Get tomorrow's brief in your inbox
Today: The FTC warned 12 major tech platforms they are violating the Take It Down Act by failing to offer compliant removal processes for nonconsensual intimate images, with fines up to $53,088 per violation. Discord migrated all users to end-to-end encryption by default while federal courts continue blocking DOJ attempts to obtain invasive medical records of transgender minors through administrative subpoenas. A federal judge condemned DOJ attorneys for misrepresenting information to courts in support of Trump's anti-trans agenda.
FTC warns 12 major tech firms of violating Take It Down Act
The Federal Trade Commission on May 20 sent compliance warning letters to Alphabet, Amazon, Apple, Automattic, Bumble, Discord, Match Group, Meta, Microsoft, Pinterest, Reddit, SmugMug, Snapchat, TikTok and X for failing to comply with the Take It Down Act (TIDA), which began enforcement on May 19, 2026. The law requires platforms to provide removal processes for nonconsensual intimate images and delete them within 48 hours of a request. TIDA was enacted in May 2025 and gave industry one year to design compliance strategies. The platforms have no compliant removal request process in place.
Federal judge condemns DOJ for lying in transgender medical records case
U.S. District Judge Mary McElroy issued a scathing ruling condemning the Department of Justice for misrepresenting and withholding information from both her court and the U.S. District Court for the Northern District of Texas in an effort to obtain invasive patient information about transgender minors receiving gender-affirming medical care. The DOJ used forum shopping tactics, attempting to enforce a subpoena issued to Rhode Island Hospital through a Texas court rather than the proper Rhode Island jurisdiction. Judge McElroy opened her ruling by stating DOJ "has proven unworthy of this trust at every point in this case." The ruling follows more than a half-dozen federal judges nationwide blocking similar DOJ administrative subpoenas seeking patient information from medical providers.
Trump's IRS lawsuit settlement erases $100 million tax debt
The Department of Justice announced a settlement agreement in Trump v. IRS that releases Donald Trump, his two eldest sons, and the Trump Organization from all IRS claims, examinations, and appeals related to matters raised or that could have been raised in the lawsuit. The settlement creates a $1.776 billion "Anti-Weaponization Fund" drawn from the federal Judgment Fund to compensate individuals claiming to be victims of political "lawfare," administered by a five-member board Trump controls. Reporting from 2023 indicated the IRS had calculated Trump owed over $100 million in unpaid taxes plus interest and penalties. The settlement agreement is three paragraphs long and permanently bars the U.S. from prosecuting or pursuing any tax claims against the plaintiffs or related individuals, trusts, and affiliated entities.
Home Depot faces class action over license plate tracking and law enforcement sharing
A new class action lawsuit alleges Home Depot illegally used automated license plate recognition (ALPR) technology to track customers' vehicles in parking lots and shared this data with law enforcement without customer knowledge or consent. The complaint challenges both the collection of biometric-equivalent location data and the third-party disclosure to government agencies without adequate legal process or privacy protections.
Rolling Stone Magazine settles lifetime subscription breach of contract claims
Penske Media Corp. agreed to a class action settlement resolving claims it breached contracts for "lifetime" subscriptions to Rolling Stone Magazine. The lawsuit alleged the publisher terminated or failed to honor perpetual subscription agreements sold to readers who paid for lifetime access. Settlement terms were not disclosed in available filings.
Connecticut trial begins over allegedly misleading Hefty recycling bags
Connecticut state officials told a state court that Hefty "recycling" bags marketed by Reynolds Consumer Products were routinely discarded at recycling facilities because plastic bags jam sorting machinery and contaminate recycling streams. The trial addresses whether Reynolds' marketing of the bags as suitable for recycling constitutes consumer deception under Connecticut law when the bags are systematically rejected by municipal recycling programs.
Eyemart Express sued over data breach failure to safeguard patient information
A new class action lawsuit alleges Eyemart Express failed to properly secure and safeguard the personally identifiable information (PII) and protected health information (PHI) of thousands of individuals in a data breach. The complaint asserts violations of state consumer protection laws and negligence in implementing adequate security measures for sensitive health data subject to HIPAA protections.
Supreme Court grants review in Title IX employment discrimination case
The Supreme Court granted certiorari in Crowther v. Board of Regents of the University System of Georgia after two relists and a call for the views of the Solicitor General. The case asks whether employees of federally funded schools may sue for sex discrimination in employment under Title IX or must instead proceed under Title VII's more elaborate administrative exhaustion scheme. A circuit split exists on the issue. The Solicitor General's brief recommended granting review due to the split. Justice Brett Kavanaugh noted he would have granted the petition in a related pension law case that was denied.
Discord migrates all users to end-to-end encryption by default
Discord announced on May 20 that video and voice messages sent through the service are now end-to-end encrypted with no opt-in required for all users across all devices except stage channels used for live events. The platform spent nearly three years building the system after beginning experiments in August 2023. Discord's end-to-end encryption protocol supports simultaneous use across laptops, mobile phones, PlayStation, Xbox, and web browsers in the same conversation, a capability no other available protocol provides. The announcement comes as Instagram and TikTok recently killed their end-to-end encryption features, while Google and Apple announced expansion of default end-to-end encryption for Android-iPhone conversations.
Austrian court upholds GDPR ruling against ORF cookie banner dark patterns
The Federal Administrative Court of Austria upheld a 2024 decision by the Austrian Data Protection Authority ordering the Austrian Broadcasting Corporation (ORF) to redesign its cookie banner on ORF.at to comply with GDPR consent requirements. The court ruled that highlighting the "Accept" button in color while making the "Reject" button less prominent constitutes a misleading dark pattern that leads to unintended consent, violating GDPR principles of unambiguous consent and transparency. The ruling originated from one of 422 GDPR complaints filed by noyb in August 2021 against websites using misleading cookie banners. The court's reasoning makes clear that simply implementing a "Reject" button in less conspicuous styling is insufficient; both consent options must have equal prominence.
7-Eleven confirms data breach after ShinyHunters claims stolen franchisee documents
Convenience store giant 7-Eleven reported to state regulators in Maine, Vermont and Massachusetts that hackers breached systems used to store franchisee documents, gaining access to names, addresses and Social Security numbers. The company discovered the breach on April 8, 2026. The breach notification follows claims by the ShinyHunters cybercriminal organization in late April that it stole data from 7-Eleven held on Salesforce. ShinyHunters was listed alongside dozens of other companies attacked by the group last month. The group has repeatedly targeted data storage tools to steal large amounts of information from high-profile companies and recently caused a nationwide scandal with an attack on educational software giant Instructure affecting thousands of universities and K-12 schools.
Russia and China pledge cooperation on AI, satellite systems and cyber policy
Chinese leader Xi Jinping and Russian President Vladimir Putin issued a joint statement on May 20 pledging closer cooperation on satellite internet technologies, artificial intelligence, cybersecurity and internet governance. The agreement includes joint software development projects and expanded collaboration on open-source technologies to reduce reliance on Western technology. Moscow and Beijing will work on creating interoperability between Russia's GLONASS and China's BeiDou satellite navigation systems and coordinate on radio frequencies, satellite orbits, satellite internet and Internet of Things systems. Both countries support "internet sovereignty," the concept that governments should retain broad authority over domestic digital environments. Russia welcomed China's proposal to establish a global organization dedicated to AI cooperation, with both sides opposing the use of AI "as a geopolitical tool" by individual countries. Ukraine recently warned that Russia is embedding AI directly into malware capable of generating malicious commands on the fly.
EFF newsletter highlights end-to-end encryption developments
The Electronic Frontier Foundation's EFFector newsletter covered recent developments in end-to-end encryption technology, including the expansion of encrypted messaging between Apple and Android devices and Discord's migration to default end-to-end encryption for voice and video. The newsletter emphasized that end-to-end encryption, when used correctly, turns online conversations into secret messages decodable only by intended recipients, preventing tech companies, governments and other eavesdroppers from accessing content.
Take It Down Act compliance deadline passed May 19. If your platform allows user-generated content or hosts intimate images, implement a compliant removal request process immediately. Required elements: conspicuous notice, direct request mechanism from content, 48-hour deletion timeline, hashing technology for duplicate removal, hash sharing with NCMEC (minors) or StopNCII.org (adults), and request tracking numbers for victims. Civil penalties are $53,088 per violation.
Cookie consent interfaces must offer equal prominence for accept and reject options. The Austrian Federal Administrative Court ruling establishes that color-highlighting the "Accept" button while making "Reject" less prominent violates GDPR consent requirements. Review your cookie banners to ensure both buttons have identical visual weight (color, size, position). The ruling's reasoning applies broadly to any consent interface using design to steer users toward acceptance.
ShinyHunters targeting Salesforce and cloud storage platforms. Review access logs for Salesforce and similar cloud data storage tools between late March and early April 2026. If you identify suspicious activity or receive extortion demands from ShinyHunters, contact the FBI immediately and do not pay ransoms. The group specializes in large-scale breaches targeting tech, finance, retail and educational institutions, often stealing millions of records at once.
Automated license plate recognition (ALPR) use faces legal challenges. The Home Depot class action highlights privacy risks in collecting and sharing ALPR data with law enforcement. If your organization uses ALPR technology in parking lots or facilities, review your privacy policy disclosures, data retention policies, and any agreements with law enforcement for warrantless data sharing. State biometric privacy laws may apply to location tracking even when not explicitly covering license plates.
End-to-end encryption adoption accelerating while some platforms retreat. Discord's default end-to-end encryption for all users contrasts with Instagram and TikTok killing their encryption features. Organizations providing messaging services should evaluate user privacy expectations and regulatory requirements. Google and Apple's expansion of default encryption for cross-platform messaging (Android-iPhone) establishes a higher baseline for consumer messaging privacy.