Following the coordinated attack against 30 Minnesota water and wastewater utilities from July 26-27, 2026, hackers have attacked at least 11 other state water systems in the last week. As of July 30, 2026, the Federal Bureau of Investigation (FBI) confirmed that at least seven states were affected and issued an alert detailing the hackers’ actions and their impact on water and wastewater systems.

Shortly thereafter, both Georgia and Michigan confirmed that they were targeted and experienced “hostile cyber activity,” including nine systems in Michigan, though both states reported no operational disruption or public health concern.

As of today, it is being reported that “at least 12 states have been hit.” In addition to Minnesota, Michigan, and Georgia, a water system in South Dakota reported a cyberattack “that appears to be part of the same campaign.”

In addition to alerts issued by the FBI and the Cybersecurity and Infrastructure Security Agency, Infracritical published a detailed report on the Minnesota attack and—to  a lesser extent—Michigan, including the attack overview and vector, threat actor profile, and the public health risk to residents as a result of the attack happening during a regional heat event. The report notes that, for the first time confirmed in U.S. water sector history, “at least one utility experienced flooding as a direct result of PLC manipulation — the first cyber-caused flooding event documented in U.S. water infrastructure. This indicates adversary willingness to cause physical infrastructure damage, not merely access loss or service interruption.”

The report provides a statewide hardening roadmap that state utility operators should consider in the face of this ongoing threat by foreign adversaries.

The fact that the hackers of 12 statewide water systems did not think twice about damaging physical infrastructure is a wake-up call that our water, electrical, and financial systems must be hardened against these new cyber warfare threats for national security.

A recent decision from a federal district court in Virginia adds to the growing body of Telephone Consumer Protection Act (TCPA) litigation over whether its “Do Not Call” protections apply to marketing texts sent to cell phones. In McGonigle v. Dickey’s Barbecue Restaurants, Inc., No. 1:25-cv-01062, 2026 WL 2114507 (E.D. Va. July 22, 2026), the plaintiff alleged that he received unsolicited promotional text messages from Dickey’s after registering his cell phone number on the National Do Not Call Registry.

Dickey’s moved to dismiss, arguing that the TCPA’s Do Not Call provisions apply only to “residential” telephones and that a cell phone does not qualify. On July 22, the court rejected that argument, holding that a cell phone may plausibly be treated as residential for TCPA purposes when it is used primarily for personal, household purposes. The court also explained that this approach was consistent with the TCPA’s regulations and the FCC’s interpretation of them. In particular, the court noted that the relevant FCC regulations apply to entities making telephone solicitations or telemarketing calls to wireless telephones, and that the FCC has recognized that many consumers no longer maintain landlines and instead rely only on wireless service. The court quoted the FCC’s view that allowing wireless subscribers to receive the full range of TCPA protections is “more consistent with the overall intent of the TCPA.”

The court then held that the allegations in the plaintiff’s complaint were sufficient to avoid dismissal at the pleading stage. The complaint alleged that the plaintiff’s phone number was his only phone number, that he used it to communicate with friends and family, schedule personal appointments, and conduct household-related activities, and that he did not use it for business or commercial purposes. The court found those allegations sufficient to plead that the phone was used residentially.

However, Dickey’s did obtain a partial win. The court dismissed the request for treble damages, holding that the complaint did not include enough factual allegations that Dickey’s willfully, or knowingly, violated the TCPA. The court otherwise denied the motion to dismiss and declined to strike the class allegations at this early stage.

The decision addresses one recurring TCPA issue—whether a cell phone can be a residential telephone—but leaves another developing issue largely untouched: whether text messages qualify as “telephone calls” under the TCPA’s Do Not Call private right of action. For now, the case is a reminder that TCPA Do Not Call claims involving text messages may survive early motion practice when the complaint pleads personal, residential use of the number with enough detail.

Recent privacy litigation against Shopify and the NBA highlights a shared theme: companies may face risk not only for what their websites say about privacy choices, but for how embedded technologies actually collect data behind the scenes.

In the Shopify case, a California federal court refused to dismiss claims alleging that Shopify collected California consumers’ personal, payment, location, and browsing information through its checkout technology without adequate notice or consent, then used that information to build consumer profiles. The court found the plaintiff plausibly alleged that Shopify knowingly designed its system to collect the data at issue, relying on Shopify’s prior disclosures, order-confirmation emails, hosted product images, archived page source information, and Shopify-linked URLs in the merchant checkout flow.

The ruling followed a major Ninth Circuit decision reviving the case on personal jurisdiction grounds, with the court finding that Shopify’s alleged use of geolocation technology supported California-specific contacts because Shopify could know when a consumer’s device was in California. See Briskin v. Shopify, Inc., 135 F.4th 739 (9th Cir. 2025) (en banc) (personal jurisdiction); see also Briskin v. Shopify, Inc., No. 4:20-cv-06940-PJH (N.D. Cal.) (post-remand order addressing statutory and privacy claims).

The NBA case raises a related but distinct issue about whether privacy banners and cookie opt-outs actually stop the tracking they appear to control. Yee v. NBA Props., Inc., No. 4:26-cv-07919 (N.D. Cal. removed July 29, 2026). The proposed class action alleges that visitors to nba.com are tracked by tools from Google, Amplitude, and others when they browse schedules, tickets, player information, game highlights, and related content.

According to the complaint, these tools collect user activity and identifying information for advertising, marketing, analytics, and cross-platform tracking purposes. The plaintiff’s main theory is that the NBA’s cookie opt-out banner gives users a false sense of control because trackers allegedly deploy as soon as a user lands on the site before privacy preferences can be selected and because technologies such as session recording, canvas fingerprinting, pixels, and other scripts may continue operating even after a user opts out of cookies.

The complaint brings claims under statutes and legal theories including the California Invasion of Privacy Act, the federal Wiretap Act, California’s Computer Data Access and Fraud Act, the California Constitution’s privacy provision, and California’s Unfair Competition Law.

Together, the cases are a reminder that checkout flows, pixels, cookies, SDKs, hosted content, session replay, analytics tags, and embedded vendor tools should be treated as part of the privacy compliance perimeter, not as invisible background infrastructure.

Businesses should understand what each technology collects, when it fires, where the user is located, whether collection begins before notice or choice, and whether opt-out or consent signals fundamentally change website behavior. They should also review privacy notices, consent-management settings, tag deployment rules, vendor configurations, and historical records together, because plaintiffs are increasingly focused on the gap between user-facing privacy promises and technical reality. In this environment, a cookie banner is not a universal fix; it is only as defensible as the data flows and controls behind it.

AI-enabled mental health tools are moving quickly from novelty to mainstream use, and regulators are starting to draw sharper lines around what those tools can and cannot claim to do. Recent lawsuits against Character Technologies Inc.,  the company behind Character.ai, allege that the platform hosted bots that mimicked licensed therapists, including one persona that allegedly claimed fictional professional credentials and engaged in tens of thousands of patient interactions. The litigation comes amid growing AI chatbot use for mental health advice, particularly among adolescents and young adults, and follows reports of serious safety concerns involving minors and crisis-related conversations.

In the absence of a comprehensive federal framework, states are filling the gap. Colorado, Maine, Rhode Island, Tennessee, and Vermont have advanced AI therapy restrictions, joining Illinois, Nevada, and Utah. These laws vary in scope, but the emerging themes are clear: restrictions on advertising AI as a licensed mental health professional, limits on direct patient engagement by AI tools in clinical settings, and greater scrutiny of chatbots used by, or marketed to, children. At the same time, regulators and clinicians are distinguishing between general-purpose chatbots that users may treat as “pocket therapists” and more purpose-built digital therapeutics designed with clinical guardrails and therapeutic datasets.

For companies developing or deploying AI tools in health, wellness, youth engagement, or consumer support, this is a moment to reassess product design, marketing claims, age-gating, crisis escalation, disclaimers, professional oversight, and state-by-state compliance obligations. Disclaimers alone may not be enough if a bot’s persona, outputs, or user experience suggests professional diagnosis, treatment, or therapy. The Federal Food and Drug Administration has not yet authorized generative AI tools for mental health treatment, and professional groups are urging Congress and federal agencies to set clearer standards. Until that happens, companies should expect continued litigation risk, a growing patchwork of state laws, and closer attention from regulators where AI systems appear to provide mental health advice without appropriate clinical controls.

A new California federal lawsuit against AI notetaking provider Granola highlights a growing privacy risk for companies using meeting transcription tools: consent cannot be an afterthought. According to the complaint, Granola’s software allegedly recorded a virtual meeting participant without giving notice that an AI notetaker was present or seeking permission to record. The plaintiff claims this differs from other AI transcription tools that visibly join meetings, announce their presence, or give participants the ability to remove the notetaker. The suit also alleges that Granola used meeting contents by default for commercial purposes, including training AI systems, unless the Granola user turned that setting off.

The case combines several legal theories that have become increasingly common in privacy litigation involving recording and tracking technologies, including claims under the federal Electronic Communications Privacy Act, the California Invasion of Privacy Act, California’s confidential communications statute, common law invasion of privacy, and California’s computer access statute. While the allegations remain unproven, they reflect a key plaintiff-side theory that when a company designs technology to capture communications without clear notice to everyone involved, especially in a two-party consent state like California, privacy and wiretapping claims may follow.

For businesses deploying AI notetakers, meeting bots, transcription tools, or other AI-enabled collaboration products, the takeaway is straightforward: build consent and transparency into the workflow. Companies should review whether meeting participants receive clear notice before recording begins, whether consent is obtained from all required parties, whether participants can object or opt out, and whether meeting data is used for model training or other secondary purposes by default. As AI tools become more embedded in ordinary business communications, the privacy controls around them need to be just as visible as the productivity benefits.

The families of four teenagers who died by suicide recently sued Meta, TikTok, Snapchat, and YouTube, alleging that the teenagers’ use of the platforms over many years was addicting, and caused sleep deprivation, depression, anxiety, and suicidal ideation. The teenagers committed suicide at the ages of 13, 14, 17, and 18, respectively. 

These are not the first suits filed against social media platforms, but they have not made an impact on continued use by children and teens.

Research shows that spending more than three hours a day on social media platforms doubles teenage depression and anxiety risk. According to the Child Mind Institute, “kids are growing up with more anxiety and less self-esteem” because of  social media use. This is not solely related to the overuse of social media, just the use.

The social media companies maintain that monitoring children’s and teens’ use of their platforms is the parents’ sole responsibility. At the same time, the debate continues as a growing body of research suggests that platform algorithms may encourage compulsive or addictive behavior. Many parents report feeling overwhelmed by the challenge, struggling to counter the influence of technologies designed to maximize user engagement.

That said, as these claims and defenses weave their way through the cumbersome legal system, there are practical steps parents can take to help manage their children’s social media use, including utilizing parental controls and other safety features available on many platforms.

Here are a few additional resources:

https://www.aacap.org/AACAP/Families_and_Youth/Facts_for_Families/FFF-Guide/Children-And-Watching-TV-054.aspx

https://www.strong4life.com/en/parenting/screen-time/digital-detox-how-to-limit-screen-time-for-kids

https://support.apple.com/en-us/105121

In addition, the Federal Trade Commission has launched Youville, a tool designed to teach kids about online safety skills beyond limiting screen time. It provides activity sheets, discussion topics, and arts and crafts projects designed to teach kids about safe online activities. Parents and caregivers should be aware of the risks social media can pose to children’s mental health and behavior. They can play an important role in limiting screen time, teaching safe  and responsible online habits, and fostering healthy digital boundaries to reduce potential risks to their children and families.

Parents and caregivers should be aware of the risks social media can pose to children’s mental health and behavior. They can play an important role in limiting screen time, teaching safe and responsible online habits, and fostering healthy digital boundaries to reduce potential risks to their children and families

Over 30 individual Minnesota water and wastewater treatment facilities were simultaneously hit with a cyber-attack from an unknown source on July 26 and 27, 2026. The coordinated attack targeted the utilities’ operational technology systems and caused some affected communities to request that residents minimize water use due to limited stored water. Other communities experienced equipment malfunctions requiring them to implement contingency plans and switch to manual operations.

The Minnesota IT Services agency activated its incident response plan statewide in response to the attack. Although the attacker is unknown, there is speculation that it may be attributable to Iran-backed hackers in response to attacks on a southern Iranian water treatment plant.

Australia and the U.S. Cybersecurity & Infrastructure Security Agency (CISA) issued guidance on July 28, 2026, for critical infrastructure operators to isolate vital systems during cyber attacks “or periods of increased cyber threat.” CISA has been warning critical infrastructure operators about increased threats from Iranian-affiliated cyber actors repeatedly since the war in Iran commenced.

The fact that the threat actors coordinated this attack to affect multiple utilities across an entire state is rather frightening. Critical infrastructure operators should stay informed of the CISA issued guidance and take the warnings seriously.

Sony smart TV owners have voluntarily dropped their proposed class action against Samba TV, an analytics company accused of collecting and selling television-viewing information to third-party advertisers in violation of state and federal privacy laws. DellaSalla v. Samba TV, Inc., No. 3:25-cv-03470 (N.D. Cal. 7/23/26).The dismissal came after the federal court had already allowed several claims to proceed, including intrusion upon seclusion, unjust enrichment, and claims under the Federal Wiretap Act and the California Invasion of Privacy Act (CIPA).

The plaintiffs alleged that Samba TV technology embedded in Sony televisions intercepted unique identifiers associated with their TVs and private video-viewing data without consent. Earlier in the case, District Court Judge Jacqueline Scott Corley found that allegations that Samba TV collected and sold detailed video-viewing information tied to political leanings and other private characteristics were enough to establish federal standing.

Even though this case has been dropped, the court’s earlier ruling remains important regarding the privacy risks connected device data, viewing data, device identifiers, ad-tech integrations, and inferred sensitive attributes can present when companies do not have clear consent flows, accurate disclosures, and tight controls over third-party data sharing. Companies using smart-device analytics, pixels, SDKs, automatic content recognition, or cross-device advertising tools should review what data is collected, whether it is linked to households or individuals, how consent is obtained, and whether vendor contracts and public disclosures match the technical reality.

On July 20, 2026, Pennsylvania Governor Josh Shapiro signed SB 992, updating and expanding Pennsylvania’s Telemarketer Registration Act of 1996 and strengthening restrictions on unwanted telemarketing communications. The law reflects that telemarketing is no longer limited to live calls and that texts, prerecorded messages, and other automated tools are increasingly reaching consumers and businesses .

The bill broadens “telephone solicitation” to cover traditional calls, voicemails, ringless voicemails, and text messages sent to residential, business, or wireless subscribers for sales-solicitation purposes or to obtain information for a future solicitation. It also expands who may qualify as a “telemarketer” to include persons or businesses that initiate or receive calls or messages involving Pennsylvania subscribers, and updates “robocall” to include certain automated solicitations using prerecorded or artificial voice calls or messages.

The law also creates a prior express written consent framework for robocalls and text messages. That consent must be documented in a written agreement that identifies the number that may be contacted, clearly discloses the consumer’s agreement to receive solicitations, states that consent is not required as a condition of purchase, and is signed electronically or otherwise. Subject to certain exceptions, SB 992 prohibits robocalls to residential, business, or wireless lines without that consent.

The bill also adds operational restrictions as well. Telemarketers may not place telephone solicitations on Sundays, legal holidays, before 9 a.m., or after 7 p.m. They also must promptly identify the call’s purpose, the telemarketer or telemarketing business, and, if applicable, the offer. For text solicitations, recipients may opt out by replying with terms such as “STOP” or “UNSUBSCRIBE.”

The law extends do-not-call protections to business and wireless subscribers and requires telemarketers to obtain applicable Pennsylvania do-not-call listings quarterly or use a service provider that does so. It also targets deceptive technology use, including improper consent practices and synthetic or computer-generated messaging that defrauds, deceives, or misleads recipients.

Violations may carry civil penalties of up to $1,000, or up to $3,000 if the person contacted is age 60 or older. Although the new law does not take effect until October, businesses using outbound calls, texts, prerecorded messages, ringless voicemail, or telemarketing vendors should review consent language, opt-out processes, suppression-list practices, and vendor oversight for Pennsylvania-directed telemarketing activity.

The White House is moving closer to a voluntary framework under which AI companies would submit their most advanced models to the federal government before public release. The White House’s Office of the National Cyber Director reportedly circulated the draft framework by to OpenAI, Anthropic, and Google, and those companies jointly submitted edits. Although the review process details are not yet public, the continued federal interest in pre-release review of frontier AI models follows earlier discussion of a possible FINRA-like watchdog for advanced AI systems. 

For businesses, the key takeaway is that voluntary AI governance is increasingly becoming a practical expectation, even where formal legal mandates remain unsettled. Companies developing, deploying, or procuring AI tools should be prepared to document model governance, risk assessment, testing, security controls, data provenance, privacy considerations, and human oversight in a way that can stand up to regulator, customer, investor, and board scrutiny. Even if the initial federal framework applies most directly to major AI model developers, downstream users should expect those norms to flow through vendor diligence, contract terms, audit rights, procurement questionnaires, and enterprise AI policies.

Business clients should use this moment to get their AI governance house in order: inventory AI systems and vendors, classify higher-risk use cases, update privacy and security reviews for AI-enabled tools, and build clear internal approval processes before rolling out new tools . For companies buying AI products, contracts should address testing, transparency, cybersecurity, data use restrictions, confidentiality, model training rights, regulatory cooperation, incident notice, and responsibility allocation if the tool produces harmful or noncompliant outputs. The practical step now is not to wait for a final federal rule, but to establish a defensible governance record that reflects a thoughtful assessment of risks, sound decision-making processes, and clear oversight and explanations of AI system management.