Get tomorrow's brief in your inbox
Today: Lloyd's of London settles a $3.57 million insurance price-fixing class action while ABC Legal Services agrees to pay $2.5 million over a data breach. The Supreme Court blocks Trump administration mail-in voting rules weeks before November midterms, with Justice Kavanaugh citing insufficient implementation time. EFF analysis reveals police across the US are entering nonsensical justifications like "LOL" and "LMAO" into ALPR mass surveillance databases, exposing systemic abuse of license plate tracking networks with no warrant requirements.
Lloyd's of London Insurance Price-Fixing Settlement
Lloyd's of London agreed to pay $3.57 million to settle class action claims alleging the company conspired to artificially raise insurance prices. The settlement resolves allegations of anti-competitive conduct in the insurance market.
Revolut Disclosed Customer Data to Fraudsters via Compromised Government Email
British fintech company Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government agency domain email account, allegedly an Italian government domain. The perpetrators targeted high-net-worth individuals, particularly those involved in cryptocurrency businesses. Exposed data includes birth dates, postal and email addresses, phone numbers, passport and driver's license copies, verification selfies, bank statements, IBANs, withdrawal records, and transaction histories including Bitcoin activity. Revolut detected the impersonation scam and blocked the compromised address, then notified the relevant government agency, enforcement agencies, data protection authorities, and financial regulators.
ABC Legal Services Data Breach Class Action Settlement
ABC Legal Services agreed to pay $2.5 million to settle class action claims arising from a data breach affecting customer personal and service-of-process information. Class members who were impacted by the breach may qualify for cash payments from the settlement fund.
Seventh Circuit Grants Qualified Immunity for Two-Day Interrogation of 14-Year-Old
The U.S. Court of Appeals for the Seventh Circuit reversed a district court ruling and granted qualified immunity to Peoria, Illinois police officers who subjected 14-year-old Johnnie Lee Savory to two days of coercive interrogation in a 1977 murder case, resulting in a false confession. The appeals court ruled that despite clearly established law prohibiting coercive interrogation tactics, the officers could not have known their conduct was unconstitutional. Savory was convicted twice (the first conviction was thrown out due to the interrogation), served time, was paroled in 2006, and pardoned by Governor Patrick Quinn in 2014 before bringing a civil rights lawsuit. The district court had denied qualified immunity, finding disputes of material fact and clearly established law put officers on notice their tactics were unconstitutional. The Seventh Circuit disagreed.
Multiple Class Actions Filed Over Aesto Health Data Breach
Three new class action lawsuits accuse Aesto Health of failing to protect personal and medical information of thousands of patients in a nationwide data breach. The lawsuits seek damages for inadequate data security measures and failure to prevent unauthorized access to protected health information.
H&M Class Action Alleges Spam Emails Violate Washington Law
A new class action lawsuit alleges H&M bombards Washington shoppers with spam emails falsely claiming discounts are about to disappear, creating false urgency through misleading sale deadline representations.
Supreme Court Blocks USPS Mail-In Voting Rule Implementation
The Supreme Court denied the Trump administration's request to implement parts of a new U.S. Postal Service rule on mail-in voting, leaving in place a preliminary injunction issued by U.S. District Judge Indira Talwani in Massachusetts. Justice Brett Kavanaugh concurred, noting that even if the Postal Service has authority to issue the rule, election officials lack sufficient time to reasonably implement it before November elections. Justice Samuel Alito dissented, joined by Justice Clarence Thomas. The blocked rule would impose requirements for mail-in ballot envelope design and require states to submit voter data into a USPS portal. The injunction bars the Trump administration from requiring states to comply with the rule indefinitely while litigation continues.
California Legislature Passes SB 690 to Eliminate Private CIPA Pen Register Claims
The California Legislature passed SB 690 on August 28, 2026, which would eliminate the private right of action for website-based "pen register" claims under the California Invasion of Privacy Act (CIPA). The bill passed the Senate 35-0 and cleared both houses without further revision. Key provisions: (1) claims arising from conduct on internet websites, online applications, or mobile applications could be brought only by the Attorney General; (2) the bill would apply retroactively to pending claims in actions commenced on or after January 1, 2025; (3) Attorney General enforcement authority is preserved; (4) private rights of action under CIPA's wiretapping provision (Section 631) and confidential recording provision (Section 632) remain intact. Governor Newsom has until September 30 to sign or veto. If enacted, the bill becomes operative January 1, 2027.
EFF Exposes Systemic ALPR Surveillance Abuse by Police
An EFF analysis of automated license plate reader (ALPR) search logs from Flock Safety systems revealed officers across the United States are conducting mass surveillance searches with nonsensical justifications including "LOL" (laugh out loud), "LMAO" (laughing my ass off), "sexy," "idk" (I don't know), and random keyboard mashing. A Goshen Police Department officer searched 6,474 ALPR networks representing data from 82,413 cameras on May 7, 2025 with the justification "idk." Officers routinely search ALPR databases without legitimate justification, no warrant requirements, limited guardrails, and deficient audit processes. Examples include: Barberton Police Department (Ohio) employees ran numerous searches listing "LOL" between March 2024 and May 2026. The analysis documents use of ALPRs for stalking romantic partners, surveilling protests, tracking abortion seekers, profiling Romani people using terms like "roma" and "g*psy," and investigating trivial matters like loud music complaints and school zone residency verification. Flock Safety claims improved systems requiring dropdown crime selection, but this does not require proof the stated reason matches the actual search purpose.
Anthropic Reports AI-Enabled Weapons Development by Yemeni Threat Actors
Anthropic released a detailed document describing misuses of Claude models, including a cell of threat actors in northern Yemen running three weapons development programs using Claude Code to develop guidance, navigation, and control software for guided rockets, multi-stage ballistic missiles (range goal above 2,000 km), and hypersonic glide vehicles. The actors used multiple Claude instances simultaneously, assigning different roles (code writing, research, code review) to evade safeguards. Anthropic's safeguards blocked many requests but not all. The actors concealed their goals, split work across multiple sessions, and conducted a field test of a guided rocket (which failed). Anthropic has no evidence of an operational device but confirmed sustained weapons development efforts using AI.
Debevoise Proposes Employee-Style Controls for Agentic AI
Debevoise & Plimpton analysis recommends financial services firms apply employee-style governance controls to AI agents, drawing on existing employee supervision frameworks. FINRA's 2026 Annual Regulatory Oversight Report identified agentic AI risks (data mishandling, unauthorized agent conduct) as key supervisory considerations for broker-dealers. Federal banking agencies' April 2026 Model Risk Management Guidance clarifies existing risk management obligations apply to agentic AI. Singapore's 2026 Model AI Governance Framework for Agentic AI emphasizes firms deploying AI agents remain accountable for agent actions. Recommended controls include: defined responsibilities, technical access limitations, supervision layers, approval requirements, ongoing monitoring, training on firm policies, and mandatory escalation procedures. Firms should distinguish between an agent's access to systems and its authority to act.
Supreme Court Analysis: Judicial "Drift" and Ideological Movement
SCOTUSblog analysis examines the phenomenon of Supreme Court justices ideologically "drifting" after appointment, particularly in response to President Trump's criticism of Justices Barrett and Gorsuch for votes against his administration. The analysis traces historical examples including Justice David Souter (predicted as conservative "home run," became liberal-leaning after Planned Parenthood v. Casey) and the "Greenhouse Effect" theory that justices shift leftward to gain favor with media. University of Virginia research estimates roughly one quarter of justices have drifted leftward historically. The conservative legal movement's "no more Souters" mantra reflects efforts to prevent ideological drift through rigorous vetting.
SCOTUSblog Series: "Born Free and Equal" Clauses and Buck v. Bell
Fifth installment in a seven-part series examining the "born free and equal" clauses appearing in state constitutions and their relevance to constitutional law. This article addresses Buck v. Bell (1927), the 8-1 Supreme Court decision upholding Virginia's eugenics statute allowing compulsory sterilization of individuals deemed to have genes resulting in feeblemindedness or intellectual disability. The article traces eugenics laws to 1883 social Darwinist Sir Francis Galton and notes Progressive Era support including President Theodore Roosevelt's endorsement of preventing "degenerates" from reproducing. The analysis argues the "born free and equal" clauses, constitutionalized through the 14th Amendment's privileges or immunities clause, should inform reconsideration of such precedents.
Emergency data requests: Financial institutions must implement callback verification and audit recent emergency disclosures following the Revolut incident where fraudsters used compromised government email accounts to obtain customer data.
ALPR audit controls: Law enforcement agencies using automated license plate readers must establish meaningful justification requirements and supervisor review before the systemic abuse documented by EFF leads to civil rights litigation and federal intervention.
California CIPA pending litigation: Companies with website-based pen register claims filed since January 1, 2025 should monitor SB 690 (Governor's deadline September 30) for potential retroactive dismissal opportunities effective January 1, 2027.
Agentic AI governance: Financial services firms must document AI agent authorities, implement technical access controls, and update written supervisory procedures before FINRA examinations focus on the agentic AI risks identified in the 2026 Annual Regulatory Oversight Report.
Data breach settlement reserves: Legal service providers and healthcare entities should review cyber insurance coverage and settlement reserves following the $2.5 million ABC Legal Services and multiple Aesto Health class action settlements, ensuring adequate financial preparation for breach response costs.