Data Privacy + Cybersecurity Insider
CYBERSECURITY
Threat Actors Using FIFA Spoofed Websites to Launch Attacks
The FBI and the Internet Crime Complaint Center (IC3) has issued a public service announcement warning the public about a surge in malicious spoofed websites related to the FIFA games. Cybercriminals are using these fake sites to impersonate FIFA, tricking fans into giving up personal information, credit card numbers, or buying counterfeit tickets and fake travel packages.
“The malicious domains employ typosquatting and alternative top-level domains (TLDs) to impersonate the official FIFA domain (fifa.com), deceiving users into divulging sensitive information or purchasing counterfeit tickets and hospitality packages. The sophistication of these sites is such that even experienced users may be fooled, especially as attackers leverage HTTPS certificates and cloned branding.” Read more
ENFORCEMENT + LITIGATION
Message Received: PA Courts Say TCPA Do-Not-Call Rules Apply to Text Messages
On June 17, 2026, the U.S. District Court for the Eastern District of Pennsylvania denied Brown-Daub Chevrolet of Nazareth’s motion to dismiss a putative class action alleging violations of the Telephone Consumer Protection Act’s (TCPA) National Do Not Call Registry (DNCR) provisions. In Pero v. Brown-Daub Chevrolet of Nazareth (E.D. Pa. June 17, 2026), the court considered whether a text message is a “telephone call” under Section 227(c) of the TCPA, and concluded that it is.
The TCPA restricts certain telemarketing communications and, through Section 227(c), provides a private right of action to a person who receives more than one prohibited telephone call within a 12-month period. The plaintiff alleged that she registered her number on the DNCR in 2021, gave the dealership her number in October 2024 to receive truck sales information, later opted out of texts, and then received six unwanted texts between January 8 and March 28, 2025. Read more
DATA PRIVACY
Another CIPA Warning Shot: DraftKings Sued Over Website Tracking Tools
DraftKings is the latest target in California’s wave of California Invasion of Privacy Act (CIPA) website-tracking litigation. In Hughes v. DraftKings Inc., filed in the Central District of California, plaintiff Dana Hughes alleges that DraftKings operated its website with data broker software from NextRoll, The Trade Desk, and Comscore that secretly collected data about website visitors, their devices, locations, page views, and browser characteristics to identify and track users for marketing and profiling purposes. The complaint alleges that Hughes visited the DraftKings website and that data reasonably likely to identify her was transmitted to at least three third parties through code running on the site. Read more
ARTIFICIAL INTELLIGENCE
Five Eyes Issue “Call to Action” to Protect Against AI Cyber Threats
The leaders of the Five Eyes cyber security agencies, representing Australia, New Zealand, Canada, the United Kingdom, and the United States, issued an alert on June 22, 2026, entitled “The AI Shift in Cyber Risk: Why Leaders Must Act Now” urging organizations to a “call to action” to protect against cyber threats both for organizations and society as a whole. The Five Eyes are expressing urgency because artificial intelligence (AI) is quickly changing cyber risk, and organizations need to act fast to keep up. The call to action is informed by the fact that AI can improve cyber defense, but it also makes cyber-attacks faster, larger, and more advanced, including how attacks happen and how organizations can defend against them. Read more
AI in Insurance: The Real Test Is Readiness, Not Technology
After several years of experimenting with generative AI, machine learning, and AI agents, many insurers are no longer asking whether AI belongs in the business. The harder question is whether a pilot is ready to scale. The answer usually is not found in the model architecture or the novelty of the tool. It is found in how the organization talks about AI: whether leaders can tie the use case to specific business outcomes, define the process changes required, and explain how human teams will rely on the output in day-to-day work. Read more
PRIVACY TIP #497
LastPass Security Incident Raises Concern for Targeted Phishing Attacks
LastPass has confirmed that a security incident with a vendor, a third-party market intelligence platform “which integrates with our Salesforce and Gong systems” has compromised some customers information. As a result, the threat actor was able to use credentials to access LastPass customer data within its Salesforce environment.
The compromised information includes “business contact information and related customer relationship management (CRM) data, including customer names, phone numbers, email addresses, and physical addresses, as well as support case data and sales-related data.
Read this week's Privacy Tip to see what LastPass Security recommends to keep your private information safe. Read more




