Robinson Cole LLP
High Contrast Mode
July 10, 2025 - R+C Newsletter

Data Privacy + Cybersecurity Insider

Share this page:

CYBERSECURITY

What to Know About SafePay Ransomware Group

The SafePay ransomware group has been active since fall 2024 and has increased its activity this spring and summer. According to NCC Group, SafePay hit the most victims of any threat actor in May 2025—it is linked to 248 victims to date, according to Ransomware.live and RansomFeed. Read more


ENFORCEMENT + LITIGATION

Block Inc: CEMA’s Reach Beyond the SMS Sender

On June 30, 2025, Block, Inc.—an electronic financial services company that operates Cash App—entered into a proposed settlement with customers regarding unsolicited text messages from the company. The dispute stemmed from a marketing campaign that allowed Cash App users to refer their contacts to use the application. Read more


DATA PRIVACY

Etsy Sued Over Pixel Trackers: What It Means for Your Business

If you’ve ever browsed Etsy looking for a handmade candle or a quirky T-shirt, you might have unknowingly shared more than just your shopping preferences. A new lawsuit filed in California last week claims that Etsy has been quietly allowing third-party companies like Google, Meta, and Microsoft to collect personal data from users through website tools known as pixel trackers, without clear consent. Read more

Supreme Court Upholds Texas Age-Verification Law, Raising LGBTQ+ Privacy Concerns

On June 27, 2025, the U.S. Supreme Court upheld a Texas law requiring pornography websites to verify users’ ages through government-issued ID. The 6–3 decision in Free Speech Coalition v. Paxton marks a significant shift in First Amendment jurisprudence and opens the door for expanded digital age-verification laws nationwide. Read more


HIPAA

OCR Enters into Two More Settlements for Failure to Conduct Security Risk Assessments

The Office for Civil Rights (OCR) entered into two recent settlements with covered entities alleging that they failed to conduct security risk assessments. The settlements indicate that OCR will continue to aggressively regulate potential violations of the Health Insurance Portability and Accountability Act (HIPAA), particularly for failure to conduct risk assessments. Read more


INFORMATION GOVERNANCE

Mastering Information Governance with the ARMA IGIM 2.1 Framework – Part 3: Operationalizing the Framework

Last week, we outlined the building blocks for a strong IG program. Now that you’ve laid the groundwork, it’s time to bring your IG program to life. The ARMA IGIM framework emphasizes operational execution in three key areas: Procedural Framework, Capabilities, and Information Lifecycle. These domains are where your framework tangibly interacts with AI systems, ensuring tools like machine learning models work with clean, structured data. Read more


Privacy Tip #450 - Old Routers Pose Security Risk

The Federal Bureau of Investigation (FBI) recently issued a public service announcement “to inform individuals and businesses about proxy services taking advantage of end of life routers susceptible to vulnerabilities.” When technology reaches its end of life, the manufacturer no longer supports patching the technology, which opens it to vulnerabilities. Learn more about this security risk in our latest Privacy Tip. Read more