According to a new report from Nordlayer, a credential from an employee of a Fortune 500 company is posted on the dark web every 100 seconds. The report states that almost 10 million credentials, which include both usernames and passwords of Fortune 500 employees, have been leaked on the dark web and are presently available to threat actors. And threat actors use them: boy, do they ever! This is the easiest way for threat actors to infiltrate a company network and launch different types of attacks, including the most dreaded: a ransomware attack.

The report notes that 99% of the credentials were stolen from web browsers. Many employees insert and save their usernames and passwords into their work computer browsers, whether the site visited is for personal or business purposes. Threat actors target employees to download malware called an infostealer, and when a victim downloads an infostealer without knowing, the malware is able to copy all of the logins saved in the browser. Bingo! Now they have the credentials to access the company network and have full access to the files and data that the employee has permission rights to access.

Another way threat actors obtain credentials is when a company doesn’t offboard an employee and the credential remains active. If the credential has not been decommissioned and is compromised and available on the dark web, a threat actor has full access to the company network as if the offboarded employee was still working.

What’s the fix? Nordlayer says:

With 6.6 million corporate email addresses in circulation, large organizations should assess how many of their employees’ credentials are already on the dark web and what those logins can still reach.

This is not exclusively a large organization risk. The report shows that “the highest individual rates [of compromised credentials] come from midsize technology companies.” The risk is much higher for companies where most employees hold a corporate email account and save logins in a browser. On the other hand, companies where much of the workforce doesn’t receive a corporate email address, the risk is obviously lower as they do not have credentials to expose.

Credential harvesting and stealing continues to be the easiest way for threat actors to access company networks. The dark web is obviously full of them. Employees need to be counseled on the risks presented, that they should never provide their credentials to anyone who asks, how to change their passwords and phrases frequently, and to be cautious about saving passwords in web browsers. In addition, companies need to be aware of this growing problem, monitor the dark web for company credential leaks, and have a tight process for decommissioning credentials.

A two-minute apartment tour may not sound like the kind of video Congress had in mind when it passed the Video Privacy Protection Act (VPPA) in 1988, but that question was at the heart of the recent oral argument in Banks v. CoStar Realty Info., Inc., No. 25-03320 (8th Cir. argued Sept. 23, 2026).

The VPPA bars a “video tape service provider” from knowingly disclosing, without a consumer’s express consent, personally identifiable information linking the consumer to specific video materials or services. The statute defines covered providers by their business of renting, selling, or delivering prerecorded tapes or similar audiovisual materials, a definition courts are now applying to online video.

The plaintiff, Banks, alleged that CoStar’s delivery of videos through Apartments.com brings it within the statute. The district court dismissed the case, finding CoStar was not a video tape service provider and Banks was not a “consumer.” On appeal, Banks argued that videos are central to CoStar’s business; CoStar responded that it markets real estate and videos are just one promotional option. If offering video is enough, companies that use it as one feature of a broader service could face VPPA exposure.

The judges also questioned whether apartment-tour clips qualify as covered videos and whether online delivery meets the statute’s requirements. Judge David Stras asked whether short clips resemble the movies or video-store rentals contemplated by the VPPA. Banks’s counsel argued that Congress used “video,” not “movie,” and intended the law to keep pace with technology. CoStar, meanwhile, argued that the clips lack the tangible form required by Eighth Circuit precedent. Judge Stras tested that position with a hypothetical: could a video downloaded onto a USB drive qualify? CoStar’s lawyer said no; storing a file on a physical device does not give the file itself a physical existence.

In contrast, the upcoming oral argument in Salazar v. Paramount Global before the U.S. Supreme Court will address a different question: who qualifies as a VPPA “consumer?” Docket No. 25-459, argument scheduled for Oct. 14, 2026. The answer to this question includes whether any purchase or subscription from a video provider is enough, or whether the consumer must have a relationship with its video services. Banks instead asks which businesses and videos the statute covers. Together, the cases could clarify if, and when, the VPPA applies to companies that offer video alongside other services.

A panel of judges sitting on the federal Court of Appeals for the Seventh Circuit appeared skeptical of a challenge to the use of automatic license plate readers by the Illinois state police, questioning whether the cameras’ collection of vehicle snapshots amounts to an improper search under the Fourth Amendment of the U.S. Constitution. Plaintiffs Stephanie Scholl and Frank Bednarz argued that a network of more than 300 cameras near Cook County expressways, combined with 90 days of retained data, lets police reconstruct drivers’ movements without a warrant or probable cause. Plaintiffs argued that compiling a person’s travel over time can reveal more than any single snapshot, and that law-abiding drivers have Fourth Amendment protections. Judge Amy St. Eve, however, questioned whether the plaintiffs’ theory differed meaningfully from circuit precedent involving real-time location tracking.

The government’s attorney countered that the cameras capture license plates at fixed locations on public expressways, and that state law limits both where the cameras may be installed and how the resulting data may be used. The district court dismissed the case, finding the alleged risk of future tracking too abstract to support the requested relief and concluding that the challenged plate reading was not an intrusive search. The federal Department of Justice also supported the state’s position. The Seventh Circuit’s questions suggest that the plaintiffs might face substantial hurdles. However, questions from the bench do not necessarily signal a ruling: we will have to wait until the court releases its formal decision.

Following the hacking incidents of OpenAI agents of Hugging Face, Ruby Gems, and an Australian government website, two suits have been filed against OpenAI.

One suit was filed by not-for-profit Legal Advocates for Safe Science & Technology (LASST), which claimed “that the hack in which OpenAI ‘agents stole credentials, uploaded malicious files, and gained control over key parts of Hugging Face’s internal systems … is unquestionably illegal under California law.’”

The laws which had been allegedly violated include the California Computer Data Access and Fraud Act and the California Unfair Competition Law. In support of its complaint, LASST stated: “OpenAI and frontier AI developers more broadly can’t avoid the consequences of their unsafe actions just by claiming that ‘an AI did it.’ Autonomous AI agents will continue to hack, steal data, disrupt systems, and violate rights until a court steps in.”

OpenAI is vigorously defending the suit and stated that “it published a technical report and other information about ‘third-party impact from misaligned models,’ slowed development of its AI, and held back the release of a model that doesn’t meet its safety standards.”

OpenAI’s legal battles continue with a second suit filed by Florida Attorney General James Uthmeier against OpenAI and its CEO Sam Altman this week. The suit requests a temporary injunction to stop OpenAI “from harming Floridians with your reckless, unacceptably risky product.”

The suit requests that “Defendants should be enjoined from developing new artificial intelligence models without third-party approved safety guardrails.” In support of its motion, the AG cites the Hugging Face hack, the Ruby Gems hack, and the hack of an Australian governmental website that contained health information. In addition, the suit notes that, as of September 25, 2026, the number of hacks by OpenAI agents:

rose to several dozen, including attempted hacks of the U.S. Department of Commerce and the Securities and Exchange Commission—all without the Defendants’ knowledge. Another incident surfaced the same day, revealing that OpenAI agents leaked images from ChatGPT users and posted them online.

The suit further alleges that “On September 27, 2026, it was discovered that Defendants and their competitors were investigating tens of thousands of instances of their AI products ‘bypassing guardrails, creating message boards, escaping sandboxes, website hijacking, [and] self-prompting or seeking to bypass monitors.’”

The suit requests that OpenAI be enjoined from:

  • further development of AI tools without guardrails;
  • falsely advertising ChatGPT as safe, accurate, or reliable;
  • giving ChatGPT false human attributes;
  • offering ChatGPT to minors in Florida;
  • collecting and processing data from minors under the age of 13 in Florida;
  • Misrepresenting ChatGPT’s safety, reliability, and accuracy; or
  • failing to warn that ChatGPT is unsafe, unreliable, and inaccurate.

We suspect that more state Attorneys General are watching the Florida suit and may follow its lead.

One hack that didn’t make the Florida AG’s suit is that OpenAI agents attempted to brute force the United Nations’ website API fields and launched over 16,500 scans “using proxies, obfuscation, and Google’s XSS game.”

I suspect that more of these alarming incidents will surface in the coming weeks.

Consumer AI agents are software tools designed to do more than answer questions. They can break a request into steps, use external tools and apps, and carry out tasks such as comparing products, managing digital workflows, or booking travel. Some can also work in the background on repetitive tasks. That added autonomy may make agents more useful, but it also raises the stakes: to act on a user’s behalf, an agent may need access to personal information, accounts, or payment details, along with permission to make decisions or purchases.

AI companies are betting that agents will become the next everyday interface. But curiosity about products such as Meta’s Muse does not necessarily translate into routine use, or a willingness to give an agent access to one’s digital life. The Pew Research Center found that 51% of Americans had avoided AI chatbots, citing privacy concerns as a leading reason. Surveys cited in recent coverage also suggest reluctance to let agents read emails, rebook travel, move money, or shop independently.

For companies building or deploying agents, the question is not only what technology can do, but whether it solves problems people want solved. Adoption appears concentrated among higher-income, highly educated, and white-collar users, while many people place greater value on relationships, exercise, cooking, time outdoors, and spirituality than on using AI tools. That gap is a reason to test products against real user needs, and to explain what information an agent can access, what actions it can take, and how people can review, limit, or stop those actions. An agent may be transformative for some tasks, but broader adoption will depend in part on whether people trust it with the keys to their digital lives.

To read the full report click here.

The Health Information Sharing and Analysis Center (ISAC) recently warned that ShinyHunters is using voice-phishing attacks to target the healthcare sector. “The hackers used medical-themed impersonation domains to trick healthcare employees into exposing their credentials.” More than a dozen organizations have been hit by these social-engineering attacks.

Health ISAC recommends:

  • Employee Training and Awareness: Implement targeted security awareness training that educates staff on modern social engineering tactics, such as aggressive vishing calls and voicemail lures, ensuring they understand how to identify look-alike domains and safely verify internal IT communications.
  • Enforce Device-Context Verification: Restrict SaaS applications, internal portals, and APIs to corporate-managed devices verified via client certificates, EDR health checks, or MDM profiles. Identity verification alone is insufficient without a defense-in-depth architecture.
  • Transition to Phishing-Resistant MFA: Prefer FIDO2/WebAuthn security keys or passkeys for all admins and high-risk groups, and disable or tightly restrict SMS/voice MFA and weak fallback methods.
  • Harden Helpdesk & MFA Reset Workflows: Require strict identity verification for MFA resets and ensure employees are trained that IT will “not reset MFA on inbound calls”.
  • Monitor Lookalike Infrastructure: Track lookalike domain registrations, newly observed domains (NODs), and branded subdomains targeting corporate single sign-on services.
  • Session Management: Set session timeouts that effectively support user workflows while ensuring security, restrict IdP visibility for non-compliance.

ShinyHunters continues to be a dangerous threat, and it is escalating its efforts in the healthcare sector, while simultaneously boldly attacking the FBI. Implementing the recommendations above should be a priority as it continues to ramp up its attack vectors.

Ransomware gang ShinyHunters boldly attacked the FBI this week, alleging that it hacked into the FBI’s job site, defaced it, then stole sensitive records of employees and applicants, including human resources records of current employees.

The gang alleges that it exploited a vulnerability in Oracle’s PeopleSoft product that enabled remote code execution allowing them to download between two and three terabytes of data. The group released a sampling of the data to journalists, including FBI employees’ names, home addresses, telephone numbers, Social Security numbers, assignments, dates of birth, and details about relatives.

ShinyHunters says it attacked the FBI following an FBI cyber alert published in May that the gang alleges made false statements.

While ShinyHunters’ claims have not been verified, picking a fight with the agency that is responsible for prosecuting cyber crime is surely an escalation that the FBI will no doubt respond to in kind.

Those using Oracle’s PeopleSoft are urged to update the software with patches when they become available.

This post was authored by Business Litigation group partner Eric Del Pozo.

In United States v. Alisigwe, No. 24-960 (2d Cir. Sept. 17, 2026), a divided Second Circuit held that border agents may conduct searches of international travelers’ cellphones without a judicial warrant, reasonable suspicion of criminal activity, or any individualized justification. This decision should be of interest to anyone planning to enter (or reenter) the United States via New York, Connecticut, or Vermont, whether for business or personal reasons, with a smartphone, tablet, or laptop.

Whereas many international travelers rack up sky miles, the defendant Alisigwe racked up airport searches. In 2018, the United States government began criminally investigating Alisigwe, from whom British border authorities had seized a fraudulent passport. In 2019, upon his arrival at JFK International Airport, federal agents pulled Alisigwe aside, interviewed him, scrolled through his cellphone, and found other people’s names, birthdates, and social security numbers. In 2021, federal agents again stopped Alisigwe upon arrival at JFK Airport, and again scrolled through his cellphone, this time viewing an incriminating communication. On both occasions, he was released into the country.

Later indicted on charges of bank fraud, money laundering, and identity theft, Alisigwe moved to suppress (or prohibit) the cellphone-derived evidence from being introduced at his trial. The district court denied the motion because the presence of reasonable suspicion that Alisigwe was engaged in criminal activity permitted the border agents to examine his phone. On appeal, the Second Circuit agreed that the evidence was admissible, but disagreed that the officers needed any independent justification to search the cellphone of someone entering the country.

Writing for the majority, Judge Steven Menashi highlighted that existing precedent distinguished between searches at the border, including at an airport, that are deemed “routine” (such as those of a traveler’s luggage or personal belongings) and those that are more invasive and “nonroutine” (such as strip searches or involuntary x-rays). While the Fourth Amendment allows the former without a warrant, or any objective level of suspicion, the latter demands at least reasonable suspicion that the prospective entrant has committed a crime.

Essentially likening a smartphone to a digital suitcase, the panel held that “the search of a traveler’s property at the border—including a cellphone—is a routine search that the government may conduct without suspicion.” It expressly limited Riley v. California, 573 U.S. 373 (2014), which generally required a warrant to search a suspect’s smartphone incident to an arrest, to that specific context. The panel reasoned that border searches of travelers, by contrast, implicate diminished privacy interests and promote the sovereign’s right to determine “who and what may enter the country.”

Concurring in the result only, Judge Eunice Lee would have upheld the admission of the cellphone evidence as deriving from a nonroutine border search supported by reasonable suspicion. Judge Lee wrote that, from a privacy standpoint, an “unrestricted and suspicionless search of a cellphone is intrusive enough to warrant greater protection than the majority gives it today—which is none.” She would not endorse officers’ rummaging “with no suspicion and for any reason” through what is “perhaps the single most comprehensive, sensitive and closely-guarded repository of a person’s private information and data.” As support for these ideas, the concurring opinion relied on Riley and United States v. Carpenter, 585 U.S. 296 (2018)—the latter generally requiring a warrant before officers may access cell site location data to chronicle a phone user’s historical movements.

In this author’s view, any analogy to Carpenter goes only so far: a border search focuses on an individual’s being in a single, known place. But Riley presents a much closer call: the Court there rooted the warrant requirement in the sheer breadth of personal information that the average smartphone contains, as well as their ubiquity. Memorably, the Riley Court wrote that a smartphone could be mistaken for “an important feature of human anatomy.” And today’s phone fits more than any suitcase ever could.

However, important questions remain. After Alisigwe, may border agents, lacking an independent justification, permissibly download the entire contents of a smartphone or laptop that someone brings into the country? And if one person’s whole device were fair game, could agents download the entirety of every device passing through the international arrivals terminal, for mass querying? The Second Circuit’s decision appears to reserve judgment on these questions. Three times, the majority emphasized that the agents had not used sophisticated forensic search methods or extracted the cellphone’s whole contents.

As things stand, travelers entering the United States through New York, Connecticut, or Vermont should assume that information accessible on their devices may be subject to federal inspection. Organizations whose executives or employees travel internationally should thus review their internal protocols to minimize the potential exposure of privileged communications, company secrets, customer data, or other sensitive information. In addition, organizations should ensure that any relevant policies are clearly communicated and, insofar as possible, actually followed.

Chatbots and AI-powered customer service tools are no longer limited to technology companies. Businesses across industries are using AI to answer customer questions, summarize conversations, provide recommendations, and help users complete transactions. These tools can offer real value, but they also introduce legal and operational considerations that may not arise with a traditional website feature. Before deployment, a business should understand what information the tool collects, where that information goes, how long it is retained, and whether the vendor may use customer interactions to train or improve its models. The analysis becomes especially important if customers might share personal, confidential, financial, health, or other sensitive information.

Transparency and appropriate guardrails are equally important. Customers should understand when they are interacting with AI, whether their conversations are being recorded or analyzed, and what the tool can and cannot do on their behalf. Depending on the business, its customers, and their locations, privacy, consumer protection, AI transparency, and recording-consent laws may apply. Businesses should also decide who will monitor the tool’s responses, how mistakes will be addressed, what happens when sensitive information is submitted, and when a conversation should be escalated to a person.

Existing website documents may need attention as well. A privacy policy drafted before the adoption of AI may no longer accurately describe the company’s data practices, while website terms may need to address the chatbot’s role, the limitations of its responses, prohibited uses, and circumstances in which users should seek human assistance. The goal is not to discourage businesses from adopting useful AI tools, but to pair adoption with basic diligence: map the data flows, review vendor terms, establish clear limits, provide appropriate disclosures, and update relevant policies. AI may be new, but the foundation remains familiar: know your technology, know your data, communicate clearly, and put practical safeguards in place before problems arise.

Last week, a federal District Court judge largely rejected Anthropic’s demurrer to Reddit’s suit accusing it of improperly gathering user content to train its AI model Claude. Reddit, Inc. v. Anthropic PBC, No. 3:25-cv-05643 (N.D. Cal. Sept. 19, 2026).  In the 2025 lawsuit, Reddit accused Anthropic of breach of contract, interference with contract, and unfair competition when it learned that Claude was scraping content, including user data, off Reddit’s platform to help train the model.  Reddit specifically asserted that Anthropic’s scraping violated Reddit’s user agreement, and that Anthropic, unlike Google and OpenAI, did not enter into a licensing agreement with Reddit before using its content.

Anthropic argued that federal copyright law preempted Reddit’s state-law claims and that they were copyright claims in disguise. The judge largely disagreed, holding that the contract, interference, and unfair competition claims each required an extra element beyond unauthorized copying and involved substantial state interests outside the Copyright Act. The judge also held that Reddit adequately alleged intentional interference by claiming that Anthropic continued scraping after being told it lacked permission. Finally, Claude’s own admission that it did not know if Reddit user data scraped for training was deleted was used as evidence that Reddit had sufficiently alleged the interference claim.  Anthropic did score a partial win regarding Reddit’s unjust-enrichment and trespass-to-chattels claims, but the court gave Reddit an opportunity to amend them.

The case is still pending, so the ruling does not decide whether Anthropic is ultimately liable.  Still, it is a useful reminder that well-drafted user agreements, terms of service, and licensing terms may give website operators claims that go beyond copyright law. Companies looking to protect their users’ content and data should clearly address automated scraping, AI-training uses, deletion obligations, and licensing requirements. Clear rules may not stop every scraper, but they can put a company in a much stronger position if a dispute ends up in court. They should also consider reasonable technical controls and consistent enforcement practices.