Robinson Cole LLP
High Contrast Mode
September 10, 2026 - R+C Newsletter

Data Privacy + Cybersecurity Insider

Share this page:

CYBERSECURITY

ShinyHunters Hits Florida DMV Database

Ransomware group ShinyHunters alleges on its online platform that it has compromised the Florida Department of Motor Vehicles’ Driver and Vehicle Information Database (DAVID) and stole the DMV records of over 200,000 individuals. The threat actor posted a screenshot of Jeffrey Epstein’s DMV record as proof.

The DAVID records of drivers include their name, address, Social Security number, birthdate, driver’s license ID, and other information. ShinyHunters told BleepingComputer they “breached DAVID through a password-reset flaw that let them compromise multiple accounts in the system. These accounts allegedly belonged to DMV employees and an FBI agent.” ShinyHunters no longer has access to the database and the “password-reset flaw used to compromise accounts is being patched.” Read more


ENFORCEMENT + LITIGATION

18,607 Privacy Requests, 13 Injuries, and No FCRA Class

On August 26, 2026, LexisNexis won an important, but limited, victory in a proposed class action: a federal court refused to certify a class of people seeking damages for

the company’s response to privacy requests which violated the Fair Credit Reporting Act (FCRA). The court did not decide whether LexisNexis had violated the FCRA, only deciding that the plaintiffs could not pursue their claims as the proposed class. Read more


DATA PRIVACY

California SB 690 Could Narrow CIPA Website-Tracking Lawsuits

California Senate Bill 690 is finally moving forward. The original bill would have broadly exempted disclosures made for a “commercial business purpose,” as defined under the California Consumer Privacy Act (CCPA), potentially eliminating many California Invasion of Privacy Act (CIPA) claims involving common website technologies. The amended version is narrower but could still offer meaningful relief to businesses facing the recent wave of CIPA litigation. Read more


PRIVACY TIP #507

Coordinated Vishing Attacks Hit Microsoft Teams Users

A recent article released by the Palo Alto Threat Research Center found that, between January and April 2026, a coordinated effort by threat actors was successful in launching vishing attacks using Microsoft Teams accounts to compromise companies across multiple industries.

The threat actor uses an external Teams account and creates a chat “using identities designed to mirror legitimate internal support units.” Usually these include names like help desk, IT support, or something else that makes the user believe the chat is coming from an internal IT support professional. The chat has a sense of urgency that something needs to be done on the user’s computer. The threat actors then call the victim and, if the user picks up, the scam commences. The threat actor then guides the employee through steps to allow remote control or to download malicious malware. If the caller doesn’t pick up, the threat actor calls back multiple times, scaring the user into believing it is urgent.

Learn how threat actors are using Microsoft Teams messages and phone calls to trick employees into granting access to their systems in this week's Privacy Tip. Read more