Get tomorrow's brief in your inbox
Today: The Ninth Circuit ruled that building a web browser doesn't violate the Computer Fraud and Abuse Act in Amazon v. Perplexity, rejecting Amazon's attempt to use the CFAA against agentic AI tools. A coalition challenged the Trump administration's attempt to share TANF recipient data with immigration enforcement agencies without Privacy Act compliance. EFF research revealed that advertising SDKs from InMobi, BidMachine, Verve, and Huawei share users' precise location data by default, feeding location data brokers used for surveillance.
$56 Million eBay Settlement for Harassment Campaign
eBay and three former executives agreed to pay $56 million to settle claims that they orchestrated a campaign of harassment against journalists Ina and David Steiner of eCommerceBytes. The harassment included sending threatening items to their home, stalking them in Massachusetts, and planning to install tracking devices on their vehicle. Then-CEO Devin Wenig's text message directing staff to take down critic "whatever it takes" triggered the campaign. Multiple eBay employees were criminally convicted and sentenced to prison, with security chief Jim Baugh receiving 57 months. The settlement includes $49 million to the victims and $7 million in charitable commitments.
OpenAI Disrupts Cambodian Scam Centers Using ChatGPT
OpenAI banned accounts associated with scam centers in Poipet, Cambodia, that used ChatGPT to conduct investment fraud, romance scams, and human trafficking operations targeting Indian nationals. The scammers used ChatGPT to create fake passports, legal notices, and stock purchase confirmations, translate messages between staff, and generate recruitment fliers promising fake employment in India. The operation "may have interacted with hundreds of targets across multiple scam types" with some conversations referencing thousands lost by victims.
Capital One Cites Money Laundering Concerns in Trump Account Closures
Capital One filed a motion to dismiss claims by the Trump Organization that it closed 385 accounts due to political discrimination following the January 6 Capitol riot. Capital One's filing states the closures were "expressly permitted by the governing agreement" and resulted from "months of analysis and a careful review by Capital One's AML team in accordance with bank policies and regulatory guidance." The bank never publicized the termination decision and granted several extensions for the Trump Organization to find new banking services.
Ninth Circuit: Building a Web Browser Doesn't Violate CFAA
The Ninth Circuit Court of Appeals held that Perplexity AI was unlikely to violate the Computer Fraud and Abuse Act by building the Comet browser with an optional AI Assistant that can access websites like Amazon for comparison shopping. Amazon argued the Assistant violated the CFAA because Amazon did not "authorize" Perplexity to access Amazon users' accounts. The court held that users operate the tool, not Perplexity, and that the Assistant "is a tool, not a person for statutory purposes." The court noted that invoking the CFAA against browser developers was both legally baseless and bad policy that "could expose users themselves to criminal liability."
ZOLL Medical Corp. $3.5M Data Breach Settlement
ZOLL Medical Corp. agreed to a $3.5 million class action settlement for individuals who received data breach notifications. Settlement details and eligibility requirements are available through the claims process.
Payactiv Data Breach Class Action Settlement
Individuals who received data breach notifications from Payactiv may be eligible for class action settlement benefits. No settlement amount has been disclosed.
Supreme Court Rejects Equal Protection Challenge to Haitian TPS Termination
In Mullin v. Doe, the Supreme Court majority held that Trump administration officials' comments describing Haiti as a "shithole country," claiming Haitians were "eating the dogs and eating the cats," accusing migrants of "poisoning the blood" of the nation, and calling Haitians "leeches" and "foreign invaders" were not "overtly racial" and "could rest on race-neutral justifications." Justice Alito's majority opinion altered existing equal protection doctrine by requiring plaintiffs to show racial discrimination was not only a motivating factor (the Arlington Heights standard) but that the policy could not be justified on non-discriminatory grounds. Justices Kagan, Sotomayor, and Jackson dissented.
25 States Sue Over Trump Section 301 Tariffs
Twenty-five Democratic-led states filed suit in the U.S. Court of International Trade challenging President Trump's July 24 tariffs on 60 trading partners imposed under Section 301 of the Trade Act of 1974. The states argue Section 301 tariffs have historically targeted specific nations and industries to combat unfair or discriminatory economic practices, and Trump's broad-brush approach has no historical precedent and exceeds his legal authority.
Coalition Challenges TANF Data Sharing with Immigration Enforcement
Make the Road States, Common Cause, and EPIC filed suit challenging the Trump administration's policy allowing federal and state agencies, particularly DHS, access to Temporary Assistance for Needy Families (TANF) recipient information including Social Security Numbers and immigration status. The Office of Family Assistance published notice on June 23, 2026, granting access without following Privacy Act notice and comment requirements. The lawsuit alleges violations of the TANF statute, Social Security Act, Privacy Act of 1974, Computer Matching of Privacy Protection Act of 1988, and the Administrative Procedure Act. TANF funds over $16 billion annually in grants to states for cash assistance to low-income families.
EFF Report: Advertising SDKs Share Location Data by Default
EFF identified four advertising SDKs that collect and share users' precise location data by default when embedded in Android apps granted location permissions: InMobi, BidMachine, Verve's HyBid, and Huawei's Petal Ads. The SDKs feed location data into real-time bidding systems where location data brokers participate in ad auctions to collect personal information contained in bid requests. Location data sourced from the advertising industry has been used for ICE investigations, global spy tools, outing a gay priest, tracking union organizers, and tracking US military personnel. Many developers in a 2025 Gravy Analytics breach claimed they had no knowledge their apps were sharing location data with the broker.
Apple Challenges UK iCloud Access Demands
Apple filed a new challenge in the UK Investigatory Powers Tribunal against a Technical Capability Notice requiring Apple to retain the ability to access iCloud account content instead of protecting it with Advanced Data Protection (ADP). ADP generates and stores encryption keys on users' devices rather than Apple's servers, making content technically inaccessible to Apple even with a lawful warrant. The Financial Times reported the TCN sought British access to U.S. citizens' data, potentially violating data-sharing rules between the US and UK prohibiting intentional targeting of each other's citizens.
Russia Designates Telegram Founder Durov as Terrorist
Russia's Federal Security Service (FSB) designated Telegram founder Pavel Durov as a terrorist and extremist, charging him with aiding terrorist activity for allegedly failing to remove channels and bots used by Ukrainian intelligence and terrorist groups. Under Russian law, designated individuals face frozen assets, limited banking access, and increased scrutiny. Russian businesses removed Durov-linked books and films from sale, but Telegram itself remains accessible and Russian state institutions continue using official Telegram channels. Durov rejected the allegations, saying Moscow was retaliating for his refusal to comply with demands for mass surveillance and censorship.
Coachella Website Tracking Class Action
A class action alleges the Coachella music festival illegally collects data about visitors to its website, potentially violating California privacy laws prohibiting tracking without consent.
Senate Commerce Committee to Vote on Four Internet Age-Gating Bills
The Senate Commerce Committee will vote on KOSA (Kids Online Safety Act), the SCREEN Act, Youth AI Privacy Act, and CHATBOT Act. EFF opposes all four bills, arguing they would create sweeping privacy and data security problems by requiring age verification and forcing platforms to adopt unconstitutional content restrictions for both adults and teenagers. EPIC and a coalition of advocacy organizations support the Youth AI Privacy Act, which would establish limits on manipulative chatbot design, ban advertising to minors through AI chatbots, and prohibit using minors' personal data to train AI models.
Trump Administration Targets Antifa as Domestic Terrorist Organization
President Trump signed an executive order on September 22, 2025, purporting to designate antifa as a domestic terrorist organization despite no legal authority existing to designate domestic organizations as terrorist groups. National Security Presidential Memorandum 7 directs Treasury to identify and disrupt financial networks funding domestic terrorism and instructs banks to file suspicious activity reports with FinCEN. The memorandum directs FBI Joint Terrorism Task Forces to investigate and prosecute entities and individuals. Intelligence analysts have declined to brief on antifa at interagency meetings because they do not regard it as a serious counterterrorism threat.