Robinson Cole LLP
High Contrast Mode
April 16, 2026 - R+C Newsletter

Data Privacy + Cybersecurity Insider

Share this page:

CYBERSECURITY

Social Engineering Schemes Target C-Suite Executives

March was a busy month for former Black Basta affiliates who are using old social engineering techniques to target executives in the manufacturing, professional, scientific, and technical services industries. According to Reliaquest, the activity of the threat actors indicates that these sectors “were likely direct targets.”

According to its report, “Attackers are using automation to compress a multi-step social engineering attack into minutes, reducing the time defenders have to intervene before a live remote management session is established on a senior leader’s machine.” Read more


ENFORCEMENT + LITIGATION

Click to Join, Hard to Leave: FTC Reopens Negative Option Rulemaking

On March 11, 2026, the Federal Trade Commission (FTC) announced an Advance Notice of Proposed Rulemaking highlighting its Rule Concerning the Use of Prenotification Negative Option Plans, seeking comment on whether the rule should be amended or supplemented to better address deceptive or unfair negative option practices.

The FTC describes negative options as marketing arrangements in which a consumer’s silence or failure to act is treated as consent to be charged for goods or services. Negative option marketing includes automatic renewals, continuity programs, free-to-pay conversions, and prenotification plans. Read more


DATA PRIVACY

CNN Must Defend Privacy Suit Alleging Data Sharing with Microsoft and Adtech Firms 

A federal judge has ruled that CNN must face a proposed class action alleging that its website shared consumers’ personal information with Microsoft and adtech firms without consent, in alleged violation of the California Invasion of Privacy Act (CIPA). The lawsuit challenges CNN’s alleged use of online tracking tools and the downstream sharing of data in the digital advertising ecosystem. Read more


Privacy Tip #487

Eurail Notifies 300,000+ Individuals of Data Breach

I have very fond memories of using a Eurail pass back in the day while backpacking through Europe as a student. I was saddened to see that Eurail was the victim of a data breach in December 2025 when attackers obtained access to travelers’ full names and contact information, including email addresses, passport details, ID numbers, bank account and health information, and published it on the dark web for sale.

The incident affected 308,777 travelers. In its notification to affected individuals, Eurail provides information on fraud alerts, credit or security freezes and urges those affected to stay “alert to suspicious messages or activity,” and obtain a free copy of your credit report.

Learn the importance of frequently checking your credit report in this week’s Privacy Tip. Read more


RECENT EVENTS + NEWS

Kathryn Rattigan + Jim Merrifield to Present on AI and IG at ARMA’s InfoNext 2026

Chief Data Officer Jim Merrifield and Artificial Intelligence team partner Kathryn Rattigan will present at ARMA’s InfoNext 2026, from April 20-21, 2026, in Chandler, AZ.

Jim will moderate a panel titled “InfoNEXT Launch: Pursuing the Why,” which will examine the purpose, relevance, and impact of information governance programs, in addition to, its increasing importance in establishing business value, trust, and resilience.

Kathryn will co-present a program, titled, “AI as a Friend, Not Foe: Welcoming AI to Master Information Governance,” discussing how law firms of all sizes can adopt AI to automate routine legal and information governance tasks, mitigate risks, and drive innovation.

Jim serves as Chair of ARMA International’s Board of Directors.