← Carolina Clear Tech

Legal & Privacy Brief

2026-08-27

Listen to this brief (16:26)

Download MP3
Show Notes

Show Notes - 2026-08-27

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Today: Meta settles for $17 billion with 52 state AGs, mandating strict child safety controls and expanded age verification across its platforms. Federal prosecutors seize Chinese government hacking infrastructure used against the Federal Reserve, DOJ, and U.S. Senate. France's Constitutional Council strikes down a social media ban for minors under 15, ruling it violates free expression and privacy rights.

Enforcement Actions

Meta Reaches $16.7 Billion Settlement with 52 State AGs Over Child Safety Violations

Meta agreed to pay between $12.7 billion and $18 billion (capped at $16,680,647,753.21) to settle claims that it violated the Children's Online Privacy Protection Act (COPPA) by collecting data from users under 13 through self-reported ages rather than rigorous verification, and concealed research showing Facebook and Instagram are addictive to minors. The settlement requires Meta to limit daily usage to two hours for users under 18, block platform access between midnight and 6 a.m., ban cosmetic surgery filters for minors, disable "likes" visibility for underage users, offer non-algorithmic feeds, and hire an independent auditor with direct reporting access to state AGs. Meta must respond to 90% of teen-reported harmful content within 12 hours and is barred from making false safety claims. The final payment amount depends on whether YouTube, TikTok, and Snapchat implement similar controls.

DOJ Seizes Chinese Government Hacking Tools Used Against Federal Agencies

The Department of Justice announced the takedown of "QScan" and "QTRouter," hacking platforms operated by China-based Nanjing Xinjiuwei Network Technology Company and used by China's Ministry of State Security and People's Liberation Army. The tools were used to breach the Federal Reserve, Department of Energy, DOJ, U.S. Senate, NASA, Department of Health and Human Services, National Institutes of Health, multiple hospitals, telecommunications providers, power companies, financial institutions, and defense contractors since 2018. QScan automatically infected IoT devices globally, while QTRouter created an obfuscation network making attacks appear to originate from infected devices in over 130 countries. The seized domains were hard-coded into both platforms, rendering them inoperable.

Boston Scientific Confirms Cyberattack Disrupting Medical Device Shipments

Boston Scientific disclosed a cybersecurity incident discovered on August 26 that disrupted access to operating systems and business applications, preventing the company from processing and shipping customer orders globally. The medical device manufacturer, which produces pacemakers and stents and reported $5.4 billion in net sales during Q2 2026, hired a cybersecurity firm to respond but has not confirmed whether the incident involved ransomware. The company stated that the financial impact remains unclear and that a restoration timeline is unknown, with investors told recovery may take weeks.

Litigation Updates

Equinox Agrees to $685,000 Data Breach Class Action Settlement

Equinox agreed to a $685,000 class action settlement to resolve claims arising from a 2024 data breach that compromised consumer information. Settlement details, claim deadlines, and covered class members were not disclosed in the initial announcement.

State Farm Louisiana Settles Total Loss Claims Dispute

State Farm agreed to compensate Louisiana car insurance policyholders who submitted total loss claims that excluded purchasing fees. Class members must submit claims by October 19, 2026. The settlement amount was not disclosed.

Detroit Water Rates Class Action Settlement Provides $4.45 Million in Relief

The Detroit water rates class action settlement provides $4.45 million to customers who paid allegedly unfair water rates. Eligibility criteria and claim procedures were not disclosed in the initial announcement.

Amazon Reaches $309 Million Settlement Over Returns Policy

Amazon.com agreed to a $309.5 million class action settlement with consumers alleging the company shortchanged them on refunds for returned items. Settlement details regarding eligibility and claim procedures remain pending preliminary approval.

Pornhub Settles Child Abuse Content Claims for $120 Million

A federal judge will consider preliminary approval of a $120 million Pornhub class action settlement combining claims from California plaintiff Jane Doe and an Alabama plaintiff involving allegations that the platform hosted child sexual abuse material. The settlement does not resolve numerous other lawsuits from parents, users, and school districts.

CareCloud Data Breach Affects 3.75 Million Patients

CareCloud confirmed a data breach affecting more than 3.75 million patients nationwide, initially disclosed to the SEC in March 2026. The breach involved personal patient data, though specific data types compromised were not detailed.

11th Circuit Remands Georgia Redistricting Case After Supreme Court VRA Ruling

The U.S. Court of Appeals for the 11th Circuit remanded Georgia's congressional redistricting dispute to a lower court for review in light of the Supreme Court's recent Louisiana v. Callais decision, which limited how redistricting maps can remedy racial discrimination under the Voting Rights Act. The Supreme Court held 6-3 that Louisiana's second majority-Black congressional district was an unconstitutional racial gerrymander. In the Georgia case, a judge had previously ordered creation of two majority-Black Senate districts and three majority-Black House districts to remedy vote dilution in metro Atlanta.

Grand Jury Declines to Indict Flock ALPR Camera Vandalism Suspect

A Clermont County grand jury dismissed felony vandalism charges against Cody Morelock, who was accused of destroying a Flock Safety automated license plate reader camera in Union Township, Ohio, on June 13, 2026. Police had surveillance footage of the incident. The case reflects growing public opposition to Flock's ALPR network, which captures 20 billion plate/vehicle images monthly and has been linked to law enforcement stalking and unauthorized federal access.

Regulatory Guidance

France's Constitutional Council Strikes Down Social Media Ban for Minors

France's Constitutional Council struck down legislation that would have banned social media use for people under 15 years old, scheduled to take effect January 2027. The Council ruled the ban violated Article 34 of the French Constitution by infringing on freedom of expression and communication in a manner that was not appropriate, necessary, or proportionate. The decision noted the law failed to distinguish between different online services and ignored individual circumstances such as exact age, maturity level, and family situation. The Council also found that requiring all users, including adults, to prove their age before accessing platforms violated the right to private life under Article 2 of the Déclaration de 1789. President Emmanuel Macron tasked Prime Minister Sébastien Lecornu with reworking the legislation.

Louisiana and Texas Teachers Challenge Ten Commandments Display Laws

Louisiana teacher Chris Dier filed a petition urging the Supreme Court to hear his constitutional challenge to a state law requiring Ten Commandments displays in K-12 and college classrooms. Texas families filed a related petition challenging a similar 2025 Texas law. Both cases raise Establishment Clause questions about government-mandated religious displays in public school classrooms.

Trump Administration Proposes Governmentwide Nondisclosure Agreement for Federal Employees

The Trump administration proposed in May 2026 the first governmentwide nondisclosure agreement covering nearly everything federal employees learn on the job, including "pre-decisional or deliberative material," with obligations extending beyond federal service. Under a companion suitability rule, refusing to sign is grounds for removal and debarment from federal employment for up to three years.

Privacy Developments

EFF Publishes Policy Position on ALPR Surveillance

The Electronic Frontier Foundation released a formal policy position stating that automated license plate reader (ALPR) mass surveillance should not exist because it creates irredeemable harm through indiscriminate, continuous collection and retention of location data on every driver regardless of suspicion. EFF called for outright refusal of ALPR purchasing at the city level and urged state legislatures to establish strict limits including warrant requirements and data deletion deadlines. EFF is currently litigating against the San Jose Police Department in California state court (with ACLU-NC, on behalf of SIREN and CAIR-CA) over warrantless searches of stored plate data occurring over 100,000 times per year, arguing violations of the California Constitution.

AI Watermarking Mandates Create Surveillance Risks for Journalists

Human rights organization WITNESS released a report warning that mandatory AI watermarking under the EU AI Act and similar laws creates surveillance risks for journalists, human rights defenders, and documentary filmmakers. The C2PA standard, implemented by tech companies for image and video watermarking, currently attaches creator identity details (name, email, country) to Content Credentials by default. WITNESS documented a scenario where a filmmaker using C2PA-enabled software unknowingly exported footage of labor organizing with her personal details embedded, compromising source anonymity when submitting the clip to a press freedom organization.

Iran-Linked Hackers Expand Infrastructure Across Europe and Middle East

Group-IB researchers identified new infrastructure linked to Iranian threat actor Tortoiseshell, including servers hosted in Britain ("uk1" and "uk2"), Belgium, Saudi Arabia, and the United Arab Emirates. Researchers discovered new malware samples including a TwoStroke backdoor variant and a reverse SSH tunnel tool. Tortoiseshell, active since 2018 and linked to Iran's Islamic Revolutionary Guard Corps, primarily targets defense, aerospace, technology, and military organizations. The purpose of the European infrastructure remains unclear.

Policy Changes

NSA Hosts First-Ever Reunion for Elite Hacking Unit

The National Security Agency hosted a first-of-its-kind reunion on August 29, 2026, for alumni of Tailored Access Operations (TAO), the agency's elite hacking unit responsible for breaking into foreign computer systems. The event, spearheaded by NSA Deputy Director Tim Kosiba, included a tour of the new TAO building and recruitment pitches to former members. NSA organized the gathering partially through an invitation-only Signal group chat dubbed "Terminated Async Operations" that ballooned to over 250 former hackers, developers, and analysts. The outreach reflects NSA's broader push to build public trust, including creation of a Cybersecurity Directorate in 2019 and launch of an agency podcast in 2024.

OpenAI Disrupts Cambodian Social Engineering Network Using ChatGPT

OpenAI disrupted a social engineering operation from Cambodia that used ChatGPT to conduct multiple scam types simultaneously, including romance scams transitioning to fraudulent cryptocurrency investments, fake online gambling bonuses, and law enforcement impersonation demanding fine payments. Operators created fake dating profiles, fictitious investment experts, fraudulent law enforcement personas, and generated images of forged documents including passports, legal notices, stock-purchase confirmations, and gambling platform interfaces.

Compliance Takeaways