← Carolina Clear Tech

Legal & Privacy Brief

2026-07-14

Listen to this brief (17:22)

Download MP3
Show Notes

Show Notes - 2026-07-14

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - July 14, 2026

Today: The US Treasury sanctioned a VPN provider for enabling ransomware attacks on critical infrastructure. EU and UK imposed coordinated cyber sanctions against Russia's FSB for attempted sabotage of Poland's energy grid. The EU Commission proposed a harmonized social media ban for children under 13, while the UK moved forward with similar restrictions for under-16 users.

Enforcement Actions

US Sanctions First VPN Service for Ransomware Support

The US Treasury sanctioned First VPN Service (1VPNS) and its Ukrainian administrator Dmytro Rashevskyi for providing tools to ransomware groups that enabled attacks on American municipalities, hospitals, schools and businesses. Rashevskyi used fake identities to purchase infrastructure from companies that would otherwise refuse service due to abuse complaints. The service marketed itself as low-risk because it does not keep logs of user identities or activities and refuses to cooperate with law enforcement investigations. First VPN has operated since 2014 and promoted its services on Russian cybercrime forums and dark web sites. Treasury also sanctioned Belarusian national Yegeniy Vladimirovich Silayev for selling cryptors that make malware harder to detect.

EU and UK Issue Joint Cyber Sanctions Against Russia's FSB

The European Union and United Kingdom imposed coordinated cyber sanctions against Russia's Federal Security Service (FSB) Center 16 for attempted sabotage of Poland's energy grid and water treatment facilities. The December attack on Poland's energy grid came "very close" to causing a blackout that would have cut heating to half a million people. France's Cyber Crisis Coordination Center identified 11 FSB interception centers across Russia, including Unit 61240 focused on targeting France. The sanctions package targets more than 30 individuals and entities, including intelligence officers, private companies recruiting hackers from Russian universities, operators of the Lumma Stealer credential-theft malware, and individuals connected to the pro-Kremlin Rybar blog. The EU stated that government networks and critical infrastructure in Austria, Cyprus, Finland, France, Germany, the Netherlands, Poland, Romania and Slovakia have been targeted in recent years.

Litigation Updates

Class Certification Granted in ICE Warrantless Arrest Lawsuit (Case No. 6:25-CV-02011-MTK)

An Oregon federal court certified a Rule 23(b)(2) class action challenging alleged ICE warrantless arrest practices in M-J-M-A- et al. v. Lyons et al., No. 6:25-CV-02011-MTK, 2026 WL 1815866 (D. Or. June 24, 2026). The court certified a "Warrantless Arrest Class" and an "Unassessed Escape Risk Subclass" focused on whether ICE made individualized assessments required before conducting warrantless immigration arrests. Plaintiffs allege federal immigration officials arrested them without a warrant, without probable cause of an immigration violation, and without probable cause that they were likely to flee before a warrant could be obtained. The court found Rule 23(b)(2) was satisfied because defendants' alleged policy and practice of conducting unlawful warrantless arrests applied to all class members, making final injunctive relief appropriate. The ruling shows how Rule 23(b)(2) can function as the procedural vehicle for broad prospective relief against allegedly unlawful government practices after the Supreme Court's decision limiting universal injunctions directed attention back to class certification as a pathway for broader relief.

Apple Faces Class Action Over Safari Browser Fingerprinting (Case No. 5:26-cv-06307)

Plaintiff Sarah Simpson filed a class action lawsuit against Apple in the US District Court for the Northern District of California, San Jose Division, alleging the company falsely advertised Safari as protecting users from online tracking while allowing third parties to track them through browser fingerprinting. Simpson claims Safari transmits large amounts of user data to third parties, allowing advertisers to track consumers' online activities by creating unique profiles for each user. The complaint alleges Safari's default settings do not protect users from fingerprinting and that users must make changes in Safari's settings to enable any fingerprinting protection. Simpson further claims Safari does not accurately flag fingerprinting scripts in its privacy report, even in private browsing mode. The lawsuit raises claims for breach of express contract, breach of implied contract, breach of the implied covenant of good faith and fair dealing, and violations of California's Unfair Competition Law, False Advertising Law and Consumers Legal Remedies Act. Simpson seeks to represent a class of all US residents who purchased an Apple device with Safari pre-installed.

Gymshark Sued Over Undisclosed Influencer Relationships (Case No. 1:26-cv-05073)

Plaintiff Mihaela Lupea filed a class action lawsuit against Gymshark USA Inc. in the US District Court for the Southern District of New York, alleging the company engages in deceptive marketing practices by failing to disclose paid relationships with influencers. Lupea claims Gymshark's marketing strategy relies heavily on influencers who fail to disclose they are being paid to promote the brand's products, misleading consumers into believing endorsements are genuine and unbiased. The complaint alleges Gymshark deliberately targets influencers who are "typically not household names" to make their endorsements appear more authentic and to avoid scrutiny. Lupea argues the failure to disclose paid relationships violated Federal Trade Commission guidelines and social media platform rules. The lawsuit claims unjust enrichment and violations of New York General Business Law, and seeks declaratory and injunctive relief plus actual, statutory and punitive damages.

Albany Park Furniture Settles Deceptive Advertising Claims for $15 Million

Albany Park reached a $15 million class action settlement over deceptive advertising claims. Class members can receive a $115 store credit or cash payment. The settlement resolves allegations that the company engaged in misleading discount advertising practices.

Costco Sued Over Grain-Free Dog Food Heart Risks (Case No. 2:26-cv-02182)

Plaintiff Taylor West filed a class action lawsuit against Costco Wholesale Corp. in the US District Court for the Western District of Washington, claiming the company misleadingly markets its Kirkland Signature Nature's Domain grain-free dog food as healthy and safe when it increases the risk of dilated cardiomyopathy (DCM) in dogs. West argues the dog food contains high amounts of legume or pulse ingredients that can contribute to the development of DCM, a potentially fatal heart disease. The complaint alleges Costco has been aware of risks associated with grain-free diets since at least 2018 when veterinarians began publishing research linking such diets to heart disease. West claims Costco failed to conduct adequate safety testing on its grain-free dog food and has not disclosed any feeding studies substantiating its health and safety claims. West seeks to represent a nationwide class and California subclass of consumers who purchased the product within the applicable statute of limitations period.

Privacy Developments

Lidl Discloses Third-Party Data Breach Affecting Germany, Belgium, Netherlands

European discount supermarket giant Lidl disclosed a data breach affecting online shop customers in Germany, Belgium and the Netherlands after attackers gained access to customer information stored by an external IT service provider. The stolen information includes customers' titles, first and last names, phone numbers, email addresses, dates of birth and customer numbers. Lidl stated there is no indication that passwords, billing or delivery addresses, bank details or other payment information were compromised. The company filed a criminal complaint and notified the relevant data protection authority. Lidl warned affected customers to remain alert for phishing emails and potential identity theft attempts because the exposed data could be used in targeted scams. The company did not identify the affected IT service provider or disclose how many customers were impacted.

Russian Journalist Ksenia Sobchak's Telegram Channels Compromised Via Email Breach

Hackers briefly took control of several Telegram channels belonging to Russian journalist Ksenia Sobchak after compromising her email account. The hacker group Black Mirror claimed to have stolen more than 350 gigabytes of Sobchak's data spanning 2015 to 2026 and offered the archive for sale. According to the hackers, the archive includes conversations between Sobchak and senior Russian officials. Sobchak claimed the correspondence was fabricated and the screenshots were fake. Black Mirror has operated since at least 2019, marketing alleged data stolen from people connected to the Russian state.

Policy Changes

EU Commission Proposes Social Media Age 13 Start Date

European Commission President Ursula von der Leyen stated she is considering a "harmonised EU-wide delay to social media" for children under age 13 who are not under the supervision of a caregiver. Von der Leyen envisions giving gradual access to children once they turn 13, "depending on the proof given by the platforms that they are age-appropriate and safe for teenagers." The announcement comes amid growing pressure from EU member states. Several countries already have imposed their own bans or are working with legislatures to do so, including France, Spain and Greece. Most platforms already require users be over age 12, though those restrictions have been easily sidestepped. It is unclear if the age-13 threshold will satisfy critics in member countries where governments have been seeking bans for children age 15 and under.

UK Moves Forward With Under-16 Social Media Ban

The UK government announced plans for a social media ban for users under 16 set to take effect in Spring 2027. The Children's Wellbeing and Schools Bill requires "highly-effective age assurance measures" to prevent children under 16 from becoming or being users of "all regulated user-to-user services." Platforms including Snapchat, TikTok, YouTube, Instagram, Facebook and X are included in the ban. MPs proposed an amendment enabling the Secretary of State to introduce provisions requiring providers of specified internet services to prevent access by children under age 18 rather than 16. The provision also requires internet service providers to limit the time kids spend online and establishes rules about who can contact them online. Users of all ages will be burdened with proving their age before accessing content. There remains no reliable, privacy-preserving method of verifying the age of every internet user, and methods vary from one platform to the next.

Trump Administration Subpoenas New York Times Reporters Over Air Force One Coverage

The Trump administration issued subpoenas to several New York Times journalists after the outlet reported on security concerns involving the president's Qatari-donated Air Force One. The subpoenas seek to force reporters to testify before a federal grand jury in Manhattan. In some cases, subpoenas were delivered by federal agents who showed up at reporters' homes. The New York Times reported that the new Air Force One lacks the same defensive countermeasures that were security features of the old model, including advanced antimissile capabilities. The subpoenas represent an escalation in the administration's efforts to threaten and intimidate independent news organizations.

Regulatory Guidance

Sony Eliminates Physical Game Discs for PlayStation

Sony's decision to eliminate physical game discs represents the latest attack on consumer ownership rights for digital media. The move deprives gamers of "right of first sale" protections that allow lawful sharing, resale, alteration or destruction of copyrighted works. Courts have held that digital media does not carry the same first sale rights as physical media, meaning no such protection is afforded to digital purchases. The elimination of physical discs also imposes significant data storage and bandwidth costs on consumers. Unlike other digital media like film and TV, video games require substantial storage. Access to high-speed internet needed for digital game downloads remains limited in the US. Most digital distributors lock down content with restrictive user agreements and digital rights management (DRM) software. Section 1201 of the Digital Millennium Copyright Act makes it illegal to alter DRM software, and is used by companies to restrict how consumers can lawfully use their purchases. Since much DRM is tied to user accounts, ownership of a game is revocable and modifiable for reasons outside of consumer control.

Compliance Takeaways