Get tomorrow's brief in your inbox
Today: The Supreme Court allowed Texas to enforce age verification requirements on app stores while the constitutionality is litigated. Medtronic notified 3.8 million patients of a data breach exposing SSNs and health data. The DOJ assigned gang and terrorism prosecutors to implement White House directives targeting political opposition groups.
Medtronic Data Breach Notification (3.8 Million Affected)
Medical device manufacturer Medtronic confirmed on June 29 that an unauthorized party accessed corporate IT systems on April 24, exposing social security numbers, health data, names, contact information, and dates of birth for approximately 3.8 million patients with Medtronic medical devices. The attack is reportedly linked to the ShinyHunters cybercrime group. Medtronic stated it has no evidence that the compromised data has been posted publicly or exposed online. The company is providing affected individuals with 24 months of free credit monitoring, dark web monitoring, and identity theft restoration services.
Canadian Intelligence Agency Disrupts Ransomware and Criminal Groups
Canada's Communications Security Establishment (CSE) disclosed in its 2025 annual report that it executed state-authorized cyber operations against three foreign criminal groups: a ransomware-as-a-service gang, drug traffickers selling fentanyl precursor chemicals, and a violent extremist group recruiting in Western countries. The ransomware operation rendered the gang's infrastructure inoperable and deleted stolen data advertised for sale on the dark web. CSE also conducted authorized technical disruptions against 10 major ransomware gangs to make their infrastructure unusable. The operations used signals intelligence and data from internet-connected devices to map criminal networks and disrupt operations.
Google Sues Chinese Phishing-as-a-Service Operation Using Gemini AI
Google filed a lawsuit against Outsider Enterprise, a Chinese group operating through Telegram that offers phishing-as-a-service using Google's Gemini AI to create fraudulent websites impersonating Google, YouTube, and government agencies including New York's E-ZPass. The group provided nearly 300 scam templates and instructions to non-technical users on how to set up phishing campaigns. Google coordinated with AT&T, Verizon, and T-Mobile to block malicious text messages and reports that its AI-powered scam detection in Google Messages blocks approximately 10 billion scam texts monthly, likely catching some Outsider Enterprise activity.
Japanese Teen Arrested for Cyberattack on Anime Streaming Service
Tokyo Metropolitan Police arrested a 15-year-old high school student who exploited a vulnerability in Bandai Channel's servers to fraudulently cancel more than 46,000 user subscriptions in November 2025. The student developed a malicious program using ChatGPT to automate attacks after identifying the vulnerability through network traffic analysis. The attack forced the service to suspend operations for more than a month while systems were repaired and affected subscribers were refunded. Police linked the suspect through analysis of communication records after the company reported the incident. The suspect continued attacks after initial blocking by repeatedly changing IP addresses.
Supreme Court Allows Texas Age Verification Law to Take Effect (SB 2420)
The Supreme Court denied requests to block enforcement of Texas's App Store Accountability Act (SB 2420), which requires app stores to verify users' ages and obtain parental consent for minors to download apps and purchase in-app content. The unsigned orders contained no public dissents. Two groups challenged the law: Students Engaged in Advancing Texas and the Computer and Communications Industry Association (CCIA), both arguing the law violates the First Amendment. U.S. District Judge Robert Pitman had blocked enforcement in December, but the Fifth Circuit reversed that order last month. The challengers argued that the Fifth Circuit's decision would render virtually all internet content "commercial speech" subject to government restriction. Texas countered that SB 2420 regulates commercial transactions, not speech, and that the law applies content-neutral restrictions to all apps regardless of content.
Merrick Bank Class Action Over Debt Collection Despite Attorney Representation
A new class action lawsuit alleges Merrick Bank and its debt collection partner Halsted Financial Services violated federal and state law by directly contacting a consumer after he obtained legal representation. The lawsuit claims the contact violated the Fair Debt Collection Practices Act (FDCPA), which prohibits debt collectors from communicating with consumers known to be represented by an attorney without that attorney's consent.
Washington Post Class Action Alleges Data-Driven Dynamic Pricing
A class action lawsuit claims The Washington Post used subscribers' personal data to determine individualized subscription prices. The complaint alleges the practice violates consumer protection laws by using personal information to charge different customers different prices for the same product without adequate disclosure or consent.
Audi Class Action Over Alleged Subframe Defect
Audi faces a class action lawsuit alleging the company concealed a structural defect in Q5 and SQ5 vehicles affecting subframes and denied warranty coverage to owners facing costly out-of-pocket repairs. The complaint claims violations of consumer protection laws and breach of warranty obligations.
SheaMoisture Class Action Over Product Labeling
Sundial Brands faces a class action lawsuit claiming SheaMoisture products are falsely advertised as being made entirely with virgin coconut oil when they allegedly contain other ingredients. The complaint alleges violations of consumer protection laws regarding false and misleading labeling.
Disinformation Research Lawsuit Dismissed After Three Years
Louisiana federal judge Terry Doughty dismissed a lawsuit filed by Jill Hines and Jim Hoft (represented by Stephen Miller's America First Legal) against academic researchers and their institutions, including the Stanford Internet Observatory. The lawsuit alleged researchers studying disinformation violated plaintiffs' First Amendment rights through coordination with social media platforms. Judge Doughty ruled the plaintiffs failed to establish traceability between the researchers' work and any content moderation actions taken against their social media accounts, finding no evidence researchers flagged plaintiffs' specific posts to platforms. The case ran for over three years, during which several researchers curtailed their work and Stanford Internet Observatory effectively shut down due to litigation pressure.
RICO Lawsuit Continues in Bricks & Minifigs Consignment Dispute
BAM Franchising filed a lawsuit accusing Bryan Mansell of engaging in a RICO conspiracy, despite public statements claiming the company wants to reach an amicable resolution. The dispute originated when Mansell contracted with a Bricks & Minifigs franchise to sell his father's Star Wars Lego collection on consignment, but corporate takeover of the franchise led to conflicting claims about the value and disposition of remaining inventory. YouTuber involvement escalated the dispute, resulting in a temporary restraining order against content creator Reckless Ben Schneider that includes First Amendment concerns regarding prior restraint.
DOJ Assigns Gang and Terrorism Prosecutors to Political Opposition Task Force
The Department of Justice has assigned two prosecutors with expertise in organized crime and terrorism to implement White House directives targeting political opposition groups. Brian W. Lynch, a Violent Crime and Racketeering Section prosecutor since 2020 with experience on the Guantanamo prosecution team, and Jason Kellhofer, a longtime counterterrorism prosecutor from Raleigh, North Carolina, are co-directing the initiative. The assignment follows the National Security Presidential Memorandum (NSPM-7) declaring domestic political opposition as terrorism threats. The prosecutors bring experience with tools used against sophisticated criminal organizations, including real-time communications interception, aggressive use of conspiracy statutes, and confidential informants. The initiative follows terrorism convictions against anti-ICE protesters in Texas, including a 30-year sentence for a defendant charged with providing material support for transporting left-wing magazines.
Bipartisan State AGs Support Texas Age Verification Law
A bipartisan coalition of 27 state attorneys general filed an amicus brief supporting Texas's App Store Accountability Act, arguing states have the right to prevent minors from accessing inappropriate or mature content online. The brief, led by Florida Attorney General James Uthmeier, comes amid rising public skepticism of tech companies and legislative debates on Capitol Hill about regulating minors' online experiences. The coalition's position reflects broader state-level efforts to impose age verification and parental consent requirements on digital platforms.
Supreme Court Internal Tensions Over Emergency Docket
The Supreme Court's 2025-26 term saw heightened internal tensions following an unusually active summer 2025 recess, during which justices handled multiple emergency docket cases involving the Trump administration. Seven of nine justices wrote separately at least once in interim docket cases last summer addressing federal workforce reductions, Consumer Product Safety Commission removals, grant terminations, and immigration enforcement. Justice Sonia Sotomayor publicly criticized Justice Brett Kavanaugh in April for misrepresenting the impact of immigration stops, later apologizing. Justice Ketanji Brown Jackson described conservative colleagues' emergency docket decisions as "scratch-paper musings" that "seem oblivious and thus ring hollow." The term concluded with major rulings on birthright citizenship, presidential removal power, transgender athletes, and immigration, with justices exchanging written criticism in dissents and majority opinions.
BonkDAO Cryptocurrency Governance Attack Drains $20 Million
Attackers exploited the decentralized governance system of BONK cryptocurrency to vote themselves $20 million in coins through a malicious governance proposal. BonkDAO identified exchange wallets used to purchase approximately $4 million worth of BONK ahead of the proposal, accumulating enough voting power to approve the fraudulent transfer. The organization notified law enforcement and is working with relevant parties to recover funds. South Korean exchange Upbit temporarily suspended BONK deposits and withdrawals. The dog-themed memecoin on the Solana blockchain saw its price drop 7 percent, with overall market capitalization of approximately $400 million. The attack differs from smart contract exploits by corrupting the voting process itself rather than exploiting code vulnerabilities.
Russian Hackers Escalate Targeting of Ukrainian Media Organizations
Ukraine's Security Service (SBU) warned that Russian-linked hackers have elevated Ukrainian media organizations to "priority targets" for cyberattacks aimed at disrupting broadcasts, spreading propaganda, and undermining public trust. The SBU disclosed two previously unreported incidents: a three-hour DDoS attack generating 200,000 requests per minute against a nationwide television channel, and a phishing campaign combined with infrastructure compromise attempts targeting a leading television group to publish propaganda disguised as legitimate content. Ukraine's State Service of Special Communications reported more than 200 successful cyberattacks against Ukrainian media since the invasion began, employing phishing, DDoS, website defacements, destructive malware, and unauthorized publication of disinformation. Physical attacks on media infrastructure continue, with 80 incidents documented in the first half of this year, including Channel 5's office being damaged for the second time this week.
Microsoft Vulnerability Disclosure Dispute Highlights Trust Erosion
Microsoft's ambiguous threats of legal action against security researcher Nightmare Eclipse, who identified unpatched Windows vulnerabilities, exposed industry-wide problems in coordinated vulnerability disclosure (CVD) systems. The incident demonstrates eroding trust and communication between companies and researchers who help secure products. CVD relies on the same design principle as whistleblowing systems: people surface risk when they trust the channel and believe they can use it safely. Researchers facing potential legal exposure may delay reporting, stay silent, or disclose outside vendor processes. The episode parallels the Continental Congress's 1778 protection of sailors and marines who reported naval commander misconduct and faced criminal libel suits.
Healthcare sector: Review HIPAA breach notification procedures and vendor business associate agreements following the Medtronic breach affecting 3.8 million patients. Confirm incident response plans include timely notification obligations and remediation service provision.
App stores and developers: Implement age verification and parental consent systems for Texas users in compliance with the App Store Accountability Act (SB 2420). Monitor ongoing Supreme Court litigation that may affect constitutionality but does not currently block enforcement. Review similar legislation in the 27 states whose attorneys general filed supporting briefs.
Subscription services: Audit dynamic pricing algorithms for compliance with state privacy laws requiring disclosure of automated decision-making using personal data. Ensure privacy policies adequately describe how customer information influences pricing, following the Washington Post class action allegations.
Debt collection operations: Immediately cease direct consumer contact once attorney representation is confirmed, per FDCPA Section 805(a)(2). Implement verification procedures to prevent violations like those alleged in the Merrick Bank lawsuit.
Decentralized organizations: Review governance token concentration limits and implement time-locks on large fund transfers to prevent malicious governance proposal attacks like the $20 million BonkDAO drain. Monitor large token purchases preceding governance votes as potential attack indicators.