← Carolina Clear Tech

Legal & Privacy Brief

2026-09-10

Listen to this brief (11:21)

Download MP3
Show Notes

Show Notes - 2026-09-10

Stories Covered

Read the full brief

Get tomorrow's brief in your inbox

Compliance Questions?

HIPAA, privacy, and regulatory compliance consulting.

View Services

Legal & Privacy Brief - September 10, 2026

Today: DOJ disrupted a $24 billion Chinese cybercrime marketplace and seized $53 million in cryptocurrency. Veradigm disclosed a vendor breach exposing Social Security numbers of millions of patients. The Supreme Court continues wrestling with election-related emergency motions as Missouri's congressional map remains in chaos.


Enforcement Actions

US Disrupts Xinbi Guarantee Cybercrime Marketplace

Treasury sanctioned Xinbi Guarantee, a Chinese-language Telegram marketplace that processed at least $24 billion in transactions supporting pig butchering scams, money laundering, and human trafficking. DOJ seized $52.8 million from 52 cryptocurrency wallets and obtained court authorization to take down Xinbi's Telegram channels. The platform, created in 2022 after Telegram shut down Huione Guarantee, operated as an escrow service for cybercrime vendors offering stolen data, deepfakes, and money laundering services. Treasury also sanctioned Anwen Technology (developer of XinbiPay) and SafeW Technology (encrypted messaging app used by Xinbi's networks).

Grindr Settles UK Privacy Lawsuit for $35 Million Over HIV Status Disclosures

Grindr agreed to pay £26 million ($35.2 million) to resolve UK litigation alleging the LGBTQ+ dating app shared users' HIV status and other sensitive health data with advertisers. The incidents occurred before early 2020 when Grindr was owned by Chinese company Kuntun. The settlement includes no admission of liability but resolves claims from 12,000 class members alleging violations of UK privacy law.


Litigation Updates

MCNA Data Breach Settlement Offers $2,500 Plus Two Years of Monitoring

Individuals affected by the Managed Care of North America data breach may qualify for up to $2,500 in compensation for out-of-pocket losses plus two years of free medical data monitoring. The settlement resolves class action claims following a breach that exposed protected health information.

FCA US Emissions Warranty Settlement

FCA US reached a class action settlement benefiting owners of certain Dodge, Jeep, and Chrysler vehicles who paid for repairs to valve train system components related to emissions warranty claims.

AMC Accused of Charging Junk Fees for Online Movie Tickets

A new class action lawsuit accuses AMC Theatres of charging hidden convenience fees when consumers purchase movie tickets online. The complaint alleges deceptive pricing practices that violate consumer protection laws.

Edikted Accused of Deceptive Shipping Fees

Women's online fashion retailer Edikted faces a class action lawsuit alleging the company deceptively adds junk shipping fees to consumers' shopping carts during checkout.


Privacy Developments

Veradigm Data Breach Exposes Social Security Numbers of Millions

Electronic health records company Veradigm disclosed that hackers obtained vendor credentials to a Veradigm API and downloaded personal data of patients, including Social Security numbers. Veradigm, which provides health record technology to thousands of hospitals, reported the breach to the SEC but stated no clinical or medical data was involved. The Gentlemen ransomware gang claimed to have stolen health records of 3.5 million patients and added Veradigm to its leak site.

Baylor Genetics, Aesto, and CareCloud Report Massive Healthcare Data Breaches

Healthcare data migration company Aesto reported 9 million people had information leaked during a security incident. Baylor Genetics disclosed that more than 2.8 million people had medical testing information and laboratory test results stolen during a June cyber incident. CareCloud's March breach impacted 3.7 million people.

153 Million Driver's License Records for Sale on Dark Web

A database containing 153 million driver's license records is being sold on the dark web following a breach of IDScan.net. The vendor claims to have been exfiltrating data continuously for over a year.

SCHUFA Rejects noyb Cease-and-Desist, Lawsuit Certain

European privacy group noyb will file an injunction against German credit bureau SCHUFA after the company rejected demands to cease operating what noyb calls a "shadow database" in violation of GDPR. SCHUFA's deadline to comply with the cease-and-desist letter expired, and the company publicly rejected the allegations.

EFF Releases WISeR Medicare AI Records Showing Widespread Delays and Denials

EFF obtained approximately 1,000 pages of records from CMS regarding the Wasteful and Inappropriate Service Reduction (WISeR) model, which uses AI to evaluate Medicare prior authorization requests. Documents show widespread delays (including one request unanswered for 83 days), inappropriate denials, and vendor payment structures that create financial incentives to deny care. Internal status reports confirm vendors failed to respond within the required 72 hours for a significant number of requests.

EU Coalition Urges Support for Automated Privacy Signals to Kill Cookie Banners

A coalition of 19 civil society organizations is urging EU lawmakers to support Article 88b in the Digital Omnibus package, which would create legally binding automated privacy signals. The proposal would allow users to set privacy preferences once in their browser rather than clicking through misleading consent banners on every website. The tracking industry is lobbying to remove the provision from the legislation.


Policy Changes

Law Enforcement Agencies Instructed to Conceal ALPR Surveillance Use

Internal policy documents from Iowa and Houston police departments instruct officers not to mention automated license plate reader (ALPR) usage when detaining vehicle occupants or writing reports. One Iowa county policy states "DO NOT MENTION ALPR USAGE TO THE OCCUPANTS OF THE VEHICLE" and "DO NOT MENTION ALPR USAGE IN YOUR REPORT OR COMPLAINT UNLESS ABSOLUTELY NECESSARY." Houston officers are told to "be as vague as permissible" about Flock ALPR searches to avoid public records requests.

DOJ Blocked Civil Rights Charges Against ICE Officer in Minneapolis Shooting

DOJ leadership in Washington quashed plans by federal prosecutor Matthew Evans to bring civil rights charges against ICE officer Christian Castro, who shot a Venezuelan immigrant and allegedly lied about the incident. Evans objected "in the strongest possible terms" but was overruled by Main Justice and the U.S. Attorney. Castro now faces only false statements charges rather than the assault and civil rights violations Evans recommended.


Regulatory Guidance

Multiple Chinese Hacking Groups Using Identical Chrome Zero-Day Exploit

At least four Chinese state-linked cyber-espionage groups exploited the same Chrome zero-day vulnerability using an identical exploit kit dubbed BlueMoon. The groups targeted U.S. defense contractors, NGOs, and Southeast Asian government agencies. The vulnerability was patched in Chromium in early August but took four weeks to reach stable Chrome users, creating a patch gap that attackers exploited.

Ford Recalls 148,000 Mustang Vehicles for Power Loss Defect

Ford issued a recall for more than 148,000 Mustang vehicles due to a defect that may cause loss of power while driving.


Compliance Takeaways