Get tomorrow's brief in your inbox
Today: Lemonade settles data breach class action for $10.5 million after exposing 190,000 driver's licenses. Forbes agrees to $10 million settlement over tracking California users without consent. Educational platform Infrastructure suffers breach by ShinyHunters gang affecting 9,000+ schools, with 3.6TB of data allegedly stolen. Section 702 surveillance reauthorization pushed back six weeks after GOP cryptocurrency ban attachment fails in Senate.
Infrastructure Data Breach (ShinyHunters)
Infrastructure, the company behind Canvas learning management system, confirmed a cybersecurity incident over the weekend that affected user data at multiple educational institutions. The company's CISO Steve Proud stated that hackers gained access to names, email addresses, student ID numbers, and messages between users at some schools. ShinyHunters claimed responsibility Sunday, alleging theft of 3.6TB of data from more than 9,000 schools. No financial information, passwords, or government documents were compromised. This marks ShinyHunters' second attack on Infrastructure since September, following a string of breaches targeting ADT, McGraw Hill, and Rockstar over the past month. The breach follows PowerSchool's January 2025 incident that exposed 62 million students and 9.5 million teachers.
Lemonade $10.5M Driver's License Data Breach Settlement
Lemonade agreed to pay $10.5 million to resolve a class action lawsuit alleging its online insurance quote platform exposed the driver's license numbers of approximately 190,000 individuals. The settlement addresses claims that the company failed to protect sensitive personal identification data collected during the quote process. The case demonstrates ongoing liability for insurance platforms that handle government-issued identification numbers without adequate security controls.
Forbes $10M California Privacy Settlement
Forbes Media preliminarily agreed to pay $10 million and modify its business practices to settle allegations it violated California's Invasion of Privacy Act and Unfair Competition Law. Plaintiffs alleged Forbes used pen registers and trap and trace devices to collect IP addresses and unique identifiers from website visitors without consent. The trackers, developed by LinkedIn and Microsoft, collected user data and transmitted it to third parties who compiled databases of browsing and shopping habits across the internet. Forbes will provide "greater notice" of tracker use and add controls for California residents over data collection and sharing. Class members will receive an estimated $32 to $189 each.
Wiretapping Suit Dismissed on Standing, Consent, and Class Grounds (Timothee v. Meta Platforms)
A California federal court dismissed a putative class action challenging third-party pixel technology on nonprofit food bank websites. In Timothee v. Meta Platforms, Inc., No. 25-CV-05106-LB, the court held plaintiffs failed to plausibly plead concrete injury under Article III, consented to data collection via privacy policies, and proposed an impermissibly broad nationwide class. The decision followed the Ninth Circuit's Popa v. Microsoft framework, requiring plaintiffs to show alleged privacy harms are "highly offensive" and similar to common-law interferences. The court found disclosure of food bank website usage insufficient to establish standing. Critically, the court considered privacy policies incorporated by reference to establish consent, and struck the proposed class as facially overbroad because many website visitors would not have transmitted relevant information.
J.G. Wentworth Class Action Over Data Sharing
J.G. Wentworth faces a new class action lawsuit accusing it of sharing sensitive financial information from loan applications with third parties without consumer knowledge or consent. The complaint alleges unauthorized disclosure of data collected during the application process. Details of specific third parties, data categories, or alleged statutory violations were not disclosed.
Transamerica Life Insurance $57M Rate Increase Settlement
Transamerica Life Insurance agreed to a $57 million class action settlement over allegations it raised the cost of insurance on certain life insurance policies without proper notice. The settlement addresses claims that policyholders received inadequate notification before premium increases. The case demonstrates ongoing exposure for insurance carriers that modify policy terms without complying with notice requirements in insurance contracts and state insurance regulations.
Supreme Court Denies Vaccine Mandate Challenge (Stockton v. Brown)
The Supreme Court denied review of a lawsuit brought by NBA Hall of Famer John Stockton challenging the Washington Medical Commission's investigation of physicians who discourage COVID-19 vaccination. The Ninth Circuit held plaintiffs, including Children's Health Defense (formerly headed by HHS Secretary Robert F. Kennedy, Jr.), lacked standing because none suffered concrete injury required to establish a right to sue. The denial without comment leaves in place the appeals court's standing determination.
Louisiana Redistricting Litigation (Louisiana v. Callais)
The Supreme Court granted a request to immediately finalize its April 29 decision in Louisiana v. Callais, which struck down Louisiana's congressional map containing two majority-Black districts. The 6-3 ruling invalidated the 2024 map adopted after lower courts found the prior single majority-Black district map violated Section 2 of the Voting Rights Act. Louisiana postponed its May 16 congressional primaries to allow time to draw a remedial map expected to favor Republicans. Justice Ketanji Brown Jackson dissented from the immediate finalization, arguing it creates "chaos" and has a "strong political undercurrent." Tennessee and Alabama called special sessions to redraw congressional maps in response to the ruling. Multiple lawsuits were filed against Louisiana Governor Jeff Landry over his order suspending the primary election.
Section 702 Reauthorization Delayed Six Weeks
Congress extended Section 702 warrantless surveillance authority for another six weeks after the House attached a permanent ban on Federal Reserve digital currency issuance to the three-year reauthorization bill. Senate Majority Leader John Thune warned the digital currency ban was "not happening" as part of spy law renewal, stalling the House version. As part of the extension deal, Senate Intelligence Committee leaders Tom Cotton and Mark Warner will send a letter directing DNI Tulsi Gabbard and DOJ to declassify an annual 702 court opinion within 15 days for use in negotiations. The Senate approved the extension by voice vote, followed by House passage on a 261-111 vote.
EFF Submission to UK Digital ID Consultation
The Electronic Frontier Foundation submitted comments to the UK government's consultation on a proposed national digital ID scheme. EFF's submission identified six interconnected risks: mission creep, privacy rights infringements, security risks, reliance on inaccurate technologies, discrimination and exclusion, and deepening power imbalances between the state and public. EFF argued that even strong safeguards cannot resolve the fundamental problem that mandatory digital ID shifts power from individuals to the state by allowing government to determine what citizens can access, not just verify identity. The submission urged the UK government to reject the digital ID proposal and ensure no one is coerced into digital systems to participate in public life.
Mediaworks Hungary Ransomware Breach
World Leaks ransomware group claimed responsibility for a breach of Hungarian media company Mediaworks, allegedly releasing 8.5TB of data including payroll records, contracts, financial statements, and internal communications. Mediaworks confirmed the incident and warned journalists that using, processing, or disclosing the illegally obtained data could constitute a criminal offense. Independent media outlets reported the leaked documents included notes from a January 2025 editorial meeting suggesting Mediaworks would "contact Moscow for help" regarding articles discrediting Ukrainian President Zelensky. Mediaworks threatened legal action against Media1 for publishing the information, but the outlet refused to remove the article, citing public interest. World Leaks emerged in early 2025 as a rebrand of Hunters International, focusing on data theft and extortion rather than encryption.
Section 230 and the Open Social Web
Analysis published in TechDirt argues that reducing Section 230 protections would benefit Big Tech at the expense of the Open Social Web and decentralized platforms. Section 230 states that "No provider or user of an interactive computer service shall be treated as the publisher or speaker of any information provided by another information content provider." The author argues that while multi-billion dollar companies can absorb multimillion-dollar lawsuits, small hosts and decentralized Fediverse servers would be picked off one by one without Section 230 immunity. The article contends that weakening Section 230 would entrench corporate control of speech online rather than undermining it, as small server operators cannot sustain litigation costs that incumbents easily absorb.
Trump Administration Fires National Science Board
The Trump administration terminated all 22 members of the National Science Board via email on Friday, with no explanation provided. The NSB helps steer the National Science Foundation and acts as an independent advisory body for the president and Congress on scientific and engineering issues. Multiple dismissed members believe the timing was deliberate, as the board was finalizing a report highlighting a widening U.S.-China gap in research and development spending in areas including artificial intelligence, quantum computing, and the Moon race. The move follows HHS Secretary Robert F. Kennedy Jr.'s firing of the CDC's entire ACIP vaccination panel last summer. Trump has nominated investor Jim O'Neill to be the next NSF Director.
Audit third-party tracking technologies on all websites and apps. Ensure California users receive conspicuous notice of data collection and sharing practices per CCPA, with functional opt-out controls. Forbes' $10 million settlement demonstrates ongoing exposure for tracker deployments without adequate consent mechanisms.
Verify multifactor authentication is deployed on all systems handling sensitive user data, particularly educational platforms and SaaS applications. Infrastructure's breach by ShinyHunters follows PowerSchool's failure to implement MFA, which contributed to a $17.25 million settlement.
Review loan application and quote system data flows. Document third-party sharing agreements and ensure applicants receive clear notice and provide affirmative consent before data transmission to avoid exposure under California privacy laws. J.G. Wentworth and Lemonade cases demonstrate liability for inadequate controls on sensitive financial and identification data.
Prepare privacy policy consent defenses for website tracking litigation. Ensure policies explicitly notify users of third-party pixels, are incorporated into terms of use, and document user acceptance. The Timothee dismissal shows courts will credit clear privacy policies as consent when they explicitly describe tracking practices.
Monitor Section 702 developments through late May. When final reauthorization language is enacted, review compliance obligations for any organization handling communications data for foreign intelligence targets or subject to FISA collection.