An advisory issued jointly this week by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and the Republic of Korea’s National Police Agency alerted organizations about an emerging threat from the Gunra ransomware group and provided guidance on detection and mitigation.

Gunra emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti ransomware source code. It expanded in 2026 as a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums for cybercriminals. Gunra actors demand ransom through a customized Tor-based negotiation portal and threaten to publish exfiltrated data on a leak site if victims do not comply. According to the alert, Gunra is actively recruiting penetration testers and ethical hackers as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access. I’m hoping ethical hackers will remain “ethical.”

Organizations listed on the actors’ leak site have included multiple business sectors across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific region including:

• Healthcare and public health;

• Financial services and insurance;

• Critical manufacturing and construction;

• Transportation systems and logistics;

• Government services and facilities;

• Utilities;

• Academia;

• Media and communications;

• Retail; and

• Professional and nonprofit services.

Organizations in these sectors are urged to implement the recommendations for mitigation including:

• Prioritizing the patching of known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure;

• Implementing and regularly testing offline, immutable backups stored in a physically separate, segmented location to ensure recovery without paying a ransom; and

• Segmenting networks to restrict lateral movement from an initially compromised device to other systems within the organization.

The advisory provides technical details that should be reviewed and implemented by IT professionals, including pinpointing the legitimate tools that are being used by Gunra that can evade existing monitoring tools.

A recent federal decision shows how data-breach claims can turn on the connection between the exposed information and the alleged harm. In Volio v. Sugarhouse HSP Gaming, L.P., No. 2:25-cv-00039 (E.D.Pa. Aug. 7, 2026), current and former employees and casino patrons sued after Rivers Casino Philadelphia allegedly discovered unauthorized access to its network and exfiltration of files containing names, dates of birth, Social Security numbers, driver’s license and passport information, and bank account information used for direct deposits.

The complaint alleged that Cicada3301, a ransomware group, stole about 2.561 terabytes of data and later published the stolen data on the dark web. Several plaintiffs alleged post-breach activity, including attempted account access, increased spam and phishing communications, and fraudulent credit inquiries.

The judge allowed the negligence claim to proceed. The court relied on Dittman v. UPMC,  196 A.3d 1036 (Pa. 2018), for the point that an entity who collects and stores sensitive personal information owes a duty to exercise reasonable care in protecting it from foreseeable breach risks. On causation, the court found it significant that plaintiffs alleged misuse of the same categories of information Rivers allegedly failed to protect, not merely suspicious activity that happened sometime after the breach. On damages, the court held that time spent monitoring accounts, changing passwords, placing fraud alerts or freezes, communicating with financial institutions, buying credit monitoring, and actual misuse were sufficiently alleged at the early pleading stage.

However, most other theories did not survive. Negligence per se was dismissed because the judge concluded that Pennsylvania does not treat it as a standalone cause of action. The implied-contract claim failed because the complaint alleged an expectation of data security, not mutual assent to a contractual promise, and the privacy policy disclaimed any guarantee that personal information would always remain private or secure. The court also dismissed claims of breached fiduciary duty, breach of confidence, invasion of privacy, and unjust enrichment, emphasizing that ordinary data collection, a failure to prevent third-party theft, and general payment-for-services allegations did not supply the missing elements of those claims. The order suggests that a negligence claim may survive where plaintiffs allege specific compromised data, later misuse of the same types of information, and concrete response costs.

However, the court was not willing to let the same breach allegations support every adjacent theory. Expectations about data security did not create an implied contract, ordinary data collection did not create fiduciary duties, and a third-party hack was not treated as an affirmative disclosure by the company.

California’s privacy regulator just sent a clear message to the data broker ecosystem: compliance failures will be viewed across both the California Consumer Privacy Act (CCPA) and the Delete Act. The California Privacy Protection Agency (CPPA) announced a $116,490 settlement with LocateSmarter LLC, an Iowa-based company that allegedly operated as a data broker without registering as one. The CPPA also alleged that LocateSmarter made it too difficult for consumers to opt out of the sale of their personal information by requiring them to provide the last four digits of their Social Security numbers before submitting an opt-out request. According to the CPPA, LocateSmarter collected sensitive and high-risk data, including names, driver’s license information, dates of birth, and information about employment, bankruptcy, and litigation. The CPPA’s order emphasized that requiring consumers to provide more personal information than necessary, particularly sensitive information, can violate California’s data minimization requirements and discourage the exercise of privacy rights.

The takeaway for companies that are data brokers, or those that may fall within California’s broad data broker definition, is practical and immediate. First, companies should reassess whether they are required to register in California, especially if they buy, sell, license, trade, or otherwise share personal information about consumers with whom they do not have a direct relationship. Second, opt-out and deletion-rights workflows should be simple, low-friction, and limited to information reasonably necessary to process the request; asking for sensitive identifiers “just in case” may create enforcement risk. Third, low opt-out volumes should not be viewed as a compliance success story if the request process is confusing, intimidating, or overly burdensome. The CPPA’s comments also suggest that California regulators are increasingly looking at privacy practices through multiple legal lenses at once, meaning companies should treat CCPA compliance, data broker registration, data minimization, and consumer rights operations as connected parts of the same compliance program, not separate boxes to check.

The California Consumer Privacy Act’s (CCPA) cybersecurity audit requirement marks a significant shift in privacy and security accountability. Beginning January 1, 2027, covered businesses will need to complete annual, independent, evidence-backed cybersecurity audits showing that their privacy and security controls are not only designed appropriately, but operating effectively over time. For many companies, this will be the first recurring, regulator-visible audit cycle that ties cybersecurity governance, privacy compliance, executive accountability, and legal defensibility together. Businesses that meet the applicable revenue and data-processing thresholds, including those processing large volumes of Californians’ personal information or sensitive personal information, should be preparing now, because the first audit period is quickly approaching.

These audits will require more than a technical controls review. Covered businesses will need to define audit scope, identify relevant systems and data flows, assess third-party and vendor access, document control performance, and support scoping decisions with clear evidence. Legal teams, privacy leaders, security, technology, compliance, and business stakeholders should be aligned early on what is in scope, what evidence will be used, who will own remediation, and how decisions will be documented. Chief legal officers and legal departments have an important role to play here: helping the business interpret regulatory expectations, pressure-test assumptions, assess whether auditor independence requirements are met, and frame the organization’s risk posture in a way that can withstand external scrutiny.

Companies can start by revisiting their data maps, identifying systems that collect, store, transmit, or provide access to California residents’ personal information, and comparing existing cybersecurity frameworks against the CCPA’s required audit domains. Organizations with mature compliance programs may have a head start, but even well-resourced companies should expect meaningful work around documentation, evidence standards, remediation tracking, and executive certification. The key is to move from “we have a program” to “we can prove the program works.” By 2027, the CCPA cybersecurity audit requirement will not be just another compliance milestone, it will be a credibility test for how well companies understand, govern, and protect the personal information they hold.

The current statistics on how many people upload their medical information into a generative AI tool are staggering. It is clear to me that people are unaware of the risks of doing so, and if you are contemplating sharing your medical information with a generative AI tool, like ChatGPT, Gemini or Claude, please read this first.

Earlier this year, OpenAI announced the launch of a version of the chatbot dedicated to assist individuals with navigating their health records. Whether you are contemplating sharing your medical information with ChatGPT, or another chatbot, there are risks of doing so that have been outlined in the article “When Patients Share Everything With an AI Chatbot – Risks and Opportunities of Large Language Models” published in the Journal of the American Medical Association.

The article outlines the “potential benefits and discuss the attendant risks of privacy violations, discrimination, and the exacerbation of health disparities that may accompany the unfiltered upload of EHRs” into large language models. These risks include the fact that once the health information is shared with a commercial company, it is not protected by HIPAA, the federal law that protects health information that is created or maintained by medical providers. In addition, the shared information could be disclosed as output for other prompts by other people. Further, the results could be inaccurate, biased, or discriminatory. Finally, the information can be shared with other third parties as outlined in the company’s privacy policy.

It is imperative that prior to uploading any medical information, you read the company’s privacy policy thoroughly, understand the risks, minimize uploading the actual medical records, and be cautious about relying too heavily on the results.

There are studies that show that caution should be used when receiving diagnosis or treatment information from an AI tool. Several individuals have sued AI developers for misdiagnosis that allegedly caused them harm. One individual is suing ChatGPT and its CEO alleging that “ChatGPT’s medical advice nearly killed him.” OpenAI’s terms state that individuals should not rely on it for medical advice. Unfortunately, it is well-known that it is rare for individuals to read privacy policies in depth.

The takeaway? As we have said before, it is really important to read privacy policies before you share your information, even if they are long. Take the time, as that is the only way you will find out how companies are using and disclosing your most sensitive information.

It is similarly important to understand that your medical information is not protected when you share it with a third party. Protect your most sensitive information, and know the risks before you share it with a commercial entity or rely on the results of an AI bot.

Following the coordinated attack against 30 Minnesota water and wastewater utilities from July 26-27, 2026, hackers have attacked at least 11 other state water systems in the last week. As of July 30, 2026, the Federal Bureau of Investigation (FBI) confirmed that at least seven states were affected and issued an alert detailing the hackers’ actions and their impact on water and wastewater systems.

Shortly thereafter, both Georgia and Michigan confirmed that they were targeted and experienced “hostile cyber activity,” including nine systems in Michigan, though both states reported no operational disruption or public health concern.

As of today, it is being reported that “at least 12 states have been hit.” In addition to Minnesota, Michigan, and Georgia, a water system in South Dakota reported a cyberattack “that appears to be part of the same campaign.”

In addition to alerts issued by the FBI and the Cybersecurity and Infrastructure Security Agency, Infracritical published a detailed report on the Minnesota attack and—to  a lesser extent—Michigan, including the attack overview and vector, threat actor profile, and the public health risk to residents as a result of the attack happening during a regional heat event. The report notes that, for the first time confirmed in U.S. water sector history, “at least one utility experienced flooding as a direct result of PLC manipulation — the first cyber-caused flooding event documented in U.S. water infrastructure. This indicates adversary willingness to cause physical infrastructure damage, not merely access loss or service interruption.”

The report provides a statewide hardening roadmap that state utility operators should consider in the face of this ongoing threat by foreign adversaries.

The fact that the hackers of 12 statewide water systems did not think twice about damaging physical infrastructure is a wake-up call that our water, electrical, and financial systems must be hardened against these new cyber warfare threats for national security.

A recent decision from a federal district court in Virginia adds to the growing body of Telephone Consumer Protection Act (TCPA) litigation over whether its “Do Not Call” protections apply to marketing texts sent to cell phones. In McGonigle v. Dickey’s Barbecue Restaurants, Inc., No. 1:25-cv-01062, 2026 WL 2114507 (E.D. Va. July 22, 2026), the plaintiff alleged that he received unsolicited promotional text messages from Dickey’s after registering his cell phone number on the National Do Not Call Registry.

Dickey’s moved to dismiss, arguing that the TCPA’s Do Not Call provisions apply only to “residential” telephones and that a cell phone does not qualify. On July 22, the court rejected that argument, holding that a cell phone may plausibly be treated as residential for TCPA purposes when it is used primarily for personal, household purposes. The court also explained that this approach was consistent with the TCPA’s regulations and the FCC’s interpretation of them. In particular, the court noted that the relevant FCC regulations apply to entities making telephone solicitations or telemarketing calls to wireless telephones, and that the FCC has recognized that many consumers no longer maintain landlines and instead rely only on wireless service. The court quoted the FCC’s view that allowing wireless subscribers to receive the full range of TCPA protections is “more consistent with the overall intent of the TCPA.”

The court then held that the allegations in the plaintiff’s complaint were sufficient to avoid dismissal at the pleading stage. The complaint alleged that the plaintiff’s phone number was his only phone number, that he used it to communicate with friends and family, schedule personal appointments, and conduct household-related activities, and that he did not use it for business or commercial purposes. The court found those allegations sufficient to plead that the phone was used residentially.

However, Dickey’s did obtain a partial win. The court dismissed the request for treble damages, holding that the complaint did not include enough factual allegations that Dickey’s willfully, or knowingly, violated the TCPA. The court otherwise denied the motion to dismiss and declined to strike the class allegations at this early stage.

The decision addresses one recurring TCPA issue—whether a cell phone can be a residential telephone—but leaves another developing issue largely untouched: whether text messages qualify as “telephone calls” under the TCPA’s Do Not Call private right of action. For now, the case is a reminder that TCPA Do Not Call claims involving text messages may survive early motion practice when the complaint pleads personal, residential use of the number with enough detail.

Recent privacy litigation against Shopify and the NBA highlights a shared theme: companies may face risk not only for what their websites say about privacy choices, but for how embedded technologies actually collect data behind the scenes.

In the Shopify case, a California federal court refused to dismiss claims alleging that Shopify collected California consumers’ personal, payment, location, and browsing information through its checkout technology without adequate notice or consent, then used that information to build consumer profiles. The court found the plaintiff plausibly alleged that Shopify knowingly designed its system to collect the data at issue, relying on Shopify’s prior disclosures, order-confirmation emails, hosted product images, archived page source information, and Shopify-linked URLs in the merchant checkout flow.

The ruling followed a major Ninth Circuit decision reviving the case on personal jurisdiction grounds, with the court finding that Shopify’s alleged use of geolocation technology supported California-specific contacts because Shopify could know when a consumer’s device was in California. See Briskin v. Shopify, Inc., 135 F.4th 739 (9th Cir. 2025) (en banc) (personal jurisdiction); see also Briskin v. Shopify, Inc., No. 4:20-cv-06940-PJH (N.D. Cal.) (post-remand order addressing statutory and privacy claims).

The NBA case raises a related but distinct issue about whether privacy banners and cookie opt-outs actually stop the tracking they appear to control. Yee v. NBA Props., Inc., No. 4:26-cv-07919 (N.D. Cal. removed July 29, 2026). The proposed class action alleges that visitors to nba.com are tracked by tools from Google, Amplitude, and others when they browse schedules, tickets, player information, game highlights, and related content.

According to the complaint, these tools collect user activity and identifying information for advertising, marketing, analytics, and cross-platform tracking purposes. The plaintiff’s main theory is that the NBA’s cookie opt-out banner gives users a false sense of control because trackers allegedly deploy as soon as a user lands on the site before privacy preferences can be selected and because technologies such as session recording, canvas fingerprinting, pixels, and other scripts may continue operating even after a user opts out of cookies.

The complaint brings claims under statutes and legal theories including the California Invasion of Privacy Act, the federal Wiretap Act, California’s Computer Data Access and Fraud Act, the California Constitution’s privacy provision, and California’s Unfair Competition Law.

Together, the cases are a reminder that checkout flows, pixels, cookies, SDKs, hosted content, session replay, analytics tags, and embedded vendor tools should be treated as part of the privacy compliance perimeter, not as invisible background infrastructure.

Businesses should understand what each technology collects, when it fires, where the user is located, whether collection begins before notice or choice, and whether opt-out or consent signals fundamentally change website behavior. They should also review privacy notices, consent-management settings, tag deployment rules, vendor configurations, and historical records together, because plaintiffs are increasingly focused on the gap between user-facing privacy promises and technical reality. In this environment, a cookie banner is not a universal fix; it is only as defensible as the data flows and controls behind it.

AI-enabled mental health tools are moving quickly from novelty to mainstream use, and regulators are starting to draw sharper lines around what those tools can and cannot claim to do. Recent lawsuits against Character Technologies Inc.,  the company behind Character.ai, allege that the platform hosted bots that mimicked licensed therapists, including one persona that allegedly claimed fictional professional credentials and engaged in tens of thousands of patient interactions. The litigation comes amid growing AI chatbot use for mental health advice, particularly among adolescents and young adults, and follows reports of serious safety concerns involving minors and crisis-related conversations.

In the absence of a comprehensive federal framework, states are filling the gap. Colorado, Maine, Rhode Island, Tennessee, and Vermont have advanced AI therapy restrictions, joining Illinois, Nevada, and Utah. These laws vary in scope, but the emerging themes are clear: restrictions on advertising AI as a licensed mental health professional, limits on direct patient engagement by AI tools in clinical settings, and greater scrutiny of chatbots used by, or marketed to, children. At the same time, regulators and clinicians are distinguishing between general-purpose chatbots that users may treat as “pocket therapists” and more purpose-built digital therapeutics designed with clinical guardrails and therapeutic datasets.

For companies developing or deploying AI tools in health, wellness, youth engagement, or consumer support, this is a moment to reassess product design, marketing claims, age-gating, crisis escalation, disclaimers, professional oversight, and state-by-state compliance obligations. Disclaimers alone may not be enough if a bot’s persona, outputs, or user experience suggests professional diagnosis, treatment, or therapy. The Federal Food and Drug Administration has not yet authorized generative AI tools for mental health treatment, and professional groups are urging Congress and federal agencies to set clearer standards. Until that happens, companies should expect continued litigation risk, a growing patchwork of state laws, and closer attention from regulators where AI systems appear to provide mental health advice without appropriate clinical controls.

A new California federal lawsuit against AI notetaking provider Granola highlights a growing privacy risk for companies using meeting transcription tools: consent cannot be an afterthought. According to the complaint, Granola’s software allegedly recorded a virtual meeting participant without giving notice that an AI notetaker was present or seeking permission to record. The plaintiff claims this differs from other AI transcription tools that visibly join meetings, announce their presence, or give participants the ability to remove the notetaker. The suit also alleges that Granola used meeting contents by default for commercial purposes, including training AI systems, unless the Granola user turned that setting off.

The case combines several legal theories that have become increasingly common in privacy litigation involving recording and tracking technologies, including claims under the federal Electronic Communications Privacy Act, the California Invasion of Privacy Act, California’s confidential communications statute, common law invasion of privacy, and California’s computer access statute. While the allegations remain unproven, they reflect a key plaintiff-side theory that when a company designs technology to capture communications without clear notice to everyone involved, especially in a two-party consent state like California, privacy and wiretapping claims may follow.

For businesses deploying AI notetakers, meeting bots, transcription tools, or other AI-enabled collaboration products, the takeaway is straightforward: build consent and transparency into the workflow. Companies should review whether meeting participants receive clear notice before recording begins, whether consent is obtained from all required parties, whether participants can object or opt out, and whether meeting data is used for model training or other secondary purposes by default. As AI tools become more embedded in ordinary business communications, the privacy controls around them need to be just as visible as the productivity benefits.