← Carolina Clear Tech

Legal & Privacy Brief

2026-05-27

Listen to this brief (17:34)

Download MP3
Show Notes

Show Notes - 2026-05-27

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - May 27, 2026

Today: Dutch authorities arrested two IT entrepreneurs suspected of providing infrastructure for Russian cyber operations and violating EU sanctions, seizing over 800 servers. EFF analysis revealed widespread ALPR mission creep, with police using license plate readers for school residency verification and noise complaints without warrants. A CISA contractor exposed AWS GovCloud credentials in a public GitHub repository after disabling GitHub's default security protections, in what security researchers called "the worst leak I've witnessed."

Enforcement Actions

Dutch Authorities Dismantle Russian Cyber Infrastructure (EU Sanctions Violations)

Dutch Fiscal Information and Investigation Service (FIOD) arrested a 57-year-old Amsterdam resident and a 39-year-old from The Hague for violating EU sanctions by providing hosting infrastructure used in pro-Russian cyberattacks and disinformation campaigns. The company under investigation, founded February 10, 2022 (two weeks before Russia's Ukraine invasion), was sanctioned by the EU on May 20, 2025. Investigators searched three business premises and two data centers, seizing administration records, laptops, phones, and over 800 servers. Reporting by Correctiv and de Volkskrant identifies the suspects as concert pianist Andrey N. (operator of MIRhosting) and business consultant Youssef Z. (owner of WorkTitans), who allegedly provided services to Moldovan brothers Ivan and Juri Neculiti's Stark Industries hosting firm. The infrastructure was used to host Reliable Recent News websites tied to the Doppelgänger disinformation campaign and DDoS attacks by pro-Russian group NoName057(16) targeting European government agencies.

Federal Court Dismisses Criminal Charges Against Kilmar Abrego Garcia for Vindictive Prosecution

U.S. District Judge Waverly Crenshaw dismissed criminal charges against Kilmar Abrego Garcia, finding the Trump administration engaged in vindictive prosecution. Garcia was among the initial wave of deportations sent to El Salvador's CECOT maximum security prison despite fact-free allegations of MS-13 gang membership. The court found HSI Agent VanWie's decision to reopen a closed November 2022 traffic stop investigation, combined with acting Attorney General Todd Blanche's public statements tying the investigation to Garcia's successful lawsuit, created a presumption of vindictiveness the government failed to rebut. The court cited former Attorney General Robert H. Jackson's warning about prosecutors picking the person first and the crime second. Associate Deputy Attorney General Aakash Singh's close substantive oversight of the prosecution team further demonstrated vindictive intent.

Litigation Updates

Supreme Court Reverses 4th Circuit in Immigration Judge Speech Case (Margolin v. NAIJ)

The Supreme Court reversed the U.S. Court of Appeals for the 4th Circuit in a five-page unsigned order, finding the lower court relied on an argument the National Association of Immigration Judges had not made and had affirmatively waived. The case challenged a Department of Justice policy requiring immigration judges to obtain permission before making official speeches at immigration conferences and pro bono training sessions. U.S. District Judge Leonie Brinkema originally dismissed the case under the Civil Service Reform Act, which channels federal employee claims to the Office of Special Counsel and Merit Systems Protection Board rather than district courts. The 4th Circuit had questioned whether those CSRA entities were still functional given MSPB's lack of quorum and the Trump administration's position that the president can remove the Special Counsel and MSPB members for any reason. The Supreme Court held federal courts must respect CSRA jurisdictional limits regardless of downstream entity functionality concerns.

Florida Denied Original Jurisdiction in Interstate Driver's License Dispute

The Supreme Court declined to serve as the court of first review for Florida's contention that California and Washington are allowing undocumented immigrants to obtain commercial driver's licenses. Florida sought to invoke the court's original jurisdiction for disputes between states. The justices did not add the case to their 2026-27 term docket. Original jurisdiction cases are rare and typically involve territorial boundary disputes or interstate resource conflicts where no lower court forum exists.

Hustler Hollywood FACTA Class Action Settlement

Hustler Hollywood reached a class action settlement benefiting customers whose receipts displayed more than the last five digits of a card number, violating the Fair and Accurate Credit Transactions Act (FACTA). FACTA amendments to the Fair Credit Reporting Act prohibit merchants from printing more than the last five digits of card numbers or expiration dates on electronically printed receipts. Violations carry statutory damages of $100 to $1,000 per violation.

Kalshi Faces Washington TCPA Class Action Over Unsolicited Refer-a-Friend Texts

Prediction market exchange Kalshi Inc. faces a class action alleging it sent unsolicited commercial text messages to Washington state residents without their knowledge or consent under the Telephone Consumer Protection Act. Washington's state TCPA analog provides private right of action and treble damages for violations. Refer-a-friend programs must obtain prior express written consent before sending marketing texts, with consent defined as a signed written agreement clearly authorizing specific marketing messages.

Canvas Learning Platform Data Breach Exposed Millions of Student and Teacher Records

Instructure disclosed a data breach involving its Canvas learning management platform in late April potentially exposing millions of student and teacher records worldwide. Canvas serves over 6,000 educational institutions globally. No additional details on the breach vector, compromised data types, or remediation timeline were provided in the disclosure.

Privacy Developments

EFF Uncovers Widespread ALPR Mission Creep in Police Searches

EFF analysis of millions of Flock Safety automated license plate reader searches revealed police agencies using ALPR databases far beyond specific criminal investigations, including school residency verification, employment background checks, and noise complaints. Buford City Schools in Georgia ran over 375 ALPR searches between January 2025 and March 2026 for residency verification, accounting for over half of all searches and three-quarters of 2026 searches. Officers searched across more than 5,800 different networks nationwide, revealing when families go to doctors, worship services, nighttime activities, and vacation travel. The analysis found no warrant requirement has fostered unrestricted access to sensitive location data. ALPR networks have been used to surveil protesters, abortion seekers, immigrants, and ethnic Roma populations.

Lithuania Investigates Theft of 600,000 State Registry Records by Foreign Actor

Lithuanian prosecutors are investigating a major data breach affecting the Centre of Registers that exposed over 600,000 records from the Real Estate and Legal Entities Registers. Attackers misused login credentials assigned to institutions authorized to access the databases, with the breach likely originating from a foreign country. Compromised data included names, dates of birth, national identification numbers, property addresses, cadastral information, and registry numbers. Financial damage exceeds €111,000 ($129,000). Centre of Registers chief Adrijus Jusas resigned following the breach and blamed years of underinvestment in state IT infrastructure, estimating €60 million ($69.8 million) in upgrades needed to meet modern cybersecurity standards. Former defense minister Laurynas Kasciunas alleged the breach showed hallmarks of a Russian intelligence operation, though prosecutors have not confirmed Russian involvement.

WiFi Sensing Technology Can Identify Individuals Through Radio Wave Patterns

Researchers at Karlsruhe Institute of Technology (KIT) demonstrated WiFi sensing technology that identifies individuals by analyzing how WiFi signals interact with their physical presence. When radio signals travel through a space, they are reflected, scattered, or absorbed by objects and people. By comparing expected signal behavior with actual received signals, researchers can create images of surroundings and identify persons present, similar to how cameras work with light waves. Professor Thorsten Strufe explained the technique observes radio wave propagation to infer details about the environment.

Policy Changes

RFK Jr.'s ACIP Charter Amendment Withdrawn for Procedural Violations

Health and Human Services Secretary Robert F. Kennedy Jr.'s revised charter for the CDC's Advisory Committee on Immunization Practices (ACIP) was withdrawn for failing to follow federal public notification requirements. Federal law requires the Secretary to provide a written statement that discretionary advisory committees are being formed in the public interest, establish what that public interest is, and publish public notice to the Federal Register. Kennedy rewrote the ACIP governing charter to allow members without expertise in immunizations and public health but did not follow any of these procedural requirements. The withdrawal follows a district court injunction on Kennedy's initial ACIP overhaul for violating the Administrative Procedures Act by hand-picking unqualified members without following procedural law. The Trump administration is appealing the injunction.

NPR Announces Layoffs Following Republican Attacks on Public Broadcasting

NPR is implementing buyouts and layoffs to trim $8 million from its $300 million annual budget following Trump administration attacks on public broadcasting. Congress obliterated the Corporation for Public Broadcasting (CPB) budget of $1.1 billion for fiscal years 2026 and 2027 after an executive order targeting NPR, PBS, and member station funding. The CPB voted to dissolve itself in January 2026 after losing all funding. A federal judge later ruled the defunding violated the First Amendment, but the ruling came too late to save the CPB. NPR received $113 million in private donations ($80 million from Connie and Steve Ballmer) to offset losses, but that money is dedicated to "technological innovation" rather than saving journalism jobs. The CPB historically distributed over 70 percent of its funding to approximately 1,500 public radio and TV stations.

Supreme Court Analysis: Louisiana v. Callais Effectively Dismantled Voting Rights Act Section 2

Legal scholars argue Louisiana v. Callais rewrote the Voting Rights Act despite Justice Samuel Alito's claims the court was merely updating evidentiary requirements. The ruling makes vote dilution claims under Section 2 effectively impossible by changing the benchmark for determining whether district boundaries unlawfully dilute minority electoral opportunity. The 1982 amendments to the VRA created a "results" or "effects" test replacing the intent requirement from Mobile v. Bolden. Gingles v. Thornburg established preconditions including that minority voters must be sufficiently numerous and compact to constitute a reasonably configured district without violating traditional districting criteria. Callais may have turned Fourteenth Amendment racial gerrymandering claims into a tool to undo VRA-compliant redistricting maps.

Regulatory Guidance

CISA Contractor Exposed AWS GovCloud Credentials in Public GitHub Repository

A CISA contractor left AWS GovCloud credentials in a public GitHub repository named "Private-CISA," exposing cloud keys, tokens, plaintext passwords, logs, and other sensitive CISA/DHS assets. GitGuardian researcher Guillaume Valadon flagged the repository on May 15, noting the CISA administrator disabled GitHub's default setting that blocks users from publishing SSH keys or other secrets in public code repositories. Security expert Brian Krebs called it "the worst leak I've witnessed," noting it represented textbook poor security hygiene. The exposure comes after the Trump administration gutted CISA by moving officials from cybersecurity work to deportation paperwork processing and conducting mass firings. In 2020, CISA director Chris Krebs was fired after accurately stating the 2020 election had been secure.

Compliance Takeaways