Get tomorrow's brief in your inbox
Today: The Supreme Court allowed Texas's age verification law for app downloads to take effect while lower courts continue review, marking continued momentum for state-level child safety legislation despite First Amendment challenges. The Court also issued a significant ruling limiting enforcement of federal spending conditions against individual government officials, effectively nullifying RLUIPA's private right of action. Federal courts continue to narrow Article III standing in privacy cases, requiring plaintiffs to show concrete injury beyond technical data collection.
First Financial Security Data Breach Settlement ($1.2M)
First Financial Security reached a $1.2 million class action settlement for a data breach affecting customer information. The settlement provides cash payments to affected class members who submit valid claims.
Supreme Court Allows Texas App Store Law to Take Effect
The Supreme Court denied emergency requests to block Texas's App Store Accountability Act (TASAA), allowing the state to enforce age verification requirements and parental consent mandates for app downloads while the Fifth Circuit reviews the case in August. The law requires developers and app stores to use age verification tools to ensure children under 18 cannot download apps without parental consent and mandates that developers age-rate their apps. A Texas federal judge initially blocked enforcement in December, but the Fifth Circuit reinstated the law last month. The Computer and Communications Industry Association argues the law violates the First Amendment and forces users to turn over personal data to access the internet. A bipartisan group of more than two dozen state attorneys general filed an amicus brief supporting TASAA.
Landor v. Louisiana Department of Corrections: Federal Spending Programs as Contracts
The Supreme Court ruled 6-3 in Landor v. Louisiana Department of Corrections that individual government officials cannot be sued under the Religious Land Use and Institutionalized Persons Act (RLUIPA) unless they consent to being sued. Justice Gorsuch's majority opinion treated RLUIPA, a federal spending program, as a contract and held that individual prison guards who violated the statute by forcibly shaving a Rastafarian prisoner's hair cannot be held liable because they never consented to suit. The decision effectively nullifies enforcement of RLUIPA against individual officers who violate the statute, as none will consent to being sued. The ruling extends a broader trend of treating federal spending programs through contract law principles, with troubling implications for enforcement of federal grant conditions.
Meta Social Media Addiction Lawsuits Proceed to August Trial
A federal judge cleared Meta Platforms for an August bellwether trial in multidistrict litigation alleging Facebook and Instagram were designed to be addictive to young users. The trial will test plaintiff theories and damages models that could shape settlement negotiations across hundreds of similar cases consolidated in federal court.
California Court Dismisses Hotel Website Wiretapping Suit for Lack of Standing (Crano v. Sojern)
A California federal judge dismissed for the second time a putative class action alleging Sojern violated the Federal Wiretap Act and California privacy laws by deploying tracking technology on hotel websites. In Crano v. Sojern, 2026 WL 1670136 (N.D. Cal. June 9, 2026), the court held plaintiff failed to allege a concrete injury sufficient for Article III standing. Relying on the Ninth Circuit's decision in Popa v. Microsoft Corp., the court rejected standing theories based on intangible privacy injury, finding plaintiff did not allege collection of "personal" information analogous to "highly offensive" common law interferences. The court distinguished In re Facebook, Inc. Internet Tracking Litigation, noting that unjust enrichment standing requires collection of "sensitive" and "personal" information, not merely technical identifiers like cookie IDs, IP addresses, and device types.
Anti-Abortion Lawmakers Target Online Speech Four Years After Dobbs
Four years after Dobbs v. Jackson Women's Health Organization, state attorneys general continue targeting websites that provide abortion-related information with cease-and-desist letters and takedown demands. Alabama Attorney General Steve Marshall sent cease-and-desist letters to Plan C, a public health campaign providing educational resources on abortion access, claiming the website "facilitates, aids, and abets" illegal abortion despite not selling or shipping abortion pills. Arkansas similarly targeted Mayday Health, which provides only information. North Dakota Attorney General Drew Wrigley threatened legal action and ordered the Prairie Abortion Fund to remove website content linking to informational resources. South Dakota passed a law making it a felony to "advertise" anything "described in a manner calculated to lead another to use or apply it for producing an abortion," language that could reach purely educational websites. Mayday Health has sued South Dakota in federal court to block the law, arguing it violates the First Amendment.
KDDI Data Breach Exposes 12.2 Million Email Addresses in Japan
Japanese telecommunications provider KDDI disclosed a cyberattack exposed more than 12.2 million customer email addresses and 7.6 million passwords from an email platform it operates for five internet service providers. Attackers exploited a vulnerability in third-party software used by the email platform. KDDI patched the flaw immediately after detection and stated investigators found no evidence attackers compromised systems beyond the exploited vulnerability. The company said affected ISPs are working to complete mandatory password resets. KDDI's consumer email services run on separate infrastructure and were not affected.
Britain Announces AI-Powered "Cyber Shield" for National Defense
The UK National Cyber Security Centre announced plans to build a sovereign AI-powered defense capability called Cyber Shield, designed to use autonomous AI agents to discover and fix cybersecurity weaknesses across government networks and critical national infrastructure at machine speed. The program pairs "red" and "blue" AI agents, with red agents probing systems for weaknesses and blue agents defending in real time. The NCSC said adversaries aided by AI can already compress reconnaissance and vulnerability discovery from weeks into minutes, creating potential to overwhelm traditional defenses. The agency acknowledged some core functions "present challenges which will need significant progress in research to unlock" and set no timeline for delivery. The NCSC invited academia, critical infrastructure operators, frontier AI labs, and the cyber defense sector to help develop the blueprint.
UK Cyber Resilience Pledge Draws Limited Uptake from FTSE 350 Companies
Fewer than 15 of Britain's 350 largest listed companies signed the government's voluntary Cyber Resilience Pledge at its launch, eight months after ministers wrote personally to every FTSE 350 chair and CEO urging participation. Seventy founding signatories were named, but 20 are strategic government suppliers invited through a separate Government Cyber Charter. The pledge asks signatories to make cybersecurity a board-level responsibility, register for the NCSC's free Early Warning service, and take a risk-based approach to requiring Cyber Essentials certification across supply chains. The activities remain voluntary with no enforcement mechanism. The government stated it will review the pledge's suitability after 12 months with potential to refine the actions.
FCC Phone Unlocking Battle: SpaceX vs. Verizon
SpaceX filed comments with the FCC urging adoption of a 180-day automatic phone unlocking rule, joining smaller providers in pushing for uniform unlocking requirements. The filing came after the Trump FCC destroyed phone unlocking rules at Verizon's request earlier this year, which previously required Verizon to unlock phones within 60 days. Verizon lobbied the Trump administration claiming unlocking requirements were a boon to criminals without evidence. SpaceX's support for unlocking appears driven by Starlink's strategy to partner with cellular providers like T-Mobile to extend connectivity when customers are outside traditional tower range. FCC Chair Brendan Carr has largely supported big telecom positions and provided no evidence to support claims that unlocking rules needed to be destroyed to "fight crime."
PACER Fees Increasing to 12 Cents Per Page
The Judicial Conference of the United States announced it will increase PACER document download fees from 10 cents to 12 cents per page for a five-year period starting January 1, 2027. The judiciary claims the increase is necessary to accelerate development of a new, more secure case management and public access system. Critics note the fees already violate the statute authorizing PACER, which limits fees to recouping system costs, and that making PACER free would actually save money by eliminating costly payment and user management systems. A Congressional Budget Office analysis found making PACER free would be cost-neutral. The judiciary has never reduced PACER fees after previous increases.