Get tomorrow's brief in your inbox
May 1, 2026
Today: The Supreme Court struck down Louisiana's majority-black congressional district as an unconstitutional racial gerrymander in a 6-3 decision, potentially reshaping redistricting ahead of November midterms. Absolute Dental agreed to a $3.3 million settlement for a 2025 data breach, while Utah becomes the first state to regulate VPN usage to enforce age-verification mandates starting May 6. Congress punted FISA Section 702 renewal to June 21 after Senate rejected a House bill containing a digital currency ban.
Absolute Dental $3.3M Data Breach Settlement
Absolute Dental has agreed to a $3.3 million class action settlement to resolve claims that it failed to prevent a 2025 data breach that compromised patient information. The settlement addresses allegations that the dental practice chain did not implement adequate security measures to protect sensitive health and personal data.
France Arrests 15-Year-Old Over National ID Agency Breach
Paris prosecutors charged a 15-year-old suspect, allegedly operating under the alias "breach3d," with breaching the National Agency for Secure Documents (ANTS) and attempting to sell 12 to 18 million French citizens' records on cybercriminal forums. The teen was taken into custody on April 25 and faces up to seven years in prison and a €300,000 ($350,000) fine under French law. Compromised data includes login credentials, names, email addresses, birth dates, postal addresses, phone numbers, and places of birth. ANTS manages passports, national identity cards, residence permits, driver's licenses, and a new age-verification app for social media.
FBI Advisory on Cargo Hijacking via Compromised Freight Systems
The FBI issued an advisory warning that cybercriminals have stolen nearly $725 million worth of cargo in the U.S. and Canada in 2025, a 60% increase from 2024. Threat actors breach freight broker and carrier systems, impersonate legitimate companies on load boards, and redirect shipments. Attacks involve malicious carrier-broker agreements that compromise computer systems, followed by double-brokering schemes where cybercriminals divert cargo to unauthorized locations. Some attackers have changed carrier registration information with the Federal Motor Carrier Safety Administration and updated insurance records to accept previously unauthorized loads. Victims include car dealerships and vape companies, with individual thefts reaching $1 million.
Louisiana v. Callais: Supreme Court Strikes Down Majority-Black District as Racial Gerrymander
The Supreme Court ruled 6-3 in Louisiana v. Callais that Louisiana's congressional map creating a second majority-black district constitutes an unconstitutional racial gerrymander. The decision immediately affects Louisiana's May 16 primary elections, with Governor Jeff Landry preparing to suspend the primaries to allow the Legislature to draw a new map. The "non-African American" voters who challenged the map requested expedited finalization of the Supreme Court's decision, bypassing the normal 32-day waiting period. Louisiana confirmed it will postpone congressional primary elections, with early voting previously scheduled to begin May 2. The ruling may allow Republicans to gain one or two seats, as the party currently holds four of six House seats. Black voters who defended the map urged the court to delay judgment issuance until after the 2026 election, noting mail-in ballots have already been distributed to overseas voters.
First Choice Women's Resource Centers v. Davenport: Religious Nonprofits Can Challenge Donor Subpoenas in Federal Court
The Supreme Court ruled unanimously that First Choice Women's Resource Centers has standing to challenge New Jersey Attorney General Matthew Platkin's subpoena demanding donor information in federal court. Justice Neil Gorsuch wrote that the subpoena's threat of contempt charges and penalties constitutes an "actual or imminent" injury sufficient for standing, as it deters donors from associating with the group. The decision reverses lower courts' holdings that First Choice had not suffered sufficient injury because New Jersey had not yet imposed sanctions for non-compliance.
Hikma Pharmaceuticals: Justices Signal Protection for Generic Drug Manufacturers from Inducement Liability
Oral arguments in Hikma Pharmaceuticals USA v. Amarin Pharma indicate the Supreme Court will likely rule that generic manufacturers are not liable for "actively inducing" patent infringement when pharmacists dispense their products for patented uses. The case concerns whether Hikma's FDA-mandated label, investor press releases, and website statements constitute active inducement of infringement. Justices expressed skepticism that FDA-required labeling can establish intent to induce infringement, that press releases directed to investors rather than prescribers show inducement, and that disclaimers on websites negate inducement claims. The ruling may establish that generic manufacturers cannot be held liable for independent decisions by pharmacists about how to prescribe their products.
Consumer Class Actions
DXL Big + Tall faces a class action in Washington state alleging the retailer sent spam emails containing false or misleading information. Nutro is defending a class action claiming its Natural Choice dog food falsely advertises "no artificial preservatives." Campbell's faces a lawsuit alleging its microwavable soup products are falsely advertised as safe to heat in the microwave. Hyundai is recalling nearly 300,000 vehicles due to a seat belt anchor defect that could cause detachment.
Congress Extends FISA Section 702 Until June 21
Congress approved a 45-day extension of Section 702 of the Foreign Intelligence Surveillance Act (FISA) hours before the midnight deadline, punting long-term reauthorization to June 21. The House voted 261-111 to approve the extension after the Senate rejected the previous bill because it included a ban on the Federal Reserve's ability to issue a digital currency. The extension includes a provision requiring declassification of a recent Foreign Intelligence Surveillance Court opinion on 702 usage. Senate Majority Leader John Thune stated the extension provides additional time to negotiate a long-term reauthorization. The Senate is working on its own three-year extension proposal.
EU/UK Market Abuse Regulation: Cybersecurity Incidents as "Inside Information"
Cybersecurity incidents may constitute "inside information" under EU/UK Market Abuse Regulation (MAR), triggering immediate disclosure obligations for issuers with financial instruments admitted to trading on regulated markets. Information qualifies as "inside information" if it is (1) precise, (2) not public, and (3) likely to have a significant effect on the price of financial instruments if disclosed. Disclosure may be delayed only if immediate disclosure would prejudice legitimate interests, delay would not mislead the public, and the issuer can ensure confidentiality. Factors indicating a cybersecurity incident constitutes inside information include material impact on revenue or financial performance, operational disruption to critical infrastructure, required withdrawal of earnings guidance, regulatory investigations or fines, and significant reputational risk affecting customer trust.
Utah's VPN Regulation Takes Effect May 6
Utah Senate Bill 73, the "Online Age Verification Amendments," takes effect May 6, 2026, making Utah the first state to regulate VPN usage to enforce age-verification mandates. The law establishes that individuals are considered to be accessing websites from Utah based on physical location, regardless of VPN or proxy server use. Commercial entities hosting "a substantial portion of material harmful to minors" are prohibited from facilitating or encouraging VPN use to bypass age checks, including providing VPN instructions. The law creates liability for websites that cannot verify the age of Utah residents using VPNs, potentially forcing sites to ban VPN IP addresses or mandate age verification globally. A separate 2% tax on online adult content revenues takes effect in October 2026.
State ALPR Data Transparency Under Threat
Arizona and Connecticut are considering legislation to block public access to automated license plate reader (ALPR) data, following similar measures enacted in other states. Public records requests have revealed ALPR abuse, including racist uses, surveillance of protestors, abortion clinic tracking, and fraudulent narratives about law enforcement use. The laws would exempt ALPR data from freedom of information requests, preventing oversight of data-sharing between agencies, scan volumes, hit ratios, false match rates, and images of individuals' vehicles. EFF opposes the legislation, arguing that while raw ALPR data raises privacy concerns, accountability information such as data-sharing reports, network audits, and usage statistics should remain accessible.
GUARD Act Threatens to Block Minors from AI Tools
Congressional lawmakers are moving forward with the GUARD Act, an age-gating bill that would require age verification and block minors under 18 from accessing "AI chatbots" and "AI companions." The bill defines "AI chatbot" as any system generating responses not fully pre-written by developers, covering basic functionality of all AI-powered tools. "AI companion" is defined as any chatbot producing human-like responses designed to "encourage or facilitate" interpersonal or emotional interaction, which could include homework helpers, customer service bots, and general-purpose assistants. The bill requires "reasonable age verification" measures beyond simple checkboxes, likely necessitating government ID or third-party age-checking systems. A key vote is expected this week.
Zambia Cancels Global Digital Rights Conference Days Before Start
Zambia cancelled RightsCon, the world's largest digital human rights conference scheduled for May 5, days before 5,000 delegates from 150 countries were set to arrive in Lusaka. Zambia's Minister of Technology and Science Felix Mutati cited incomplete security clearances and concerns about the conference's "dialogue" and "thematic issues." Secretary for Information and Media Thabo Kawana stated the cancellation was "necessitated by the need for comprehensive disclosure of critical information relating to key thematic issues proposed for discussion." ARTICLE 19 stated that "pressure from foreign governments contributed to the Zambian government's decision." Local reports suggest the cancellation occurred because Taiwanese delegates were scheduled to speak at a Chinese-government-funded venue. The Mulungushi International Conference Center was built with a $30 million grant from China.
U.S. Conference of Catholic Bishops v. O'Connell Awaits Cert Decision
The Supreme Court is considering whether to grant certiorari in U.S. Conference of Catholic Bishops v. O'Connell, a case examining the scope of the First Amendment's church autonomy doctrine. The D.C. Circuit held that church autonomy provides only a defense to liability, not immunity from litigation, allowing courts to require churches to litigate religious disputes even if damages cannot be awarded. The D.C. Circuit also held that church autonomy defenses cannot receive immediate interlocutory appeal and can be circumvented if plaintiffs plausibly allege claims arise under "neutral principles of law." The case involves a putative class action from a Catholic parishioner claiming a description of Peter's Pence religious offerings he heard at Mass misled him about how donations would be used. Fifteen amicus briefs urged the Court to take the case. The Supreme Court removed the case from the May 1 conference and will consider it at a later date.
Adam Cassady Advances as Cyber Ambassador Nominee
The Senate Foreign Relations Committee approved Adam Cassady, President Trump's nominee for cyber ambassador to helm the State Department's Bureau of Cyberspace and Digital Policy, by a vote of 17-5. The nomination now goes to the full Senate. The bureau has been without a leader since the start of the second Trump administration and has seen its portfolio divided among three offices. Cassady, a senior leader at the National Telecommunications and Information Administration, stated that digital infrastructure including subsea cables, semiconductors, and satellites is "as strategically significant as sea lanes, airspace and energy routes were in earlier eras." During his confirmation hearing, Cassady declined to take a position on the administration's decision to allow Nvidia to sell advanced AI processors in China, stating he had not been briefed at a classified level.
Public companies subject to EU/UK MAR: Establish cybersecurity incident assessment protocols that evaluate whether incidents constitute "inside information" requiring immediate disclosure. Document delay decisions and confidentiality controls.
Healthcare providers: Review Absolute Dental settlement ($3.3M for 2025 breach) and audit data security controls for patient information. Verify breach response plans and incident detection capabilities are current.
Freight brokers and carriers: Implement multi-factor authentication for load board access following FBI advisory on $725M in cargo hijacking losses. Verify carrier identities through secondary channels and monitor FMCSA registration for unauthorized changes.
Websites with age-gated content: Prepare for Utah's May 6 VPN regulation requiring age verification regardless of VPN use. Assess VPN detection capabilities, review whether site content includes VPN instructions, and evaluate geofencing or universal age verification strategies.
Companies operating AI-powered tools: Evaluate whether products meet GUARD Act definitions of "AI chatbot" or "AI companion" ahead of congressional vote. Assess whether conversational design features trigger "facilitating interpersonal interaction" classification and prepare age-verification plans or minor access restrictions.
Generated by Carolina Clear Tech • carolinacleartech.com