The Enforcement Bureau of the FCC recently issued a Notification of Suspected Illegal Traffic to RGTN USA Inc. (RGTN) for “transmitting apparently illegal calls originating from abroad, including spoofed calls, fraudulent robocalls, and calls conveying false emergencies.”

Vishing attacks have increased over the past year and have been surprisingly successful. (To learn more about the threat, check these previous articles.) To combat this growing problem, it is heartening to see the FCC Enforcement Bureau take action.

On August 24, 2026, the FCC issued a notice letter to RGTN alleging that the transmission of illegal traffic from abroad where RGTN served as the gateway provider:

has taken several forms, each directed at defrauding victims: spoofed[] calls posing as a private business to obtain internal e-mail communications from employees; spoofed calls posing as a local police department and the U.S. Customs and Border Protection (CBP); robocalls posing as a financial institution; robocalls posing as major retailers to notify consumers about nonexistent orders; and swatting[] calls.

The letter notifies RGTN of its legal obligations and “steps RGTN must take to address this apparently illegal traffic.” It warns RGTN that “failure to comply with the steps outlined in this letter may result in downstream providers permanently blocking all of RGTN’s traffic.”

The letter goes on to detail the complaints made by companies located in the U.S. of the vishing attacks against them that the FCC alleges were transmitted by RGTN. It further outlines how the alleged misconduct violated numerous laws and regulations, including the Telephone Consumer Protection Act, and the Truth in Caller ID Act. It requires RGTN to respond to the letter within 48 hours and report how it is mitigating illegal traffic on its network to the FCC.  Hopefully, this notice will eliminate some of the vishing attacks companies face every day. It is also a strong warning to telecommunications providers that the FCC is focused on illegal robocalls and to have measures in place to limit the use of their service for fraudulent purposes.

On August 19, 2026, the Federal Trade Commission (FTC) and the state of Connecticut announced a proposed $4 million settlement with Manchester City Nissan and several of its officers. The settlement reminds any organization that advertises to consumers: the price customers see should be the price they can expect to pay.

The case involves alleged deceptive and unfair practices in advertising, selling, leasing, and financing vehicles. The FTC brought its claims under Section 5 of the FTC Act, while Connecticut relied on the Connecticut Unfair Trade Practices Act (CUTPA). The agencies challenged Manchester City Nissan’s representations about advertised prices, mandatory charges, add-on products, customer authorization, and vehicle certifications and warranties.

Price transparency is central to this case. If a dealership advertises a vehicle at a particular price, it should not later add mandatory charges that make the vehicle unavailable at the advertised price. The proposed order would require Manchester City Nissan’s most prominently displayed price to include all mandatory fees and charges, except certain government-required charges.

The same principle applies throughout the customer journey. An online price may attract a customer, but it can become misleading if the vehicle is unavailable or the price depends on undisclosed fees or conditions. The proposed order would prohibit the defendants from misrepresenting vehicle availability or whether particular charges, products, and services are optional or required.

The proposed order also addresses add-ons. Manchester City Nissan will have to explain what a charge covers, how much it costs, and whether it is optional before obtaining the customer’s clear agreement to pay. The broader message here is that a signature or final payment screen should not be used to cure unclear disclosures earlier in a transaction. A customer’s agreement should confirm an informed choice, not substitute for a clear explanation.

The takeaways from this case extend beyond car dealerships. Any organization that advertises a headline price and later adds mandatory fees should review the entire customer journey, from the initial advertisement through checkout, contracting, or enrollment. Businesses should compare advertised prices with final charges, clearly identify optional products and services, and avoid describing an add-on as required when it is not. Ultimately, customers should receive a clear and consistent account of the price before they commit. The advertised price should start, and remain, the real price.

Connecticut Attorney General William Tong announced in the past week that his office has entered into two settlements focused on the privacy of consumer data.

The first, announced on August 19, 2026, is a settlement with TaxAct, a Texas company that assists taxpayers with filing tax returns. In the action, the AG alleged TaxAct was disclosing sensitive taxpayer information with Meta and Google, including “detailed financial information for its customers, including rounded adjusted gross income, rounded tax refunds and/or taxes owed, and certain types of income and deductions, including number of dependents and whether taxpayers made charitable contributions, or had investment income or mortgage or student loan interest.” TaxAct’s contract with Meta did not limit its sharing with third parties, despite TaxAct’s privacy notice that said it would “safeguard consumer privacy and to prohibit third parties from sharing TaxAct data.”

In announcing the settlement, Tong stated:

“Taxpayers trusted TaxAct with their most sensitive financial records for one specific purpose—to prepare their tax returns. Behind the scenes, our investigation showed that TaxAct abused that trust and allowed Meta and Google access to sensitive taxpayer data. This was a breach of trust that could have exposed taxpayers to potential scams and financial harm. In addition to the financial penalty, this settlement forces TaxAct to deploy groundbreaking new safeguards to monitor and govern third-party tracking on their site to ensure this never happens again.”

TaxAct agreed to pay $275,000 in fines and penalties and agreed to implement new third-party tracking compliance terms, create a review committee, develop written policies and procedures to govern and approve the use of any new third-party tracking technologies or changes to existing tracking, and regularly scan the company’s website to “ensure third-party technologies are functioning as approved.” These measures are good practices for all companies to adhere to when considering the use of third-party technologies.

On August 26, 2026, Tong announced a $17.1 billion multistate settlement with Meta, which resolves claims made against Meta by 51 state attorneys general. According to the press release:

“The agreement resolves claims by 51 attorneys general that the company designed Instagram with addictive features, knowingly exposed young users to serious mental harms, and intentionally misled the public about the safety of its platforms, among other things. This settlement is a monumental victory for the protection of America’s children and will fundamentally transform how the entire social media industry designs products for kids and teens.”

The settlement also resolves the multistate investigation led by Connecticut against Meta “for its sharing of nonpublic information about Facebook users with third parties, like Cambridge Analytica, leading up to the 2016 election.” Connecticut will receive up to $265.4 million from the settlement, “with at least half of all funds directed to remediate youth harms from social media, including but not limited to support for mental health and crisis intervention, after school and summer school programming, and implementation of phone-free school zones. This is the largest state settlement with a single defendant in history.”

The Department of Justice has issued a press release announcing that it has agreed to settle its allegations that TikTok and its parent company, ByteDance violated the Children’s Online Privacy Protection Act (COPPA).

The settlement requires TikTok to pay “$300 million immediately and an additional $100 million upon entry of an order vacating a prior consent decree entered against TikTok’s predecessor, Musical.ly.” The press release states that “the settlement represents one of the largest recoveries ever obtained in a COPPA case.”

The case filed against TikTok in 2024 alleged that it violated COPPA by failing to provide notice and obtain parental consent prior to collecting and using personal information of children under the age of 13.

Multiple states have also filed suit against TikTok alleging that the platform is “addicting.” They allege that TikTok is harmful and dangerous to children and youth, including “increased rates of depression, anxiety, loneliness, low self-esteem, and suicide, interfering with sleep and education, fueling body dysmorphia and eating disorders, and contributing to youth addiction” and that TikTok is engaging in deceptive and unfair acts and practices in violation of state consumer protection laws.

The lawsuits filed against TikTok by multiple states continue to wind through the courts, and the settlement with the DOJ does not affect those proceedings.

The DOJ indicated that the settlement was reached because TikTok has undergone a series of “changes to its ownership, management, compliance functions, and privacy practices. The company has implemented extensive measures designed to strengthen safeguards for younger users, improve age-related controls, and enhance parental oversight.” It does not appear that any of these changes have addressed the underlying allegations that states have asserted about the addicting and harmful effects of the use of TikTok to children and youth.

TikTok’s annual income in 2025 was estimated at $33 billion, is expected to reach $44 billion in 2026, and there are over 170 million U.S. users in the U.S. Despite being the one of the largest COPPA settlements in history, it pales in comparison to the potential harm TikTok is causing and its profits.

On August 18, 2026, the Cybersecurity & Infrastructure Security Agency, Federal Bureau of Investigation, and U.S. Department of Health & Human Services issued an update to a previous advisory to the health care industry warning against Medusa ransomware. The advisory provided tactics, techniques, and procedures as well as the indicators of compromise gathered to assist with response and remediation.

Medusa ransomware has been hitting the healthcare space particularly hard, but it’s also affecting the defense industry, critical manufacturing information technology, and financial services.

The advisory outlines how Medusa is a ransomware-as-a-service (RaaS) variant that was first identified in June 2021. Since its inception, Medusa developers and affiliates have hit over 500 victims, including “medical, education, legal, insurance, technology, and manufacturing.”

Although Medusa originally operated as a closed organization, since 2023 it has developed into an affiliate model, selling RaaS to affiliates that are paid different amounts depending on their experience and how effective they are in extorting victims. Medusa is a double extortion program, where they deploy ransomware to decrypt data, then extort victims for payment to decrypt and suppress publication of the data.

Medusa recruits access brokers in cybercriminal forums and marketplaces. The access brokers are the ones who attack the company through phishing campaigns, or exploit unpatched software vulnerabilities, including ScreenConnect, Fortinet, Fortra, and BeyondTrust. They pay the access brokers between $100 and $1 million to break into the company and sell that access to Medusa operators. They leverage new vulnerabilities within 24 hours and sometimes before they are announced. Once in, the access brokers use legitimate tools to cover their tracks to give them time to sell their wares to Medusa (and other ransomware gangs). Medusa then uses legitimate remote monitoring software to evade detection to exfiltrate data, deploy the ransomware, and extort the victim.

The advisory lists the indicators of compromise that companies should review and block. It also provides common remediation, including eviction countermeasures, and mitigations, which should be applied as soon as possible.

The advisory reinforces how important it is to continue internal phishing tests, employee training, and patching programs as priorities to help avoid becoming a victim.

On August 17, 2026, the Federal Trade Commission (FTC) announced a $2.1 million settlement with online bill-payment company Doxo over allegations that the company, and its two co-founders, deceived consumers through search ads, fees, and subscription practices. The case shows that consumer protection risk can begin at the first click, especially when ads or landing pages make a third-party service look like an official payment channel.

The FTC alleged that Doxo used search ads and other advertising to make consumers believe they were paying utilities, car loans, and other bills through their billers’ official channels. The FTC also alleged that Doxo landing pages often displayed biller names and sometimes logos, even though Doxo had no relationship with the many companies it claimed were in its payment network.

The proposed settlement order starts with the core problem: Doxo allegedly made its payment pages look more official than they were. The order prohibits Doxo from suggesting that a customer paying through a Doxo-controlled site is paying the biller directly or using a service authorized by the biller. It also restricts Doxo from using biller website addresses, names, and logos in search ads, URLs, webpages, and other payment-related advertising in ways that falsely imply sponsorship or approval.

That focus reflects a broader point about consumer perception. A disclaimer may not cure an overall impression created by the rest of the page. If a landing page uses a biller’s name in the headline, places a familiar logo near the payment button, or shows a display URL that looks official, consumers may reasonably think they are dealing with the biller itself. The FTC’s position is that companies need to evaluate the full context, not isolate each word or design choice.

The order also addresses how Doxo presented fees. The FTC alleged that Doxo charged “delivery fees” without clear disclosure and did not adequately explain that those fees were waived only for certain payment methods. Under the order, Doxo cannot misrepresent what consumers will pay, why a fee applies, its total cost, or important limits and conditions. Essentially, fees that matter to the purchase decision need to appear before the consumer enters payment information or commits to the transaction.

The subscription allegations also raise a related issue: consent. The FTC alleged that Doxo enrolled consumers in a recurring subscription program without clearly disclosing the subscription price. Recurring subscriptions often involve a “negative option” feature, where the consumer’s silence or failure to cancel is treated as acceptance. For those features, the order requires Doxo to disclose the key terms before collecting billing information, obtain express informed consent before charging consumers, and provide cancellation methods that are easy to find and use.

The settlement is a reminder that compliance review should follow the customer’s experience from the first search result through cancellation. The question is not only whether each disclosure is technically present, but what the overall flow communicates. If a payment page uses another company’s name, offers a fee waiver, or includes a recurring charge, those terms should be clear before the customer pays. Companies should also be able to show that customers affirmatively agreed to the terms and can cancel without unnecessary steps or confusion. Overall, the checkout flow should make the relationship, cost, and commitment clear before the consumer clicks to pay.

AI governance is often treated as a policy problem: define approved uses, create an oversight framework, publish acceptable use rules, and document compliance. These steps matter, especially as increasingly more regulations are introduced that raise expectations for accountability, transparency, data governance, and lifecycle risk management. However, the harder question for many organizations is no longer whether they have AI rules in place, but whether those rules can keep pace with how AI is being adopted across the business. Public AI tools, embedded platform features, developer copilots, automated workflows, and AI agents are often introduced faster than security, legal, compliance, and risk teams can map what they access, what they influence, and what new exposures they create.

This is why AI governance must become operational. AI risk does not sit neatly inside a single model or use case. It changes depending on the data the system can reach, the identities and permissions it inherits, the applications it connects to, and the business processes it can affect. A tool that appears low risk in one context can become much more sensitive when it is connected to confidential information, privileged accounts, payment approvals, procurement workflows, or critical infrastructure. As AI agents begin acting across enterprise environments, organizations are no longer managing only human users, devices, and applications. They are also managing non-human actors that can retrieve information, make decisions, and initiate actions at machine speed.

The organizations best positioned for responsible AI adoption will be those that treat governance as a living operating model, not a static compliance document. That means identifying AI capabilities across the enterprise, classifying them by business risk, reviewing their access rights, limiting unnecessary permissions, monitoring how they interact with systems and data, and adjusting controls as use cases evolve. Regulation may define the destination, but operational governance builds the road. The objective is not to put the brakes on AI adoption; it is to give organizations the visibility, control, and confidence to innovate safely as AI becomes part of everyday work. The real test of AI governance will be whether organizations can move from written rules to practical controls that support innovation while keeping risk within clear, defensible boundaries.

This week, Apple notified customers in 110 countries around the world (150 countries to date) that they “may have been targeted with spyware capable of hacking into their devices.” Apple notifies users “directly on their iPhone lock screen with a push notification that urges the person to take action.” The threat alert will read “Apple detected a mercenary spyware attack targeted at your iPhone. There are actions you can take now to protect your data and device.” Apple will send notifications to users via email as well.

If you receive this notification from Apple, take it seriously and follow it urgently.

Why?

Spyware is “software that is secretly or surreptitiously installed into an information system to gather information on individuals or organizations without their knowledge” and is a type of malicious code. The spyware then passes the information to another entity without consent or asserts control over the device without the user’s knowledge. Spyware includes password stealers, banking trojans, and keyloggers.

On mobile devices, spyware steals information including “SMS messages, incoming/outgoing call logs, contact lists, emails, browser history, and photos. Mobile spyware can even log keystrokes, activate and record from any connected microphones or cameras, take screenshots of the phone’s background and track the device using GPS.” The ways threat actors can install spyware on mobile devices is through unsecured free wi-fi, operating system flaws, and malicious apps.

Spyware allows the controller to literally take over your phone without your knowledge or consent.

Spyware is also known as stalkerware, which can be applied to a device for an abusive partner or ex-partner to secretly track an individual’s device and online activity. The FTC has provided guidance on how to detect whether you have become the victim of spyware and how to protect yourself.

How to Detect and Protect Yourself from Spyware

First, if you get an alert from Apple or another manufacturer, take it seriously and follow their instructions.

It is difficult to detect spyware. The signs may be minimal, but be aware of changes to your device’s behavior including: overheating, battery drainage, old messages and pop-ups, excessive data usage, and the presence of new apps on your phone.

To protect yourself against spyware, Guardian Digital suggests the following tips:

CISA also has tips to consider:

  • Use lock-down mode on your phone;
  • Reboot your device weekly;
  • Implement user account control;
  • Routinely update your OS and apps;
  • Install antivirus and anti-malware software;
  • Manage your application permissions;
  • Vet apps before you install them;
  • Keep physical control of your devices;
  • Use secure messaging apps; and
  • Only visit websites beginning with HTTPS://

These tips include basic cybersecurity hygiene to protect your device from compromise, but more importantly, from spyware, which apparently is becoming a bigger problem than in the past. Be aware of the burgeoning problem and implement the above tips to best protect yourself.

An advisory issued jointly this week by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and the Republic of Korea’s National Police Agency alerted organizations about an emerging threat from the Gunra ransomware group and provided guidance on detection and mitigation.

Gunra emerged in April 2025 as a sophisticated double-extortion ransomware variant derived from the leaked Conti ransomware source code. It expanded in 2026 as a structured ransomware-as-a-service (RaaS) affiliate program advertised on dark web forums for cybercriminals. Gunra actors demand ransom through a customized Tor-based negotiation portal and threaten to publish exfiltrated data on a leak site if victims do not comply. According to the alert, Gunra is actively recruiting penetration testers and ethical hackers as initial access brokers, offering a share of the ransom profits in exchange for enterprise network access. I’m hoping ethical hackers will remain “ethical.”

Organizations listed on the actors’ leak site have included multiple business sectors across the Americas, Europe, the Middle East, Africa, and the Asia-Pacific region including:

• Healthcare and public health;

• Financial services and insurance;

• Critical manufacturing and construction;

• Transportation systems and logistics;

• Government services and facilities;

• Utilities;

• Academia;

• Media and communications;

• Retail; and

• Professional and nonprofit services.

Organizations in these sectors are urged to implement the recommendations for mitigation including:

• Prioritizing the patching of known exploited vulnerabilities in internet-facing systems, including virtual private network (VPN) gateways and remote desktop protocol (RDP)-exposed infrastructure;

• Implementing and regularly testing offline, immutable backups stored in a physically separate, segmented location to ensure recovery without paying a ransom; and

• Segmenting networks to restrict lateral movement from an initially compromised device to other systems within the organization.

The advisory provides technical details that should be reviewed and implemented by IT professionals, including pinpointing the legitimate tools that are being used by Gunra that can evade existing monitoring tools.

A recent federal decision shows how data-breach claims can turn on the connection between the exposed information and the alleged harm. In Volio v. Sugarhouse HSP Gaming, L.P., No. 2:25-cv-00039 (E.D.Pa. Aug. 7, 2026), current and former employees and casino patrons sued after Rivers Casino Philadelphia allegedly discovered unauthorized access to its network and exfiltration of files containing names, dates of birth, Social Security numbers, driver’s license and passport information, and bank account information used for direct deposits.

The complaint alleged that Cicada3301, a ransomware group, stole about 2.561 terabytes of data and later published the stolen data on the dark web. Several plaintiffs alleged post-breach activity, including attempted account access, increased spam and phishing communications, and fraudulent credit inquiries.

The judge allowed the negligence claim to proceed. The court relied on Dittman v. UPMC,  196 A.3d 1036 (Pa. 2018), for the point that an entity who collects and stores sensitive personal information owes a duty to exercise reasonable care in protecting it from foreseeable breach risks. On causation, the court found it significant that plaintiffs alleged misuse of the same categories of information Rivers allegedly failed to protect, not merely suspicious activity that happened sometime after the breach. On damages, the court held that time spent monitoring accounts, changing passwords, placing fraud alerts or freezes, communicating with financial institutions, buying credit monitoring, and actual misuse were sufficiently alleged at the early pleading stage.

However, most other theories did not survive. Negligence per se was dismissed because the judge concluded that Pennsylvania does not treat it as a standalone cause of action. The implied-contract claim failed because the complaint alleged an expectation of data security, not mutual assent to a contractual promise, and the privacy policy disclaimed any guarantee that personal information would always remain private or secure. The court also dismissed claims of breached fiduciary duty, breach of confidence, invasion of privacy, and unjust enrichment, emphasizing that ordinary data collection, a failure to prevent third-party theft, and general payment-for-services allegations did not supply the missing elements of those claims. The order suggests that a negligence claim may survive where plaintiffs allege specific compromised data, later misuse of the same types of information, and concrete response costs.

However, the court was not willing to let the same breach allegations support every adjacent theory. Expectations about data security did not create an implied contract, ordinary data collection did not create fiduciary duties, and a third-party hack was not treated as an affirmative disclosure by the company.