Maybe attacking the FBI was not such a brilliant idea. Following the FBI attack, one of the suspected leaders of ShinyHunters has been detained and is in custody. Apparently, there is no honor among thieves, as he is reportedly assisting law enforcement by naming other members of the cyber gang.

The suspect, Saif al-Din Khader, a teenager from Amman, Jordan, was in the process of extorting a company that allegedly employed his father when he was detained. What a guy.

His detainment follows the arrest of a 24-year-old man in Amsterdam, also allegedly a part of the ShinyHunters criminal gang.

According to the FBI, ShinyHunters affiliates “have allegedly breached more than 140 organizations and taken at least $70 million in extortion payments,” since 2025.

Hopefully the detainment and arrest of these members of ShinyHunters is the beginning of the dismantling of this vexatious group.

On September 30, 2026, a New York federal judge denied Major League Baseball’s digital-ticketing arm, MLB Advanced Media, L.P. (MLBAM), a chance to send to arbitration most claims over tickets that disappeared from the MLB Ballpark app after a cyberattack. Lanham v. MLB Advanced Media, L.P., No. 25-cv-7780 (AS), slip op. at 6–8 (S.D.N.Y. Sept. 30, 2026). The order is a reminder that arbitration language in online terms of use does not guarantee a cyber dispute will be arbitrated.

The complaint alleged that attackers used credentials leaked or stolen from other websites to access MLBAM accounts and steal fans’ tickets. The plaintiffs claimed the app’s security flaws enabled the intrusions.

The court saw two main hurdles to arbitration. The first was whether the plaintiffs had agreed to MLBAM’s 2024 terms of use at all. MLBAM pointed to emails and app pop-ups announcing the changes, plus terms linked on sign-up and login screens during the 2025 season. However, most plaintiffs had opened their accounts years earlier, and the court held that the record did not establish whether and when they encountered a screen that required them to accept the updated terms.

Second, the terms excluded claims related to alleged violations of users’ privacy rights or interests. MLBAM argued that plaintiffs alleged only potential privacy violations and that exposed information was publicly available. The judge focused instead on the alleged account intrusions: users had a privacy interest in their accounts and contents, even if the claims also involved missing tickets. Because the carveout covered “any” related claim and its examples were nonexclusive, it was “capacious.”

Organizations should keep in mind that notice of revised terms may not establish assent, particularly for longtime users. Records showing which version each user accepted, when, and through what screen, can help demonstrate user agreement. They should also consider how broadly a privacy carveout may reach claims involving account access, exposed information, or missing digital property. If certain disputes are intended to remain in arbitration, the carveout’s boundaries should be clear. Otherwise, the exception could take arbitration out of play.

The Federal Trade Commission’s (FTC) proposed enforcement policy statement on personalized pricing signals that businesses may face scrutiny when they use consumer-specific data to set different prices for different customers without disclosing that practice. The statement is not binding law, but the FTC says it intends to use its existing Section 5 authority to address potentially deceptive or unfair practices. Its focus is distinct from ordinary dynamic pricing based on market-wide factors such as supply, demand, or inventory: personalized pricing relies on information or inferences tied to an individual consumer or household.

For businesses, the practical question is not only whether a price varies, but what data and assumptions drive the variation, and what consumers are told about them. The FTC’s position is that an effective disclosure should clearly state that the price is personalized, explain the basis for the personalization, and identify the types of data used; privacy notices and consent practices may also warrant review.

Companies can start by mapping where consumer-specific data affects prices, then assessing disclosures across websites, checkout flows, phone scripts, and chat interfaces. To view the full FTC statement, click here.

In the wake of two lawsuits against it, California Attorney General Rob Bonta recently served an investigative subpoena on OpenAI as part of the California Department of Justice’s (DOJ) ongoing investigation of incidents resulting from the operations of OpenAI and its artificial intelligence (AI) models.

According to the Attorney General’s press release, the DOJ announced last month that it “is conducting a formal investigation into the Hugging Face incident, while continuing to more broadly monitor the AI industry’s compliance with California laws. The subpoena is part of a broader inquiry into cybersecurity incidents and risks involving the company and its models.”

The DOJ’s subpoena seeks answers to “additional questions regarding cybersecurity incidents and risks involving the company and its AI models.”

It may take some time for the two lawsuits and the subpoena to wind through the legal system, but hopefully more information will be obtained through these processes on how the OpenAI agents are hacking other companies and what OpenAI is doing to rein them in.

Clients are increasingly turning to AI before they speak with outside counsel, and sometimes after, by pasting legal advice, contract language, or other work product into a public AI model to ask follow-up questions. Used thoughtfully, these tools can help clients frame questions and organize information, but an answer that sounds confident is not necessarily grounded in the facts, current law, or the company’s actual obligations. Additionally, sharing sensitive business or legal information with a public tool can raise separate confidentiality and data-handling concerns.

A familiar example is the California Consumer Privacy Act (CCPA). AI-generated privacy-policy suggestions often recommend adding CCPA disclosures, even when the business may not be subject to the law or the suggested language does not fit its practices. Adding statements about consumer rights, data uses, or processes that the company does not actually follow can create confusion and potential legal exposure; removing language counsel drafted can create its own problems. The issue is not that AI is always wrong, it is that generic answers can turn on facts the tool was never given, or cannot reliably assess.

The practical question for clients and counsel is how to use AI without letting plausible-sounding outputs become an unreviewed legal position or business commitment. That means being deliberate about what information goes into a tool, checking its sources and assumptions, and treating its output as a starting point, not a substitute for advice grounded in the company’s facts. This is a useful conversation for General Counsel and outside counsel to have together: where AI can help, where it can mislead, and what review practices make its use safer and more productive. Outside counsel, General Counsel, and AI platforms can work as an efficient, effective team if parameters and expectations are put in place.

California is taking a leading role in regulating artificial intelligence at work. A newly signed package of laws limits employers’ use of AI in several high-stakes settings: employers may not rely entirely on AI to decide whether to fire a worker; use AI to predict employees’ emotional states; collect workers’ neural data; or use AI surveillance in workplace bathrooms. The laws also require notice when AI-caused layoffs occur. Together, these measures respond to growing concerns about job loss, discrimination, and intrusive workplace monitoring, and may provide a model for other states considering broader protections.

The laws arrive as employers adopt tools that can monitor workers’ movements, assess their interactions, or inform employment decisions, but their reach and practical effect remain open questions. The package is narrower than a general requirement to disclose workplace AI use, and, according to the source material, enforcement rests with the government rather than individual workers bringing lawsuits. Employers should review how AI tools are used in hiring, performance management, discipline, layoffs, and workplace monitoring, while tracking implementation and enforcement guidance as it develops.

California’s approach may also sharpen a broader policy debate about how to protect workers without unnecessarily restricting beneficial uses of AI. Some employers may not currently use the specific practices targeted by these laws, while advocates argue that safeguards should anticipate harms before they become widespread. As other states consider workplace AI rules, California’s package offers an early test of whether targeted restrictions can address workers’ concerns and where more comprehensive disclosure and accountability measures may still be needed.

I recently had the pleasure to participate in a podcast on Privacy Lawls about the dangers of sharing medical information with AI tools. In the September 21, 2026, episode, “The Dangers of Sharing Medical Information with AI,” Donata Stroink-Skillrud, President of Termageddon LLC, and I explored how consumers are increasingly using generative AI tools to interpret medical records, evaluate symptoms, and seek health-related guidance. We discussed why users should carefully consider both the privacy and safety implications of sharing sensitive health information with AI systems, including that information entered into consumer AI platforms may not be protected by health privacy laws such as HIPAA.

The podcast outlines common misconceptions about the legal protections surrounding medical information, the limitations of AI-generated responses, and the potential consequences of relying on AI tools for medical diagnoses or treatment recommendations. Throughout the conversation, we focus on the importance of understanding how personal information may be collected, stored, and used when interacting with generative AI technologies.

The bottom line is that consumers need to be very careful about the data they upload into generative AI tools, as the information is not protected by laws, can be used to train algorithms, can be freely disclosed to third parties and can become outputs for queries. Most importantly, the response could be wrong and detrimental to one’s health.

Listen to the full episode, “The Dangers of Sharing Medical Information with AI,” on the Privacy Lawls podcast.

According to a new report from Nordlayer, a credential from an employee of a Fortune 500 company is posted on the dark web every 100 seconds. The report states that almost 10 million credentials, which include both usernames and passwords of Fortune 500 employees, have been leaked on the dark web and are presently available to threat actors. And threat actors use them: boy, do they ever! This is the easiest way for threat actors to infiltrate a company network and launch different types of attacks, including the most dreaded: a ransomware attack.

The report notes that 99% of the credentials were stolen from web browsers. Many employees insert and save their usernames and passwords into their work computer browsers, whether the site visited is for personal or business purposes. Threat actors target employees to download malware called an infostealer, and when a victim downloads an infostealer without knowing, the malware is able to copy all of the logins saved in the browser. Bingo! Now they have the credentials to access the company network and have full access to the files and data that the employee has permission rights to access.

Another way threat actors obtain credentials is when a company doesn’t offboard an employee and the credential remains active. If the credential has not been decommissioned and is compromised and available on the dark web, a threat actor has full access to the company network as if the offboarded employee was still working.

What’s the fix? Nordlayer says:

With 6.6 million corporate email addresses in circulation, large organizations should assess how many of their employees’ credentials are already on the dark web and what those logins can still reach.

This is not exclusively a large organization risk. The report shows that “the highest individual rates [of compromised credentials] come from midsize technology companies.” The risk is much higher for companies where most employees hold a corporate email account and save logins in a browser. On the other hand, companies where much of the workforce doesn’t receive a corporate email address, the risk is obviously lower as they do not have credentials to expose.

Credential harvesting and stealing continues to be the easiest way for threat actors to access company networks. The dark web is obviously full of them. Employees need to be counseled on the risks presented, that they should never provide their credentials to anyone who asks, how to change their passwords and phrases frequently, and to be cautious about saving passwords in web browsers. In addition, companies need to be aware of this growing problem, monitor the dark web for company credential leaks, and have a tight process for decommissioning credentials.

A two-minute apartment tour may not sound like the kind of video Congress had in mind when it passed the Video Privacy Protection Act (VPPA) in 1988, but that question was at the heart of the recent oral argument in Banks v. CoStar Realty Info., Inc., No. 25-03320 (8th Cir. argued Sept. 23, 2026).

The VPPA bars a “video tape service provider” from knowingly disclosing, without a consumer’s express consent, personally identifiable information linking the consumer to specific video materials or services. The statute defines covered providers by their business of renting, selling, or delivering prerecorded tapes or similar audiovisual materials, a definition courts are now applying to online video.

The plaintiff, Banks, alleged that CoStar’s delivery of videos through Apartments.com brings it within the statute. The district court dismissed the case, finding CoStar was not a video tape service provider and Banks was not a “consumer.” On appeal, Banks argued that videos are central to CoStar’s business; CoStar responded that it markets real estate and videos are just one promotional option. If offering video is enough, companies that use it as one feature of a broader service could face VPPA exposure.

The judges also questioned whether apartment-tour clips qualify as covered videos and whether online delivery meets the statute’s requirements. Judge David Stras asked whether short clips resemble the movies or video-store rentals contemplated by the VPPA. Banks’s counsel argued that Congress used “video,” not “movie,” and intended the law to keep pace with technology. CoStar, meanwhile, argued that the clips lack the tangible form required by Eighth Circuit precedent. Judge Stras tested that position with a hypothetical: could a video downloaded onto a USB drive qualify? CoStar’s lawyer said no; storing a file on a physical device does not give the file itself a physical existence.

In contrast, the upcoming oral argument in Salazar v. Paramount Global before the U.S. Supreme Court will address a different question: who qualifies as a VPPA “consumer?” Docket No. 25-459, argument scheduled for Oct. 14, 2026. The answer to this question includes whether any purchase or subscription from a video provider is enough, or whether the consumer must have a relationship with its video services. Banks instead asks which businesses and videos the statute covers. Together, the cases could clarify if, and when, the VPPA applies to companies that offer video alongside other services.

A panel of judges sitting on the federal Court of Appeals for the Seventh Circuit appeared skeptical of a challenge to the use of automatic license plate readers by the Illinois state police, questioning whether the cameras’ collection of vehicle snapshots amounts to an improper search under the Fourth Amendment of the U.S. Constitution. Plaintiffs Stephanie Scholl and Frank Bednarz argued that a network of more than 300 cameras near Cook County expressways, combined with 90 days of retained data, lets police reconstruct drivers’ movements without a warrant or probable cause. Plaintiffs argued that compiling a person’s travel over time can reveal more than any single snapshot, and that law-abiding drivers have Fourth Amendment protections. Judge Amy St. Eve, however, questioned whether the plaintiffs’ theory differed meaningfully from circuit precedent involving real-time location tracking.

The government’s attorney countered that the cameras capture license plates at fixed locations on public expressways, and that state law limits both where the cameras may be installed and how the resulting data may be used. The district court dismissed the case, finding the alleged risk of future tracking too abstract to support the requested relief and concluding that the challenged plate reading was not an intrusive search. The federal Department of Justice also supported the state’s position. The Seventh Circuit’s questions suggest that the plaintiffs might face substantial hurdles. However, questions from the bench do not necessarily signal a ruling: we will have to wait until the court releases its formal decision.