Data Privacy + Cybersecurity Insider
CYBERSECURITY
Cyber-attacks Against State Water Supplies Continue—12 to Date
Following the coordinated attack against 30 Minnesota water and wastewater utilities from July 26-27, 2026, hackers have attacked at least 11 other state water systems in the last week. As of July 30, 2026, the Federal Bureau of Investigation (FBI) confirmed that at least seven states were affected and issued an alert detailing the hackers’ actions and their impact on water and wastewater systems.
Shortly thereafter, both Georgia and Michigan confirmed that they were targeted and experienced “hostile cyber activity,” including nine systems in Michigan, though both states reported no operational disruption or public health concern. Read more
ENFORCEMENT + LITIGATION
TCPA Residential Line Claims Stay on the Menu
A recent decision from a federal district court in Virginia adds to the growing body of Telephone Consumer Protection Act (TCPA) litigation over whether its “Do Not Call” protections apply to marketing texts sent to cell phones. In McGonigle v. Dickey’s Barbecue Restaurants, Inc., No. 1:25-cv-01062, 2026 WL 2114507 (E.D. Va. July 22, 2026), the plaintiff alleged that he received unsolicited promotional text messages from Dickey’s after registering his cell phone number on the National Do Not Call Registry. Read more
DATA PRIVACY
Recent privacy litigation against Shopify and the NBA highlights a shared theme: companies may face risk not only for what their websites say about privacy choices, but for how embedded technologies actually collect data behind the scenes.
In the Shopify case, a California federal court refused to dismiss claims alleging that Shopify collected California consumers’ personal, payment, location, and browsing information through its checkout technology without adequate notice or consent, then used that information to build consumer profiles. The court found the plaintiff plausibly alleged that Shopify knowingly designed its system to collect the data at issue, relying on Shopify’s prior disclosures, order-confirmation emails, hosted product images, archived page source information, and Shopify-linked URLs in the merchant checkout flow. Read more
ARTIFICIAL INTELLIGENCE
AI “Therapists” Draw State Scrutiny as Mental Health Chatbot Use Surges
AI-enabled mental health tools are moving quickly from novelty to mainstream use, and regulators are starting to draw sharper lines around what those tools can and cannot claim to do. Recent lawsuits against Character Technologies Inc., the company behind Character.ai, allege that the platform hosted bots that mimicked licensed therapists, including one persona that allegedly claimed fictional professional credentials and engaged in tens of thousands of patient interactions. The litigation comes amid growing AI chatbot use for mental health advice, particularly among adolescents and young adults, and follows reports of serious safety concerns involving minors and crisis-related conversations. Read more
AI Meeting Tools Face Wiretapping Wake-Up Call
A new California federal lawsuit against AI notetaking provider Granola highlights a growing privacy risk for companies using meeting transcription tools: consent cannot be an afterthought. According to the complaint, Granola’s software allegedly recorded a virtual meeting participant without giving notice that an AI notetaker was present or seeking permission to record. The plaintiff claims this differs from other AI transcription tools that visibly join meetings, announce their presence, or give participants the ability to remove the notetaker. The suit also alleges that Granola used meeting contents by default for commercial purposes, including training AI systems, unless the Granola user turned that setting off. Read more
PRIVACY TIP #502
The families of four teenagers who died by suicide recently sued Meta, TikTok, Snapchat, and YouTube, alleging that the teenagers’ use of the platforms over many years was addicting, and caused sleep deprivation, depression, anxiety, and suicidal ideation. The teenagers committed suicide at the ages of 13, 14, 17, and 18, respectively.
These are not the first suits filed against social media platforms, but they have not made an impact on continued use by children and teens.
Research shows that spending more than three hours a day on social media platforms doubles teenage depression and anxiety risk.
Learn what recent lawsuits and research reveal about the risks facing young users in this week’s Privacy Tip. Read more
RECENT NEWS
Linn Freedman Explains Privacy Implications in Case of AI Company’s Purchase of Genetic Testing Firm
Data Privacy + Cybersecurity team and AI practice chair Linn Freedman underscored the potential legal implications surrounding the sale of genetic information in the article, “AI Company Acquiring Genetics Firm Raises De-Identification and Other Questions,” published in Privacy Daily, August 3, 2026. In the consolidated class action In re Tempus AI Genetic Privacy Litigation, potentially impacting hundreds of thousands of customers, plaintiffs argue that Tempus AI improperly collected and disclosed genetic information without consent during its acquisition of Ambry Genetics in 2025. While there likely wasn’t “a lot of conversation about what would happen with those genetic tests,” most people believe that when they’re undergoing a genetic or medical test, the “test is going to be protected and confidential,” Linn said. She pointed out this was the standard when direct-to-consumer genetic testing company 23andMe went bankrupt and was later sold.
“Something ‘compelling’ about the lawsuits is that the plaintiffs ‘went to genetic counselors…very specific genetic counseling,” which puts the alleged violations ‘in a different category,” Linn explained. “…once this information gets into the hands of a commercial AI company…there is no regulation around the [genetic] data,” outside maybe a state law, depending on where the conduct took place.”
Linn noted that although Tempus AI claims to use de-identified data, there are “pretty compelling facts and statements by plaintiffs that would question whether the genetic information was actually de-identified…it’s a very difficult process” to de-identify data to meet HIPAA standards. Linn said that Tempus AI should get the “benefit of the doubt” because courts have yet to hear its side of the story, and it could be that there was a data use or other sort of agreement that went along with the sale that included the genetic information. Read the article.
Linn Freedman Appointed as Co-Chair of Privacy, Cybersecurity & Digital Law Section
Data Privacy + Cybersecurity team and AI practice chair Linn Freedman was recently appointed as co-chair of the Boston Bar Association’s (BBA) Privacy, Cybersecurity & Digital Law Section. During her one-year term, Linn will help shape the section’s programming with innovative and timely presentations focusing on the evolving regulatory landscape surrounding data privacy, cybersecurity, digital rights, and AI. The BBA’s section leadership team ensures that the association remains a hub for learning, collaboration, and community.




