← Carolina Clear Tech

Legal & Privacy Brief

2026-05-14

Listen to this brief (16:40)

Download MP3
Show Notes

Show Notes - 2026-05-14

Stories Covered

CVEs Referenced

CVE-2026-41089, CVE-2026-41096

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - May 14, 2026

Today: Fidelity settles data breach class action for $2.5 million. TransUnion faces class certification over fraudulent credit report items affecting 281,000 consumers. UK announces Computer Misuse Act reforms to shield security researchers, while European Commission pushes social media age restrictions.

Enforcement Actions

$2.5M Fidelity Investment data breach class action settlement

Fidelity Investments agreed to pay $2.5 million to settle claims that it failed to prevent a 2024 data breach compromising sensitive consumer information. The settlement covers class members whose personal data was exposed in the breach. This represents another in a series of financial services data breach settlements where companies face liability for inadequate security measures protecting customer information.

Dream Market administrator arrested in Germany, faces 240 years on money laundering charges

German and U.S. authorities arrested Owe Martin Andresen, 49, alleged administrator of Dream Market, a dark web marketplace that operated from 2013 to 2019. Andresen faces six charges of money laundering and six charges of international money laundering in the U.S., totaling up to 240 years in prison, plus up to five years on German charges. Prosecutors allege Andresen laundered approximately $2 million between August 2023 and April 2025 by converting cryptocurrency commissions from illegal marketplace sales into gold bars shipped to Germany. During May 7 raids, authorities seized $1.7 million in gold bars, $23,000 in cash, and located bank accounts and crypto wallets holding another $1.2 million. At its peak, Dream Market facilitated the sale of 90 kilograms of heroin, 450 kilograms of cocaine, 25 kilograms of crack cocaine, 36 kilograms of fentanyl, stolen personal information, and counterfeit identification documents. U.S. Attorney Theodore Hertzberg confirmed Andresen will be prosecuted in both jurisdictions.

DOJ admits DHS press release falsely accused federal judge, faces contempt charges

The Department of Justice publicly admitted that a Department of Homeland Security press release falsely accused U.S. District Judge Melissa DuBose of knowingly releasing an ICE detainee wanted for murder. DOJ attorney Kevin Bolan acknowledged the allegation "simply was not true" during a court hearing. The DHS press release, which remains live on the agency's website, labeled Judge DuBose an "Activist Biden Judge" and claimed she released "a criminal illegal alien from the Dominican Republic with an international warrant for homicide." Assistant US Attorney Kevin Bolan admitted he failed to disclose the warrant information to the judge because ICE told him it was confidential, despite ICE having already publicly disclosed the same information on April 16, 2026. Judge DuBose stated the false press release put her personal security at risk and is considering contempt charges against DOJ attorneys.

Litigation Updates

TransUnion class action certified over alleged failure to block fraudulent credit report items

A Pennsylvania federal judge certified a class of nearly 281,000 consumers in a lawsuit alleging TransUnion failed to properly block fraudulent transactions from credit reports. The certification allows the case to proceed as a class action rather than individual claims. The lawsuit centers on TransUnion's compliance with Fair Credit Reporting Act requirements to investigate and block fraudulent items when consumers dispute them.

HVAC manufacturers face price-fixing class action

Seven major heating, ventilation and air conditioning manufacturers including Carrier, Trane, and Rheem face a class action lawsuit alleging they conspired to fix prices for HVAC equipment. The lawsuit claims the manufacturers coordinated to artificially inflate equipment prices across the United States. Price-fixing allegations typically involve antitrust violations under the Sherman Act and can result in both civil damages and criminal penalties.

Snapfish faces class action over misleading discount claims

Photo printing service Snapfish faces a class action lawsuit alleging the company misleads customers with fake discounts by keeping products "always on sale" at inflated original prices. The lawsuit claims Snapfish engaged in deceptive pricing practices in violation of consumer protection laws. These claims typically fall under state unfair and deceptive trade practices statutes that prohibit false reference pricing and perpetual "sales."

Regulatory Guidance

UK announces Computer Misuse Act reforms to shield security researchers

The British government announced it will rewrite the Computer Misuse Act 1990 as part of a broader national security package. The reforms, outlined in briefing documents published with the King's Speech, aim to address cybersecurity industry complaints that the 1990 law creates legal uncertainty for legitimate security research, vulnerability testing, penetration testing, and threat intelligence operations. The Computer Misuse Act was drafted before cloud computing, ransomware, cryptocurrency, and the modern cybersecurity industry existed. While in opposition, the Labour Party proposed a public interest defense for hackers that was not passed. The government has not yet published draft legislation, and key questions remain about whether ministers will introduce a formal statutory defense for public-interest cybersecurity research or focus on updated investigative powers. The briefing notes also referenced proposed "Cyber Crime Risk Orders" that could impose restrictions on individuals considered to pose ongoing cyber threats. The CyberUp Campaign stated the reforms represent "a genuine turning point for cyber security in the UK" but emphasized the need for "a clear, workable statutory defence for good-faith cyber security activity."

Microsoft patches over 130 vulnerabilities as AI-driven discovery accelerates

Microsoft issued patches for more than 130 security vulnerabilities in May 2026, following 173 patches in April, putting the company on pace to break its annual vulnerability record. Tom Gallagher, vice president of engineering at Microsoft's Security Response Center, attributed the surge to AI tools enabling security researchers to examine software more carefully than was practical previously. Microsoft publicly revealed MDASH, an internal AI system that found 16 of the May vulnerabilities including four rated critical without human identification. In retrospective testing on five years of known Windows vulnerabilities, MDASH found 96% of known flaws in one component and 100% in another. The UK's National Cyber Security Centre warned in April that organizations should prepare for a surge of urgent software updates driven by AI-assisted vulnerability discovery. Critical vulnerabilities include CVE-2026-41089 in Windows Netlogon rated 9.8 out of 10 severity, allowing remote code execution via network requests to domain controllers without authentication, and CVE-2026-41096 in Windows DNS Client, also rated 9.8, allowing remote code execution in certain unspecified configurations.

Privacy Developments

European Commission head pushes for social media age restrictions across EU

European Commission President Ursula von der Leyen announced Tuesday that she believes Europe must delay social media access for children, signaling the EU could soon limit young teenagers' platform use. An expert panel appointed by the commission will release recommendations in coming weeks on safeguarding children online. Von der Leyen said she expects their work could lead to a legal proposal delaying the age at which children can access social media as soon as summer 2026. The commission can only recommend legislation, requiring Europe's parliament to pass a law for limits to take effect. Von der Leyen stated "discussions about a minimum age for social media can no longer be ignored" and focused on what she characterized as addictive design features embedded in platforms. The forthcoming Digital Fairness Act will "target addictive and harmful design practices like attention capture, complex contracts, subscription traps." Several European countries including Spain, Greece, Norway, France, Denmark, Turkey and the Netherlands are considering or implementing age verification protocols. The commission is investigating Meta for possible Digital Services Act violations including insufficient minor protections and addictive design features, and has launched a probe into xAI's Grok nudification tool.

EFF challenges commercial surveillance enabling government data purchases

The Electronic Frontier Foundation published an advocacy piece highlighting how widespread commercial surveillance and weak privacy laws allow data brokers to harvest and sell user data to law enforcement agencies including the FBI, CBP, and ICE. EFF argues the government exploits this system to buy sensitive information, particularly location data over time, that would ordinarily require a warrant to collect. The organization is advocating for stronger privacy laws, consumer rights litigation, technology investigations, and tools like Privacy Badger to block tracking at the source. EFF emphasizes that commercial surveillance directly feeds government surveillance, enabling mass spying used to control and intimidate people.

Policy Changes

Fourth Amendment dispute over race in seizure analysis reaches Supreme Court

The federal government petitioned for certiorari in United States v. Carter, asking the Supreme Court for a categorical rule that race is constitutionally off-limits in any Fourth Amendment reasonable-person analysis. The case involves Donte Carter, a Black man approached by D.C.'s gun recovery unit for "firearm interdiction" based on an alleged "uptick in shootings." Officers asked Carter whether he had anything on him and directed him to hike his pants up, discovering a stolen firearm. The D.C. Court of Appeals held Carter was improperly seized and considered his race as part of the totality of circumstances, explaining that "a Fourth Amendment reasonable-suspicion seizure inquiry would be incomplete, and indeed, incongruent with the objective reality that people of color face during interactions with law enforcement." The D.C. court noted Black Americans face disproportionate police violence, leading to perceptions of being unsafe around law enforcement, and are especially distrustful of police and less likely to terminate encounters due to skepticism their constitutional rights will be respected. The government's position contradicts its argument in Noem v. Vasquez-Perdomo where it contended "by definition, no particular circumstantial factor is categorically off-limits" and that race or ethnicity "can be a factor supporting reasonable suspicion in appropriate circumstances." Justice Brett Kavanaugh agreed in Vasquez-Perdomo that race or ethnicity can be a "relevant factor."

South Africa withdraws AI policy after AI-generated fake citations discovered

South Africa withdrew its first draft national AI policy after researcher Damien Charlotin discovered it contained at least four fictitious citations that appeared to be AI-generated hallucinations. The policy, which addressed dangers of AI-generated misinformation, included fake sources in its reference list. Minister of Communications and Digital Technologies Solly Malatsi stated "the most plausible explanation is that AI-generated citations were included without proper verification. This should not have happened." Malatsi characterized the failure as compromising "the integrity and credibility of the draft policy" and stated "this unacceptable lapse proves why vigilant human oversight over the use of artificial intelligence is critical."

Compliance Takeaways