Data Privacy + Cybersecurity Insider
CYBERSECURITY
CISA Issues Malware Analysis Report on RESURGE Malware
On March 28, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) released a Malware Analysis Report (MAR) on RESURGE malware, which is associated with the product Ivanti Connect Secure.
According to the MAR, RESURGE contains capabilities of the SPAWNCHIMERA malware variant, including surviving reboots; however, RESURGE contains distinctive commands that alter its behavior. Read More
ENFORCEMENT + LITIGATION
EdTech and Privacy of Student Information: A Case Study
On March 27, 2025, a class action lawsuit was filed against the education technology (EdTech) company Instructure, the parent company of Canvas, a popular learning management system. The complaint alleges that Instructure violated children’s federal and state privacy rights. According to the complaint, Instructure states that it collects various account information about children, including name, gender/pronouns, academic institution and student ID, as well as profile pictures. Read More
ARTIFICIAL INTELLIGENCE
Cleo AI Agrees to $17 Million Settlement with FTC
Sometimes, deals are too good to be true. That was the case for Cleo AI, an online cash advance company that promised consumers fast, up-front cash payments. According to the Federal Trade Commission (FTC), Cleo AI offered consumers a mobile personal finance application that “promises consumers instant or same-day cash advances of hundreds of dollars.” When a consumer requests a cash advance, Cleo AI offers two subscription models, Cleo Plus and Cleo Builder. Once the consumer picks a subscription, they must provide a payment method that Cleo AI can use to obtain a cash advance repayment, subscription fees, and other fees. Read More
PRIVACY TIP #438
FTC Chairman Shares Concerns Over 23andMe Data
In the ongoing saga of the 23andMe bankruptcy, Federal Trade Commission Chairman Andrew N. Ferguson recently sent a letter to the Trustee overseeing the 23andMe bankruptcy proceeding stating, “As Chairman of the Federal Trade Commission, I write to express the FTC’s interests and concerns relating to the potential sale or transfer of millions of American consumers’ sensitive personal information.” For 23andMe customers, now is the time to request the deletion of their data. Read More
RECENT EVENTS AND NEWS
Upcoming Webinar: Tuesday, 4/15, “AI, Access to Corporate Data + the 2024 ECCP Update: A Benchmarking Discussion"
Internal Investigations + Corporate Compliance team partner David Carney and Artificial Intelligence team co-chair Linn Freedman will present an R+C hosted webinar titled “AI, Access to Corporate Data + the 2024 ECCP Update: A Benchmarking Discussion” on April 15, 2025. The 2024 Evaluation of Corporate Compliance Programs (ECCP) update provides a roadmap for high-impact compliance enhancements, including ai risk mitigation, the use of artificial intelligence (AI) in compliance, and greater access to corporate data sources. Given the significant benefits that can be derived, companies must be able to navigate the map, but deciphering it isn’t always straightforward.
David will moderate the webinar while Linn will discuss the use of artificial intelligence (ai) in compliance and ai risk mitigation. The webinar will also feature discussions from two experienced chief compliance officers who will break down the 2024 evaluation of corporate compliance program and share real-world implementation insights and practical strategies for implementation. For more information and to register, please contact events@rc.com.
Jen Driscoll Quoted in LegalTech News from LegalWeek 2025 Panel on Regulatory Divergence Between US and EU on AI
Artificial Intelligence team counsel Jennifer Driscoll was recently quoted in the LegalTech News article “Legalweek Day 1: Blurring the Build Buy Distinction, U.S. and Europe Oceans Apart” published on March 25, 2025. The article covered the LegalWeek2025 presentation “Global Compliance Deep Dive: Mastering EU AI Act and International Data Regulations, which Jen was among the panelists for, and recaps her insights on the growing divergence between the United States and the European Union concerning artificial intelligence (AI) regulation as the EU AI Act has become the global standard in the absence of federal regulation in the United States.
“Thirty or 40 years ago it would have been inconceivable to lawyers at the DOJ that they would not be leading the charge,” said Jen. “It is no longer the U.S. setting the common denominator of how data privacy laws are going to be applied and enforced.” Read the article.



