Robinson Cole LLP
High Contrast Mode
Marquee

Data Privacy + Cybersecurity

Data privacy and cybersecurity increasingly affects all businesses and industries. To handle this complex and rapidly changing area of law, our Data Privacy + Cybersecurity practice group collaborates with lawyers throughout Robinson+Cole’s diverse practice areas.

Each member of our highly experienced team understands the spectrum of challenges businesses may face with evolving digital technologies. We are dedicated to helping you achieve success, providing you with the right resources to match your specific business needs.

Our Services

Our clients include public and private companies in all industries, including:

  • Software companies
  • Companies with websites and mobile apps
  • Health care providers and hospital systems
  • Retail and marketing companies
  • Higher education providers
  • Start-up companies
  • Tax-exempt organizations
  • Utilities, manufacturing, energy, and wireless telecommunications service providers

Our team regularly works with federal and state data privacy and security rules and regulations, including:

  • California Consumer Privacy Act (CCPA) and Privacy Rights Act and implementing regulations and state data privacy laws and emerging privacy regulations
  • Laws and regulations applicable to tracking technology and pixels
  • Children's Online Privacy Protection Act (COPPA)
  • Controlling the Assault of Non-Solicited Pornography and Marketing Act (CAN-SPAM Act)
  • European Union (EU) General Data Protection Regulation (GDPR) and revised Standard Contractual Clauses (SCCs)
  • Fair Credit Reporting Act (FCRA)
  • Family Educational Rights and Privacy Act (FERPA)
  • Federal Aviation Administration’s (FAA) Small Unmanned Aerial Systems (UAS) regulations (Part 107), and state and local laws related to the use of UAS and privacy concerns
  • Federal Trade Commission Act (FTC Act)
  • FTC's Telemarketing Sales Rule (TSR)
  • Gramm-Leach-Bliley Act (GLBA)
  • Health Insurance Portability and Accountability Act (HIPAA)
  • New York Department of Financial Services Cybersecurity Regulations
  • Consumer protection enforcement actions by Attorneys General or federal agencies including the Office for Civil Rights and the Federal Trade Commission
  • SEC cybersecurity regulations
  • State data security laws and regulations, including implementation of statutorily required Written Information Security Programs
  • State and federal data privacy and security laws and regulations related to employee and workplace privacy
  • State specific biometric information privacy laws and regulations
  • Telephone Consumer Protection Act (TCPA)
  • Video Privacy Protection Act (VPPA)

Our lawyers are knowledgeable about data collection technology, including the use of tracking technology like cookies and pixels for targeted advertising and behavioral advertising. We also understand the value and risks of collecting and using data for marketing and strategic purposes.

The team has a significant HIPAA compliance practice and assists covered entities and business associates navigate the intricacies of HIPAA, guidance from the OCR, and OCR enforcement actions. We have vast experience with HIPAA data breach response and statutory requirements.

Our Financial Services Cyber-Compliance team helps protect our banking, insurance, and financial services clients on a wide range of issues, including implementation of enterprise-wide cybersecurity programs, and adoption of required written cybersecurity policies and procedures to comply with state and federal laws.

Our Team

Our team is well-versed in incident and data breach response, mitigation, remediation, coordination, and litigation, including investigations by the U.S. Office for Civil Rights and state Attorneys General (AGs). We coordinate forensic investigations and mitigation tactics in the event of ransomware or other cyber attacks.

Our attorneys advise our clients in data mapping and development of enterprise-wide privacy and security plans, and compliance with privacy requirements and industry-specific regulations. We also advise on sharing and transfer of collected data and assist with strategy to minimize risk associated with the collection, use and disclosure of data. We regularly structure arrangements relating to data transfer, and prepare technology contracts and information security addenda to outline appropriate protection obligations for the sharing and care of customer and patient data.

We promote practices and policies to safeguard data against accidental or deliberate disclosure, including security programs. We provide tailored education programs for employees, executives and boards. We have completed dozens of cybersecurity tabletop exercises, which are designed to experience a live cybersecurity event and response.

Our lawyers also work with clients to develop website and mobile app privacy policies and terms and conditions of use, and social media policies, practices, and procedures.

Our Robinson+Cole team members also author the Data Privacy + Cybersecurity Insider blog, providing clients with timely, thoughtful, and cutting-edge legal news and perspectives about data privacy and cybersecurity issues. The widely-recognized blog has received multiple Readers Choice Awards distinction from JD Supra and featured in FeedSpot's "100 Best Infosec Blogs and Websites in 2025."

We actively speak at industry-sponsored programs on data privacy and cybersecurity developments, cases, trends, and agendas. We proactively track updates to federal and state privacy and security laws and proposals.

Our Data Privacy + Cybersecurity team is here to help you navigate the ever-evolving complexities of nationwide laws and regulations, providing skilled legal services for businesses in the digital sphere.

Data Privacy + Cybersecurity Insider


Threat Actors Aligned with China Attacking U.S. University Physics + Engineering Depts.

Researchers at cybersecurity firm Proofpoint have discovered that a “suspected China-aligned threat cluster named UNK_MassTraction” is attacking mailservers belonging to physics and engineering departments of U.S. and Canadian based universities. They have been tracking the activity since May 2026. The threat actors are exploiting multiple n-day cross-site scripting vulnerabilities in Roundcube mailservers to “steal credentials and either install a webshell for follow-on access or deploy the VShell backdoor into the server’s memory.” The threat actors are targeting administrators and professors that have national security ties or are focusing on astrophysics and particle physics. According to Proofpoint, “the exploit only requires that the email is opened in the mail client to achieve access to the mailserver.” The messages sent to the administrators and professors were generic and innocuous, including resembling marketing or spam messages, so when the targets open the message, they overlook it and fail to report it to IT. However, the mere opening of the email (without having to interact with it) was enough for the threat actors to gain access to the content. The scheme is quite elaborate, and if you want to learn more about its technicalities, read Proofpoint’s blog outlining the scheme in detail. Proofpoint reminds universities that “email delivery can facilitate compromise of mailservers, and that Chinese operators will continue to treat them like any other edge device. Defenders should prioritize defending the mailservers of their networks as thoroughly as they do their VPN concentrators and other remote access nodes on their networks.” I would add that universities conducting research related to national security, physics, astrophysics, particle physics, and engineering recognize that adversaries are very interested in stealing the vital and valuable information they maintain. Therefore, they should consider implementing strong cybersecurity measures to protect that information, including training all administrators and professors in those departments about how they are specifically targeted by adversaries, and their crucial role in protecting the information from disclosure for national security.

Visit Blog

Chatrie + the Shrinking Third-Party Doctrine: What Data Custodians Should Watch

This post was authored by William S. Fallon, Associate in Robinson+Cole’s Business Litigation group. In Chatrie v. United States, No. 25-112 (U.S. June 29, 2026), the Supreme Court took another step in redefining digital privacy under the Fourth Amendment, building directly on its landmark decision in Carpenter v. United States, 585 U.S. 296 (2018). These cases signal that businesses holding customer data face an evolving legal landscape worth understanding. The Fourth Amendment protects “persons, houses, papers, and effects” against unreasonable government searches, and thus generally requires a warrant based on probable cause before the government can search people, their homes, or their belongings. Under the long-standing “third-party doctrine,” however, information voluntarily shared with a third-party company, like a bank or phone company, historically lost that protection. In Carpenter, 585 U.S. at 310 n.3, 316, though, the Court carved out a “narrow” exception, holding that police need a warrant to obtain seven days of a cellphone user’s location data from a wireless carrier, even though the carrier held that location data , not the cellphone user.  Chatrie went even further—the Court held that police need a warrant to access a user’s Google location history, even if the data covers only two hours, is held by a third-party company, and is voluntarily shared by the user. The Court again refused to apply the third-party doctrine, reasoning that such location data is “not truly ‘shared’” simply because a user enables Google to track his or her location. Chatrie’s reasoning matters for any business that holds customer data. The Supreme Court now treats information on a company’s servers—emails, photographs, location logs, etc.—as information a user might “reasonably view[] as his own,” even when that information has been voluntarily conveyed to the company. Custodians of that data increasingly find themselves positioned between their customers and the government, fielding law enforcement demands for the customers’ data. As courts continue to recognize strong privacy interests in hosted data, those protections influence a custodian’s legal exposure, shape its obligations when responding to law enforcement and government demands, and inform customer expectations regarding the security and privacy of their data. The third-party doctrine may continue to change—and erode. Justice Gorsuch’s separate opinions in Carpenter and Chatrie illustrate where this could lead. In both Carpenter and Chatrie, the Court sought to find an escape hatch from its third-party doctrine without expressly overruling the doctrine—an approach that detractors view as confusing—but Justice Gorsuch believes he has identified a workable route forward. Building off his separate opinion in Carpenter, where he urged an approach to Fourth Amendment protections grounded in property law and statutes, Justice Gorsuch’s Chatrie concurrence applied those theories, treating location history as Chatrie’s personal property under state digital-property statutes and finding “hints” of the same reasoning in the majority’s acknowledgement that users regard such data as their own. In practice, this approach would look to what statutes, traditional property law, and a company’s own contracts say about who owns and controls customer data, and it would use those sources to decide whether the data stays protected once a customer hands it over. For companies that hold customer data, that makes the terms of their privacy policies, terms of service, and consent forms all the more important, because those documents may increasingly bear on how customer data is treated constitutionally. Whatever direction the doctrine takes, Chatrie is a useful signal that courts are willing to recognize privacy interests in third party data , and that businesses should account for that trend as they design their data practices.

Visit Blog

Kenneth Cole Website Tracking Case Dismissed After Cookie Opt-Out Claims

A proposed class action accusing Kenneth Cole Productions, Inc., of unlawfully sharing website visitor data with Meta, Google, and other third parties was voluntarily dismissed in the Northern District of California. The plaintiffs alleged that Kenneth Cole used third-party tracking tools on its website that allowed those companies to collect data about consumers’ interactions with the site, including after users had opted out through the site’s cookie-consent banner. The complaint asserted invasion of privacy, intrusion upon seclusion, unjust enrichment, and common-law fraud claims, and alleged violations of the wiretapping and pen-register provisions of the California Invasion of Privacy Act.  Last week, the named plaintiffs filed a notice voluntarily dismissing all of their claims with prejudice, while preserving the ability of putative class members to bring their own claims. The court acknowledged the dismissal the same day, ordered that each side bear their own attorneys’ fees and costs, and directed the clerk to terminate the case. The reason for the dismissal, or whether the parties reached any settlement, is unknown. For companies, the takeaway is not that website tracking litigation risk has faded. It is that cookie banners, consent tools, pixels, tags, session replay, analytics tools, and advertising integrations need to work exactly as represented to users. Companies should regularly test whether opt-out signals actually stop the data flows they are supposed to stop, map which thirdparties receive website event data, review vendor configurations, and align privacy disclosures with the site’s technical reality. This is especially important where plaintiffs continue to plead website tracking claims under privacy, wiretapping, pen-register, fraud, and unjust enrichment theories.

Visit Blog

Garden State Plants New Data Broker Rule

On June 30, 2026, New Jersey’s Governor Mikie Sherrill signed a new data broker law, largely effective immediately, that adds significant new obligations for businesses involved in personal data sales. The law reaches traditional data brokers that collect or purchase personal data about consumers with whom they do not have a direct relationship and then sell or license that information to third parties. It also creates obligations for “data collectors,” meaning businesses or business units that collect personal data directly from consumers and then sell or license that information to data brokers. A central feature of the law is an annual registration requirement for covered data brokers and data collectors engaged in selling or licensing New Jersey consumers’ personal data . The state’s Division of Consumer Affairs will establish and maintain a public registry that includes contact information, privacy policy information, website information, and relevant opt-out information for each registrant. Registration fees are based on volume, starting at $5,000 for 100,000 or fewer New Jersey consumers and increasing to $1.5 million for entities involving personal data of more than 4.5 million New Jersey consumers. Registration submissions must address opt-out rights, deletion rights, activities from which individuals may not opt out, purchaser credentialing, cybersecurity event history, information concerning individuals under 18, and processors handling personal data on the entity’s behalf. The law also prohibits data brokers and data collectors from selling or licensing sensitive data, and it separately amends New Jersey’s privacy law to prohibit controllers from selling sensitive data regardless of processing volume. Sensitive data includes categories such as health information, certain financial account information, citizenship or immigration status, genetic or biometric data used for identification, personal data collected from a known child, and precise geolocation data. The statute includes exclusions for certain regulated data and entities, including specified health, financial, insurance, consumer reporting, government, research, and securities-related contexts. Civil penalties include $2,500 per day for registration or update failures and $50,000 per record for certain sensitive data violations. Although most of the law took effect immediately, the registry provision remains inoperative for 270 days following enactment. For businesses holding data about New Jersey residents, the new law reinforces the need for accurate data inventories, clear data sale and licensing arrangement oversight, and careful review of any sensitive data practices. As state privacy laws become more specific, companies should be prepared to show not only what their policies say, but how their data practices actually work.

Visit Blog

FTC Frames AI Output Steering as a Potential Section 5 Risk

The Federal Trade Commission’s (FTC) proposed policy statement puts a new consumer-protection frame around AI model behavior: if an AI company represents that its system is designed to deliver accurate, objective, or user-directed outputs, the company may create a reasonable consumer expectation that the system is trying to provide the best answer it can within its technical limits. The FTC’s concern is that an AI provider could secretly steer outputs toward undisclosed objectives, including ideological objectives, while still marketing the system as accurate, useful, or fit for the user’s task. In the FTC’s view, that kind of hidden steering may be deceptive under Section 5 of the FTC Act, even if the company says it is doing so to comply with state law.  The proposed statement is especially notable because it connects AI accuracy, disclosures, and state AI regulation in one enforcement theory. The FTC says AI products are not exempt from Section 5, and points to prior enforcement involving deceptive AI-related claims about performance, efficacy, and product capabilities. The proposal also aims at state AI laws that the FTC believes could pressure companies to alter model outputs, including Colorado’s revised AI law, which the statement says may create incentives for companies to suppress accuracy or prioritize other objectives without telling users. The FTC further notes that state law may be impliedly preempted where it is inconsistent with or otherwise conflicts with the federal consumer protection framework. For AI developers and enterprise customers, the practical takeaway is that disclosures, product claims, and governance controls around model behavior are going to matter. The FTC acknowledges that companies can shape user expectations through truthful, non-misleading disclosures, but warns that those disclosures must be clear, conspicuous, prominent, and strong enough to counter any contrary impression created by marketing or product design. Comments on the proposed policy statement are due July 31, 2026, giving AI companies, customers, and other stakeholders a short window to weigh in on how the FTC should draw the line between permissible model governance and deceptive manipulation of AI outputs. Read the full statement here.

Visit Blog

Privacy Tip #498 – ShinyHunters Hits Medtronic

Threat group ShinyHunters continues its incessant campaign to torture companies trying to provide products and services to consumers, with no indication of letting up. One of its latest victims, Medtronic, the manufacturer of medical devices, healthcare technologies, and therapies, confirmed that it was the victim of an April cyberattack where over nine million records from the company were stolen. ShinyHunters claimed responsibility. Medtronic recently notified affected customers, informing them that the data exposed during the attack included some customers’ names, contact information, dates of birth, Social Security numbers, and health-related information. Although the data was compromised during the attack, Medtronic has confirmed that the attack did not impact its medical devices, and they remain safe to use. Medtronic is offering affected customers 24 months of credit monitoring and identity theft protection services. If you receive a letter from Medtronic, it is important to follow the instructions provided. While recent arrests and extraditions of individuals linked to Scattered Spider (another notoriously active threat actor group) are a positive development, I’m hopeful that similar law enforcement progress against ShinyHunters associates will follow soon.

Visit Blog

Threat Actors Using FIFA Spoofed Websites to Launch Attacks

The FBI and the Internet Crime Complaint Center (IC3) has issued a public service announcement warning the public about a surge in malicious spoofed websites related to the FIFA games. Cybercriminals are using these fake sites to impersonate FIFA, tricking fans into giving up personal information, credit card numbers, or buying counterfeit tickets and fake travel packages. “The malicious domains employ typosquatting and alternative top-level domains (TLDs) to impersonate the official FIFA domain (fifa.com), deceiving users into divulging sensitive information or purchasing counterfeit tickets and hospitality packages. The sophistication of these sites is such that even experienced users may be fooled, especially as attackers leverage HTTPS certificates and cloned branding.” Two cybersecurity research firms have identified over 1400 malicious spoofed websites. These websites include operating fake visa and travel portals, and fraudulent hospitality and ticketing sites. In addition, “the scale of credential theft is staggering, with more than 1.5 million compromised accounts and 7,300+ leaked credentials related to FIFA and its partners being traded on the dark web.” Enjoy watching the games, but don’t let these fake domains fool or scam you. Here are some tips to avoid becoming a victim: Access FIFA resources only via https://www.fifa.com and official subdomains. Block and monitor the IOCs listed above at the network perimeter. Educate staff and fans about the risks of fake ticketing and job sites. Monitor for phishing campaigns using World Cup themes. Coordinate with law enforcement and FIFA’s official cybersecurity partners for incident response.

Visit Blog

Message Received: PA Courts Say TCPA Do-Not-Call Rules Apply to Text Messages

On June 17, 2026, the U.S. District Court for the Eastern District of Pennsylvania denied Brown-Daub Chevrolet of Nazareth’s motion to dismiss a putative class action alleging violations of the Telephone Consumer Protection Act’s (TCPA) National Do Not Call Registry (DNCR) provisions. In Pero v. Brown-Daub Chevrolet of Nazareth (E.D. Pa. June 17, 2026), the court considered whether a text message is a “telephone call” under Section 227(c) of the TCPA, and concluded that it is. The TCPA restricts certain telemarketing communications and, through Section 227(c), provides a private right of action to a person who receives more than one prohibited telephone call within a 12-month period. The plaintiff alleged that she registered her number on the DNCR in 2021, gave the dealership her number in October 2024 to receive truck sales information, later opted out of texts, and then received six unwanted texts between January 8 and March 28, 2025. The court’s analysis is notable in the current  environment. The Supreme Court recognized that Chevron deference has been abolished and that courts must exercise independent judgment rather than defer automatically to agency interpretations. At the same time, it emphasized that agency interpretations may still deserve respect as the product of “a body of experience and informed judgment,” particularly where Congress delegated implementation authority to the FCC. Turning to the statutory text, the court focused on Section 227(a)(4), which defines “telephone solicitation” as the initiation of a “telephone call or message” for telemarketing purposes. Although texts did not exist when Congress enacted the TCPA, the court found that Congress “intended to prohibit more than solicitations by telephone” because it also used the phrase “by message.” Applying ordinary meaning, the court concluded that a text message is “a communication (message) transmitted by a telephone,” and therefore falls within the statute. The court also gave “considerable weight” to the FCC’s interpretation and noted the FCC’s 2024 clarification that DNCR protections extend to text messages. Considering the statutory language, FCC rules, and the “overwhelming majority of courts,” the court held that texts are calls under Section 227(c). For companies using SMS campaigns, they should treat texts to DNCR-listed numbers as regulated telemarketing contacts, confirm the required consent, and make opt-outs durable across systems and personnel. The decision also suggests that post-Loper Bright challenges to FCC TCPA interpretations may face headwinds where the agency’s position aligns with statutory text and the weight of judicial authority.

Visit Blog

Another CIPA Warning Shot: DraftKings Sued Over Website Tracking Tools

DraftKings is the latest target in California’s wave of California Invasion of Privacy Act (CIPA) website-tracking litigation. In Hughes v. DraftKings Inc., filed in the Central District of California, plaintiff Dana Hughes alleges that DraftKings operated its website with data broker software from NextRoll, The Trade Desk, and Comscore that secretly collected data about website visitors, their devices, locations, page views, and browser characteristics to identify and track users for marketing and profiling purposes. The complaint alleges that Hughes visited the DraftKings website and that data reasonably likely to identify her was transmitted to at least three third parties through code running on the site.  The core CIPA theory is familiar but still high stakes: the complaint claims the tracking code operated as an unlawful “trap and trace device” under California Penal Code section 638.51 because it captured electronic signals and identifying information from visitors’ devices without a court order or consent. Hughes seeks class certification, statutory damages under CIPA, punitive damages, restitution, disgorgement, injunctive relief, attorneys’ fees, and other relief. For companies, the warning is straightforward: plaintiffs are continuing to scrutinize routine website advertising and analytics tools through the lens of California’s wiretap and trap-and-trace laws. The DraftKings complaint targets third-party tags that many businesses may view as standard marketing infrastructure, including retargeting pixels, cookie-based identifiers, browser fingerprinting, cookie matching, and cross-site tracking tools. Businesses that receive CIPA demands or complaints should quickly map which third-party scripts run on their sites, what data those scripts collect or transmit, whether the vendors are data brokers or advertising technology providers, and what consent, disclosure, and vendor controls are in place before responding.

Visit Blog

Five Eyes Issue “Call to Action” to Protect Against AI Cyber Threats

The leaders of the Five Eyes cyber security agencies, representing Australia, New Zealand, Canada, the United Kingdom, and the United States, issued an alert on June 22, 2026, entitled “The AI Shift in Cyber Risk: Why Leaders Must Act Now” urging organizations to a “call to action” to protect against cyber threats both for organizations and society as a whole. The Five Eyes are expressing urgency because artificial intelligence (AI) is quickly changing cyber risk, and organizations need to act fast to keep up. The call to action is informed by the fact that AI can improve cyber defense, but it also makes cyber-attacks faster, larger, and more advanced, including how attacks happen and how organizations can defend against them. Because of this, the Five Eyes urge that cyber resilience is critical for business continuity, market confidence, and long-term success. The Five Eyes encourage leaders to: understand and assess risks, readiness, and accountability  focus on basic cybersecurity practices and controls  give cyber leaders the authority and resources they need  stay involved as threats and guidance change  The alert emphasizes how “success for organizations depends on getting the basics right, acting quickly, and making cybersecurity part of the core business strategy.” It stresses that cyber risk is not just a technical issue—it is a business risk and a leadership responsibility. Boards and executives must ensure systems are resilient and work under pressure. It is not enough to have controls; leaders must know those controls will work during a real incident. This may require rethinking past decisions and using AI carefully to strengthen defenses, not just improve efficiency. The alert outlines key actions for leaders, including: Build systems to be secure from the start and by default  Do not rely on a single solution—use multiple layers of defense  Expect new and unknown vulnerabilities as AI evolves, including zero-day risks It also lists “urgent” practical actions: Reduce your attack surface: Limit unnecessary access and external connections. Only expose systems when truly needed.  Speed up patching: AI is reducing the time between finding and exploiting vulnerabilities. Delays increase risk, especially for older systems.  Fix legacy systems: Unsupported systems are easy targets and create serious risk.  Strengthen access controls: Limit who can access critical systems. Use strong authentication and regularly review permissions.  Prepare for incidents: Test response plans, train teams, and assume breaches will happen. Focus on quick containment and recovery. It also suggests that leaders use AI to strengthen defense against cyber-attacks. Getting ahead of cyber-attacks when threat actors are using AI requires continued preparedness and the ability to use tools to detect, monitor, and defend against them, including AI tools developed for defense purposes. If ever there was digital warfare, it is now with the proliferation of AI enhanced tools. Leaders of all organizations should review the recommendations by the Five Eyes and implement them for the preparedness of the organization and society.

Visit Blog

AI in Insurance: The Real Test Is Readiness, Not Technology

After several years of experimenting with generative AI, machine learning, and AI agents, many insurers are no longer asking whether AI belongs in the business. The harder question is whether a pilot is ready to scale. The answer usually is not found in the model architecture or the novelty of the tool. It is found in how the organization talks about AI: whether leaders can tie the use case to specific business outcomes, define the process changes required, and explain how human teams will rely on the output in day-to-day work. That distinction matters because AI can easily become a solution in search of a problem. A technically impressive pilot may still fail if it addresses an “interesting” problem rather than an important one. The AI use cases most likely to scale are the ones embedded into core workflows, not bolted on as side experiments. In insurance, that often means giving underwriters, claims teams, or operations personnel tools that help them review, prioritize, and decide more effectively, while preserving clear human oversight and accountability. For carriers, the scaling question is also a governance question. Before expanding an AI pilot, organizations need to be clear about whether AI is making decisions, recommending actions, summarizing information, or helping employees work faster. They also need data showing whether users trust the tool, when they override it, and where it may create downstream risk across interconnected systems. Moving too fast without governance creates obvious regulatory and operational concerns. But waiting too long has its own risk. The carriers best positioned for the next phase of AI adoption will be those that treat scaling as a readiness exercise: aligning business value, workflow design, oversight, infrastructure, and regulatory expectations before the pilot becomes part of the enterprise.

Visit Blog

Privacy Tip #497 – LastPass Security Incident Raises Concern for Targeted Phishing Attacks

LastPass has confirmed that a security incident with a vendor, a third-party market intelligence platform “which integrates with our Salesforce and Gong systems” has compromised some customers information. As a result, the threat actor was able to use credentials to access LastPass customer data within its Salesforce environment. The compromised information includes “business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.” LastPass is recommending that customers: “remain vigilant of potential phishing attacks or social engineering attempts, which could leverage exposed contact details. Always exercise caution regarding unsolicited communications, including emails, phone calls, or requests for sensitive information. Please remember that no one at LastPass will ever ask for your master password. All official communication from LastPass comes through our trusted support channels. “ These are sound tips generally, but particularly helpful if you have a LastPass account.

Visit Blog

Darktrace Report Highlights Cyber Threats Against Global Sporting Sector

In a recently released report titled Cybersecurity in Global Sport: Threats, Signals, and Strategic Implications for a Digitized Industry, cybersecurity firm Darktrace has outlined “the current challenges the global sporting sector faces and...forward-looking views on future challenges as AI increasingly becomes adopted across the sector.” The Report’s conclusions were the result of a survey to 875 IT cybersecurity professionals across sports organizations located in the U.S., U.K., Australia, and Germany. Because the global sports industry “has undergone a rapid and continuous digital transformation” (including digital ticketing platforms, broadcasting, mobile applications, and third-party vendor support), and sports organizations are adopting generative AI and agentic AI tools, emerging cybersecurity threats are targeting these organizations. The Report’s key takeaways include: 84% of professional sports organizations surveyed have experienced at least one cyber incident in the past 12 months, with more than half (57%) hit multiple times. This underscores that cyber risk is already an operational issue for the sector. 34% of respondents cited stadium operations as the most critical function to protect during a live event, reinforcing that cyber resilience in sport is defined by high-visibility moments where downtime is least acceptable. Sports sector customers received 19% more phishing emails than non-sports sector customers, reinforcing that email and identity remain dominant attack vectors for sports organizations. 21% of phishing emails targeting sports sector customers were sent to VIPs, while 37% contained novel social engineering techniques, highlighting how attackers are focusing on high value identities and adapting tactics to exploit urgency, trust, and operational complexity in the sports sector. 47% of respondents cited AI prompt risks and attacks and AI development risks and deployment as top concerns for AI use within their organizations. 72% of IT cybersecurity professionals from sports organizations surveyed believe AI will increase cyber risk over the next 12 months as adoption grows in high stakes areas including stadium operations, ticketing and fan engagement, and business operations. Sports organizations have been victimized by various threats including: “client-side payment skimming, ransomware outbreaks, and compromise of ecommerce infrastructure through third-party scripts. Fan platforms and mobile applications have been accessed via exposed keys and weak API security, placing large user populations at risk.” Darktrace suggests that organizations treat cyber risk “as an operational and governance challenge” to be resilient against attacks. This includes: 1.         Threat modeling for emerging technologies, including AI misuse; 2.         Rigorous supply chain governance and vendor access control; 3.         Strong segmentation across IT, OT, and fan-facing systems; 4.         Identity-centric security with anomaly detection and universal multi-factor authentication (MFA); 5.         Phishing resilience across all channels, including QR-based vectors; and 6.         Operational playbooks aligned to live event constraints. The Report is a must read for those in the sports sector

Visit Blog

ShinyHunters Targeting Higher Education Sector

Researchers from Mandiant and Google Threat Intelligence Group are warning the higher education sector, including universities, that ShinyHunters has exploited an Oracle PeopleSoft zero-day vulnerability and has “potentially infiltrated the networks of more than 100 organizations in an attack spree that largely impacted higher education.” ShinyHunters has reportedly started publishing the names of the compromised victims and stolen data. The vulnerability (CVE-2026-35273) “allows unauthorized attackers to execute remote code and takeover affected servers.” Oracle has published mitigation steps, but a patch has not yet been released. According to Mandiant, “This campaign is still active.” Google adds that “most of the potential victim pool is based in the United States and 68% are in the higher education sector.” If you are in the higher education sector, implement Oracle’s mitigation steps  as soon as possible, and look out for a released patch.

Visit Blog

Honey, Where’s the Harm?

A recent court order from the Northern District of California offers a useful reminder that not every alleged collection of browsing data will support an invasion-of-privacy claim. In Campbell v. Honey Science, LLC (N.D. Cal. June 15, 2026), the plaintiffs alleged that PayPal’s Honey browser extension promised to search for and apply the “best” coupons or discount codes when users shopped online, but sometimes failed to provide the lowest available price. According to the complaint, Honey allegedly did not actually search the internet for discount codes and instead used codes from affiliate networks, a website, or Honey subscribers, while also allegedly maintaining vendor agreements that affected which discounts would be applied. The plaintiffs asserted claims under California’s Unfair Competition Law, unjust enrichment, and invasion of privacy. On the invasion of privacy front, the plaintiffs alleged that Honey examined users’ visited websites and browser cookies without adequate disclosure or consent. The court assumed, for purposes of the motion, that browsing history could involve a legally protected privacy interest and a reasonable expectation of privacy. However, the court held that this was not enough. To state a California invasion-of-privacy claim, according to the court, the plaintiffs also had to allege conduct that was “highly offensive” and amounted to a serious invasion of privacy. That element turned on context. The court contrasted Honey with cases involving more surreptitious tracking, including tracking after a user logged out of an account. Honey, by contrast, was a browser extension downloaded for the “express purpose” of monitoring online shopping activity and applying coupon codes at checkout. Therefore, the court held that the alleged collection looked more like “routine commercial behavior” than a highly offensive privacy intrusion. The court also held that the pleading lacked the details needed to turn tracking into an actionable privacy claim. The plaintiffs did not allege what specific browsing behavior Honey tracked, what information was collected, or why that information was “embarrassing, invasive, or otherwise private” enough to make the collection highly offensive. The court rejected the idea that collection of browsing data, standing alone, was enough “without more detail.” Browser extensions, plug-ins, apps, shopping tools, and loyalty technologies should still be built around clear disclosures, appropriate consent flows, and data minimization. Still, where data collection aligns with the product’s apparent function, plaintiffs may need specific allegations of sensitive, unexpected, or intrusive tracking to state a privacy claim.

Visit Blog

Experience


Software + Technology Contract Negotiations

Represented multiple companies in the negotiation of software and technology contracts with third-party vendors.

Start-Up Policy Development

Worked with multiple start-up organizations in developing privacy policies and terms of use for websites and mobile applications, as well as privacy and security plans and compliance programs.

Data Breach Assistance

Assisted dozens of organizations with reportable data breaches, including notification, mitigation, and regulatory enforcement, as well as class action defense.



News


July 15, 2026

Robinson+Cole Unites Multidisciplinary Sports Capabilities Under New Industry Team

Today, Robinson+Cole announced the formalization of its Professional + Collegiate Sports industry team, bringing together attorneys and professionals from the firm’s Immigration, Labor + Employment, Litigation, Education, Real Estate, Construction Law, Intellectual Property, Data Privacy, and Artificial Intelligence practices. The team draws on the firm’s extensive experience in these areas to provide coordinated counsel to sports leagues and teams, institutions, talent—athletes and coaches, investors, and sports-related businesses as they navigate issues involving name, image, and likeness (NIL), Title IX compliance, global mobility and sports tourism, media rights, private investment, emerging technologies, venue development, and the continued growth of women’s sports. "The sports industry represents an estimated $2.3 trillion global economy, and its continued growth is creating both opportunities and complexity across professional and collegiate athletics," said Robert C. Seiger, Chair of the new team. "As the sports industry continues to evolve, clients are increasingly seeking counsel that spans multiple disciplines and aligns with their broader strategic objectives. The formalization of this team reflects that demand and our commitment to serving clients across the sports ecosystem through an integrated approach." The team's focus will center on three strategic areas: Sports Immigration and Talent Mobility: Visa strategy, athlete and coach immigration, executive movement, global talent support, compliance, and mobility planning. Sports Venues, Infrastructure, and Development: Stadium and arena projects, training facilities, leasing and real estate transactions, construction and infrastructure matters, public and private financing, naming rights, sponsorship arrangements, and land use considerations. Collegiate Athletics and Institutional Risk Management: NIL matters, Title IX compliance, eligibility issues, employment matters, governance, investigations, litigation, licensing, and institutional risk management. Robinson+Cole's work spans athlete and executive mobility, intellectual property protection, commercial transactions, venue development, employment matters, investigations, litigation, and regulatory compliance. Representative matters include providing immigration and mobility services for NHL, NFL, MLS, and NWSL organizations, obtaining an industry-first O-1 visa for an IndyCar race team, representing professional race drivers and teams, managing trademark matters for high-profile sports figures, advising a WNBA organization on the design and construction of a new training facility, and handling real estate and leasing matters involving major sports properties. "This team reflects Robinson+Cole’s significant strength and capability across multiple disciplines to address the full range of issues facing sports organizations," said J. Michael Wirvin, the firm’s Managing Partner. "Many of the challenges in today’s sports industry do not fit neatly within a single practice area. By formalizing this effort, we are creating a more coordinated experience for clients while positioning the firm to continue growing alongside this dynamic industry." Beyond its client work, Robinson+Cole is actively engaged in advancing the sports industry through leadership, scholarship, and engagement. Team members regularly contribute to national conversations on emerging sports law developments and are frequently sought by media outlets for commentary on issues affecting professional and collegiate athletics, most recently USA Today and the Sports Business Journal. They also participate in leading industry organizations, such as the Sports Lawyers Association, where Seiger currently serves as Chair of the Immigration Committee. The firm is recognized for its role at the intersection of sports and global talent mobility.

Harnessing decades of collective experience, the team offers coordinated, cross-disciplinary business, operational, and legal counsel to sports industry stakeholders
July 8, 2026

Linn Freedman Provides Context On Info Stolen in Data Breach

Massachusetts Lawyers Weekly
June 29, 2026

Linn Freedman Recognized Among 2026 Cybersecurity/Data Privacy “Go To Lawyers”

Massachusetts Lawyers Weekly
July 15, 2026

Robinson+Cole Unites Multidisciplinary Sports Capabilities Under New Industry Team

Today, Robinson+Cole announced the formalization of its Professional + Collegiate Sports industry team, bringing together attorneys and professionals from the firm’s Immigration, Labor + Employment, Litigation, Education, Real Estate, Construction Law, Intellectual Property, Data Privacy, and Artificial Intelligence practices. The team draws on the firm’s extensive experience in these areas to provide coordinated counsel to sports leagues and teams, institutions, talent—athletes and coaches, investors, and sports-related businesses as they navigate issues involving name, image, and likeness (NIL), Title IX compliance, global mobility and sports tourism, media rights, private investment, emerging technologies, venue development, and the continued growth of women’s sports. "The sports industry represents an estimated $2.3 trillion global economy, and its continued growth is creating both opportunities and complexity across professional and collegiate athletics," said Robert C. Seiger, Chair of the new team. "As the sports industry continues to evolve, clients are increasingly seeking counsel that spans multiple disciplines and aligns with their broader strategic objectives. The formalization of this team reflects that demand and our commitment to serving clients across the sports ecosystem through an integrated approach." The team's focus will center on three strategic areas: Sports Immigration and Talent Mobility: Visa strategy, athlete and coach immigration, executive movement, global talent support, compliance, and mobility planning. Sports Venues, Infrastructure, and Development: Stadium and arena projects, training facilities, leasing and real estate transactions, construction and infrastructure matters, public and private financing, naming rights, sponsorship arrangements, and land use considerations. Collegiate Athletics and Institutional Risk Management: NIL matters, Title IX compliance, eligibility issues, employment matters, governance, investigations, litigation, licensing, and institutional risk management. Robinson+Cole's work spans athlete and executive mobility, intellectual property protection, commercial transactions, venue development, employment matters, investigations, litigation, and regulatory compliance. Representative matters include providing immigration and mobility services for NHL, NFL, MLS, and NWSL organizations, obtaining an industry-first O-1 visa for an IndyCar race team, representing professional race drivers and teams, managing trademark matters for high-profile sports figures, advising a WNBA organization on the design and construction of a new training facility, and handling real estate and leasing matters involving major sports properties. "This team reflects Robinson+Cole’s significant strength and capability across multiple disciplines to address the full range of issues facing sports organizations," said J. Michael Wirvin, the firm’s Managing Partner. "Many of the challenges in today’s sports industry do not fit neatly within a single practice area. By formalizing this effort, we are creating a more coordinated experience for clients while positioning the firm to continue growing alongside this dynamic industry." Beyond its client work, Robinson+Cole is actively engaged in advancing the sports industry through leadership, scholarship, and engagement. Team members regularly contribute to national conversations on emerging sports law developments and are frequently sought by media outlets for commentary on issues affecting professional and collegiate athletics, most recently USA Today and the Sports Business Journal. They also participate in leading industry organizations, such as the Sports Lawyers Association, where Seiger currently serves as Chair of the Immigration Committee. The firm is recognized for its role at the intersection of sports and global talent mobility.

Harnessing decades of collective experience, the team offers coordinated, cross-disciplinary business, operational, and legal counsel to sports industry stakeholders
July 8, 2026

Linn Freedman Provides Context On Info Stolen in Data Breach

Massachusetts Lawyers Weekly
June 29, 2026

Linn Freedman Recognized Among 2026 Cybersecurity/Data Privacy “Go To Lawyers”

Massachusetts Lawyers Weekly
June 4, 2026

Robinson+Cole Recognized Across Practices and Regions with 46 Chambers USA 2026 Rankings

Chambers & Partners
Robinson+Cole Recognized Across Practices and Regions with 46 Chambers USA 2026 Rankings teaser
April 17, 2026

Kathryn Rattigan Joins the Beta Gamma Sigma Society as Honorary Inductee

Beta Gamma Sigma Society
Kathryn Rattigan Joins the Beta Gamma Sigma Society as Honorary Inductee teaser
April 15, 2026

Robinson+Cole Presented with 2026 Law Firm Excellence in Innovation Award

Massachusetts Lawyers Weekly
Robinson+Cole Presented with 2026 Law Firm Excellence in Innovation Award teaser
March 19, 2026

Roma Patel Authors Article on Secondary Liability and AI

The Licensing Journal
March 18, 2026

Linn Freedman Sounds the Alarm About the Growth of Deepfake Content

Corporate Counsel
March 16, 2026

Kathryn Rattigan Quoted on Disney CCPA Opt-Out Settlement

Cybersecurity Law Report

June 4, 2026

Robinson+Cole Recognized Across Practices and Regions with 46 Chambers USA 2026 Rankings

Chambers & Partners
Robinson+Cole Recognized Across Practices and Regions with 46 Chambers USA 2026 Rankings teaser
April 17, 2026

Kathryn Rattigan Joins the Beta Gamma Sigma Society as Honorary Inductee

Beta Gamma Sigma Society
Kathryn Rattigan Joins the Beta Gamma Sigma Society as Honorary Inductee teaser
April 15, 2026

Robinson+Cole Presented with 2026 Law Firm Excellence in Innovation Award

Massachusetts Lawyers Weekly
Robinson+Cole Presented with 2026 Law Firm Excellence in Innovation Award teaser
March 19, 2026

Roma Patel Authors Article on Secondary Liability and AI

The Licensing Journal
March 18, 2026

Linn Freedman Sounds the Alarm About the Growth of Deepfake Content

Corporate Counsel
March 16, 2026

Kathryn Rattigan Quoted on Disney CCPA Opt-Out Settlement

Cybersecurity Law Report

Events


Past

2026 Pennsylvania Legal Awards

Jun 11 2026
Hilton Philadelphia at Penn’s Landing
Past

Managing Matter Mobility - Setting Defensible Rules for Data Leaving or Entering the Firm

Mar 9 2026
Law.com Legalweek 2026
Past

2026 Pennsylvania Legal Awards

Jun 11 2026
Hilton Philadelphia at Penn’s Landing
Past

Managing Matter Mobility - Setting Defensible Rules for Data Leaving or Entering the Firm

Mar 9 2026
Law.com Legalweek 2026
Past

Mastery of IG: Legal and Regulatory

Feb 19 2026
ARMA IG Mastery Session 4
Past

State AI Laws and the Federal EO: Effective Dates, Scope, Enforcement, Compliance Planning

Jan 27 2026
Barbri Webinar
Past

Deepfakes: A Demonstration of How They are Made and Used by Threat Actors

Nov 19 2025
Boston Bar Association 2025 Privacy, Cybersecurity & Digital Law Conference
Past

Fireside Chat | The Cyber Brief: Law, Liability & Response

Sep 19 2025
SCG Legal 2025 Annual Meeting
Past

Mastery of IG: Legal and Regulatory

Feb 19 2026
ARMA IG Mastery Session 4
Past

State AI Laws and the Federal EO: Effective Dates, Scope, Enforcement, Compliance Planning

Jan 27 2026
Barbri Webinar
Past

Deepfakes: A Demonstration of How They are Made and Used by Threat Actors

Nov 19 2025
Boston Bar Association 2025 Privacy, Cybersecurity & Digital Law Conference
Past

Fireside Chat | The Cyber Brief: Law, Liability & Response

Sep 19 2025
SCG Legal 2025 Annual Meeting

Publications


Data Privacy + Cybersecurity Insider teaser
July 9, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
June 26, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
June 18, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
July 9, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
June 26, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
June 18, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
June 12, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
June 5, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 28, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 21, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 14, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 7, 2026

Data Privacy + Cybersecurity Insider



Data Privacy + Cybersecurity Insider teaser
June 12, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
June 5, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 28, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 21, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 14, 2026

Data Privacy + Cybersecurity Insider

Data Privacy + Cybersecurity Insider teaser
May 7, 2026

Data Privacy + Cybersecurity Insider