A recent federal decision shows how data-breach claims can turn on the connection between the exposed information and the alleged harm. In Volio v. Sugarhouse HSP Gaming, L.P., No. 2:25-cv-00039 (E.D.Pa. Aug. 7, 2026), current and former employees and casino patrons sued after Rivers Casino Philadelphia allegedly discovered unauthorized access to its network and
data protection
CCPA Cybersecurity Audits Are Coming: What Companies Should Do Now
The California Consumer Privacy Act’s (CCPA) cybersecurity audit requirement marks a significant shift in privacy and security accountability. Beginning January 1, 2027, covered businesses will need to complete annual, independent, evidence-backed cybersecurity audits showing that their privacy and security controls are not only designed appropriately, but operating effectively over time. For many companies, this will…
Chatrie + the Shrinking Third-Party Doctrine: What Data Custodians Should Watch
This post was authored by William S. Fallon, Associate in Robinson+Cole’s Business Litigation group.
In Chatrie v. United States, No. 25-112 (U.S. June 29, 2026), the Supreme Court took another step in redefining digital privacy under the Fourth Amendment, building directly on its landmark decision in Carpenter v. United States, 585 U.S. 296…
Privacy Tip #495 – What We Can Learn from The Worst Breaches of 2026
I apologize that this post is not light reading. It’s critically important to know what the threats are so you can avoid becoming a victim.
Although disconcerting, it is crucial to know what has happened in the first half of this year. TechCrunch recently issued a report outlining the worst breaches of 2026—so far:…
Privacy Tip #491 – ShinyHunters Hit Zara
According to HaveIBeenPwned, ShinyHunters targeted fashion brand Zara in a cyber-attack and claimed that it had stolen 197,000 unique email addresses, product SKUs, order IDs, and the originating market. The incident involved a former technology provider (AI analytics platform Anodot) for Zara’s parent company, Inditex, which resulted in the exposure of the personal information.
Privacy Tip #483 – Whistleblower Alleges DOGE Employee Stole Social Security Data on a Thumb Drive
The Washington Post has published a report detailing a whistleblower complaint alleging that a former Department of Government Efficiency (DOGE) employee stole two complete databases from the U.S. Social Security Administration while employed as a DOGE software engineer.
The databases stolen include the “’Numident’ and the ‘Master Death File,’ which could cover records for more…
Privacy Tip #441 – Identity Theft Statistics Increasing in 2025
- 1.4 million complaints of identity theft were received by the Federal Trade Commission
- Total fraud and identity theft cases have nearly tripled over the last decade
- Cybercrime
Privacy Tip #437 – 23andMe Files for Bankruptcy—What to Do If It Has Your Genetic Information
Genetic testing company 23andMe has filed for Chapter 11 bankruptcy protection, and its CEO has resigned. It is seeking to sell “substantially all of its assets” through a reorganization plan that will have to be approved by a federal bankruptcy judge.
Mark Jensen, Chair and member of the Special Committee of the Board of…
Adobe Issues Patches for ColdFusion “High Severity” Vulnerability
Adobe recently issued a patch for a high-severity vulnerability for ColdFusion versions 2023.11 and 2021.17 and earlier; according to the National Institute of Standards and Technology (NIST), “an attacker could exploit this vulnerability to access files or directories that are outside of the restricted directory set by the application. This could lead to the disclosure…
Scary Halloween News: Jumpy Pisces Using Play Ransomware to Attack Organizations
Unit 42 recently reported that it has identified “Jumpy Pisces, a North Korean state-sponsored threat group associated with the Reconnaissance General Bureau of the Korean People’s Army, as a key player in a recent ransomware incident.” Its investigation indicates “with moderate confidence that Jumpy Pisces, or a faction of the group, is now collaborating with…