← Carolina Clear Tech

Legal & Privacy Brief

2026-09-03

Listen to this brief (11:17)

Download MP3
Show Notes

Show Notes - 2026-09-03

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Today: Meta's $17 billion settlement with 52 state AGs embeds age-assurance technology that threatens privacy for all users, not just minors. Aesto's healthcare data breach exposed 9.5 million patient records across 30+ organizations. Texas and Florida governors issued executive orders curtailing automated license plate reader surveillance networks. USPS built an untested ballot-blocking system in defiance of a court injunction, per whistleblower disclosures.

Enforcement Actions

Russian National Indicted for Malware Campaign Targeting 80,000 Freelancers

Searzhudin Aktulaev appeared in San Francisco federal court after extradition from Cyprus on charges related to a 2016-2017 campaign using TVRAT and DarkVNC malware. Aktulaev operated 255 fake accounts on a freelance employment platform, distributing malicious Excel attachments that gave him remote access to victim devices. About half the victims were U.S.-based, primarily in California. Charges carry a maximum 20-year sentence; next hearing is October 5.

Sality Botnet Disrupted After 20+ Years of Operation

DOJ announced the disruption of the Sality botnet, active since 2003, through a coordinated operation with Bulgaria, Hungary, Romania, CrowdStrike, and Shadowserver Foundation. The peer-to-peer sinkhole operation severed connections to 15,000+ infected machines. No arrests were announced. The operator, assessed to be based in Russia's Bashkortostan region, stole at least $150,000 in cryptocurrency through clipboard-hijacking malware.

Litigation Updates

Meta's $17 Billion Settlement with 52 State Attorneys General

The settlement requires Meta to deploy age-assurance technology across Instagram and Facebook for all users in participating states within one year. Teen accounts face severe default restrictions modifiable only by parents, in exchange for detailed usage and community data. The agreement empowers AGs to enforce Meta's content restrictions on "age inappropriate content." Florida, New Mexico, and Texas are not parties to the settlement. EFF analysis warns the settlement mandates more data collection about teens, not less, and embeds flawed age-estimation technology that threatens online anonymity for all users.

$75M Northrop Grumman Soil Contamination Class Action Settlement

Northrop Grumman agreed to a $75 million settlement for property owners in Canoga Park affected by soil and groundwater contamination. Claims are open for eligible property owners.

$1.01M Sportsman's Guide Data Privacy Settlement

Sportsman's Guide will pay $1.015 million to resolve claims it shared firearm purchase information without consumer consent. Pennsylvania residents are eligible to file claims.

Butterball and Hormel Turkey Price-Fixing Settlements

An Illinois federal judge granted preliminary approval to two settlements resolving remaining direct purchaser claims in long-running turkey price-fixing litigation.

Sony Defends Digital Purchase Licensing Model in California Court

PlayStation gamers sued Sony alleging noncompliance with California's digital purchase disclosure law, which restricts use of "buy" and "purchase" for licensed digital goods without proper disclosure. Sony's store already displays license acknowledgment language, links to terms, and requires confirmation. Sony further argued that "reasonable consumers" already understand digital purchases are licenses. The case tests the boundaries of California's relatively new digital goods transparency statute.

Regulatory Guidance

House to Vote on Constitutional Amendment Capping SCOTUS at 9 Justices

Speaker Mike Johnson announced a House vote on a constitutional amendment to permanently fix the Supreme Court at nine justices. The amendment requires two-thirds support in both chambers before going to states for ratification. The vote is primarily a messaging exercise forcing members on record regarding court expansion proposals.

Supreme Court Term Preview: Religion, Education, and Locke v. Davey

The upcoming term includes a Catholic preschool's challenge to Colorado's universal preschool program, potential review of state laws requiring Ten Commandments displays in public school classrooms, and two petitions asking the court to overturn Locke v. Davey (2004), which allowed states to exclude ministry students from public scholarship programs. Given the court's shift toward requiring equal access to state funds for religious institutions, Locke may not survive review.

Privacy Developments

Aesto Healthcare Data Breach: 9.5 Million Records Exposed

Healthcare data company Aesto notified HHS that 9.5 million people were affected by a December 2025 breach of its AWS infrastructure. Stolen data includes SSNs, medical information, driver's license numbers, financial account numbers, and health insurance data. At least 30 healthcare organizations were affected. Separately, Baylor Genetics reported 2.8 million records stolen, CareCloud reported 3.7 million, and Park Dental Partners disclosed an attack to the SEC. McKesson, Nutex, and Paylogix also announced breaches in the past two weeks.

Texas and Florida Restrict Automated License Plate Readers

Texas Governor Abbott banned state agency spending on Flock cameras after a Texas Tribune investigation revealed $30 million in secret ALPR procurement. Florida DOT ordered removal of all ALPRs from state highway rights-of-way within 30 days, revoked all existing permits, and barred future installations. Multiple Florida local governments have since paused or canceled vendor contracts. Both orders leave local government and private installations untouched.

Hackers Expose Donor Data from Russian Fundraisers Supporting Ukraine

Attackers compromised Stripe/WooCommerce integrations used by two Russian fundraising projects (Davayte and You Are Not Alone), exposing donor email addresses and partial payment card data. Under Russian law, donating to these "undesirable" organizations carries up to five years in prison, making donor identification data exceptionally sensitive. Stripe blocked full database exfiltration. The breach occurred amid broader reports of Stripe merchant targeting; a June dataset containing 669 merchant records and 1,000+ access keys was posted to a cybercrime forum.

Policy Changes

USPS Ballot-Blocking System Built in Defiance of Court Injunction

A whistleblower disclosed that USPS built an untested, undocumented system to flag and potentially block mail-in ballots, defying injunctions issued by Judge Indira Talwani in two cases challenging Trump's executive order restricting mail-in voting. The court held that states have constitutional authority over election administration under Article I, Section 4 and the Electors Clause. Over 20 states have won litigation challenging the administration's demand for voter rolls.

GOP Emergency Motion on Political Ad Discount Rates

Republican committees asked the Supreme Court to block a 4th Circuit ruling that prevents political parties and joint fundraising committees from accessing preferential broadcast ad rates under FCC rules. Response is due by Thursday noon EDT. The 60-day discount period starts September 4, creating urgency. The case follows the Supreme Court's June ruling in National Republican Senatorial Committee v. FEC striking down coordinated expenditure limits.

Compliance Takeaways