Get tomorrow's brief in your inbox
Today: Equifax agreed to a $100M settlement over a 2022 credit score coding error affecting consumers nationwide. A California federal court set important precedent for AI privacy litigation, ruling that allegations about what an AI tool "could" do are insufficient for Article III standing. Congress requested a GAO investigation into CISA's ability to protect critical infrastructure after losing nearly one-third of its workforce. CBP officers and contractors systematically abused government databases to stalk ex-partners and supply intelligence to drug traffickers.
CBP Officers and Contractors Abused Government Databases for Stalking and Criminal Intelligence
FOIA records from DHS's Office of Professional Responsibility reveal hundreds of allegations over more than a decade of CBP employees and contractors misusing law enforcement databases for personal purposes. Officers queried systems to monitor romantic interests, track family members, look up flight attendant contact information, pull data from trusted-traveler applications to solicit dates, share border-crossing data in divorce disputes, and provide intelligence to suspected drug-trafficking organizations. One DHS employee used ad-tech-derived location data to track coworkers' cell phones, the first known internal abuse case involving that data type.
Equifax Agrees to $100M Settlement Over Credit Score Coding Error
Equifax will pay $100 million to resolve a class action claiming the company inaccurately reported consumers' credit scores due to a coding error in 2022. The settlement covers consumers whose credit scores were misreported during the affected period.
Gemini AI Tracking Allegations Dismissed for Lack of Article III Standing (Thele v. Google LLC, 2026 WL 1970746, N.D. Cal.)
A California federal court dismissed privacy claims against Google's Gemini AI features, holding that plaintiffs failed to demonstrate concrete harm. Plaintiffs alleged Google switched Gemini from opt-in to default-enabled for Gmail, Chat, and Meet, allowing it to track private communications. The court ruled that alleging what an AI tool "could have" accessed, without identifying what data it actually accessed or used, is insufficient for Article III standing. Plaintiffs also failed to show a real or immediate threat of future harm because they could disable the feature.
$3.6M Anthem Denied Benefits Class Action Settlement
Anthem agreed to a $3.6 million settlement to resolve claims it denied coverage for proton beam radiation therapy for prostate cancer treatment. The settlement is currently open.
$1.5M The Money Source Robocalls Settlement (TCPA)
The Money Source will pay $1.5 million to resolve claims it violated the Telephone Consumer Protection Act with unsolicited robocalls. The settlement is open for claims.
FCC Abandons 1 Gbps Broadband Speed Goal
The FCC eliminated its long-term broadband speed goal of 1 Gbps downstream / 500 Mbps upstream as part of its annual Section 706 Report. FCC Chairman Brendan Carr stated the goal was not "technologically neutral" and that predicting long-term technological developments was impossible. The agency retained its current baseline definition of 100 Mbps down / 20 Mbps up. The decision benefits satellite broadband providers whose systems cannot reliably reach gigabit speeds and cable operators with limited upstream capacity.
Congress Requests GAO Investigation Into CISA Staffing Cuts
Rep. Bennie Thompson (D-MS) and other Democratic members of the House Committee on Homeland Security sent a letter asking the GAO to examine the impact of workforce reductions at CISA. Nearly 1,000 employees have been fired or departed since the current administration took office, representing roughly one-third of CISA's workforce. Acting director Nick Andersen has indicated plans to hire 300 employees, but the FY2027 budget proposes eliminating 900 additional positions and cutting over $700 million from CISA. State and local officials have reported reduced responsiveness and support from the agency.
EFF Coalition Calls for Halt to Live Facial Recognition in Nottinghamshire, UK
EFF, Big Brother Watch, Liberty, and five other civil society organizations wrote to Nottinghamshire Police urging an immediate halt to live facial recognition (LFR) deployment. The coalition raised six concerns: LFR constitutes biometric mass surveillance treating everyone as a suspect; the "nothing to hide" argument does not hold for people seeking medical care, legal advice, or exercising union or protest rights; planned use against children as young as 11 for anti-social behavior (Operation View) is disproportionate; LFR risks increasing adversarial police-child relationships; and polling shows 48% of people oppose facial scanning on high streets absent an imminent threat.
Brazil Implements New Intermediary Liability Regime After Supreme Court Ruling
Brazil's Supreme Court issued a June 2026 decision clarifying its 2025 finding that the prior liability regime (Article 19 of the Marco Civil da Internet) was partially unconstitutional. Two presidential decrees (12.975 and 12.976) now detail implementation. Under the new rules, platforms that curate content face liability for third-party material if they fail to remove it after user notification, unless there is reasonable doubt the content is unlawful. For serious crimes (human trafficking, crimes against women), platforms have a duty of care to remove content immediately and face liability for systemic failures. The decrees require platforms to notify both the content reporter and author about removal decisions and provide appeal mechanisms.
Zero-Knowledge Proofs Found Insufficient as Age Verification Solution
Analysis of zero-knowledge proof (ZKP) implementations for age verification reveals practical vulnerabilities. While ZKPs theoretically allow age attestation without revealing personal data, the token-issuance model creates a single point of failure. The issuing entity can track every credential use, generating metadata trails. Authoritarian governments could pressure issuers to revoke access, effectively blocking individuals from internet services. Recent implementations of zk-SNARK-based systems have proven gameable and hackable.
U.S. Bank Data Theft Claims Traced to Fourth-Party Incident
U.S. Bancorp confirmed that LockBit ransomware gang claims of data theft are related to a breach involving a contractor for a third-party vendor, not the bank's own systems. The bank stated there is no evidence its systems, networks, or data repositories were compromised. LockBit threatened to leak data in two weeks but provided no samples. U.S. Bancorp declined to identify the third or fourth parties involved.
SickKids Hospital Suffers Second Cyberattack, Employee Data Stolen
Canada's Hospital for Sick Children disclosed a data theft incident tied to a third-party software application. The breach exposed personal information of current and former employees, job applicants, and employees of related organizations including the SickKids Foundation. Clinical systems and patient data were not affected. The hospital previously suffered a ransomware attack in 2022 that disabled pharmacy systems, diagnostic imaging, and staff timekeeping. Affected individuals have been offered two years of credit monitoring.
Supreme Court Administrative Stay in White House Ballroom Construction Case
Chief Justice Roberts issued an administrative stay preserving the status quo, allowing construction of a 90,000-square-foot White House ballroom to continue while the justices consider the Trump administration's request to pause a lower court order that would have halted above-ground work. The D.C. Circuit affirmed District Judge Richard Leon's ruling requiring construction authorization from Congress. The National Trust for Historic Preservation argues the administration is trying to "outrun judicial review" by fast-tracking construction to a "point of no return." The project is reportedly 65% complete.
Trump Administration's Private-Sector Cyber Operations Memo
The administration is developing plans to authorize private companies to conduct cyber operations against criminal groups. The approach would require licensed operators to coordinate with intelligence agencies to avoid conflicts with government operations.