Data Privacy + Cybersecurity Insider
CYBERSECURITY
Gunra Ransomware Group Hitting Multiple Sectors
An advisory issued jointly this week by the Federal Bureau of Investigation, Cybersecurity and Infrastructure Security Agency, Department of Defense Cyber Crime Center, National Security Agency, U.S. Secret Service, and the Republic of Korea’s National Police Agency alerted organizations about an emerging threat from the Gunra ransomware group and provided guidance on detection and mitigation. Read more
ENFORCEMENT + LITIGATION
Philadelphia Casino Data Breach: Some Claims Win, Others Lose
A recent federal decision shows how data-breach claims can turn on the connection between the exposed information and the alleged harm. In Volio v. Sugarhouse HSP Gaming, L.P., No. 2:25-cv-00039 (E.D.Pa. Aug. 7, 2026), current and former employees and casino patrons sued after Rivers Casino Philadelphia allegedly discovered unauthorized access to its network and exfiltration of files containing names, dates of birth, Social Security numbers, driver’s license and passport information, and bank account information used for direct deposits. Read more
DATA PRIVACY
Data Brokers Beware: California Settlement Highlights Risks in High-Friction Opt-Out Processes
California’s privacy regulator just sent a clear message to the data broker ecosystem: compliance failures will be viewed across both the California Consumer Privacy Act (CCPA) and the Delete Act. The California Privacy Protection Agency (CPPA) announced a $116,490 settlement with LocateSmarter LLC, an Iowa-based company that allegedly operated as a data broker without registering as one. The CPPA also alleged that LocateSmarter made it too difficult for consumers to opt out of the sale of their personal information by requiring them to provide the last four digits of their Social Security numbers before submitting an opt-out request. According to the CPPA, LocateSmarter collected sensitive and high-risk data, including names, driver’s license information, dates of birth, and information about employment, bankruptcy, and litigation. The CPPA’s order emphasized that requiring consumers to provide more personal information than necessary, particularly sensitive information, can violate California’s data minimization requirements and discourage the exercise of privacy rights. Read more
CCPA Cybersecurity Audits Are Coming: What Companies Should Do Now
The California Consumer Privacy Act’s (CCPA) cybersecurity audit requirement marks a significant shift in privacy and security accountability. Beginning January 1, 2027, covered businesses will need to complete annual, independent, evidence-backed cybersecurity audits showing that their privacy and security controls are not only designed appropriately, but operating effectively over time. For many companies, this will be the first recurring, regulator-visible audit cycle that ties cybersecurity governance, privacy compliance, executive accountability, and legal defensibility together. Businesses that meet the applicable revenue and data-processing thresholds, including those processing large volumes of Californians’ personal information or sensitive personal information, should be preparing now, because the first audit period is quickly approaching. Read more
PRIVACY TIP #503
Read This Before You Upload Medical Information into an AI Tool
The current statistics on how many people upload their medical information into a generative AI tool are staggering. It is clear to me that people are unaware of the risks of doing so, and if you are contemplating sharing your medical information with a generative AI tool, like ChatGPT, Gemini or Claude, please read this first.
Read this week’s Privacy Tip to learn more about the privacy risks associated with sharing medical information with AI Chatbots Read more




