs Sonya Valenzuela and Tommy Purscelley filed a class action in California federal court alleging 3 Day Blinds sends spam emails to consumers without their consent in violation of California's anti-spam law. The complaint alleges the emails were sent from spoofed email addresses to conceal the sender's identity, contained misrepresented header information, and used deceptive subject lines promising substantial discounts that were actually the company's standard pricing structure. The plaintiffs claim 3 Day Blinds violated California's anti-spam law in three ways: unauthorized use of a domain name, misrepresented header information, and deceptive subject lines and contents. They seek class certification, $1,000 per email, fees, costs, and a jury trial on behalf of anyone in the United States who accessed their email while in California and received a commercial email from 3 Day Blinds containing falsified, misrepresented, or forged domain name, header information, or subject line within the past four years.
PayGOV Hidden Fees Class Action (Case No. 49D01-2511-CE-054307)
Plaintiffs Amy Burke and Angelia McGlade filed a class action in Indiana state court alleging PayGov.US LLC charges hidden junk fees when consumers pay utility bills with credit or debit cards. The complaint alleges PayGOV charges undisclosed and variable-rate convenience fees that only appear at the final payment screen, increasing with the size of the payment and disproportionately affecting consumers with larger utility bills. Burke and McGlade argue PayGOV uses a domain name and branding that closely resemble official government websites, including American flag imagery, to give the impression of government affiliation when it is a private company. The lawsuit alleges violations of the Indiana Deceptive Consumer Sales Act, unjust enrichment, and seeks damages, injunctive relief, and attorney fees for all individuals who have paid a convenience fee to PayGOV.
California Federal Court Dismisses USA Today Privacy Suit for Lack of Standing (2026 WL 932655)
A California federal court dismissed a privacy class action against USA Today for lack of subject matter jurisdiction, holding that the plaintiffs failed to allege a concrete injury sufficient to establish Article III standing. The plaintiffs sued for violations of the California Invasion of Privacy Act's trap-and-trace provision, claiming the defendant installed third-party website technologies that collected IP addresses, location, browser type, and similar information. The court held that disclosure of this information would not be highly offensive to a reasonable person, emphasizing that courts have repeatedly found no reasonable expectation of privacy in such unprotected disclosures. The court rejected allegations invoking unique and persistent identifiers as too vague to establish a concrete injury. Following the Ninth Circuit's decision in Popa v. Microsoft Corporation, the court reiterated that a bare CIPA statutory violation, standing alone, is insufficient to confer Article III standing absent a concrete injury. The court granted the plaintiffs leave to file an amended complaint.
Massachusetts Supreme Court Denies Meta's Motion to Dismiss in Commonwealth v. Meta Platforms, Inc.
The Massachusetts Supreme Judicial Court unanimously denied Meta's motion to dismiss the state attorney general's lawsuit, holding that Section 230 does not bar claims that Meta designed Instagram to be addictive to children, lied to the public about the platform's safety, failed to properly age-gate underage users, and created a public nuisance. The court distinguished between content and content presentation, holding that Section 230 does not apply unless the claim is based on the substance of third-party content. The ruling provides a template for plaintiffs to plead around Section 230 by focusing on design choices that elevated third-party content over others rather than the content itself. As a state supreme court decision, it is the final word for the Massachusetts state court system unless the U.S. Supreme Court intervenes, providing a major precedent for other courts to follow. Professor Eric Goldman noted that plaintiffs can now reframe complaints to focus on content presentation instead of substance, effectively making Section 230 irrelevant.
Nevada Federal Court Rules Mandatory Detention of Migrants Illegal
A Nevada federal court ruled that the Trump administration's mandatory detention of migrants already in the country violates constitutional due process rights. The administration argued that 8 U.S.C. Section 1225(b)(2), which authorizes mandatory detention of noncitizens seeking admission at the border, also applies to migrants already in the country for weeks, months, or years. The court rejected this interpretation, holding that Section 1225 is temporally and geographically limited to the border by other language in the Immigration and Nationality Act, while Section 1226(a) governs discretionary detention of noncitizens already in the country. The court found the two provisions are mutually exclusive and that a noncitizen cannot be subject to both mandatory detention under 1225 and discretionary detention under 1226. This ruling follows similar decisions in multiple jurisdictions outside the Fifth Circuit, where the majority has sided with the administration's interpretation.
FAA Nationwide Drone Flight Restriction (FDC 6/4375)
The FAA issued a 21-month temporary flight restriction (TFR) on January 16, 2026, lasting until October 29, 2027, that prevents any person from flying any unmanned aircraft within 3,000 feet horizontally of any facilities and mobile assets, including ground vehicle convoys and escorts, of the Departments of Defense, Energy, Justice, and Homeland Security. Violators face criminal and civil penalties, and risk having their drones seized or destroyed. In practical terms, anyone flying a drone within a half mile of an ICE or CBP agent's car is liable to face criminal charges and have their drone shot down. Immigration agents often use unmarked rental cars, cars without license plates, or switch license plates to carry out operations, and do not provide prior warning of operations. EFF and media organizations including The New York Times and The Washington Post sent a letter in January demanding the FAA lift this restriction as a blatant infringement of the First Amendment right to record law enforcement. The FAA has not responded after over two months. The TFR also violates the Fifth Amendment's due process requirement to provide fair notice before depriving liberty or property, and violates FAA regulations requiring the agency to specify the hazard or condition requiring the restriction and provide accredited news representatives with a point of contact to obtain permission to fly drones within the restricted area.
Australian Social Media Ban Fails to Keep Children Off Platforms
Sixty-one percent of Australian children between the ages of 12 and 15 told researchers from the Molly Rose Foundation and an Australian youth research agency that they can still access accounts on major platforms just as they did before the ban implemented in December. TikTok and YouTube retained 53% of previous youth users and Instagram 52%. In most cases, children can still access social media because the platforms failed to identify and remove their accounts in the first place, and respondents said they have been able to access the platforms without having to find workarounds. The findings come as the UK government is planning new restrictions for youth access to social media through May 26, with a decision expected soon after. Greek Prime Minister Kyriakos Mitsotakis announced his government will ban children under age 15 from social media beginning January 1, 2027. The French Senate voted on April 2 to ban social media for children under age 15 after the National Assembly passed similar legislation in January. The European Parliament proposed a non-binding resolution in November asserting that children 15 and younger should not be able to use video-sharing platforms, social media, or AI companions without parental consent, and that children under age 13 should be kept off platforms regardless of parental consent. Spanish Prime Minister Pedro Sanchez and the Dutch government announced plans to block children under 16 and 15 respectively from using social media.
Gulf States Intensify Speech Restrictions During Regional Conflict
Since February 2026, hundreds of people have been arrested across Gulf countries and Jordan for social media activity linked to the conflict between the United States, Israel, Iran, and related spillover attacks. Bahrain authorities cracked down on 168 people who protested or shared footage of the conflict online, with defendants potentially facing serious prison terms if convicted. UAE authorities arrested nearly 400 people for recording events related to the conflict and circulating information described as misleading or fabricated. Saudi Arabia issued a statement on March 2 banning the sharing of rumors or videos of unknown origin and launched a campaign discouraging residents from posting photos with the hashtag "photography serves the enemy." Qatar's Interior Ministry arrested more than 300 people for filming, circulating, or publishing what the ministry deemed to be misleading information. Kuwait, Qatar, and Jordan adopted similar restrictions on wartime imagery and reporting. Reporters Without Borders documented an intensifying crackdown on journalists across Gulf countries and Jordan, including restrictions on reporting, legal threats, and heightened risks for those who deviate from official narratives. The UN warned that repression of civic space and freedom of expression has significantly deepened across the region during the war.
DOJ Uses Grand Jury to Force Reddit to Unmask Anonymous User
According to a subpoena obtained by The Intercept, Reddit has until April 14 to provide a wide range of personal data on a user whom ICE agents have been trying unsuccessfully to identify for more than a month. The Reddit user's lawyers reviewed the targeted account and could not find anything criminal, noting the most aggressive posts were sharing publicly available biographical details about a public figure, suggesting anti-ICE protest sign lyrics, and writing "TSA sucks and we all know it." ICE initially issued an administrative subpoena citing the Smoot-Hawley Tariff Act of 1930, which governs boat show sales, wild animal imports, forfeited wines and spirits, and cross-border trade in other goods. The user informed the court they had nothing to do with activities governed by the near-century-old statute. ICE withdrew the tariff-related subpoena, then DOJ sent another one nearly a month later targeting Reddit itself through a grand jury subpoena. The Trump administration previously attempted to use the same customs statutes to unmask critics in 2017, which was criticized by the Office of the Inspector General.
California A.B. 2047: 3D Printer Censorware Mandate
California bill A.B. 2047 will mandate censorware software on all 3D printers and criminalize the use of open-source alternatives by making it a misdemeanor for device owners to disable, deactivate, or otherwise circumvent mandated print-blocking algorithms. The bill criminalizes use of any third-party, open-source 3D printer firmware and enables print-blocking algorithms to parallel anti-consumer behaviors seen with DRM. Manufacturers will be able to lock users into first-party tools, parts, and consumables, mandate purchases through first-party stores imposing platform taxes, and force regular upgrade cycles through planned obsolescence by ceasing updates to a printer's print-blocking system, making devices illegal for consumers to resell. Less-established manufacturers will need to dedicate considerable time and resources to implementing solutions, navigating state approval, and potentially paying licensing fees to third-party developers, while resale risks misdemeanor penalties. Compared to Washington and New York laws proposed this year, California's is the most troubling because it criminalizes open source, reduces consumer choice, and creates a bureaucratic burden.
Supreme Court Oral Arguments on Birthright Citizenship (Trump v. Barbara)
Oral arguments on April 1 in Trump v. Barbara revealed significant skepticism from multiple justices about the Trump administration's position that birthright citizenship does not apply to children of undocumented immigrants. Chief Justice John Roberts asked Solicitor General D. John Sauer whether birth tourism has any impact on the legal analysis before the court, and when Sauer tried to push back, Roberts responded "Well, it's a new world. It's the same Constitution." Justice Amy Coney Barrett raised questions about American-born foundlings of unknown parentage, babies who might be born and live their entire lives separate from the domicile of their biological parents, noting that the national citizenship words of the 14th Amendment focus on the baby not the parent and say nothing about residence or domicile. The administration argued that because the 14th Amendment uses the word "reside" in connection with state citizenship, therefore national citizenship likewise turns on residence/domicile, which critics described as gobbledygook. A hypothetical child born in the White House who lives her entire life in Washington, D.C. is surely a birthright citizen of the United States even if she never resides in or becomes a citizen of any state.
File claims by June 15, 2026 for the SouthState Bank data breach settlement if you received a breach notice regarding the February 7, 2024 incident. Document all losses with third-party receipts, statements, and invoices to maximize recovery up to $3,500, and activate the included year of free credit monitoring.
Review Microsoft 365 access logs for unauthorized logins between October 2022 and present to identify potential W3LL phishing kit compromises. Transition to hardware-based MFA where possible, as software-based multifactor authentication was specifically targeted by the W3LL platform.
Platform operators should audit content recommendation and ranking algorithms for exposure under the Massachusetts content presentation theory that bypasses Section 230. Document all product design decisions affecting content visibility to minors with clear safety rationales before implementing changes.
Prepare for divergent age verification requirements across jurisdictions ranging from 13 to 16 years old as European countries and Australia implement social media bans for minors. Implement age verification at signup that can detect and remove underage accounts proactively rather than reactively.
If you operate drones for journalism or documentation purposes, consult legal counsel before flying within potential proximity to DHS vehicles given the 21-month nationwide TFR effective through October 29, 2027. Document constitutional violations for potential litigation challenging the FAA restriction.