Get tomorrow's brief in your inbox
Today: Furniture Mart USA and Navy Federal Credit Union reach class action settlements over data breaches and unauthorized accounts. The Trump administration asks the Supreme Court to allow third-country deportations while sending Somali migrants to Guantanamo Bay. DraftKings uses AI to target problem gamblers with behavioral advertising, and Astrana reports a data breach to the SEC after hackers spoofed corporate phone numbers.
Furniture Mart USA Data Breach Settlement
Furniture Mart USA agreed to a class action settlement resolving claims from a 2024 data breach. Class members can receive up to $4,500 for documented losses related to the breach. The settlement provides compensation for financial harm suffered by affected customers whose personal information was compromised.
Navy Federal Credit Union Unauthorized Loans Settlement
Navy Federal Credit Union settled class action claims alleging it allowed third parties to open unauthorized loan accounts for members. The settlement addresses failures in account verification and authorization controls that permitted fraudulent account creation.
Digital Forensics Firm Executives Arrested for Concealing Russia Ties
DOJ arrested two executives at a data extraction and digital forensics company for allegedly lying about their technology being manufactured in Russia. The company sold software to several U.S. federal agencies while concealing the origin of its products, raising national security and supply chain integrity concerns.
Rydox Cybercriminal Marketplace Operator Pleads Guilty
Ardit Kutleshi, 28, pleaded guilty after extradition from Kosovo for running Rydox, an illicit marketplace selling stolen personal information, unauthorized device access credentials, and fraud tools. The prosecution follows the deportation of his co-conspirator brother and demonstrates international cooperation in shutting down criminal data marketplaces.
Trump SLAPP Suit Dismissed Over Poll Results
An Iowa state judge dismissed President Trump's defamation lawsuit against pollster Ann Selzer and the Des Moines Register over pre-election poll results showing Kamala Harris competitive in Iowa. The court ruled that poll data enjoys First Amendment protection and cannot constitute defamation, rejecting Trump's argument that the case had no First Amendment implications because both parties were private actors.
Hickory Farms Spam Email Class Action
A new class action alleges Hickory Farms sent Washington consumers emails with false or misleading subject lines in violation of Washington's Commercial Electronic Mail Act (CEMA). The lawsuit targets deceptive email marketing practices under state consumer protection law.
Roblox and Fortnite Sued Over Addictive Game Design
Roblox and Epic Games face a lawsuit alleging their games were designed to encourage addictive use among minors while failing to warn users and parents about alleged risks. The complaint raises product liability and failure-to-warn claims related to behavioral design features targeting children.
Third-Country Deportation Litigation at Supreme Court
The Trump administration filed its third emergency request asking the Supreme Court to allow deportations of noncitizens to countries not identified in their removal orders. U.S. District Judge Brian Murphy previously blocked these "third-country removals" and required DHS to provide written notice of destination countries and meaningful opportunities to challenge removal. Justice Ketanji Brown Jackson directed immigrants to respond by September 28.
Missouri Congressional Redistricting Returns to Supreme Court
Opponents of Missouri's Republican-favoring congressional map asked the Supreme Court to prevent its use in November elections. The state and intervening candidates filed responses Wednesday. The dispute centers on whether the redistricting plan violates constitutional requirements.
Telecommunications Cybersecurity Bill Introduced After Salt Typhoon
Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act following Chinese Salt Typhoon hacks that breached nearly all major U.S. telecommunications companies. The bill proposes voluntary cybersecurity rules for the telecom sector.
Federal Judge Questions Death Penalty Limits for Child Sex Offenses
U.S. District Judge Joshua Divine (E.D. Missouri) issued a sentencing opinion arguing that Supreme Court precedent in Kennedy v. Louisiana (prohibiting death penalty for non-homicide child sexual offenses) may no longer control. Divine cited six states enacting capital punishment laws for child rape in the past three years and argued that "evolving standards of decency" may now support expanding capital punishment beyond current bounds. The opinion raises questions about whether the Eighth Amendment's "evolving standards" doctrine can move in a more punitive direction.
DraftKings Uses AI to Target Problem Gamblers
DraftKings is using machine learning models trained on customer betting records to identify losing gamblers and send them targeted promotions designed to bring them back to the platform. The system likely targets problem gamblers who repeatedly gamble despite financial and personal harm. DraftKings uses only first-party data, highlighting that restrictions on third-party data sharing alone cannot prevent predatory behavioral advertising.
Astrana Healthcare Data Breach Reported to SEC
Astrana filed an SEC report disclosing a cyberattack in which hackers impersonated company personnel, spoofed the corporate phone number, and gained unauthorized access to company servers containing confidential information. The company had to restore systems from clean backups and notified law enforcement, regulators, and customers. Astrana warned the breach may impact business operations, financial condition, and reputation. The company is one of the largest healthcare tech firms in the U.S., serving about 20,000 medical providers with $972.5 million in quarterly revenue.
Meta's Muse AI Agent Launches With Zero-Day Vulnerability
Meta's new AI agent Muse launched with a zero-day flaw allowing any app or terminal command to access authentication tokens linking users to their Muse accounts. The vulnerability enabled unauthorized account access and non-transparent user surveillance. Security researchers criticized Meta for failing to prioritize security in the agent's design. Amazon subsequently banned Muse from its platform, calling it an "unauthorized AI agent" violating Amazon's terms of service.
Meta Settlement With State AGs Creates Competitor Bounty System
Meta's proposed settlement with state attorneys general includes $12 billion in guaranteed payments plus $5 billion in additional bonuses if state AGs impose equivalent restrictions on Meta's competitors. The settlement deputizes state AGs as "bounty-hunters" to restrict minors' usage of rival social media platforms. Critics argue the quid-pro-quo arrangement is anticompetitive, taints future enforcement actions, and demonstrates that state AG offices can be purchased to do a company's anticompetitive work.
Trump Administration Diverts Somali Migrants to Guantanamo Bay
ICE transported 12 Somali men to Guantanamo Bay after telling them they were being deported to Somalia. Seven or eight remain detained at the facility, subjected to frigid temperatures and constant shackling. DHS claimed the detainees "included some of the worst of the worst" with criminal histories including assault, weapons offenses, and DUI. However, reporting suggests none may have been convicted of violent crimes. The practice merges ICE's Migrant Operations Center with military detention operations at Gitmo.
HHS Delays COVID-19 Vaccines for Children Through VFC Program
The CDC unexpectedly delayed distribution of seasonal COVID-19 vaccines through the Vaccine for Children (VFC) program, affecting approximately 52% of all U.S. children who are uninsured, underinsured, Medicaid-eligible, or Indigenous. HHS stated it "has not yet finalized procurement decisions" but declined to provide further explanation. The delay contradicts HHS Secretary RFK Jr.'s confirmation hearing pledge to maintain CDC vaccine recommendations without changes.
Russian Strikes Damage Ukrainian Data Centers and Telecom Infrastructure
Russian drone strikes damaged data centers and telecommunications infrastructure in Kyiv, disrupting internet service for approximately 100,000 households. At least four internet providers suffered partial outages. Russia's Defense Ministry claimed it targeted New-Telco and United DC data centers supporting Ukrainian defense and intelligence agencies. Ukrainian Foreign Minister Andrii Sybiha said Russia targeted critical civilian infrastructure essential for delivering missile and drone attack warnings.
Starlink Ground Station Fire in Poland Investigated as Sabotage
A fire at a Starlink ground station in central Poland damaged electrical infrastructure including a switchboard and generator. Polish Digital Affairs Minister Krzysztof Gawkowski said authorities are investigating the incident as possible sabotage with indications the fire was deliberately set. The facility provides satellite internet connectivity across Europe, including Ukraine. Gawkowski described the incident as a possible element of hybrid warfare.
Data Breach Response: Review incident response plans to ensure timely customer notification, loss documentation for claims administration, and cyber insurance adequacy. Recent settlements show documented losses can reach $4,500 per affected customer.
Third-Party Controls: Audit vendor contracts for country-of-origin disclosures and supply chain security attestations, particularly for software handling sensitive data. Implement multi-factor authentication for third-party account origination.
Email Marketing Compliance: Review marketing email subject lines for accuracy under state commercial email laws including Washington CEMA. Ensure CAN-SPAM compliance and verify opt-in procedures.
AI and Behavioral Advertising: Assess whether predictive marketing models target vulnerable populations (addiction, financial distress). Delay deployment of AI agents with credential access until security reviews confirm authentication token protection.
Social Engineering Defense: Implement voice authentication or callback procedures for sensitive phone requests. Train employees to recognize caller ID spoofing and impersonation attacks.