Ransomware group ShinyHunters alleges on its online platform that it has compromised the Florida Department of Motor Vehicles’ Driver and Vehicle Information Database (DAVID) and stole the DMV records of over 200,000 individuals. The threat actor posted a screenshot of Jeffrey Epstein’s DMV record as proof.

The DAVID records of drivers include their name, address, Social Security number, birthdate, driver’s license ID, and other information. ShinyHunters told BleepingComputer they “breached DAVID through a password-reset flaw that let them compromise multiple accounts in the system. These accounts allegedly belonged to DMV employees and an FBI agent.” ShinyHunters no longer has access to the database and the “password-reset flaw used to compromise accounts is being patched.”

It is believed that ShinyHunters is “targeting other states’ DMV platforms using social engineering attacks.”This is a common strategy for ransomware groups—to concentrate on a particular industry and when they find a way to get into one, they use the same technique to attack others in the same industry.

State DMVs hold vast amounts of valuable personal information. State agencies should train their employees about social engineering attacks, how to identify them, and put robust security measures in place to protect this valuable information of its residents.

On August 26, 2026, LexisNexis won an important, but limited, victory in a proposed class action: a federal court refused to certify a class of people seeking damages for the company’s response to privacy requests which violated the Fair Credit Reporting Act (FCRA). The court did not decide whether LexisNexis had violated the FCRA, only deciding that the plaintiffs could not pursue their claims as the proposed class.

The facts began with Daniel’s Law, a New Jersey statute that protects the home addresses and personal telephone numbers of judges, prosecutors, police officers, certain other public officials, and their immediate family members. Covered individuals may ask a business to stop disclosing that information, and the business generally has ten days to comply.

Beginning in December 2023, thousands of covered individuals allegedly sent LexisNexis written requests to suppress their protected information. According to the plaintiffs, these were straightforward privacy requests, not requests to freeze their consumer files. Nevertheless, LexisNexis reportedly placed security freezes on approximately 18,607 files, maintaining that it could not redact the protected information from consumer reports without doing so.

Because a security freeze restricts access to a consumer report, it can affect banks, insurers, and others evaluating whether to provide credit or services. As a result, the plaintiffs alleged that the unrequested freezes violated the FCRA. However, their effort to proceed as a class ran into a proof problem. The record showed only 13 people had been denied insurance because of the freezes. For everyone else, the court would have needed individualized evidence showing that the person sought credit or services, the freeze blocked access to necessary information, and the blockage caused a denial. Those individual questions defeated the broader class, while a 13-person subclass was too small to satisfy Rule 23’s numerosity requirement.

For companies responding to statutory privacy requests, the decision illustrates how a request directed at specific information can implicate a broader consumer-reporting process. LexisNexis maintained that it could not remove the protected information from its consumer reports without placing a security freeze, and the court did not decide whether that approach violates the FCRA. The takeaway is less about prescribing a particular response and more about understanding how privacy workflows operate across connected systems. Companies should assess whether the mechanism used to honor a request changes access to a consumer report or related service and remember that a narrow request does not always have narrow effects.

California Senate Bill 690 is finally moving forward. The original bill would have broadly exempted disclosures made for a “commercial business purpose,” as defined under the California Consumer Privacy Act (CCPA), potentially eliminating many California Invasion of Privacy Act (CIPA) claims involving common website technologies. The amended version is narrower but could still offer meaningful relief to businesses facing the recent wave of CIPA litigation.

Under the amended bill, private plaintiffs could no longer bring claims under California Penal Code § 638.51 alleging that conduct on websites or online or mobile applications constitutes the unlawful use of a pen register or trap and trace device. Those claims could be brought only by the California Attorney General. The change would apply retroactively to certain pending lawsuits filed within the two years prior to the bill’s operative date. Plaintiffs could still pursue claims under § 631(a), although businesses often have stronger defenses to those claims, including consent and arguments that the information collected was not communication “content” or was not intercepted “in transit.”

SB 690 was approved unanimously by both the Assembly and Senate and has been sent to the Governor’s desk for signature, which must be completed by September 30, 2026. If enacted, it would take effect January 1, 2027. While it would not end CIPA website-tracking litigation, the bill signals legislative support for curbing private lawsuits based on increasingly common pen register and trap and trace theories. Businesses should continue monitoring the bill while reviewing their online tracking technologies, consent mechanisms, disclosures, and vendor relationships.

A recent article released by the Palo Alto Threat Research Center found that, between January and April 2026, a coordinated effort by threat actors was successful in launching vishing attacks using Microsoft Teams accounts to compromise companies across multiple industries.

The threat actor uses an external Teams account and creates a chat “using identities designed to mirror legitimate internal support units.” Usually these include names like help desk, IT support, or something else that makes the user believe the chat is coming from an internal IT support professional. The chat has a sense of urgency that something needs to be done on the user’s computer. The threat actors then call the victim and, if the user picks up, the scam commences. The threat actor then guides the employee through steps to allow remote control or to download malicious malware. If the caller doesn’t pick up, the threat actor calls back multiple times, scaring the user into believing it is urgent.

Once in the system, the threat actor has full control over the user’s access and can exfiltrate data, deploy ransomware, and start a ransomware attack.

Palo Alto has dubbed this attack as “Spring Ring.” It found that between January and April 2026, Spring Ring targeted many organizations across different industries, and more than 150 individual employees were called. In addition, this coordinated attack shows that threat actors are using legitimate tools to lull victims into believing the chats and calls are real.

It is crucial to be aware of the evolving nature of threats, including social engineering and the rise of vishing attacks, to understand that threat actors are using legitimate tools and to distrust any request for remote access to your computer. When in doubt, ignore the chat, and call your IT professional directly to a known number. If IT is really trying to get in touch with you, they will be very happy that you are calling them directly rather than falling victim to a vishing scheme.

The Enforcement Bureau of the FCC recently issued a Notification of Suspected Illegal Traffic to RGTN USA Inc. (RGTN) for “transmitting apparently illegal calls originating from abroad, including spoofed calls, fraudulent robocalls, and calls conveying false emergencies.”

Vishing attacks have increased over the past year and have been surprisingly successful. (To learn more about the threat, check these previous articles.) To combat this growing problem, it is heartening to see the FCC Enforcement Bureau take action.

On August 24, 2026, the FCC issued a notice letter to RGTN alleging that the transmission of illegal traffic from abroad where RGTN served as the gateway provider:

has taken several forms, each directed at defrauding victims: spoofed[] calls posing as a private business to obtain internal e-mail communications from employees; spoofed calls posing as a local police department and the U.S. Customs and Border Protection (CBP); robocalls posing as a financial institution; robocalls posing as major retailers to notify consumers about nonexistent orders; and swatting[] calls.

The letter notifies RGTN of its legal obligations and “steps RGTN must take to address this apparently illegal traffic.” It warns RGTN that “failure to comply with the steps outlined in this letter may result in downstream providers permanently blocking all of RGTN’s traffic.”

The letter goes on to detail the complaints made by companies located in the U.S. of the vishing attacks against them that the FCC alleges were transmitted by RGTN. It further outlines how the alleged misconduct violated numerous laws and regulations, including the Telephone Consumer Protection Act, and the Truth in Caller ID Act. It requires RGTN to respond to the letter within 48 hours and report how it is mitigating illegal traffic on its network to the FCC.  Hopefully, this notice will eliminate some of the vishing attacks companies face every day. It is also a strong warning to telecommunications providers that the FCC is focused on illegal robocalls and to have measures in place to limit the use of their service for fraudulent purposes.

On August 19, 2026, the Federal Trade Commission (FTC) and the state of Connecticut announced a proposed $4 million settlement with Manchester City Nissan and several of its officers. The settlement reminds any organization that advertises to consumers: the price customers see should be the price they can expect to pay.

The case involves alleged deceptive and unfair practices in advertising, selling, leasing, and financing vehicles. The FTC brought its claims under Section 5 of the FTC Act, while Connecticut relied on the Connecticut Unfair Trade Practices Act (CUTPA). The agencies challenged Manchester City Nissan’s representations about advertised prices, mandatory charges, add-on products, customer authorization, and vehicle certifications and warranties.

Price transparency is central to this case. If a dealership advertises a vehicle at a particular price, it should not later add mandatory charges that make the vehicle unavailable at the advertised price. The proposed order would require Manchester City Nissan’s most prominently displayed price to include all mandatory fees and charges, except certain government-required charges.

The same principle applies throughout the customer journey. An online price may attract a customer, but it can become misleading if the vehicle is unavailable or the price depends on undisclosed fees or conditions. The proposed order would prohibit the defendants from misrepresenting vehicle availability or whether particular charges, products, and services are optional or required.

The proposed order also addresses add-ons. Manchester City Nissan will have to explain what a charge covers, how much it costs, and whether it is optional before obtaining the customer’s clear agreement to pay. The broader message here is that a signature or final payment screen should not be used to cure unclear disclosures earlier in a transaction. A customer’s agreement should confirm an informed choice, not substitute for a clear explanation.

The takeaways from this case extend beyond car dealerships. Any organization that advertises a headline price and later adds mandatory fees should review the entire customer journey, from the initial advertisement through checkout, contracting, or enrollment. Businesses should compare advertised prices with final charges, clearly identify optional products and services, and avoid describing an add-on as required when it is not. Ultimately, customers should receive a clear and consistent account of the price before they commit. The advertised price should start, and remain, the real price.

Connecticut Attorney General William Tong announced in the past week that his office has entered into two settlements focused on the privacy of consumer data.

The first, announced on August 19, 2026, is a settlement with TaxAct, a Texas company that assists taxpayers with filing tax returns. In the action, the AG alleged TaxAct was disclosing sensitive taxpayer information with Meta and Google, including “detailed financial information for its customers, including rounded adjusted gross income, rounded tax refunds and/or taxes owed, and certain types of income and deductions, including number of dependents and whether taxpayers made charitable contributions, or had investment income or mortgage or student loan interest.” TaxAct’s contract with Meta did not limit its sharing with third parties, despite TaxAct’s privacy notice that said it would “safeguard consumer privacy and to prohibit third parties from sharing TaxAct data.”

In announcing the settlement, Tong stated:

“Taxpayers trusted TaxAct with their most sensitive financial records for one specific purpose—to prepare their tax returns. Behind the scenes, our investigation showed that TaxAct abused that trust and allowed Meta and Google access to sensitive taxpayer data. This was a breach of trust that could have exposed taxpayers to potential scams and financial harm. In addition to the financial penalty, this settlement forces TaxAct to deploy groundbreaking new safeguards to monitor and govern third-party tracking on their site to ensure this never happens again.”

TaxAct agreed to pay $275,000 in fines and penalties and agreed to implement new third-party tracking compliance terms, create a review committee, develop written policies and procedures to govern and approve the use of any new third-party tracking technologies or changes to existing tracking, and regularly scan the company’s website to “ensure third-party technologies are functioning as approved.” These measures are good practices for all companies to adhere to when considering the use of third-party technologies.

On August 26, 2026, Tong announced a $17.1 billion multistate settlement with Meta, which resolves claims made against Meta by 51 state attorneys general. According to the press release:

“The agreement resolves claims by 51 attorneys general that the company designed Instagram with addictive features, knowingly exposed young users to serious mental harms, and intentionally misled the public about the safety of its platforms, among other things. This settlement is a monumental victory for the protection of America’s children and will fundamentally transform how the entire social media industry designs products for kids and teens.”

The settlement also resolves the multistate investigation led by Connecticut against Meta “for its sharing of nonpublic information about Facebook users with third parties, like Cambridge Analytica, leading up to the 2016 election.” Connecticut will receive up to $265.4 million from the settlement, “with at least half of all funds directed to remediate youth harms from social media, including but not limited to support for mental health and crisis intervention, after school and summer school programming, and implementation of phone-free school zones. This is the largest state settlement with a single defendant in history.”

The Department of Justice has issued a press release announcing that it has agreed to settle its allegations that TikTok and its parent company, ByteDance violated the Children’s Online Privacy Protection Act (COPPA).

The settlement requires TikTok to pay “$300 million immediately and an additional $100 million upon entry of an order vacating a prior consent decree entered against TikTok’s predecessor, Musical.ly.” The press release states that “the settlement represents one of the largest recoveries ever obtained in a COPPA case.”

The case filed against TikTok in 2024 alleged that it violated COPPA by failing to provide notice and obtain parental consent prior to collecting and using personal information of children under the age of 13.

Multiple states have also filed suit against TikTok alleging that the platform is “addicting.” They allege that TikTok is harmful and dangerous to children and youth, including “increased rates of depression, anxiety, loneliness, low self-esteem, and suicide, interfering with sleep and education, fueling body dysmorphia and eating disorders, and contributing to youth addiction” and that TikTok is engaging in deceptive and unfair acts and practices in violation of state consumer protection laws.

The lawsuits filed against TikTok by multiple states continue to wind through the courts, and the settlement with the DOJ does not affect those proceedings.

The DOJ indicated that the settlement was reached because TikTok has undergone a series of “changes to its ownership, management, compliance functions, and privacy practices. The company has implemented extensive measures designed to strengthen safeguards for younger users, improve age-related controls, and enhance parental oversight.” It does not appear that any of these changes have addressed the underlying allegations that states have asserted about the addicting and harmful effects of the use of TikTok to children and youth.

TikTok’s annual income in 2025 was estimated at $33 billion, is expected to reach $44 billion in 2026, and there are over 170 million U.S. users in the U.S. Despite being the one of the largest COPPA settlements in history, it pales in comparison to the potential harm TikTok is causing and its profits.

On August 18, 2026, the Cybersecurity & Infrastructure Security Agency, Federal Bureau of Investigation, and U.S. Department of Health & Human Services issued an update to a previous advisory to the health care industry warning against Medusa ransomware. The advisory provided tactics, techniques, and procedures as well as the indicators of compromise gathered to assist with response and remediation.

Medusa ransomware has been hitting the healthcare space particularly hard, but it’s also affecting the defense industry, critical manufacturing information technology, and financial services.

The advisory outlines how Medusa is a ransomware-as-a-service (RaaS) variant that was first identified in June 2021. Since its inception, Medusa developers and affiliates have hit over 500 victims, including “medical, education, legal, insurance, technology, and manufacturing.”

Although Medusa originally operated as a closed organization, since 2023 it has developed into an affiliate model, selling RaaS to affiliates that are paid different amounts depending on their experience and how effective they are in extorting victims. Medusa is a double extortion program, where they deploy ransomware to decrypt data, then extort victims for payment to decrypt and suppress publication of the data.

Medusa recruits access brokers in cybercriminal forums and marketplaces. The access brokers are the ones who attack the company through phishing campaigns, or exploit unpatched software vulnerabilities, including ScreenConnect, Fortinet, Fortra, and BeyondTrust. They pay the access brokers between $100 and $1 million to break into the company and sell that access to Medusa operators. They leverage new vulnerabilities within 24 hours and sometimes before they are announced. Once in, the access brokers use legitimate tools to cover their tracks to give them time to sell their wares to Medusa (and other ransomware gangs). Medusa then uses legitimate remote monitoring software to evade detection to exfiltrate data, deploy the ransomware, and extort the victim.

The advisory lists the indicators of compromise that companies should review and block. It also provides common remediation, including eviction countermeasures, and mitigations, which should be applied as soon as possible.

The advisory reinforces how important it is to continue internal phishing tests, employee training, and patching programs as priorities to help avoid becoming a victim.

On August 17, 2026, the Federal Trade Commission (FTC) announced a $2.1 million settlement with online bill-payment company Doxo over allegations that the company, and its two co-founders, deceived consumers through search ads, fees, and subscription practices. The case shows that consumer protection risk can begin at the first click, especially when ads or landing pages make a third-party service look like an official payment channel.

The FTC alleged that Doxo used search ads and other advertising to make consumers believe they were paying utilities, car loans, and other bills through their billers’ official channels. The FTC also alleged that Doxo landing pages often displayed biller names and sometimes logos, even though Doxo had no relationship with the many companies it claimed were in its payment network.

The proposed settlement order starts with the core problem: Doxo allegedly made its payment pages look more official than they were. The order prohibits Doxo from suggesting that a customer paying through a Doxo-controlled site is paying the biller directly or using a service authorized by the biller. It also restricts Doxo from using biller website addresses, names, and logos in search ads, URLs, webpages, and other payment-related advertising in ways that falsely imply sponsorship or approval.

That focus reflects a broader point about consumer perception. A disclaimer may not cure an overall impression created by the rest of the page. If a landing page uses a biller’s name in the headline, places a familiar logo near the payment button, or shows a display URL that looks official, consumers may reasonably think they are dealing with the biller itself. The FTC’s position is that companies need to evaluate the full context, not isolate each word or design choice.

The order also addresses how Doxo presented fees. The FTC alleged that Doxo charged “delivery fees” without clear disclosure and did not adequately explain that those fees were waived only for certain payment methods. Under the order, Doxo cannot misrepresent what consumers will pay, why a fee applies, its total cost, or important limits and conditions. Essentially, fees that matter to the purchase decision need to appear before the consumer enters payment information or commits to the transaction.

The subscription allegations also raise a related issue: consent. The FTC alleged that Doxo enrolled consumers in a recurring subscription program without clearly disclosing the subscription price. Recurring subscriptions often involve a “negative option” feature, where the consumer’s silence or failure to cancel is treated as acceptance. For those features, the order requires Doxo to disclose the key terms before collecting billing information, obtain express informed consent before charging consumers, and provide cancellation methods that are easy to find and use.

The settlement is a reminder that compliance review should follow the customer’s experience from the first search result through cancellation. The question is not only whether each disclosure is technically present, but what the overall flow communicates. If a payment page uses another company’s name, offers a fee waiver, or includes a recurring charge, those terms should be clear before the customer pays. Companies should also be able to show that customers affirmatively agreed to the terms and can cancel without unnecessary steps or confusion. Overall, the checkout flow should make the relationship, cost, and commitment clear before the consumer clicks to pay.