Ransomware gang ShinyHunters boldly attacked the FBI this week, alleging that it hacked into the FBI’s job site, defaced it, then stole sensitive records of employees and applicants, including human resources records of current employees.

The gang alleges that it exploited a vulnerability in Oracle’s PeopleSoft product that enabled remote code execution allowing them to download between two and three terabytes of data. The group released a sampling of the data to journalists, including FBI employees’ names, home addresses, telephone numbers, Social Security numbers, assignments, dates of birth, and details about relatives.

ShinyHunters says it attacked the FBI following an FBI cyber alert published in May that the gang alleges made false statements.

While ShinyHunters’ claims have not been verified, picking a fight with the agency that is responsible for prosecuting cyber crime is surely an escalation that the FBI will no doubt respond to in kind.

Those using Oracle’s PeopleSoft are urged to update the software with patches when they become available.

This post was authored by Business Litigation group partner Eric Del Pozo.

In United States v. Alisigwe, No. 24-960 (2d Cir. Sept. 17, 2026), a divided Second Circuit held that border agents may conduct searches of international travelers’ cellphones without a judicial warrant, reasonable suspicion of criminal activity, or any individualized justification. This decision should be of interest to anyone planning to enter (or reenter) the United States via New York, Connecticut, or Vermont, whether for business or personal reasons, with a smartphone, tablet, or laptop.

Whereas many international travelers rack up sky miles, the defendant Alisigwe racked up airport searches. In 2018, the United States government began criminally investigating Alisigwe, from whom British border authorities had seized a fraudulent passport. In 2019, upon his arrival at JFK International Airport, federal agents pulled Alisigwe aside, interviewed him, scrolled through his cellphone, and found other people’s names, birthdates, and social security numbers. In 2021, federal agents again stopped Alisigwe upon arrival at JFK Airport, and again scrolled through his cellphone, this time viewing an incriminating communication. On both occasions, he was released into the country.

Later indicted on charges of bank fraud, money laundering, and identity theft, Alisigwe moved to suppress (or prohibit) the cellphone-derived evidence from being introduced at his trial. The district court denied the motion because the presence of reasonable suspicion that Alisigwe was engaged in criminal activity permitted the border agents to examine his phone. On appeal, the Second Circuit agreed that the evidence was admissible, but disagreed that the officers needed any independent justification to search the cellphone of someone entering the country.

Writing for the majority, Judge Steven Menashi highlighted that existing precedent distinguished between searches at the border, including at an airport, that are deemed “routine” (such as those of a traveler’s luggage or personal belongings) and those that are more invasive and “nonroutine” (such as strip searches or involuntary x-rays). While the Fourth Amendment allows the former without a warrant, or any objective level of suspicion, the latter demands at least reasonable suspicion that the prospective entrant has committed a crime.

Essentially likening a smartphone to a digital suitcase, the panel held that “the search of a traveler’s property at the border—including a cellphone—is a routine search that the government may conduct without suspicion.” It expressly limited Riley v. California, 573 U.S. 373 (2014), which generally required a warrant to search a suspect’s smartphone incident to an arrest, to that specific context. The panel reasoned that border searches of travelers, by contrast, implicate diminished privacy interests and promote the sovereign’s right to determine “who and what may enter the country.”

Concurring in the result only, Judge Eunice Lee would have upheld the admission of the cellphone evidence as deriving from a nonroutine border search supported by reasonable suspicion. Judge Lee wrote that, from a privacy standpoint, an “unrestricted and suspicionless search of a cellphone is intrusive enough to warrant greater protection than the majority gives it today—which is none.” She would not endorse officers’ rummaging “with no suspicion and for any reason” through what is “perhaps the single most comprehensive, sensitive and closely-guarded repository of a person’s private information and data.” As support for these ideas, the concurring opinion relied on Riley and United States v. Carpenter, 585 U.S. 296 (2018)—the latter generally requiring a warrant before officers may access cell site location data to chronicle a phone user’s historical movements.

In this author’s view, any analogy to Carpenter goes only so far: a border search focuses on an individual’s being in a single, known place. But Riley presents a much closer call: the Court there rooted the warrant requirement in the sheer breadth of personal information that the average smartphone contains, as well as their ubiquity. Memorably, the Riley Court wrote that a smartphone could be mistaken for “an important feature of human anatomy.” And today’s phone fits more than any suitcase ever could.

However, important questions remain. After Alisigwe, may border agents, lacking an independent justification, permissibly download the entire contents of a smartphone or laptop that someone brings into the country? And if one person’s whole device were fair game, could agents download the entirety of every device passing through the international arrivals terminal, for mass querying? The Second Circuit’s decision appears to reserve judgment on these questions. Three times, the majority emphasized that the agents had not used sophisticated forensic search methods or extracted the cellphone’s whole contents.

As things stand, travelers entering the United States through New York, Connecticut, or Vermont should assume that information accessible on their devices may be subject to federal inspection. Organizations whose executives or employees travel internationally should thus review their internal protocols to minimize the potential exposure of privileged communications, company secrets, customer data, or other sensitive information. In addition, organizations should ensure that any relevant policies are clearly communicated and, insofar as possible, actually followed.

Chatbots and AI-powered customer service tools are no longer limited to technology companies. Businesses across industries are using AI to answer customer questions, summarize conversations, provide recommendations, and help users complete transactions. These tools can offer real value, but they also introduce legal and operational considerations that may not arise with a traditional website feature. Before deployment, a business should understand what information the tool collects, where that information goes, how long it is retained, and whether the vendor may use customer interactions to train or improve its models. The analysis becomes especially important if customers might share personal, confidential, financial, health, or other sensitive information.

Transparency and appropriate guardrails are equally important. Customers should understand when they are interacting with AI, whether their conversations are being recorded or analyzed, and what the tool can and cannot do on their behalf. Depending on the business, its customers, and their locations, privacy, consumer protection, AI transparency, and recording-consent laws may apply. Businesses should also decide who will monitor the tool’s responses, how mistakes will be addressed, what happens when sensitive information is submitted, and when a conversation should be escalated to a person.

Existing website documents may need attention as well. A privacy policy drafted before the adoption of AI may no longer accurately describe the company’s data practices, while website terms may need to address the chatbot’s role, the limitations of its responses, prohibited uses, and circumstances in which users should seek human assistance. The goal is not to discourage businesses from adopting useful AI tools, but to pair adoption with basic diligence: map the data flows, review vendor terms, establish clear limits, provide appropriate disclosures, and update relevant policies. AI may be new, but the foundation remains familiar: know your technology, know your data, communicate clearly, and put practical safeguards in place before problems arise.

Last week, a federal District Court judge largely rejected Anthropic’s demurrer to Reddit’s suit accusing it of improperly gathering user content to train its AI model Claude. Reddit, Inc. v. Anthropic PBC, No. 3:25-cv-05643 (N.D. Cal. Sept. 19, 2026).  In the 2025 lawsuit, Reddit accused Anthropic of breach of contract, interference with contract, and unfair competition when it learned that Claude was scraping content, including user data, off Reddit’s platform to help train the model.  Reddit specifically asserted that Anthropic’s scraping violated Reddit’s user agreement, and that Anthropic, unlike Google and OpenAI, did not enter into a licensing agreement with Reddit before using its content.

Anthropic argued that federal copyright law preempted Reddit’s state-law claims and that they were copyright claims in disguise. The judge largely disagreed, holding that the contract, interference, and unfair competition claims each required an extra element beyond unauthorized copying and involved substantial state interests outside the Copyright Act. The judge also held that Reddit adequately alleged intentional interference by claiming that Anthropic continued scraping after being told it lacked permission. Finally, Claude’s own admission that it did not know if Reddit user data scraped for training was deleted was used as evidence that Reddit had sufficiently alleged the interference claim.  Anthropic did score a partial win regarding Reddit’s unjust-enrichment and trespass-to-chattels claims, but the court gave Reddit an opportunity to amend them.

The case is still pending, so the ruling does not decide whether Anthropic is ultimately liable.  Still, it is a useful reminder that well-drafted user agreements, terms of service, and licensing terms may give website operators claims that go beyond copyright law. Companies looking to protect their users’ content and data should clearly address automated scraping, AI-training uses, deletion obligations, and licensing requirements. Clear rules may not stop every scraper, but they can put a company in a much stronger position if a dispute ends up in court. They should also consider reasonable technical controls and consistent enforcement practices.

The American Arbitration Association (AAA) has launched an AI Ambassador Program bringing together 37 attorneys from leading law firms to examine how artificial intelligence (AI) is reshaping disputes and dispute resolution. The group will develop practical resources for users, counsel, arbitrators, mediators, and other professionals, with an initial focus on AI-based evidence and arbitration procedure, AI-related disputes, automated transactions, digital assets, and algorithmic finance. The initiative reflects a growing reality: AI is changing not only the types of matters entering arbitration, but also the evidence, procedures, and decision-making tools used to resolve them.

The program builds on the AAA’s broader work in AI, including its support for the Legal Context Protocol (LCP), an open standard designed to create a reliable legal record for transactions conducted by autonomous software agents. As agents increasingly purchase services, commit funds, and accept terms without contemporaneous human review, traditional contracting records may be incomplete or inconsistent. LCP addresses that evidentiary gap by generating a cryptographic fingerprint of the governing terms and binding it to the related payment. The protocol does not dictate contractual terms or determine whether an agreement is enforceable. Instead, it makes the terms discoverable before a transaction and verifiable afterward, while allowing the parties to identify governing law and a preferred dispute-resolution process.

Taken together, the Ambassador Program and LCP point to the next phase of AI governance: building legal infrastructure alongside technical and payment infrastructure. Organizations exploring agentic commerce should consider how their systems identify applicable terms, document an agent’s authority, preserve transaction records, and account for disputes, audits, and regulatory inquiries. At machine speed and scale, a dependable record of who acted and what was agreed is not simply good recordkeeping, it is foundational to trust and enforceability.

In November 2025, the Department of Veterans Affairs entered into an agreement with Baylor Genetics to provide nationwide pharmacogenomic (PGx) and germline genetic testing services across the VA healthcare system. The partnership allowed VA providers to use advanced precision diagnostics to tailor treatment plans for conditions like post-traumatic stress disorder (PTSD) and depression, minimize side effects of medication, and screen for hereditary cancer risks. In doing so, Baylor Genetics processed lab samples and genetic insights for thousands of service members as part of this federal healthcare initiative.

On June 15, 2026, Baylor was the victim of a cyberattack, which compromised the sensitive health and personal information of over 30,000 veterans, including their names, dates of birth, lab results, medical testing details, health insurance information, and partial Social Security numbers. The VA has been working with Baylor to notify the affected individuals, and free credit-monitoring services are available for impacted veterans.

If you receive a breach notification letter, it is always worthwhile to follow the instructions in the letter and sign up for services offered.

Our clients are increasingly experiencing HR identity fraud—when an imposter (sometimes from a foreign adversary nation like North Korea) poses as a candidate for a remote job, often in the information technology space, in order to obtain access to company information or divert funds for a nefarious purpose.

The website Hypr recently issued its “first annual report analyzing hiring and employee fraud in 2026.” The 2026 State of HR Identity Fraud Report outlines the increase of hiring fraud and identifies that a shocking 98% of the 500 U.S. HR executives surveyed “have experienced candidate fraud firsthand.” The report examines how HR identity fraud is detected, how long it takes to identify it, and how to mitigate the risk through established processes.

While 90% of HR leaders have heightened concern over hiring fraud in the last two years, surprisingly, 68% of hiring fraud is discovered by a basic gut instinct—that is, when someone in the process felt something was “off,” as opposed to having established security controls in place.

The survey showed that 42% of cases are not caught pre-hire, and that “less than 3% are flagged the same day.” In addition, only a third are detected between one and three days, “45% require four to six days, and 20% go undetected for up to three weeks, averaging 5.73 days of unmonitored access.” This means that “by the time a red flag is raised, the fraudulent hire has already been provisioned with corporate credentials and internal network access.”

Part of the issue in failing to detect fraud is that there is no single point of supervision, as companies have outsourced a significant amount of work to vendors. “It’s a set of disconnected checks operating in silos. Because no single stage reliably stops candidate fraud, clearing an earlier stage offers no guarantee of identity assurance.” The internal team has specific obligations in the hiring process, and other functions are outsourced. This fragmentation allows threat actors to “infiltrate the onboarding process while accountability is transitioning between teams.”

The survey found that “42% of hiring fraud is detected only after employment begins. Among those post-hire cases, discovery takes an average of four to six days—by which point 98% of fraudulent hires have already been issued company credentials.” This means that the imposter had access to company data for a significant amount of time, which could include proprietary data, sensitive personal information, customer information or employee information. This unauthorized access requires an internal investigation and could lead to required notifications to individuals or customers.

The survey says that “24% of organizations spend one to three months resolving a single fake hire; while the rest lose one to three weeks. Almost no one clears an incident in under a week.”

The conclusion is “Most organizations already possess the core capabilities to solve this challenge. What remains missing is a unified, continuous owner for identity across the moments where HR, IT and Security currently hand it off to one another.” Reorganizing the hiring process to establish a single point of truth and responsibility for HR identity so threat actors can’t insert themselves into the hand-off process is worth serious consideration.

Survey results released in OneTrust’s 2026 AI-Ready Governance Report shows that employees are adopting AI tools more rapidly than company AI governance programs can keep up.

Although organizations indicated they were adopting governance programs to address the use of AI in their organizations, “Some organizations know agents are being used in parts of the business without consistent oversight. Others lack visibility into where and how agents are used.”

Consistent with other research “nearly half of respondents reported at least one incident during the past year in which AI systems or agents took unapproved actions.”

The message of the survey is that you are not alone in the journey to adopt an AI governance program for your organization. Concentrating on risk classification, understanding how employees are using AI, and developing a culture of safety and security while grappling with the rapid adoption of AI will help mitigate risk. The most important thing is to keep tackling it, and don’t get overwhelmed and give up. It is an ongoing, iterative process that will need regular assessment and fine tuning, so dig in and assemble a team committed to working on it for the long term.

Last fall, the University of North Carolina at Chapel Hill School of Law reportedly used ChatGPT, Claude, and Grok as jurors in a mock trial based on a real juvenile case. At the same time, AI-powered jury research platforms are entering the litigation consulting market, offering attorneys and claims professionals rapid assessments of liability, comparative fault, and potential damages.

These tools can provide valuable early insights. They may help legal teams test competing narratives, identify themes that resonate and flag arguments that could be poorly received, all faster and at a lower cost than traditional jury research. However, lawyers should distinguish reliability from validity. An AI simulation may consistently measure individual reactions to a case summary yet still fail to capture how an actual jury reaches a verdict. Real jurors discuss evidence, challenge each other’s assumptions, and revise their views through deliberation. Venue-specific attitudes and community norms also shape outcomes in ways that broad simulated populations may not reflect.

AI jury research is therefore best viewed as a screening tool rather than a substitute for focus groups, mock trials, or other interactive methods. It can inform early case assessment and help counsel decide where deeper research is warranted, but its polished percentages and damages ranges should not be mistaken for predictions of an actual verdict. For legal teams, the key question is not whether AI or traditional research is categorically better, it is whether the chosen method measures the issue that matters. When a case turns on contested evidence, group dynamics, and collective judgment, human deliberation remains central.

Manhattan District Attorney Alvin L. Bragg, Jr., announced on September 14, 2026, the “seizure of 12 domain names of illegal websites used for unlawfully disseminating, publishing, and selling non-consensual celebrity ‘deepfake’ videos.” According to the press release, the individuals under investigation:

[A]llegedly used artificial-intelligence (‘AI’) image and video creation tools to turn pre-existing photos and videos of approximately 1,200 real people into what appear to be hyper-realistic images and videos of those individuals engaging in sexual conduct. They then used these websites to disseminate, publish, and sell these videos and other similar non-consensual intimate imagery (‘NCII’).

In announcing the seizure, Bragg stated,

[Twelve hundred] individuals had their faces and bodies stolen and turned into illegal pornography on 12 different websites – without their knowledge or consent – and today, my Office is announcing that we have seized these websites pursuant to a court order. These horrific violations of privacy follow victims into their careers and personal lives and take an immense toll on emotional and mental wellbeing…Our investigations into these websites and similar operations are ongoing. If you have been a victim, I want you to know that we are here to help. Please contact our Cyber Crime Bureau at 212-335-9600.

This is encouraging news for victims, and I applaud DA Bragg for his effort to combat this horrible problem. If you have been a victim of a deep fake, call the Manhattan DA’s Office, or the consumer division of your Attorney General’s office, depending on where you live. If victims come forward and assert pressure to prosecute those disseminating deep fakes, perhaps a dent can be made to stop them from proliferating and harming victims.