Our clients are increasingly experiencing HR identity fraud—when an imposter (sometimes from a foreign adversary nation like North Korea) poses as a candidate for a remote job, often in the information technology space, in order to obtain access to company information or divert funds for a nefarious purpose.

The website Hypr recently issued its “first annual report analyzing hiring and employee fraud in 2026.” The 2026 State of HR Identity Fraud Report outlines the increase of hiring fraud and identifies that a shocking 98% of the 500 U.S. HR executives surveyed “have experienced candidate fraud firsthand.” The report examines how HR identity fraud is detected, how long it takes to identify it, and how to mitigate the risk through established processes.

While 90% of HR leaders have heightened concern over hiring fraud in the last two years, surprisingly, 68% of hiring fraud is discovered by a basic gut instinct—that is, when someone in the process felt something was “off,” as opposed to having established security controls in place.

The survey showed that 42% of cases are not caught pre-hire, and that “less than 3% are flagged the same day.” In addition, only a third are detected between one and three days, “45% require four to six days, and 20% go undetected for up to three weeks, averaging 5.73 days of unmonitored access.” This means that “by the time a red flag is raised, the fraudulent hire has already been provisioned with corporate credentials and internal network access.”

Part of the issue in failing to detect fraud is that there is no single point of supervision, as companies have outsourced a significant amount of work to vendors. “It’s a set of disconnected checks operating in silos. Because no single stage reliably stops candidate fraud, clearing an earlier stage offers no guarantee of identity assurance.” The internal team has specific obligations in the hiring process, and other functions are outsourced. This fragmentation allows threat actors to “infiltrate the onboarding process while accountability is transitioning between teams.”

The survey found that “42% of hiring fraud is detected only after employment begins. Among those post-hire cases, discovery takes an average of four to six days—by which point 98% of fraudulent hires have already been issued company credentials.” This means that the imposter had access to company data for a significant amount of time, which could include proprietary data, sensitive personal information, customer information or employee information. This unauthorized access requires an internal investigation and could lead to required notifications to individuals or customers.

The survey says that “24% of organizations spend one to three months resolving a single fake hire; while the rest lose one to three weeks. Almost no one clears an incident in under a week.”

The conclusion is “Most organizations already possess the core capabilities to solve this challenge. What remains missing is a unified, continuous owner for identity across the moments where HR, IT and Security currently hand it off to one another.” Reorganizing the hiring process to establish a single point of truth and responsibility for HR identity so threat actors can’t insert themselves into the hand-off process is worth serious consideration.

Survey results released in OneTrust’s 2026 AI-Ready Governance Report shows that employees are adopting AI tools more rapidly than company AI governance programs can keep up.

Although organizations indicated they were adopting governance programs to address the use of AI in their organizations, “Some organizations know agents are being used in parts of the business without consistent oversight. Others lack visibility into where and how agents are used.”

Consistent with other research “nearly half of respondents reported at least one incident during the past year in which AI systems or agents took unapproved actions.”

The message of the survey is that you are not alone in the journey to adopt an AI governance program for your organization. Concentrating on risk classification, understanding how employees are using AI, and developing a culture of safety and security while grappling with the rapid adoption of AI will help mitigate risk. The most important thing is to keep tackling it, and don’t get overwhelmed and give up. It is an ongoing, iterative process that will need regular assessment and fine tuning, so dig in and assemble a team committed to working on it for the long term.

Last fall, the University of North Carolina at Chapel Hill School of Law reportedly used ChatGPT, Claude, and Grok as jurors in a mock trial based on a real juvenile case. At the same time, AI-powered jury research platforms are entering the litigation consulting market, offering attorneys and claims professionals rapid assessments of liability, comparative fault, and potential damages.

These tools can provide valuable early insights. They may help legal teams test competing narratives, identify themes that resonate and flag arguments that could be poorly received, all faster and at a lower cost than traditional jury research. However, lawyers should distinguish reliability from validity. An AI simulation may consistently measure individual reactions to a case summary yet still fail to capture how an actual jury reaches a verdict. Real jurors discuss evidence, challenge each other’s assumptions, and revise their views through deliberation. Venue-specific attitudes and community norms also shape outcomes in ways that broad simulated populations may not reflect.

AI jury research is therefore best viewed as a screening tool rather than a substitute for focus groups, mock trials, or other interactive methods. It can inform early case assessment and help counsel decide where deeper research is warranted, but its polished percentages and damages ranges should not be mistaken for predictions of an actual verdict. For legal teams, the key question is not whether AI or traditional research is categorically better, it is whether the chosen method measures the issue that matters. When a case turns on contested evidence, group dynamics, and collective judgment, human deliberation remains central.

Manhattan District Attorney Alvin L. Bragg, Jr., announced on September 14, 2026, the “seizure of 12 domain names of illegal websites used for unlawfully disseminating, publishing, and selling non-consensual celebrity ‘deepfake’ videos.” According to the press release, the individuals under investigation:

[A]llegedly used artificial-intelligence (‘AI’) image and video creation tools to turn pre-existing photos and videos of approximately 1,200 real people into what appear to be hyper-realistic images and videos of those individuals engaging in sexual conduct. They then used these websites to disseminate, publish, and sell these videos and other similar non-consensual intimate imagery (‘NCII’).

In announcing the seizure, Bragg stated,

[Twelve hundred] individuals had their faces and bodies stolen and turned into illegal pornography on 12 different websites – without their knowledge or consent – and today, my Office is announcing that we have seized these websites pursuant to a court order. These horrific violations of privacy follow victims into their careers and personal lives and take an immense toll on emotional and mental wellbeing…Our investigations into these websites and similar operations are ongoing. If you have been a victim, I want you to know that we are here to help. Please contact our Cyber Crime Bureau at 212-335-9600.

This is encouraging news for victims, and I applaud DA Bragg for his effort to combat this horrible problem. If you have been a victim of a deep fake, call the Manhattan DA’s Office, or the consumer division of your Attorney General’s office, depending on where you live. If victims come forward and assert pressure to prosecute those disseminating deep fakes, perhaps a dent can be made to stop them from proliferating and harming victims.

Ransomware group ShinyHunters alleges on its online platform that it has compromised the Florida Department of Motor Vehicles’ Driver and Vehicle Information Database (DAVID) and stole the DMV records of over 200,000 individuals. The threat actor posted a screenshot of Jeffrey Epstein’s DMV record as proof.

The DAVID records of drivers include their name, address, Social Security number, birthdate, driver’s license ID, and other information. ShinyHunters told BleepingComputer they “breached DAVID through a password-reset flaw that let them compromise multiple accounts in the system. These accounts allegedly belonged to DMV employees and an FBI agent.” ShinyHunters no longer has access to the database and the “password-reset flaw used to compromise accounts is being patched.”

It is believed that ShinyHunters is “targeting other states’ DMV platforms using social engineering attacks.”This is a common strategy for ransomware groups—to concentrate on a particular industry and when they find a way to get into one, they use the same technique to attack others in the same industry.

State DMVs hold vast amounts of valuable personal information. State agencies should train their employees about social engineering attacks, how to identify them, and put robust security measures in place to protect this valuable information of its residents.

On August 26, 2026, LexisNexis won an important, but limited, victory in a proposed class action: a federal court refused to certify a class of people seeking damages for the company’s response to privacy requests which violated the Fair Credit Reporting Act (FCRA). The court did not decide whether LexisNexis had violated the FCRA, only deciding that the plaintiffs could not pursue their claims as the proposed class.

The facts began with Daniel’s Law, a New Jersey statute that protects the home addresses and personal telephone numbers of judges, prosecutors, police officers, certain other public officials, and their immediate family members. Covered individuals may ask a business to stop disclosing that information, and the business generally has ten days to comply.

Beginning in December 2023, thousands of covered individuals allegedly sent LexisNexis written requests to suppress their protected information. According to the plaintiffs, these were straightforward privacy requests, not requests to freeze their consumer files. Nevertheless, LexisNexis reportedly placed security freezes on approximately 18,607 files, maintaining that it could not redact the protected information from consumer reports without doing so.

Because a security freeze restricts access to a consumer report, it can affect banks, insurers, and others evaluating whether to provide credit or services. As a result, the plaintiffs alleged that the unrequested freezes violated the FCRA. However, their effort to proceed as a class ran into a proof problem. The record showed only 13 people had been denied insurance because of the freezes. For everyone else, the court would have needed individualized evidence showing that the person sought credit or services, the freeze blocked access to necessary information, and the blockage caused a denial. Those individual questions defeated the broader class, while a 13-person subclass was too small to satisfy Rule 23’s numerosity requirement.

For companies responding to statutory privacy requests, the decision illustrates how a request directed at specific information can implicate a broader consumer-reporting process. LexisNexis maintained that it could not remove the protected information from its consumer reports without placing a security freeze, and the court did not decide whether that approach violates the FCRA. The takeaway is less about prescribing a particular response and more about understanding how privacy workflows operate across connected systems. Companies should assess whether the mechanism used to honor a request changes access to a consumer report or related service and remember that a narrow request does not always have narrow effects.

California Senate Bill 690 is finally moving forward. The original bill would have broadly exempted disclosures made for a “commercial business purpose,” as defined under the California Consumer Privacy Act (CCPA), potentially eliminating many California Invasion of Privacy Act (CIPA) claims involving common website technologies. The amended version is narrower but could still offer meaningful relief to businesses facing the recent wave of CIPA litigation.

Under the amended bill, private plaintiffs could no longer bring claims under California Penal Code § 638.51 alleging that conduct on websites or online or mobile applications constitutes the unlawful use of a pen register or trap and trace device. Those claims could be brought only by the California Attorney General. The change would apply retroactively to certain pending lawsuits filed within the two years prior to the bill’s operative date. Plaintiffs could still pursue claims under § 631(a), although businesses often have stronger defenses to those claims, including consent and arguments that the information collected was not communication “content” or was not intercepted “in transit.”

SB 690 was approved unanimously by both the Assembly and Senate and has been sent to the Governor’s desk for signature, which must be completed by September 30, 2026. If enacted, it would take effect January 1, 2027. While it would not end CIPA website-tracking litigation, the bill signals legislative support for curbing private lawsuits based on increasingly common pen register and trap and trace theories. Businesses should continue monitoring the bill while reviewing their online tracking technologies, consent mechanisms, disclosures, and vendor relationships.

A recent article released by the Palo Alto Threat Research Center found that, between January and April 2026, a coordinated effort by threat actors was successful in launching vishing attacks using Microsoft Teams accounts to compromise companies across multiple industries.

The threat actor uses an external Teams account and creates a chat “using identities designed to mirror legitimate internal support units.” Usually these include names like help desk, IT support, or something else that makes the user believe the chat is coming from an internal IT support professional. The chat has a sense of urgency that something needs to be done on the user’s computer. The threat actors then call the victim and, if the user picks up, the scam commences. The threat actor then guides the employee through steps to allow remote control or to download malicious malware. If the caller doesn’t pick up, the threat actor calls back multiple times, scaring the user into believing it is urgent.

Once in the system, the threat actor has full control over the user’s access and can exfiltrate data, deploy ransomware, and start a ransomware attack.

Palo Alto has dubbed this attack as “Spring Ring.” It found that between January and April 2026, Spring Ring targeted many organizations across different industries, and more than 150 individual employees were called. In addition, this coordinated attack shows that threat actors are using legitimate tools to lull victims into believing the chats and calls are real.

It is crucial to be aware of the evolving nature of threats, including social engineering and the rise of vishing attacks, to understand that threat actors are using legitimate tools and to distrust any request for remote access to your computer. When in doubt, ignore the chat, and call your IT professional directly to a known number. If IT is really trying to get in touch with you, they will be very happy that you are calling them directly rather than falling victim to a vishing scheme.

The Enforcement Bureau of the FCC recently issued a Notification of Suspected Illegal Traffic to RGTN USA Inc. (RGTN) for “transmitting apparently illegal calls originating from abroad, including spoofed calls, fraudulent robocalls, and calls conveying false emergencies.”

Vishing attacks have increased over the past year and have been surprisingly successful. (To learn more about the threat, check these previous articles.) To combat this growing problem, it is heartening to see the FCC Enforcement Bureau take action.

On August 24, 2026, the FCC issued a notice letter to RGTN alleging that the transmission of illegal traffic from abroad where RGTN served as the gateway provider:

has taken several forms, each directed at defrauding victims: spoofed[] calls posing as a private business to obtain internal e-mail communications from employees; spoofed calls posing as a local police department and the U.S. Customs and Border Protection (CBP); robocalls posing as a financial institution; robocalls posing as major retailers to notify consumers about nonexistent orders; and swatting[] calls.

The letter notifies RGTN of its legal obligations and “steps RGTN must take to address this apparently illegal traffic.” It warns RGTN that “failure to comply with the steps outlined in this letter may result in downstream providers permanently blocking all of RGTN’s traffic.”

The letter goes on to detail the complaints made by companies located in the U.S. of the vishing attacks against them that the FCC alleges were transmitted by RGTN. It further outlines how the alleged misconduct violated numerous laws and regulations, including the Telephone Consumer Protection Act, and the Truth in Caller ID Act. It requires RGTN to respond to the letter within 48 hours and report how it is mitigating illegal traffic on its network to the FCC.  Hopefully, this notice will eliminate some of the vishing attacks companies face every day. It is also a strong warning to telecommunications providers that the FCC is focused on illegal robocalls and to have measures in place to limit the use of their service for fraudulent purposes.

On August 19, 2026, the Federal Trade Commission (FTC) and the state of Connecticut announced a proposed $4 million settlement with Manchester City Nissan and several of its officers. The settlement reminds any organization that advertises to consumers: the price customers see should be the price they can expect to pay.

The case involves alleged deceptive and unfair practices in advertising, selling, leasing, and financing vehicles. The FTC brought its claims under Section 5 of the FTC Act, while Connecticut relied on the Connecticut Unfair Trade Practices Act (CUTPA). The agencies challenged Manchester City Nissan’s representations about advertised prices, mandatory charges, add-on products, customer authorization, and vehicle certifications and warranties.

Price transparency is central to this case. If a dealership advertises a vehicle at a particular price, it should not later add mandatory charges that make the vehicle unavailable at the advertised price. The proposed order would require Manchester City Nissan’s most prominently displayed price to include all mandatory fees and charges, except certain government-required charges.

The same principle applies throughout the customer journey. An online price may attract a customer, but it can become misleading if the vehicle is unavailable or the price depends on undisclosed fees or conditions. The proposed order would prohibit the defendants from misrepresenting vehicle availability or whether particular charges, products, and services are optional or required.

The proposed order also addresses add-ons. Manchester City Nissan will have to explain what a charge covers, how much it costs, and whether it is optional before obtaining the customer’s clear agreement to pay. The broader message here is that a signature or final payment screen should not be used to cure unclear disclosures earlier in a transaction. A customer’s agreement should confirm an informed choice, not substitute for a clear explanation.

The takeaways from this case extend beyond car dealerships. Any organization that advertises a headline price and later adds mandatory fees should review the entire customer journey, from the initial advertisement through checkout, contracting, or enrollment. Businesses should compare advertised prices with final charges, clearly identify optional products and services, and avoid describing an add-on as required when it is not. Ultimately, customers should receive a clear and consistent account of the price before they commit. The advertised price should start, and remain, the real price.