← Carolina Clear Tech

Legal & Privacy Brief

2026-04-24

Listen to this brief (18:25)

Download MP3
Show Notes

Show Notes - 2026-04-24

Stories Covered

CVEs Referenced

CVE-2025-20362, CVE-2025-30333

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Today: Anne Arundel Dermatology agreed to $2.4 million to settle breach claims (Case No. 1:25-cv-02274-GLR). The Supreme Court rejected military contractor immunity for war zone negligence and ruled the 30-day removal deadline to federal court is mandatory. CISA disclosed that a federal agency was breached through Cisco firewall vulnerabilities, with FIRESTARTER malware maintaining access from September 2025 through March 2026.

Enforcement Actions

CISA Federal Agency Breach (CVE-2025-30333, CVE-2025-20362)

CISA disclosed that an unnamed federal civilian agency was breached in September 2025 through two Cisco Adaptive Security Appliance vulnerabilities. Attackers deployed FIRESTARTER malware that maintained persistent access through March 2026 without re-exploiting the original vulnerabilities. A second malware strain, Line Viper, created illegitimate VPN sessions bypassing authentication policies. The attackers accessed administrative credentials, certificates, and private keys, and used federal accounts that were dormant but not deactivated. CISA issued updated directives requiring all federal civilian agencies to submit forensic data and check for infection.

US Sanctions Cambodian Senator for Scam Compound Operations

The Treasury Department sanctioned Cambodian Senator Kok An and 28 associates for operating scam compounds that stole millions from US victims. Kok An's Crown Resorts properties in Poipet, Sihanoukville, and Bavet were converted into facilities for digital asset investment fraud. Trafficking victims at these compounds were forced to execute scams and beaten if they failed to contact a certain number of victims daily. At least $1.3 million in scam proceeds traced to accounts controlled by associate Luo Hong. Eight US residents pleaded guilty to money laundering roles in the scheme, with one defendant fleeing after cutting off his ankle monitor. Total victim funds deposited exceeded $73.6 million.

IRS-ICE Data Sharing Impacts Tax Compliance

The Trump administration eliminated the firewall between IRS and ICE, allowing immigration enforcement access to tax data. The Yale Budget Lab estimates the IRS will lose between $147 billion and $479 billion over the next decade as immigrants disengage from formal tax filing. One Maryland accounting firm reported losing 550 clients (15% of customer base) as Tax Day approached. Immigrants account for higher employment rates and generate more tax revenue per capita than US-born populations by working more cumulative hours, despite lower hourly wages. Without immigrant tax contributions, public debt would exceed 200% of GDP.

Litigation Updates

$2.4M Anne Arundel Dermatology Data Breach Settlement (Case No. 1:25-cv-02274-GLR)

Anne Arundel Dermatology agreed to a $2.4 million class action settlement for a December 2025 data breach that compromised patient PII and PHI across Virginia, North Carolina, South Carolina, and Maryland locations. Class members who experienced documented out-of-pocket losses can receive up to $5,000 in reimbursement for fraud losses, bank charges, and credit expenses. Class members without documented losses receive an estimated $100 pro rata payment. All class members receive three years of medical data monitoring services including credit monitoring, dark web scanning, and $1 million identity theft insurance. Claims deadline is July 8, 2026, with final approval hearing July 16, 2026.

Adobe Wiretap Class Action Over Optum Patient Communications (Case No. 5:26-cv-02958)

Plaintiff Gil Hodges filed a class action in California federal court alleging Adobe intercepted, recorded, and eavesdropped on patient communications on Optum's website through its Marketo Engage platform. The complaint claims Adobe used tracking technology to intercept PII and PHI without consent, duplicating and transmitting patient data to Adobe servers in real time. The lawsuit alleges violations of the Federal Wiretap Act and California's Invasion of Privacy Act, seeking statutory damages of $5,000 per violation under California law plus Federal Wiretap Act damages. The case follows Adobe's $150 million settlement with DOJ over deceptive subscription practices violating the Restore Online Shoppers' Confidence Act.

Supreme Court Rejects Military Contractor Immunity (Hencely v. Fluor Corporation)

The Supreme Court ruled that military contractors do not have absolute immunity for negligent mistakes in active war zones. The case arose from a 2016 suicide bombing at Bagram Airfield in Afghanistan perpetrated by a former Taliban member working as a Fluor employee. Survivors argued Fluor's failure to follow military rules about tracking native employees made it responsible for the attack. Justice Clarence Thomas wrote that state tort law is not preempted when contractor conduct "was not authorized by, but was even contrary to, federal instructions." Military officials found Fluor "failed in its contractual obligations." The ruling distinguishes Boyle v. United Technologies Corp., which recognized a defense only when "the government directed the contractor to do the very thing that is the subject of the claim."

30-Day Federal Court Removal Deadline is Mandatory (Enbridge Energy, LP v. Nessel)

The Supreme Court unanimously held that 28 U.S.C. § 1446(b)(1)'s 30-day deadline for removing cases from state to federal court is mandatory and not subject to equitable tolling. Justice Sonia Sotomayor wrote that district courts cannot extend the deadline based on extenuating circumstances. Enbridge filed its removal notice 857 days after the deadline expired, arguing "exceptional circumstances" warranted tolling due to federal issues and potential collision with another pending federal case. The Sixth Circuit reversed the district court's acceptance of the late removal, and the Supreme Court affirmed in a 14-page unanimous opinion.

Overpayment Claims Require Plausible Economic Injury (Monahan v. Southwest Airlines Co., 2026 WL 1035070)

The Fifth Circuit dismissed overpayment claims by airline passengers who never flew on Boeing MAX 8 aircraft but alleged Southwest breached purchase agreements by operating the planes before the FAA grounding. Plaintiffs claimed tickets were less valuable because Southwest could have placed them on a MAX 8. The court held the overpayment theory was implausible because Southwest would have charged higher prices had it known about defects and removed MAX 8s from routes, decreasing available seats. The ruling reaffirms that invoking "overpayment" does not establish Article III standing without plausible allegations of actual economic injury.

Honda Fuel Pump Settlement (Oliver v. American Honda Motor Co., Case No. 5:20-cv-00666)

Honda reached a proposed class action settlement covering 6.2 million vehicles equipped with allegedly defective Denso fuel pumps that could cause stalling while driving. The settlement covers 2021-2025 Honda vehicles including Escalade, Silverado, Tahoe, Suburban, Sierra, Yukon models. Honda will extend warranty coverage to 15 years or 150,000 miles, whichever comes first. Vehicles beyond that limit remain eligible for 90 days after final approval. The settlement provides reimbursement for out-of-pocket repair expenses and free loaner vehicles during repairs. The case has been pending for six years since April 2020 shortly after Honda's recall.

Regulatory Guidance

France DNS Blocking Orders Extended to Third-Party Resolvers

A Paris Court of Appeal validated DNS blocking orders requiring Google, Cloudflare, and Cisco to block pirate sites through their third-party DNS resolvers. The ruling goes beyond traditional ISP resolver blocking that France has required for years. The court rejected arguments that DNS resolvers serve a "neutral and passive function" similar to a phone book, holding that the ability to help block access is sufficient under Article L. 333-10 of the French Sport Code regardless of liability. The court ruled that DNS blocking is "proportionate" as long as it stops some subset of users, despite being easily circumvented by VPNs or alternative resolvers. Canal+ brought the case arguing users were switching to third-party DNS to circumvent ISP-level blocking.

Privacy Developments

FBI Extracts Deleted Signal Messages from iPhone Notification Database

The FBI forensically extracted incoming Signal messages from a defendant's iPhone even after the app was deleted by accessing copies stored in the device's push notification database. The extraction demonstrates that secure messaging apps leave data artifacts in unexpected system locations when forensic tools are used with physical device access. Signal already implemented changes to address notification data retention, but the case highlights limitations of encryption when devices are physically compromised.

Surveillance Companies Exploit Telecom Systems for Location Tracking

Citizen Lab researchers identified surveillance vendors exploiting SS7 and Diameter protocol weaknesses to secretly track targets' locations by posing as cellular providers. One campaign sent malicious hidden SMS commands to turn devices into covert tracking beacons. Another exploited SS7 protocols in 3G networks, which lack source verification, authentication, and encryption. Diameter protocols for 4G/5G networks were also attacked because operators failed to implement security protections. Three mobile networks "repeatedly appear as surveillance entry and transit points" functioning as gateways for threat actors. Evidence suggests an Israeli surveillance company may be behind the campaigns based on traffic routing to Israel. Researchers described the attacks as "massive, massive amounts of unauthorized traffic" with over 90% generated by third parties accessing mobile signaling environments.

Wireless Carriers Challenge FCC Location Data Fines

Major wireless carriers AT&T, Verizon, and T-Mobile face $196 million in FCC fines ($91M T-Mobile, $57M AT&T, $48M Verizon) for selling user location data to third parties without adequate safeguards from 2014-2019. The Fifth Circuit vacated AT&T's fines in 2025, ruling that FCC penalties violated the Seventh Amendment right to jury trial. The Supreme Court heard arguments and expressed skepticism about the carriers' claims, but the FCC indicated it may change forfeiture order language to clarify fines are nonbinding until after jury trial. Justice Brett Kavanaugh told carriers "it seems like you've won on the law going forward, one way or the other." The FCC is defending some enforcement authority while Brendan Carr seeks to retain power to force corporate compliance with administration priorities.

Policy Changes

CISA Director Nomination Withdrawn After 13-Month Stall

Sean Plankey withdrew from consideration to lead CISA after his nomination stalled for over a year in the Senate. Plankey was nominated in March 2025 but faced holds from Senator Ron Wyden (D-OR) due to CISA's refusal to publicly release an unclassified report on telecom cyber weaknesses, and from Senator Rick Scott (R-FL) over Coast Guard work concerns. CISA is currently run by Acting Director Nick Andersen. The agency lost approximately 30% of its workforce to layoffs and experienced furloughs during the recent government shutdown. CISA has operated without Senate-confirmed leadership for over a year during heightened cyber threats.

China-Linked Hackers Use Slack, Discord for Mongolian Government Espionage

ESET researchers identified a previously undocumented China-aligned threat actor named GopherWhisper that targeted a Mongolian government entity using Discord, Slack, and Microsoft 365 Outlook for command-and-control operations. The group deployed LaxGopher backdoor malware on roughly a dozen government systems since November 2023. Custom tools written in Go included RatGopher, BoxOfFriends, JabGopher injector, FriendDelivery loader, and SSLORDoor backdoor. The data exfiltration tool CompactGopher compressed files and uploaded them to File.io. The hackers used legitimate online services to conceal malicious activity from network monitoring.

Compliance Takeaways