Get tomorrow's brief in your inbox
Today: The Supreme Court granted review of an Eighth Amendment excessive fines case involving a $95,000 airplane forfeiture over a six-pack of beer. Romania's land registry remains offline after a financially-motivated cyberattack exploited known vulnerabilities, halting all property transactions nationwide. New York passed legislation requiring crawlers to unmask their operators, threatening investigative journalism and cybersecurity research that relies on anonymous web scraping.
Supreme Court to Review Airplane Forfeiture Case (Jouppi v. Alaska)
The Supreme Court agreed to hear Jouppi v. Alaska, in which an Alaskan bush pilot challenges the forfeiture of his $95,000 airplane under the Eighth Amendment's excessive fines clause. Pilot Ken Jouppi was convicted of knowingly transporting alcohol to a dry village after one of his passengers brought a six-pack of beer on a one-hour flight from Fairbanks to Beaver, Alaska. The trial judge sentenced Jouppi to three days in prison and a $1,500 fine. The Alaska Supreme Court upheld the airplane forfeiture, ruling it was not grossly disproportional to the offense. The case will be argued in December 2026 and will determine whether courts must consider the specific defendant's conduct when evaluating excessive fines claims.
AT&T Washington Wage Class Action Settlement
AT&T employees in Washington state are eligible for a $1.75 million class action settlement resolving claims that the company failed to pay workers for meal and rest periods.
John Hancock Biometric Privacy Ruling Narrows Illinois BIPA
A federal appeals court narrowed the reach of Illinois' Biometric Information Privacy Act (BIPA) in a lawsuit involving voice authentication technology used during customer service calls. The ruling highlights limits on what biometric data is protected under the state law.
Timex Class Action Alleges Washington Spam Law Violations
A class action lawsuit claims Timex violates Washington's Commercial Electronic Mail Act by sending emails with false urgency in subject lines.
AppFolio Class Action Over Hidden Rent Payment Fees
A class action lawsuit alleges AppFolio charges tenants hidden transaction fees to process rent payments without properly disclosing the charges.
Arizona Beverages Sued Over '100% Natural' Labels
An AriZona tea class action lawsuit accuses the company of marketing its teas and fruit juice cocktails as natural despite containing synthetic ingredients.
ICE Officer Lies Lead to Dropped Attempted Murder Charges
Federal prosecutors dropped attempted murder charges against a Venezuelan man after bystander recordings contradicted an ICE officer's claims. Immigration and Customs Enforcement agent Craig Allrich filed an amended complaint claiming Gabriel Hurtado-Cariaco placed a female ICE officer in a chokehold during an arrest attempt. Two bystander videos showed agents placing Hurtado-Cariaco in a chokehold, not the reverse. Federal public defender Richard McWilliams said federal prosecutors sat on the recordings and refused to remove false charges.
California DROP Tool Launches for Data Broker Deletion
California's Delete Request and Opt-out Platform (DROP) officially launched January 1, 2026, with data broker compliance required beginning August 1, 2026. The tool allows California residents to submit a single request to delete personal information and opt out of sale to all 614 data brokers registered in California's registry. Data brokers have 45 days to address requests received after August 1. The DROP was created under the Delete Act to streamline privacy requests that were previously time-consuming and difficult to execute. Filing a DROP request can reduce spam, improve personal cybersecurity by limiting the number of firms holding your data, and prevent data brokers from selling information to predatory companies, scammers, stalkers, insurance companies, and law enforcement.
South Korea Data Protection Overhaul After Major Breaches
South Korea's Personal Information Protection Act amendments take effect in September 2026, allowing companies to be fined up to 10% of turnover for data breaches and explicitly designating CEOs as ultimately responsible for data protection compliance. The amendments follow a $409 million fine against e-commerce giant Coupang for a 2025 incident exposing approximately 33.7 million customer accounts, equivalent to 65% of South Korea's population. Separately, hackers compromised South Korea's Ministry of Foreign Affairs diplomat training system for nine months (April 2025 to February 2026), stealing IDs, names, emails, and encrypted passwords from the Korea National Diplomatic Academy's e-learning platform. The attacker exploited a zero-day vulnerability in server software combined with misconfigured security settings.
New York Passes Stealth Crawler Protection Act
The New York state legislature passed the NY Stealth Crawler Protection Act, which makes it illegal to crawl news websites without revealing the crawler operator's identity and all possible future uses of collected data. The law gives websites the power to obtain court orders unmasking anyone using an unidentified crawler. The Electronic Frontier Foundation warns the legislation threatens investigative journalism, academic research, and cybersecurity protection that rely on anonymous web scraping. ProPublica and The Markup have used anonymous crawlers to investigate anti-competitive practices by Amazon and other tech companies. Privacy tools including EFF's Privacy Badger crawl sites anonymously to identify trackers. The bill is currently on Governor Hochul's desk.
Australia Targets VPN Usage in Age Verification Enforcement
Australia's eSafety regulator is assessing whether adult content sites allow users to bypass age verification restrictions with VPNs. Nine in ten of the most visited adult sites used by Australians now have age checks, but enforcement officials are treating VPN use as a compliance problem. The VPN company Mullvad warned that age verification as implemented today is actually identity verification, restricting freedom of information and creating a chilling effect on criticism of authorities. The eSafety regulator expects sites to "take reasonable steps" to prevent workarounds including VPN usage.
Trump Administration Plans to Appeal Transgender Troops Ban Ruling
The Trump administration notified the U.S. Court of Appeals for the District of Columbia Circuit it intends to appeal to the Supreme Court a decision holding that President Trump's ban on transgender troops probably violated constitutional rights. The government asked the D.C. Circuit not to finalize its decision and emphasized the Supreme Court already intervened in a different challenge last year when a majority allowed the ban to be enforced during litigation. If the D.C. Circuit does not keep its ruling from taking effect, the government will ask the Supreme Court for an interim ruling pausing implementation.
Romania Land Registry Cyberattack Halts Property Transactions
Romania's National Agency for Cadastre and Land Registration (ANCPI) suffered what it described as "the most serious technical incident in the institution's history" after a cyberattack disabled its central IT infrastructure including the nationwide e-Terra cadastral and land registry platform. The attack exploited known software vulnerabilities authorities had recently warned organizations to patch, combined with previously leaked credentials. All property transactions nationwide remain halted nearly one week after the attack. Romania's National Directorate for Cyber Security Director Daniel Cimpean said the attack was financially-motivated and not very complex. The threat actor ByteToBreach claimed responsibility and advertised stolen ANCPI data for sale including internal databases and e-Terra source code. ANCPI is migrating applications to the Romanian government cloud with restoration expected Wednesday pending integrity verification.
DOJ Seizes Over 1,000 Domains Illegally Streaming World Cup
The Department of Justice announced it seized more than 1,000 domains illegally streaming World Cup games over the course of the tournament. Homeland Security Investigations (HSI) and the National Intellectual Property Rights Coordination Center led three successive operations targeting servers and domains in Bulgaria, Peru, Argentina, Ecuador, Brazil, the Dominican Republic, and Colombia. Federal officials cited the "risk to American consumers from malicious software embedded in many illicit streaming services." Colombian authorities arrested four suspected members of the cyber gang Los Ciberinfiltrados, who allegedly illegally accessed telecommunication systems and sold pirated streaming content since 2024 using fraudulent credentials, VPNs, intercepted security codes, and other tactics.
Flock Safety Abandons Acoustic Gunshot Detection Feature
Automated license plate reader company Flock Safety announced it is removing its acoustic gunshot detection device that could detect screaming and other "human distress." The feature was only available to a small number of customers as part of a limited trial and was never broadly released. The Electronic Frontier Foundation warned the system posed civil liberties concerns, could summon armed police to every loud interaction on the street, and would be illegal under state eavesdropping laws in several jurisdictions. The Los Angeles Police Department recently cut ties with Flock Safety, seeking more protections for how information collected by Flock is managed and stored.