Data Privacy + Cybersecurity Insider
CYBERSECURITY
U.S. Retailers Bracing for Scattered Spider Attacks
Google sent out a warning that the cybercriminal group Scattered Spider is targeting U.S.-based retailers. Scattered Spider is believed to have been responsible for the recent attack on Marks & Spencer in the U.K. A security researcher at Google has posited that Scattered Spider concentrates attacks on one industry at a time and predicts that it will continue to target the retail sector. They have warned that “US retailers should take note. These actors are aggressive, creative, and particularly effective at circumventing mature security programs.” Read more
DATA PRIVACY
This week, the U.S. District Court for the Northern District of California ruled in favor of children’s clothing retailer Janie & Jack, which sought to enjoin over 2,400 individual arbitration claims resulting from alleged violations of the California Invasion of Privacy Act (CIPA). Now, Janie & Jack will confront a single privacy class action suit as opposed to the more than 2,400 individual arbitration claims by its website visitors. Read more
State Data Minimization Laws Spark Compliance Uncertainty
A new wave of state consumer privacy laws focused on limiting data collection is creating anxiety among businesses—and Maryland is leading the charge. The Maryland Online Data Privacy Act (MODPA), set to take effect in October 2025, requires companies to collect only data that is “reasonably necessary and proportionate” to their stated purposes. However, with no official guidance for compliance from the Maryland Attorney General, businesses are left guessing. Read more.
ARTIFICAL INTELLIGENCE
50% of Professional Services Users Have Utilized AI Tools Not Authorized by Company
A new survey from Intapp, titled “2025 Tech Perceptions Survey Report,” summarizes findings from a survey of fee-earners that there has been a “surge in AI usage.” The professions surveyed included accounting, consulting, finance, and legal sectors. Findings include that “AI usage among professionals has grown substantially, with 72% using AI at work versus 48% in 2024.” Read more
Privacy Tip #445
Apple Users: Update to iOS 18.5
Never underestimate an operating system update from any mobile phone manufacturer. This week, Apple issued iOS 18.5 which provides enhancements to the user experience, but also fixes bugs and flaws.
This update fixes over 30 security bugs. The sooner you update to the new version, the better from a security standpoint. The security flaws that the patch responds to includes known and unknown vulnerabilities and zero-days that may or may not be exploited in the wild. Read more
RECENT EVENTS AND NEWS
Kathryn Rattigan to Present at SCCE Higher Education Compliance Conference on Navigating the New Frontier of AI
Data Privacy + Cybersecurity team and Artificial Intelligence team partner Kathryn Rattigan will present a program titled “Navigating a New Frontier: Data Breaches, Litigation and the Role of AI in Higher Ed’s Digital Risk Future” at the Society of Corporate Compliance and Ethics’ Higher Education (SCCE) 2025 Compliance Conference on June 3, 2025, in Orlando, FL. Kathryn’s program will discuss how higher education institutions can navigate the rapidly evolving world of artificial intelligence, the risks associated with its widespread use on campuses, and how compliance programs can establish guidelines for faculty and students.



