Get tomorrow's brief in your inbox
Today: Pennsylvania State Education Association settles data breach class action for $2.5 million with July filing deadline. Microsoft disrupted Fox Tempest malware-signing service used by Rhysida, INC, Qilin, and Akira ransomware groups. UK regulator Ofcom will require tech firms to use hash matching to detect and remove non-consensual intimate images within two days under updated codes taking effect this autumn.
Microsoft Disrupts Fox Tempest Malware-Signing-as-a-Service Platform
Microsoft unsealed a U.S. District Court case detailing the disruption of Fox Tempest, a malware-signing-as-a-service (MSaaS) operation active since May 2025. The service abused Microsoft's Artifact Signing to create fraudulent code-signing certificates, allowing ransomware affiliates from Rhysida, INC, Qilin, and Akira to bypass security controls. Microsoft seized the Fox Tempest website, took hundreds of virtual machines offline, revoked over 1,000 code-signing certificates, and blocked access to infrastructure. Cryptocurrency analysis showed the service received millions of dollars from cybercriminals. The service charged thousands of dollars per certificate and was used to distribute Oyster, Lumma Stealer, and Vidar malware families through purchased advertisements masquerading as legitimate software download sites.
Pennsylvania State Education Association Data Breach Settlement ($2.5 Million)
The Pennsylvania State Education Association reached a $2.5 million class action settlement for individuals affected by a data breach. The settlement establishes a compensation fund for affected members whose personal information was compromised. Class members must file claims by July 6, 2026 to qualify for compensation. The settlement covers notification costs, credit monitoring services, and direct payments to affected individuals based on documented harm.
Liberty Mutual Ransomware Attack Class Action
Liberty Mutual Insurance faces a class action lawsuit alleging failure to safeguard sensitive information belonging to more than 15,000 policyholders exposed in a ransomware attack. The complaint alleges inadequate security controls and failure to implement reasonable safeguards to protect customer data from ransomware threats. The lawsuit seeks damages for affected policyholders and injunctive relief requiring enhanced security measures. The case joins a growing body of litigation holding insurers accountable for data security failures despite their role in underwriting cyber insurance policies.
TD Bank and Airlines Reporting Corporation Data Sale Lawsuit
A class action lawsuit accuses TD Bank and Airlines Reporting Corporation (ARC) of selling airline passengers' personal and financial data to federal government agencies without consent. The complaint alleges the defendants monetized transaction data, flight records, and financial information by providing it to law enforcement and intelligence agencies. The lawsuit claims violations of state privacy laws, consumer protection statutes, and breach of implied contracts with customers who reasonably expected their transaction data would remain confidential. The case raises questions about the scope of third-party data sharing with government entities absent judicial process.
Amazon Fire TV Viewing Data Privacy Lawsuit
Amazon faces a class action lawsuit alleging violations of consumer privacy laws by collecting and selling data about what consumers watch on Amazon Fire TVs. The complaint claims Amazon secretly tracked viewing habits across all content sources, not just Amazon's own streaming services, and monetized this data for targeted advertising without obtaining informed consent. The lawsuit alleges violations of the Video Privacy Protection Act (VPPA), state consumer protection laws, and breach of contract. Amazon's privacy policy allegedly failed to adequately disclose the extent of cross-platform viewing data collection and third-party data sales.
UK Ofcom Requires Hash Matching for Non-Consensual Intimate Images
UK communications regulator Ofcom announced updated codes of practice requiring tech companies to use hash matching technology to detect and remove non-consensual intimate images, including AI-generated deepfakes. The codes will take effect this autumn pending parliamentary approval. Hash matching converts images into digital fingerprints stored in databases to prevent future uploads of the same or similar files. The requirement accompanies legislation banning nudification tools and mandating image removal within two days. Tech companies failing to remove images within the two-day window face service blocking. Prime Minister Keir Starmer characterized the issue as a national emergency following the spread of millions of nudified images via xAI's Grok chatbot.
TAKE IT DOWN Act Implementation Deadline
Online platforms face a May 20, 2026 deadline to implement notice-and-takedown processes for non-consensual intimate imagery (NCII) under the TAKE IT DOWN Act (TIDA). Covered platforms must conspicuously offer removal processes, remove reported material within 48 hours of valid removal requests from depicted individuals or authorized agents, and make reasonable efforts to identify and remove duplicates. The law applies to public-facing user-generated content platforms and sites devoted to NCII. Exemptions include ISPs, email providers, and services where user content is incidental to preselected content. The law criminalizes knowing and intentional disclosure of NCII, whether real or AI-generated, of adults or minors.
Trump FCC Proposes Know Your Customer Rules for Phone Purchases
The FCC announced consideration of Know Your Customer rules requiring buyers of new phones to present government ID, physical address, full legal name, and existing phone number at point of sale. The proposal includes $2,500 penalties per call per carrier for robocall violations. The FCC characterized the rules as addressing illegal robocalls, but privacy advocates raised concerns about surveillance implications for prepaid phone markets. The proposal would affect refugees, domestic abuse victims, journalists protecting sources, and activists seeking anonymous communications. The enforcement likelihood remains uncertain given the administration's broader deregulatory agenda.
Huawei Zero-Day Caused Luxembourg Nationwide Telecom Outage
A previously undisclosed zero-day vulnerability in Huawei enterprise router software caused a three-hour nationwide telecommunications outage in Luxembourg on July 23, 2025. The vulnerability, which has never received a CVE identifier or public disclosure, allowed specially crafted network traffic to send Huawei routers into continuous restart loops, crashing POST Luxembourg's infrastructure. POST confirmed the incident exploited "a non-public, non-documented behaviour, for which no patch was available at the time." Huawei told POST it had never encountered the attack among any customers and had no ready solution. The outage disrupted mobile, landline, and emergency communications for hundreds of thousands of residents. Luxembourg's public prosecutor concluded there was no evidence of a targeted attack against POST specifically. The vulnerability remains unexplained and unpatched ten months after the incident.
Microsoft Israel Chief Departs After Human Rights Investigation
Microsoft's Israel chief departed following an investigation into the company's business relationships with the Israeli Ministry of Defense. The Guardian reported Microsoft technologies were used in systems connected to mass surveillance and military targeting operations in Gaza in apparent violation of Microsoft's human rights standards. Microsoft suspended certain services in September 2025 after initial investigations raised concerns about cloud and AI infrastructure use in conflict settings. Civil society organizations including EFF, Access Now, Amnesty International, Fight for the Future, and 7amleh sent a May 7, 2026 letter demanding Microsoft publicly release investigation findings, suspend business relationships tied to human rights abuses, and implement safeguards to prevent technologies from contributing to further harm. The employment action represents accountability for failing to uphold Microsoft's human rights commitments, though the company has not publicly disclosed investigation scope, suspended services, or future safeguards.
Senator Wyden Demands Section 702 FISA Court Opinion Declassification
Senator Ron Wyden called out the Trump Administration for ignoring a May 15 deadline to declassify a Foreign Intelligence Surveillance Act (FISA) Court opinion about surveillance conducted under Section 702. Senate Intelligence Committee Chairman Tom Cotton and Vice-Chairman Mark Warner requested the opinion release. The FISA Court extended Section 702 surveillance powers conditionally, requiring government steps to curb documented abuses. The Trump administration refused concessions and the FISA Court declined to publish its full decision. Wyden secured a commitment from Intelligence Committee leadership to push for release but the executive branch has not responded to congressional requests.
Supreme Court Abortion Pill Mifepristone Access Restored
The Supreme Court restored telemedicine and mail access to mifepristone indefinitely while litigation continues in lower courts, addressing Louisiana's challenge to FDA policy allowing abortion providers to prescribe the drug through telemedicine and send it by mail. The Court issued its order without a Justice Department brief defending the FDA, a highly unusual decision reflecting the Trump administration's political calculus on abortion issues. The Fifth Circuit had issued a ruling blocking prescriptions without in-person visits, creating chaos among doctors, pharmacists, and patients before Justice Alito issued an administrative stay with a short deadline.
Implement NCII removal processes by today (May 20, 2026) under the TAKE IT DOWN Act. Covered platforms must offer conspicuous removal request processes, remove content within 48 hours, and implement duplicate detection technology.
Review code-signing certificate validation following Microsoft's Fox Tempest disruption. Verify endpoint security tools check certificate revocation lists and validate certificate chains to detect fraudulent certificates used by ransomware affiliates.
File PSEA data breach claims by July 6, 2026 if your organization or employees were affected by the Pennsylvania State Education Association breach. The $2.5 million settlement provides compensation for documented harm.
Prepare for UK hash matching requirements if operating platforms accessible to UK users. Ofcom's updated codes taking effect autumn 2026 require hash matching technology for non-consensual intimate images with two-day removal deadlines.
Audit viewing data collection practices for Video Privacy Protection Act (VPPA) compliance following the Amazon Fire TV lawsuit. Obtain explicit consent before collecting viewing data from third-party apps and ensure privacy policies accurately disclose data monetization practices.