Robinson Cole LLP
High Contrast Mode
July 9, 2026 - R+C Newsletter

Data Privacy + Cybersecurity Insider

Share this page:

CYBERSECURITY

Threat Actors Aligned with China Attacking U.S. University Physics + Engineering Depts.

Researchers at cybersecurity firm Proofpoint have discovered that a “suspected China-aligned threat cluster named UNK_MassTraction” is attacking mailservers belonging to physics and engineering departments of U.S. and Canadian based universities. They have been tracking the activity since May 2026.

The threat actors are exploiting multiple n-day cross-site scripting vulnerabilities in Roundcube mailservers to “steal credentials and either install a webshell for follow-on access or deploy the VShell backdoor into the server’s memory.” The threat actors are targeting administrators and professors that have national security ties or are focusing on astrophysics and particle physics. Read more


ENFORCEMENT + LITIGATION

In Chatrie v. United States, No. 25-112 (U.S. June 29, 2026), the Supreme Court took another step in redefining digital privacy under the Fourth Amendment, building directly on its landmark decision in Carpenter v. United States, 585 U.S. 296 (2018). These cases signal that businesses holding customer data face an evolving legal landscape worth understanding.

The Fourth Amendment protects “persons, houses, papers, and effects” against unreasonable government searches, and thus generally requires a warrant based on probable cause before the government can search people, their homes, or their belongings. Under the long-standing “third-party doctrine,” however, information voluntarily shared with a third-party company, like a bank or phone company, historically lost that protection. In Carpenter, 585 U.S. at 310 n.3, 316, though, the Court carved out a “narrow” exception, holding that police need a warrant to obtain seven days of a cellphone user’s location data from a wireless carrier, even though the carrier held that location data , not the cellphone user. Read more


DATA PRIVACY

Kenneth Cole Website Tracking Case Dismissed After Cookie Opt-Out Claims

A proposed class action accusing Kenneth Cole Productions, Inc., of unlawfully sharing website visitor data with Meta, Google, and other third parties was voluntarily dismissed in the Northern District of California. The plaintiffs alleged that Kenneth Cole used third-party tracking tools on its website that allowed those companies to collect data about consumers’ interactions with the site, including after users had opted out through the site’s cookie-consent banner. The complaint asserted invasion of privacy, intrusion upon seclusion, unjust enrichment, and common-law fraud claims, and alleged violations of the wiretapping and pen-register provisions of the California Invasion of Privacy Act. Read more

Garden State Plants New Data Broker Rule

On June 30, 2026, New Jersey’s Governor Mikie Sherrill signed a new data broker law, largely effective immediately, that adds significant new obligations for businesses involved in personal data sales. The law reaches traditional data brokers that collect or purchase personal data about consumers with whom they do not have a direct relationship and then sell or license that information to third parties. It also creates obligations for “data collectors,” meaning businesses or business units that collect personal data directly from consumers and then sell or license that information to data brokers. Read more


ARTIFICIAL INTELLIGENCE

FTC Frames AI Output Steering as a Potential Section 5 Risk

The Federal Trade Commission’s (FTC) proposed policy statement puts a new consumer-protection frame around AI model behavior: if an AI company represents that its system is designed to deliver accurate, objective, or user-directed outputs, the company may create a reasonable consumer expectation that the system is trying to provide the best answer it can within its technical limits. The FTC’s concern is that an AI provider could secretly steer outputs toward undisclosed objectives, including ideological objectives, while still marketing the system as accurate, useful, or fit for the user’s task. In the FTC’s view, that kind of hidden steering may be deceptive under Section 5 of the FTC Act, even if the company says it is doing so to comply with state law. Read more


PRIVACY TIP #498

ShinyHunters Hits Medtronic

Threat group ShinyHunters continues its incessant campaign to torture companies trying to provide products and services to consumers, with no indication of letting up.

One of its latest victims, Medtronic, the manufacturer of medical devices, healthcare technologies, and therapies, confirmed that it was the victim of an April cyberattack where over nine million records from the company were stolen. ShinyHunters claimed responsibility. Medtronic recently notified affected customers, informing them that the data exposed during the attack included some customers’ names, contact information, dates of birth, Social Security numbers, and health-related information.

Read this week's Privacy Tip to learn about Medtronic’s letter to consumers and the latest developments surrounding the matter. Read more


RECENT EVENTS & NEWS

Linn Freedman Provides Context On Info Stolen in Data Breach

Data Privacy + Cybersecurity team and AI practice chair Linn Freedman said she found it significant that, based on the reported facts, “no data was actually exfiltrated by the threat actor,” in the Massachusetts Lawyers Weekly article, “Data breach class action fails for lack of standing,” published on June 30, 2026. The article focuses on a recent First Circuit decision affirming the dismissal of a class action arising from a 2019 ransomware attack at a Puerto Rico hospital. The court concluded that the plaintiff failed to plausibly connect a fraudulent cellphone account opened in her name to the data breach and therefore lacked standing to pursue her claims. A notable fact in the case was that, according to the hospital’s breach notification, there was no indication that patient information had been exfiltrated or used by the threat actor during the attack.

“It makes a big difference in the analysis if it doesn’t look like they actually stole the [plaintiff’s information],” Linn said. “The chance of fraud is much less if the data just happened to be in the database that they accessed.”

Read the article.

Linn Freedman Recognized Among 2026 Cybersecurity/Data Privacy “Go To Lawyers”

Data Privacy + Cybersecurity practice and AI Team chair Linn Freedman was recognized as a “Massachusetts Go To Lawyer” in the area of Cybersecurity/Data Privacy by Massachusetts Lawyers Weekly (MLW) and profiled in a special section published on June 29, 2026.

MLW’s “Go To Lawyer” recognition showcases top lawyers in their respective fields from across the Commonwealth nominated by their colleagues and selected by a panel from Lawyers Weekly. A “Go-To Lawyer” is a senior attorney with deep command of case law, statutes, and regulations; a proven track record of success in significant matters and transactions; a trusted advisor to whom other lawyers routinely refer work because of demonstrated expertise and accomplishments; and a creative, strategic thinker who identifies and evaluates all available options to achieve the best outcomes for clients.

Read the special section, here.