← Carolina Clear Tech

Legal & Privacy Brief

2026-08-31

Listen to this brief (7:17)

Download MP3
Show Notes

Show Notes - 2026-08-31

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Today: McKesson faces a cyberattack claimed by ShinyHunters ransomware group affecting pharmaceutical distribution services. Slovenian casinos reopened after multi-day ransomware disruption. A security researcher demonstrated prompt injection techniques hidden in legal filings targeting AI legal research tools.

Enforcement Actions

No enforcement actions in today's collection.

Litigation Updates

Madewell hit with class action over alleged fake sales, inflated reference prices

Summary: Clothing retailer Madewell faces a new class action lawsuit alleging deceptive advertising practices, specifically that the company falsely represented items as being on sale or discounted when they were not. The complaint appears to involve claims of inflated reference pricing, a common consumer protection theory where retailers artificially inflate the original price to make discounts appear larger than they are.

Goodyear, Pizza Hut, 7-Eleven, Campbell's face wage and hour lawsuits

Summary: The Goodyear Tire & Rubber Company faces a class action lawsuit in Washington state alleging the company failed to pay hourly workers legally owed wages. The article mentions additional wage and hour lawsuits against Pizza Hut, 7-Eleven, and Campbell's, though specific details on those cases were not provided in the article content.

Regulatory Guidance

No new regulatory guidance in today's collection.

Privacy Developments

McKesson pharmaceutical giant warns of service degradation following cyberattack

Summary: McKesson Corporation, a pharmaceutical distributor responsible for one-third of all prescriptions in North America, disclosed a cybersecurity incident involving unauthorized access to a third-party application. The company filed an SEC notice Friday evening confirming that attackers are actively exfiltrating data and customers are experiencing intermittent service degradation. The ShinyHunters ransomware group claimed responsibility, continuing a pattern of attacks on major healthcare organizations including Boston Scientific, Medtronic, and Stryker earlier this year. McKesson reported $106 billion in revenue last quarter and distributes pharmaceuticals, oncology drugs, and medical-surgical supplies across North America.

Slovenian casinos reopen after cyberattack knocked gaming systems offline

Summary: Hit, one of Slovenia's largest gambling and tourism groups, began gradually reopening six casinos after a cyberattack forced a three-day closure. The incident affected servers and disrupted cash registers, loyalty systems, table games, and bingo operations. The company has not disclosed whether data was stolen or whether a ransom was demanded or paid. Slovenian police are investigating. The attack follows a pattern of ransomware targeting gaming companies, including 2023 attacks on MGM Resorts International (estimated $100 million loss) and Caesars Entertainment (customer loyalty data theft).

Policy Changes

Texas Politicians Slowly Realize Elon Musk Hijacked Billions In Taxpayer Broadband Grants

Summary: Bipartisan anger is growing in Texas over the redirection of $3.3 billion in federal BEAD (Broadband, Equity, Access, and Deployment) funds originally designated for fiber optic deployment toward Elon Musk's Starlink satellite broadband service. The Texas Broadband Deployment Office (BDO) placed all grant awards on hold amid investigations of favoritism and cronyism. Republican State Senator Charles Schwertner warned the BDO director about transparency and fairness concerns. The original $42.5 billion congressional appropriation was reduced after redirecting funds to satellite providers, with the Trump administration claiming $21.5 billion in "savings" that states say has disappeared. Texas lawmakers are concerned that satellite broadband cannot scale to meet state needs due to capacity limitations and that funds are being diverted from local fiber optic businesses.

Hiding Prompt Injection in Legal Filing

Summary: A security researcher demonstrated a prompt injection attack technique embedded within legal filings, targeting AI-powered legal research tools. The technique shows how adversarial content can be concealed in court documents to manipulate AI systems used by attorneys for case analysis. The demonstration highlights risks for law firms and legal professionals increasingly relying on large language models for document review and legal research.

Compliance Takeaways