Right To Know - July 2026, Vol. 43
Cyber, Privacy, and Technology Report
Welcome to your monthly rundown of all things cyber, privacy, and technology, where we highlight all the happenings you may have missed.
View previous issues and sign up to receive future newsletters by email here.
Litigation & Enforcement:
- Sixth Circuit Rules Reinstates Ohio Social Media Law: The United States Court of Appeals for the Sixth Circuit ruled that the Ohio Parental Notification by Social Media Operators Act is not facially unconstitutional and reversed the lower court’s injunction barring enforcement. The Act requires covered websites to “obtain verifiable consent” from a parent if a child under the age of 16 seeks to create an account and provide certain information. The lower court found that the Act violated the First Amendment. The Sixth Circuit, in a somewhat splintered opinion, reversed, finding that the Act, although impacting some protected speech and being content-based, passed strict scrutiny.
- Tech Companies sue Minnesota for Social Media Law: NetChoice, a lobbying arm representing technology companies, filed suit against the State of Minnesota for its law requiring this message on all social media platforms: “THE STATE OF MINNESOTA REQUIRES THIS MESSAGE: Some studies have shown that too much social media use is linked to increased mental health symptoms, including anxiety and depression, as well as harm to diet, sleep, and body image. If you need help, call or text 988 or visit 988Lifeline.org.” NetChoice claims that the law violates the First Amendment. Minnesota’s attorney general decided to hold off on enforcing the law until the court rules on its validity.
- SCOTUS Upholds FCC Power to Fine: The Supreme Court, in an 8-1 decision, held that the Federal Communications Commission’s (FCC) process for issuing forfeiture orders against AT&T and Verizon for alleged mishandling of customer location data does not violate the Seventh Amendment right to a jury trial. The Court explained that an FCC forfeiture order does not itself create a binding obligation to pay a penalty because the government cannot collect the money unless the Department of Justice brings a separate enforcement action, which must be tried de novo and can be decided by a jury. Because the FCC’s findings and penalty assessments are only preliminary and have no conclusive legal effect until a court proceeding occurs, the agency may issue those orders without a jury. The Court concluded that the Communications Act’s enforcement scheme preserves the constitutional right to a jury at the stage where liability can actually be enforced.
- First Circuit Affirms Dismissal of Data Breach Class Action for Failure to Allege an Injury Plausibly Traceable to the Breach: In Santos-Pagan v. Bayamon Medical Center (1st Cir., Jun. 11th, 2026), the First Circuit affirmed dismissal of a data breach class action for lack of standing based on failure to allege an injury plausibly traceable to the breach. The defendant medical center experienced a ransomware attack in May 2019 that exposed personally identifiable information and protected health information. The complaint alleged that the breach exposed patients to an increased risk of identity theft, required mitigation efforts, caused out-of-pocket expenses, and diminished the value of their information. In an amended complaint, the plaintiff added an allegation that a cellphone account had been opened in her name after the breach and that she spent approximately $800 addressing the issue. The court found that there were no factual allegations that the information used to open the cellular account originated from the data breach. It noted that temporal proximity alone did not establish causation, although temporal proximity can be one factor supporting traceability. It appeared that there was a gap of four years between the notice of the breach and the opening of the account.
- U.S Designation Imposition of Export Controls on Anthropic’s Fable 5 and Mythos 5 Challenged by User of the Models: As described in the complaint, on Jun. 12th, the Commerce Secretary sent Anthropic a letter warning that Anthropic needed to prevent any foreign nationals (including employees) from accessing its newest frontier models, Fable 5 and Mythos 5, which had been released the general public hours earlier. Unable to impose a governance regime that would achieve this, Anthropic instead took these frontier models down and restricted all access to them. A U.S.-based firm that had incorporated these models into its product, Legion LegalTech, filed a lawsuit in the District of Columbia federal court challenging the government’s authority to impose export controls on artificial intelligence models.
Industry Updates:
- Huntress Reports on Klue.com Incident: Cybersecurity company Huntress reported that its Salesforce instance, along with those of other entities, was potentially impacted by an incident impacting Klue.com. The threat actor group Icarus listed Klue on its leak site. Huntress reported that data including business names, individual names, emails, phone numbers, business addresses, and other sales-related information may have been impacted. Huntress also provided a timeline of the incident. Klue also provided an official update.
- FBI Warns of Malicious Website Redirection Scheme (TDS Abuse): On Jun. 18th, the FBI warned that cybercriminals are abusing Traffic Distribution Systems (TDS) to redirect users to fraudulent websites. Although TDS is a legitimate marketing tool, attackers use it to conceal malicious destinations, evade detection, and route victims through layered redirects to phishing pages, malware, scams, or ransomware access points. These attacks typically start with phishing emails, malicious ads, or compromised websites that send users to a malicious TDS. Attackers often compromise websites by exploiting weak passwords or outdated software. The TDS then filters visitors by factors such as location or device, directing high-value targets to malicious pages while showing harmless content to others. The objective is to steal credentials or access, which attackers may use directly or sell to other cybercriminals. To reduce business exposure, the FBI recommends strengthening endpoint and web infrastructure defenses; regularly auditing CMS, database, FTP, and hosting accounts; enforcing strong, unique passwords; and promptly patching CMS platforms and third-party components that attackers commonly exploit.
- “FortiBleed” Campaign Exploits Stolen Credentials: On Jun. 19th, Fortinet published an analysis of a credential-harvesting campaign, referred to as “FortiBleed,” affecting FortiGate devices. Fortinet clarifies that this activity does not stem from a newly discovered vulnerability and is unrelated to any recent security advisories. The campaign primarily relies on the reuse of previously compromised credentials, coupled with brute-force attacks targeting weak or reused passwords. The effectiveness of these tactics is largely driven by inadequate password hygiene and the absence of multi-factor authentication (MFA). Fortinet has identified potentially affected systems, proactively notified impacted customers, and is coordinating with relevant government agencies. Organizations can reduce their risk exposure by promptly:
- Resetting all credentials, particularly for administrative and remote access accounts;
- Enforcing MFA across all access points;
- Upgrading systems to supported and current versions; and
- Strengthening access controls, including limiting internet-facing management access.
This campaign underscores a persistent risk: attackers continue to successfully exploit weak credential security rather than new technical vulnerabilities. Strong authentication controls and credential hygiene remain critical defenses.
- Google Warns About Ongoing Targeted Campaign Against U.S. Law Firms: On Jun. 5th, Mandiant and Google Threat Intelligence posted “Seeking Counsel: Ongoing Targeted Campaign Against US Law Firms,” warning about social engineering attacks targeting dozens of professional, legal, and financial services in the United States. The threat actor (UNC3753) uses social engineering (phishing emails, vishing phone calls, and sometimes physical visits) to get access to confidential data, exfiltrate it, and seek extortion payments to prevent disclosure of the data. The attacks include posing as IT support in person attempt to exfiltrate information. The post includes a detailed analysis of how the attacks work and how to defend against them. For remediation and hardening, it recommends educating end users, having policies in place for physical access and verification, controls on remote access, strict controls on remote monitoring and screen-sharing, endpoint removable media hardening, monitoring networks and egress, and auditing application logs and access. The post references an FBI Flash Alert, “Silent Ransom Group Impersonating IT Personnel through Social Engineering” (May 26, 2026), which notes that the group has consistently targeted US-based law firms since Spring 2023. Silent Ransomware Group is one of the names tracked with UNC3753.
- Five Eyes Intelligence Agencies Warn that the Evolving Landscape of AI is Rapidly Transforming Cyber Risk: On Jun. 22nd, the Five Eyes Cyber Security Agencies (United States, Canada, United Kingdom, Australia, and New Zealand) issued a call to action, noting “the evolving landscape of artificial intelligence (AI) is rapidly transforming cyber risk, and we must act swiftly to remain ahead.” The alert observes that “frontier Al models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years; it is months.” It reports that AI increases the speed and complexity of attacks, but also offers powerful tools to strengthen defense. The alert urges leaders to: understand and assess risk, readiness and accountability, prioritize foundational cyber security practices and controls, empower cyber leaders with authority and resources, and stay actively engaged as threats and guidance evolve. It includes practical actions to reduce technical risk and operational, financial, and reputational exposure.
Regulatory:
- HIPAA Security Rule Updates Pushed to 2027: The Office of Management and Budget posted an update on the finalization of the HIPAA Security Rule updates that were originally scheduled for final action in May 2026. The changes to the Security Rule would substantially alter the Rule and strengthen the requirements for protecting covered health information. The proposed changes are not classified as a long-term action, and final action has been pushed to July 2027. While it is important to start taking into consideration the new rule’s requirements, it is unclear when they will be finalized.
- HHS OCR Settles Ransomware Investigation with Employer-Sponsored Health Plan: The U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) recently announced a $450,000 settlement with Spencer Gifts LLC Flexible Benefits and Welfare Benefit Plans following a ransomware attack that affected the protected health information of more than 10,000 individuals. OCR alleged that the employer-sponsored group health plan failed to conduct an accurate and thorough HIPAA security risk analysis and lacked compliant Privacy, Security, and Breach Notification Rule policies and procedures before the incident occurred. As part of the resolution, the Plan agreed to implement a two-year corrective action plan requiring a comprehensive risk analysis, updated HIPAA policies and procedures, and workforce training. The settlement, OCR’s 20th ransomware enforcement action and 14th under its Risk Analysis Initiative, reinforces OCR’s continued focus on proactive HIPAA Security Rule compliance and serves as a reminder that cybersecurity preparedness must occur before a cyberattack.
- New Executive Order Gives NSA Power to Designate Covered Frontier AI Models: A recent Executive Order provides further framework for AI development under the current administration. Of particular note is the role given to the NSA in this development. The executive order gives the NSA a prominent role in evaluating and strengthening the security of the most advanced AI systems. Under the order, developers who choose to participate in the voluntary pre-release review program may provide their frontier AI models to designated national security agencies, including the NSA, for testing and assessment. The NSA is tasked with using its expertise in cybersecurity, cryptography, and vulnerability analysis to identify potential security risks, misuse pathways, and weaknesses that could be exploited by foreign adversaries or malicious actors. The order envisions the NSA working alongside other federal agencies and private-sector developers to improve the resilience and security of advanced AI technologies before they are widely deployed. Though the program and submission are voluntary- as per the limits of executive power–the NSA would be given, in essence, a gatekeeping role. How significant that role will be for actual AI adoption or approval will have to develop with time.
- FTC Finalizes Order Against Illuminate Over Student Data Security Failures Affecting More Than 10 Million Students: The Federal Trade Commission (FTC) has finalized an order against Illuminate Education, Inc., resolving allegations that the company failed to implement reasonable safeguards to protect student information, resulting in a data breach affecting approximately 10.1 million students. According to the FTC, Illuminate failed to address known security vulnerabilities. The FTC also alleged that the company failed to timely notify affected schools, students, and parents of the breach, with some notifications occurring nearly two years after the incident. Under the final order, Illuminate must implement a comprehensive information security program, adopt data minimization and retention practices, delete unnecessary personal information, and refrain from misrepresenting its privacy and security practices. The action underscores the FTC’s continued focus on cybersecurity, data minimization, and timely breach notification, particularly where children’s and students’ sensitive information is involved. (put this link on “allegations”.
- New Executive Orders Advance U.S. Quantum Strategy and Cyber Resilience: The United States is accelerating its quantum technology strategy with two new executive orders signed by President Donald Trump – “Ushering in the Next Frontier of Quantum Innovation,” and “Securing the Nation Against Advanced Cryptographic Attacks” — aimed at advancing quantum computing while preparing for the cybersecurity risks it presents. The orders direct federal agencies to strengthen U.S. leadership in quantum technology, with an ambitious goal of developing a powerful quantum computer by 2028. At the same time, the administration is prioritizing cybersecurity by requiring key government systems to transition to post-quantum cryptography by 2030–2031, helping protect sensitive data against future quantum-enabled attacks capable of breaking today’s encryption. Beyond computing, the initiative also calls for deploying quantum sensors across defense and government applications, including navigation in GPS-denied environments and enhanced satellite detection capabilities. The orders further emphasize securing quantum supply chains, protecting intellectual property, and expanding international cooperation as the U.S. competes with China in this strategically important field. As quantum technology continues to mature, organizations should begin evaluating their cryptographic environments and planning for the transition to quantum-resistant security measures. The era of post-quantum cybersecurity is rapidly approaching.
International Updates:
- New UK Data Protection Complaint Requirements Now in Effect: As of Jun. 19th, organizations subject to the UK’s Data (Use and Access) Act 2025 (DUAA) must comply with a new requirement to maintain a formal process for handling data protection complaints. The DUAA gives individuals the right to raise data protection complaints directly with organizations before escalating them to the UK Information Commissioner’s Office (ICO). Controllers must provide a way to submit complaints, acknowledge receipt within 30 days, investigate complaints without undue delay, keep complainants informed throughout the process, and communicate the outcome promptly. The ICO has also issued guidance encouraging organizations to leverage existing complaint procedures, offer multiple reporting channels, train staff to recognize privacy complaints, and maintain records demonstrating compliance. Organizations that have not yet updated their complaint-handling processes should do so promptly to meet these new statutory obligations.
State Actions:
- Vermont Amends Data Broker Legislation Effective January 1, 2027: On Jun. 16th, the Vermont Governor signed a law significantly amending Vermont’s existing data broker registration law by expanding compliance obligations, adding data breach notification requirements, creating new consumer rights, and enhancing registration obligations, as well as increasing penalties for non-compliance. The law expanded several definitions that increase the jurisdiction of the Act. It also broadened the definition of “brokered personal information” by replacing specific data elements with a definition that aligns more closely with GDPR. Among new consumer rights, consumers now have the right to request deletion of their brokered information. And notably, fines for failing to register can incur a $200 per day penalty. Inaccurate or incomplete registration could result in fines of $1,000 a day and a $25,000 penalty for submitting materially incorrect information, plus additional daily fines if timely corrections are not made.
- Vermont Becomes 23rd State with Comprehensive Consumer Privacy Law: On Jun. 16th, the Vermont Governor signed into law the Vermont Data Privacy and Online Surveillance Act (the “Act”), which takes effect on January 1st, 2028. The jurisdictional thresholds for the Act are different from other states: 1) business who control or process the personal data of at least 35,000 Vermont consumers, or 2) control or process the sensitive data of at least 3,000 Vermont residents, or 3) offer for sale the personal data of at least 3,000 Vermont residents. Exemptions apply to a number of businesses, including state agencies, GLBA-regulated financial institutions, HIPAA-covered entities and business associates, and certain nonprofits. The Vermont Attorney General has exclusive enforcement authority. Organizations should review the law to ensure they are meeting the Act’s various consumer, data protection, and other requirements.
This publication is intended for general informational purposes only and does not constitute legal advice or a solicitation to provide legal services. The information in this publication is not intended to create, and receipt of it does not constitute, a lawyer-client relationship. Readers should not act upon this information without seeking professional legal counsel. The views and opinions expressed herein represent those of the individual author only and are not necessarily the views of Clark Hill PLC. Although we attempt to ensure that postings on our website are complete, accurate, and up to date, we assume no responsibility for their completeness, accuracy, or timeliness.