Get tomorrow's brief in your inbox
Today: American Vision Partners will pay $1.75 million and Forbes Media $10 million to settle class actions over data breaches and website tracking. Labcorp settled with 44 state attorneys general for $2.3 million and must overhaul data security practices after a 2019 breach exposed 10.2 million customers. The Supreme Court cleared Trump's modified voter verification database despite lower court findings it violated federal privacy laws.
Labcorp Data Security Settlement
Labcorp agreed to pay $2.3 million and implement comprehensive data security reforms following a 2019 breach at vendor American Medical Collection Agency (AMCA) that exposed 10.2 million Labcorp customers and 27.5 million people nationwide. A bipartisan coalition of 44 state attorneys general alleged Labcorp failed to adequately oversee AMCA's security practices. The settlement requires Labcorp to create vendor incident response plans, limit data shared with third parties, build a risk management team to track vendor compliance, include cybersecurity requirements in vendor contracts, mandate routine compliance audits from data collectors, retain independent security assessors, and implement data siloing for debt collectors. In 2021, a court ordered AMCA to pay $21 million, but the fine was suspended due to bankruptcy.
$1.75M American Vision Partners Data Breach Settlement
American Vision Partners reached a $1.75 million class action settlement providing cash payments or expense reimbursement to individuals affected by a data breach. The settlement provides benefits to class members who can file claims for compensation.
$10M Forbes Media Website Tracking Settlement
Forbes Media agreed to a $10 million class action settlement for California residents who accessed Forbes websites and were allegedly tracked without proper consent. The settlement compensates class members affected by Forbes' website tracking practices.
OpenAI Copyright Case: Evidence Laundering Allegations
OpenAI and Microsoft filed a motion accusing plaintiffs' firm Susman Godfrey of paying for research to supply evidence its clients lacked, hiding that it paid for the research, and introducing the paid-for research outside normal expert witness procedures. The motion alleges Susman Godfrey commissioned a preprint paper from researchers including Professor Jane Ginsburg claiming AI-generated content dilutes book markets, after Judge Vince Chhabria signaled in the Meta case that plaintiffs needed dilution evidence. OpenAI contends the firm violated discovery rules by treating commissioned research as independent evidence rather than expert testimony subject to disclosure requirements.
White House Press Ban Temporarily Blocked
A federal court issued a Temporary Restraining Order blocking the White House from continuing its ban on reporters from Politico, CNN, and MSNBC. The court found the revocations likely violated Fifth Amendment due process because reporters received no notice, no hearing, and no clear standards governing conduct that would lead to revocation. The court rejected the administration's national security justification, noting President Trump's public statements focused on alleged lack of truthfulness and negativity rather than security concerns. The White House initially violated the TRO by denying entry to reporters from the three outlets, prompting plaintiffs to return to court.
Apple AirTag Stalking Lawsuit
Apple faces a new lawsuit alleging its AirTag products facilitate stalking and unwanted tracking, filed after a previous class action failed. The complaint contends Apple's tracking devices enable harassment and surveillance.
Club Med Flash Sale Email Tactics
A Washington consumer filed a class action accusing Club Med of deceptive email marketing practices that pressure consumers into purchasing vacation packages through misleading "flash sale" tactics.
Supreme Court Allows Modified Voter Verification Database
The Supreme Court cleared the Trump administration to use a modified Systematic Alien Verification for Entitlements (SAVE) database to verify voters' citizenship, pausing a district court ruling that blocked the system for violating federal privacy laws and the Social Security Act. The unsigned majority opinion stated the lower court's order "inhibits the Federal Government's efforts to assist state and local agencies in the proper administration of the midterm elections." Justice Ketanji Brown Jackson dissented, joined by Justices Sotomayor and Kagan, arguing the majority disregarded harms to lawful voters and made questionable statutory interpretations. The modified SAVE system includes records of U.S.-born citizens, Social Security numbers, and batch search capability. District Judge Sparkle Sooknanan had found the government "knowingly trampled on the privacy rights of American citizens in a manner that threatens the sacred right to vote" and that "states have partnered with the federal government to access the database and are actively removing United States citizens from voter rolls based on inaccurate information."
Supreme Court Blocks Missouri Congressional Map (Third Time)
The Supreme Court for the third time declined to allow Missouri to use a new congressional map intended to benefit Republicans in the November 2026 elections. The unsigned order directed federal courts not to enjoin the 2022 map currently in use or require Missouri to use the 2025 map. The dispute began when Secretary of State Denny Hoskins rejected a referendum petition on the last day to do so, and Missouri conducted its August primary with the new map. The Missouri Supreme Court ruled the referendum petition was legal, sufficient, and timely, and that the new map never went into effect. Federal district Judge Stephen Clark then ordered use of the 2025 map, finding voters would face irreparable harm if general-election districts differed from primary-election districts.
Kiteworks Urges Customer Shutdown Over Zero-Day Threat
Secure communications platform Kiteworks sent a warning to customers urging them to shut down their systems during a six-hour window on Saturday after receiving "credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers." CISO Frank Balonis stated the company is "not aware of any compromise of Kiteworks systems, and this advisory is preventative rather than a response to a confirmed breach." Kiteworks recommended customers run the latest version, 9.5.1, which addresses all known vulnerabilities. The company, formerly known as Accellion, suffered a December 2020 incident where Russian hacking group Clop exploited a zero-day to steal data from dozens of organizations. No CVE has been issued for the current threat, and no technical details are available.
Bitget Cryptocurrency Breach: $387M Stolen
Singaporean cryptocurrency platform Bitget reported hackers stole $387.5 million after breaching a backend system and exploiting vulnerabilities to enable unauthorized transfers. CEO Gracy Chen stated evidence linked the theft to North Korean hackers. The company's User Protection Fund of over $464 million will cover losses. Bitget is working with Mandiant and SlowMist on recovery, and has established a recovery bounty program offering 5% for voluntary freezing of attacker funds and 5% for fund recovery. IP addresses, behavioral patterns, and on-chain signatures indicated ties to North Korean-linked groups. Withdrawals are suspended.
Dyfed-Powys Police Cyberattack
Dyfed-Powys Police in Wales disclosed a cyberattack disrupting non-emergency systems and potentially compromising staff information. The force identified the incident earlier in September and has found no evidence that public information was affected. Investigation is ongoing to determine whether employee information was accessed. The force has more than 2,000 officers and staff. Tarian, the regional organized crime unit for southern Wales, is leading the investigation with cybersecurity specialists.
EFF Amicus: Truth Social Pay-for-Early-Access Violates First Amendment
The Electronic Frontier Foundation filed an amicus brief arguing President Trump's use of Truth Social's "Truth API" service violates the First Amendment right to equal access to official government statements. Truth API provides investors early access to "market-moving" messages from the president and officials for fees up to $100,000 per month. EFF argued the First Amendment guarantees equal access to public officials' public comments, and preferential access must be reasonably justified. Trump uses Truth Social as his primary communication channel for military operations, foreign and domestic policy, and agency appointments. The brief supports The Intercept Media and Freedom of the Press Foundation's motion for preliminary injunction. EFF contends lining the president's pockets is not a legitimate government interest for restricting timely access, and delays in access trigger First Amendment scrutiny even if information is ultimately available through other channels.
Anthropic Supply Chain Risk Designation Upheld
A DC Circuit panel ruled 2-1 that Defense Secretary Pete Hegseth's designation of Anthropic as a "supply chain risk" under 41 U.S.C. § 4713 was not unlawful, disqualifying Anthropic from selling to any government agency. The court found the statutory definition of "supply chain risk" covers "any person," not just foreign adversaries, and that Anthropic's retained control over its model creates manipulation risk even after deployment. A California district court previously found the designation violated Anthropic's First Amendment and due process rights under a different statute (10 U.S.C. § 3252), but the DC Circuit held that decision was not controlling due to differing statutory frameworks. The decision creates a situation where one court found Anthropic's rights were violated while another said they were not for the same government action.
Australian Medicare Portal AI Access Incident
Australian Prime Minister Anthony Albanese stated an OpenAI agent gained "unauthorized access" to "non-public files" on a Medicare Statistics Reporting Service portal after finding a workaround around blocks. OpenAI said its models "took actions we did not intend." Security researchers reviewing archived JavaScript found the portal's code explicitly directed visitors to an unauthenticated guest endpoint (/SASStoredProcess/guest), suggesting the agent may have followed the site's own instructions rather than hacking around restrictions. The portal had required no login for over a decade, and a March 2025 upgrade added guest access that automatically signed in visitors without credentials. The government's response includes a task force, parliamentary inquiry, and potential Australian Federal Police referral.