Many insurers, and the businesses they cover, are still treating artificial intelligence (AI) risk as if it were cyber risk cloaked in a costume. That instinct is understandable since AI systems process data, rely on vendors, create operational dependencies, and
Data Privacy + Cybersecurity Insider
Leveraging Knowledge to Manage Your Data Risks
Data Privacy + Cybersecurity Insider, published by Robinson & Cole LLP, focuses on legal developments and issues related to data privacy, cybersecurity, and information security. The blog covers topics such as data breaches, regulatory enforcement actions, privacy litigation, law enforcement access to digital data, AI governance and risks, and the implications of forum selection clauses in privacy class actions. It also addresses emerging challenges in technology law including blockchain security vulnerabilities, cross-chain bridge incidents, and the evolving standards for protecting personal and sensitive information in various contexts.
Latest from Data Privacy + Cybersecurity Insider - Page 9
Privacy Tip #492 – FTC Enforcing the Take It Down Act
On May 19, 2026, the Federal Trade Commission (FTC) announced that it will begin enforcing the Take It Down Act (TIDA) immediately. TIDA was made law in May 2025 and requires platforms to remove non-consensual intimate imagery within 48 hours…
ShinyHunters Hit Instructure + Downs Canvas Learning Management System
Another recent victim of ShinyHunters is Instructure, the supplier of the Canvas learning management system, which disrupted the login portals of 330 colleges and universities during the critical college exam schedule.
According to Dataminr, ShinyHunters “claimed to have stolen…
FTC’s TAKE IT DOWN Act Stakeholder Letter Signals Heightened Compliance Priority
The spread of AI generated intimate imagery has turned what was already a serious online safety issue into a fast- moving platform governance problem. The Federal Trade Commission’s (FTC) latest stakeholder letter makes clear that covered platforms will be expected…
California’s GM Settlement Reveals a New Era for Connected Car Privacy
California regulators have announced a major privacy settlement with General Motors (GM) over allegations that the company unlawfully sold the location and driving data of hundreds of thousands of Californians to two data brokers: Verisk Analytics and LexisNexis Risk Solutions.…
When an AI Chatbot Calls Itself a Doctor
Pennsylvania’s lawsuit against Character Technologies, Inc., is a notable early test of how professional licensing laws may apply to consumer-facing AI chatbots. The Commonwealth, acting through the Department of State and State Board of Medicine, filed a Petition for Review…
Privacy Tip #491 – ShinyHunters Hit Zara
According to HaveIBeenPwned, ShinyHunters targeted fashion brand Zara in a cyber-attack and claimed that it had stolen 197,000 unique email addresses, product SKUs, order IDs, and the originating market. The incident involved a former technology provider (AI analytics platform…
ShinyHunters Target Medical Device Company Medtronic
Global medical device company Medtronic recently confirmed that it had been attacked by the threat actor group, ShinyHunters. According to Bleeping Computer, Medtronic is “the largest medical device maker in the world by revenue ($33.5 billion) and also develops…
CISA Warning: Firestarter Malware Persists in Cisco Devices
The Cybersecurity and Infrastructure Security Agency (CISA) and the UK National Cyber Security Centre (NCSC) have confirmed that threat actors are using FIRESTARTER malware to maintain persistence on Cisco network devices, allowing the threat actors to maintain access even after…
No Standing in the Parking Lot: Court Dismisses DPPA Suit
The Driver’s Privacy Protection Act (DPPA) may not draw as much regular attention as statutes like the VPPA, CCPA, or TCPA, but it remains a source of privacy litigation risk where motor vehicle record information is involved. The DPPA is…