Get tomorrow's brief in your inbox
Today: Zale Delaware and Sterling Jewelers will pay $1.61 million to settle Washington job posting transparency violations. The Trump administration asked the Supreme Court to review a D.C. Circuit ruling blocking expedited immigrant removals without asylum hearings. German credit agency SCHUFA faces legal action from noyb over its secret retention of millions of supposedly deleted consumer records, with affected individuals now able to register for a class action seeking damages.
SCHUFA's Shadow Database Draws Cease-and-Desist Letter, Class Action Interest List Opened
German credit information agency SCHUFA stored millions of data records that should have been deleted under GDPR, using this historical data for customers' testing purposes. SCHUFA refuses to disclose historical data even when consumers submit Article 15 GDPR access requests, claiming data subjects are only interested in current score data. Privacy advocacy group noyb has issued a formal warning and announced an injunction, while opening an interest list for a future class action for damages. The Hessian Data Protection Authority, SCHUFA's supervisor, has remained inactive despite apparent knowledge of the violations.
$1.61 Million Settlement for Washington Job Posting Transparency Violations
Zale Delaware Inc. and Sterling Jewelers Inc. agreed to pay $1.61 million to resolve claims they violated Washington state job pay transparency laws. The settlement addresses failure to include required salary information in job postings.
Interpol Operation Jackal IV Nets 58 Arrests, $2.7 Million Seized
Law enforcement agencies in 22 countries arrested 58 people and seized approximately $2.7 million during an eight-month cybercrime operation targeting romance scams, cryptocurrency investment scams, and business email compromise fraud. The operation disrupted a 196-person crime-as-a-service network in Argentina providing domains and money laundering support to West African organized crime groups like Black Axe. In Romania, 11 people were arrested for running a cryptocurrency investment scam operation with $166 million in stolen and laundered funds.
Ninth Circuit Rules Tech Companies Cannot Immediately Appeal Section 230 Denials (California v. Meta)
The Ninth Circuit ruled that Meta cannot immediately appeal a district court's partial denial of its Section 230 motion to dismiss, requiring the company to wait until the case concludes before appealing. The decision addresses thousands of consolidated lawsuits alleging Meta engineered its social media platforms to cause compulsive use in children. The court rejected Meta's argument that Section 230 denials qualify for immediate appeal under the collateral order doctrine, ruling that Meta's interests would be adequately served by appealing after trial. This marks the second federal circuit to reject such immediate appeals, forcing tech companies to proceed through discovery rather than delay cases with premature appeals.
Texas Appeals Court Slashes Alex Jones Sandy Hook Judgment from $50 Million to $6 Million
The Texas Third Court of Appeals reduced a $50 million judgment against conspiracy theorist Alex Jones to approximately $6 million under state laws limiting lawsuit damages. The ruling does not affect a separate $1.25 billion Connecticut judgment, which the Supreme Court declined to review in 2025. Jones indicated he will continue challenging the Texas judgment by appealing to the state Supreme Court.
Patent Troll Loses Defamation SLAPP Against Attorney, Ordered to Pay Fees
Patent troll Leigh Rothschild lost a defamation lawsuit against an attorney who publicly stated that his shell companies never pay court-ordered fees. The court ruled the statements were protected speech and ordered Rothschild to pay the attorney's legal fees under anti-SLAPP statutes. The underlying patent litigation involved Rothschild's pattern of creating single-patent LLCs, suing multiple defendants, and offering settlements below defense costs while allegedly underfunding the shell entities to avoid fee awards.
Paylogix Employee Benefits Platform Breach Exposes 64,383 Records in South Carolina
Hackers stole Social Security numbers, electronic signatures, financial account information, health insurance data, medical records, passport numbers, and taxpayer IDs from Paylogix between November 13-18, 2025. The company was added to the Akira ransomware gang's leak site in January 2026. Total victims include 64,383 in South Carolina, 2,304 in New Hampshire, and 1,102 in Vermont, with additional filings in California, Massachusetts, and New Jersey. Paylogix is a third-party administrator handling employee benefits, payroll, and insurance for multiple employers. The FBI is investigating. Several law firms are organizing class action lawsuits.
Trump Administration Prepares Largest Mass Visa Revocation in U.S. History
The Trump administration is preparing to revoke business and tourism visas (B1/B2) from up to 200,000 foreigners who sought asylum after entering the U.S. legally at ports of entry, as Trump previously instructed. The State Department will target visas issued between 2016 and 2026 whose holders filed asylum claims. This represents the largest single mass visa revocation in U.S. history and directly contradicts Trump's 2018 directive that asylum seekers "lawfully present themselves at a port of entry." The action is expected to face legal challenges.
Pentagon Fires Stars & Stripes Editor for Defending Editorial Independence
The Pentagon fired Stars & Stripes Editor-in-Chief Erik Slavin and a senior reporter for "insubordination" after they publicly stated in a CBS interview that Pentagon censorship of the congressionally mandated independent military newspaper would violate federal law and department policy. Slavin, who worked at the paper for over two decades, stated that hypothetical censorship would constitute a red line. Stars & Stripes operates under congressional mandate to follow First Amendment principles despite being part of the Pentagon's Defense Media Activity.
UK Government Seeks Powers to Secretly Block Tech Suppliers on National Security Grounds
The British government published amendments to the Cyber Security and Resilience Bill allowing ministers to ban technology vendors from supplying companies in critical sectors (energy, water, transport, health, telecoms, data centers) without publicly identifying the vendor. Unlike previous telecoms laws, ministers would not have to publicly designate a vendor as a security risk before acting, and vendors would not receive copies of orders. Companies receiving directions could be barred from discussing them publicly. The powers adapt mechanisms used to restrict Huawei 5G equipment but remove transparency safeguards. Ministers would publish only that a direction was issued and to whom, withholding vendor identity on national security or commercial grounds.
Ukraine Shares Battlefield AI Data with UK Under Defense Partnership
Ukraine will give Britain access to its Avengers AI Labs platform containing 5 million battlefield images and video frames collected from thousands of cameras and infrared sensors. The data trains AI models analyzing over 100,000 drone video feeds monthly, identifying approximately 70% of enemy targets in real time. British companies and researchers will use the data to develop AI systems for drones and autonomous platforms, with initial deployments planned for protecting UK defense facilities from protestors and hostile actors. Ukraine announced a similar partnership with Germany in April 2026.
GDPR Right of Access: Verify that data deletion processes actually erase records rather than hiding them from consumer view. Article 15 GDPR access requests must return complete copies of all processed data, not just currently active records. Review credit scoring and third-party data processor relationships following the SCHUFA enforcement action.
Pay Transparency Laws: Audit all job postings in Washington state and other jurisdictions with salary disclosure requirements. The $1.61 million Zale/Sterling settlement demonstrates state enforcement of these laws.
Section 230 Discovery Exposure: Tech companies in the Ninth and Tenth Circuits cannot avoid discovery by immediately appealing Section 230 motion denials. Prepare for full document production and depositions when asserting Section 230 defenses in product liability and consumer protection cases.
Third-Party Benefits Administrator Risk: The Paylogix Akira ransomware breach exposed 64,000+ employees' most sensitive data (SSNs, medical records, financial accounts). Review vendor security assessments, data minimization practices, and incident response capabilities for all benefits administrators and payroll processors.
UK Critical Infrastructure Vendor Controls: Organizations in UK-regulated sectors (energy, water, transport, health, telecoms, data centers) should develop contingency plans for government-directed vendor transitions that may occur without public disclosure or advance warning under the proposed Cyber Security and Resilience Bill amendments.