Federal and state enforcement actions involving notice failure violations, tracked from official government sources.
194
Total Actions
$1.8B
Total Fines
13
Jurisdictions
The FTC finalized an order against Vanilla Chip LLC (doing business as TruHeight) and its principals for deceptively advertising height-enhancing supplements for children and teens without scientific evidence. The company also used fake reviews and incentivized 5-star ratings. The order requires a $750,000 payment and prohibits false health claims and deceptive review practices.
$750K
Attorney General Ellison and 48 other attorneys general called on the FCC to strengthen rules to cut off scammers' access to legitimate telephone numbers. The coalition is responding to the FCC's proposed rules to combat illegal robocalls and texts, which cost Americans nearly $2 billion last year.
Texas Attorney General Ken Paxton opened an investigation into LinkedIn Corporation over allegations that the company advertised and profited from fake or misleading job opportunities ("ghost jobs") on its platform. The investigation focuses on whether LinkedIn misled consumers who paid for Premium subscriptions by failing to disclose that a significant percentage of job postings may be inactive or not genuine hiring opportunities.
Attorney General Jennifer Davenport joined a bipartisan coalition of 42 attorneys general in announcing a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised genetic data of 6.9 million people worldwide, including nearly 150,000 in New Jersey. The settlement provides $18 million to states from available bankruptcy funds, plus enhanced data security and consumer deletion rights for the successor entity, 23andMe Research Institute.
$18.0M
New York Attorney General Letitia James sued 3M, DuPont, and other chemical companies for knowingly causing decades of PFAS pollution through consumer products. The lawsuit alleges the companies hid toxicity risks, failed to warn the public, and seeks cleanup funding, damages, and injunctive relief.
Minnesota Attorney General Keith Ellison reached a settlement with Annelle Soberay and Omega Dental Care, a defunct dental clinic that shut down in late 2024 without providing advance notice or transitional care to patients. The settlement allows consumers to obtain refunds from the Consumer Protection Restitution Account for fees paid for services that were never provided.
The FTC alleged that RentGrow, a tenant screening company, violated the Fair Credit Reporting Act (FCRA) by failing to use reasonable procedures to ensure the accuracy of its reports, including by reporting duplicate records and failing to disclose data sources. RentGrow agreed to pay a $2.25 million penalty and is prohibited from further FCRA violations and from misrepresenting dispute outcomes.
$2.3M
Attorney General Tong announced a $45 million multistate settlement with Block, Inc., the company behind Cash App, for misleading consumers about the safety of the platform, failing to protect users from fraud, and not providing promised fraud protection and resolution services. The settlement requires Block to implement major reforms including real customer support, transparent communications, and security commitments, and reaffirms Block's commitment to distribute between $75 million and $120 million to compensate consumers as part of a separate CFPB settlement.
$45.0M
Attorney General Ken Paxton secured a $45 million multistate settlement with Block, Inc. (Cash App) for misleading consumers about the safety of its platform and failing to protect users from fraud. The settlement requires Cash App to maintain 24-hour customer support, cease deceptive safety claims, and fulfill its legal duty to investigate and reimburse unauthorized transactions.
$45.0M
Attorney General Keith Ellison announced a $45 million multistate settlement with Block, Inc., the company behind Cash App. The settlement resolves allegations that Block misled consumers about the safety of Cash App, failed to protect users from fraud, and did not provide promised fraud protection and resolution. Block agreed to implement responsible practices including maintaining customer support, offering live support, stopping misleading claims, and fulfilling legal obligations to investigate fraud and reimburse users.
$45.0M
Attorney General Phil Weiser announced a $45 million multistate settlement with Block, Inc., the company behind Cash App, for misleading consumers about the safety of the platform and failing to protect users from fraud. The settlement requires Block to implement antifraud measures, provide customer support, and stop deceptive marketing practices.
$45.0M
Minnesota Attorney General Keith Ellison, along with the FTC and attorneys general of Arizona, Illinois, Michigan, and Wisconsin, settled an antitrust lawsuit against John Deere. The settlement requires Deere to provide farmers and independent repair providers with the same repair resources previously only available to authorized dealers for 10 years, and to pay $1 million in legal costs.
$1.0M
Block, Inc., the parent company of Cash App, agreed to a $45 million multistate settlement with 46 states for misleading consumers about the safety of Cash App and failing to protect users from fraud. The settlement requires Block to improve customer support, stop deceptive marketing, and fulfill legal obligations to investigate fraud and reimburse unauthorized transactions.
$45.0M
Attorney General Jennifer Davenport co-led a coalition of 49 attorneys general in calling on the FCC to strengthen rules to cut off scammers' access to legitimate telephone numbers. The coalition's letter requests stronger certification rules, regular reporting, and prohibitions on number cycling to combat illegal robocalls.
Block, Inc. agreed to a $45 million multistate settlement with 46 states for allegedly misleading consumers about the safety of Cash App, failing to protect users from fraud, and not providing promised fraud protection. The settlement requires Block to improve customer support, stop misleading claims, and educate consumers about fraud.
$45.0M
New York Attorney General Letitia James and a bipartisan coalition of 45 other attorneys general secured $45 million from Block, Inc., the company behind Cash App, for misleading users about the platform's security and failing to protect them from fraud. The settlement requires Block to implement changes including maintaining live customer support, stopping misleading marketing, and fulfilling legal obligations to investigate fraud claims and reimburse users for unauthorized transactions.
$45.0M
The FTC and New York Attorney General took action against Handy Technologies for deceptive earnings claims and failure to disclose fees and fines that led to millions of dollars being withheld from workers' wages. The FTC is sending over $2.7 million in refunds to 62,893 affected consumers.
Texas Attorney General Ken Paxton secured a settlement with Walmart over deceptive practices in its Spark Driver program. Walmart misrepresented driver pay, including failing to pass on customer tips and altering base pay after drivers accepted offers. The $13 million settlement provides direct payments to affected Texas drivers and requires Walmart to implement honest compensation practices.
$13.0M
Texas Attorney General Ken Paxton announced an investigation into StubHub for failing to deliver FIFA World Cup tickets that fans purchased. The investigation focuses on reports of 'ghost ticketing,' where sellers list tickets they do not possess, collect payment, and cancel when unable to deliver.
The FTC alleged that Hopper, a travel booking app, charged consumers hidden and pre-selected fees (Tip and VIP Support) without their consent, misrepresented the benefits of VIP Support and Price Freeze services, and failed to clearly disclose total prices. Hopper agreed to pay $35 million for consumer redress and is prohibited from misrepresenting fees under a proposed order.
$35.0M
The FTC finalized a settlement with Publishing.com LLC and its principals for misleading consumers about potential earnings from self-publishing products. The company will pay $1.5 million and is prohibited from making unsubstantiated earnings claims, failing to disclose refund terms, and misrepresenting endorsements and reviews.
$1.5M
The FTC alleged that Amazon knowingly violated the Fair Credit Reporting Act (FCRA) by refusing to provide transaction records to identity theft victims whose personal information was used to commit fraud. Amazon agreed to pay a $2.25 million civil penalty and is required to comply with FCRA Section 609(e), provide notice to consumers, and contact victims who previously requested records since April 2024.
$2.3M
A Minnesota jury found home seller Chadwick Banken liable for violating the Minnesota Human Rights Act by targeting Muslim homebuyers in a deceptive contract for deed scheme. The scheme involved inflated prices, large down payments, and balloon payments designed to cause defaults, allowing Banken to keep payments and resell properties. Remedies including restitution will be determined at a later hearing.
The Colorado Attorney General settled with Unlock Partnership Solutions, Inc., which marketed home equity agreements that were determined to be consumer credit transactions subject to Colorado's Uniform Consumer Credit Code and Consumer Equity Protection Act. The company must comply with lending laws, rate caps, disclosures, and licensing, and pay $283,375 in restitution to 125 consumers, with additional payments expected.
The FTC, along with Alaska, Iowa, Nebraska, and Texas, filed a lawsuit against WPATH alleging the organization made false and unsubstantiated claims about the necessity, safety, and effectiveness of pediatric medical transition services. The complaint alleges WPATH misled parents and children about medical consensus and failed to disclose serious side effects, in violation of the FTC Act.
The FTC sued the Genesis Tech enterprise and its owners for operating deceptive internet-based subscription schemes. The defendants allegedly misled consumers about subscription terms, billed without authorization, and made cancellation difficult. The court granted a temporary halt to the operations pending trial.
Governor Sherrill and Attorney General Davenport announced coordinated executive actions to reduce and eliminate junk fees in New Jersey. The initiative includes an Executive Order directing state agencies to review industries for junk fees and an Enforcement Statement from the Division of Consumer Affairs explaining how junk fee practices may violate the New Jersey Consumer Fraud Act.
Minnesota Attorney General Keith Ellison joined a coalition of 20 attorneys general in suing the Trump administration over new federal contract terms intended to purge DEI. The lawsuit alleges the agencies violated the Administrative Procedure Act by failing to provide public notice or accept comments, exceeding legal authority, and imposing vague requirements that threaten severe penalties on contractors.
Colorado Attorney General Phil Weiser and a bipartisan coalition of 18 attorneys general announced a $4.87 million settlement with GS Labs, a former COVID-19 rapid testing business. The company was found to have violated the Colorado Consumer Protection Act by falsely advertising test results with no wait times, same day appointments, and no out-of-pocket expenses, while overcharging consumers and insurance providers.
$4.9M
Attorney General Ellison announced a $4.87 million multistate settlement with GS Labs for overcharging patients, charging unlawful administrative fees, and failing to deliver timely COVID-19 test results. The settlement includes $3.63 million in restitution to affected consumers and $1.25 million to the multistate group, along with injunctive relief if GS Labs resumes operations.
Minnesota Attorney General Keith Ellison filed a lawsuit against Bridge It, Inc. (doing business as Brigit) for violating Minnesota's payday lending laws. The lawsuit alleges Brigit operates as an unlicensed lender making short-term loans with APRs exceeding 300%, without disclosing rates or complying with state interest caps and disclosure requirements.
Attorney General Phil Weiser joined a coalition of 20 attorneys general in suing the Trump administration over new federal contract terms that impose unclear requirements on contractors regarding diversity, equity, and inclusion (DEI). The lawsuit alleges the federal agencies violated the Administrative Procedure Act by failing to provide public notice or accept comments, exceeding their legal authority, and not adequately explaining the new requirements. The coalition seeks to enjoin the agencies from imposing the new contract terms.
The FTC finalized a consent order against Illuminate Education Inc. for failing to secure students' personal data, leading to a breach affecting 10.1 million students. The order requires Illuminate to implement a data security program, delete unnecessary data, and limit data collection, but imposes no monetary penalty.
The New Jersey Bureau of Securities filed a lawsuit against Xiao Hu (aka Mark Hu) and his companies Skyline Technology USA LLC and Thunderbirds.ME, Inc. for allegedly defrauding at least 15 investors out of $2.5 million through unregistered securities offerings. Hu allegedly misappropriated at least $280,000 for personal expenses including a home purchase and vacation, and falsely claimed to have a Ph.D. from Columbia University.
The FTC filed a complaint against National Amendment Assistance and related entities for allegedly deceiving homeowners into paying unlawful upfront fees for mortgage relief services falsely associated with the CARES Act. The court granted a temporary restraining order, and the FTC seeks redress for affected consumers.
The Federal Trade Commission is seeking public comment on a petition from X Corp., formerly known as Twitter, to set aside or modify its 2022 settlement order with the agency. The petition argues that the order no longer serves a valid regulatory purpose and that X Corp. has built a world-class privacy program. The Commission will vote after the comment period closes.
The FTC and State of Nevada settled charges against the operators of American Tax Service for impersonating federal and state government tax authorities and making false promises of tax debt relief. The defendants will surrender over $8 million in cash and assets and are banned from debt relief services, tax preparation, telemarketing, and impersonation.
$8.0M
New Jersey and New York Attorneys General announced an investigation into FIFA's ticketing practices for the 2026 World Cup. The investigation focuses on reports that fans were misled about seat locations, faced soaring prices due to variable pricing, and did not receive the tickets they paid for. Subpoenas have been sent to FIFA seeking information about its ticketing practices for matches hosted in New Jersey.
The Colorado Attorney General announced a major enforcement sweep targeting thousands of fraudulently filed businesses that used false information in Colorado registrations to facilitate scams including cryptocurrency fraud, investment fraud, and romance scams. The lawsuits seek court orders to dissolve these entities and the AG's office worked to take down associated websites.
The FTC alleged that Cox Media Group (CMG), MindSift LLC, and 1010 Digital Works LLC deceived customers by falsely claiming to offer an AI-powered 'Active Listening' service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. In reality, the service did not use voice data and consumers had not consented. The companies agreed to pay a total of $930,000 and are prohibited from making misrepresentations about their services, voice data collection, and consumer consent.
$930K
The New Jersey Attorney General and Division of Consumer Affairs issued guidance warning hotels and short-term rental providers against charging hidden junk fees to consumers ahead of the 2026 FIFA World Cup. The guidance reminds businesses that New Jersey's consumer protection laws and the FTC's Unfair or Deceptive Fees Rule require transparent pricing and prohibit deceptive fee practices. No monetary penalties were imposed, but businesses are put on notice that violations may lead to enforcement actions.
The Colorado Attorney General shut down Smokin' Genie, a Fort Collins smoke shop owned by AIH Enterprises, LLC, and banned its owner from the industry for five years after the shop illegally sold kratom to a minor and failed to properly label kratom products. The settlement requires the store to cease operations, destroy inventory, and pay $200,000 if they violate the terms.
Texas Attorney General Ken Paxton launched an investigation into Meta regarding its Meta AI Glasses, alleging unlawful collection of facial biometric data, deceptive privacy representations, and unauthorized sharing of user data with subcontractors. The investigation follows concerns that the glasses’ always-on recording mode lacks proper notice, subcontractors access private user content including intimate moments, and Meta plans to deploy facial recognition technology to collect unsuspecting individuals’ facial geometry. The AG issued a Civil Investigative Demand to determine if Meta violated Texas law by deceptively misrepresenting its data use practices.
Texas Attorney General Ken Paxton launched an investigation into Meta's Meta AI Glasses over allegations of unlawful facial biometric data collection, deceptive privacy practices, and unauthorized sharing of user data with subcontractors. The investigation follows concerns that the glasses' always-on recording mode lacks proper user notice, planned facial recognition features would collect data without consent, and private user videos are accessed by third-party annotators in Kenya. The AG issued a Civil Investigative Demand to Meta to determine violations of Texas privacy laws.
Shutterstock Inc. agreed to pay $35 million to settle FTC allegations that it charged consumers without their informed consent, failed to disclose auto-renewal and cancellation terms, and made cancellation difficult. The FTC alleged Shutterstock's subscription and on-demand pack offerings violated consumer protection laws through hidden fees and complicated cancellation processes.
$35.0M
California Attorney General Rob Bonta, along with multiple district attorneys and the California Privacy Protection Agency, announced a $12.75 million settlement with General Motors for illegally selling hundreds of thousands of Californians' location and driving data to data brokers Verisk and LexisNexis without notice or consent. The settlement includes the largest CCPA penalty to date, a five-year ban on selling driving data to consumer reporting agencies, and requirements to delete retained data and implement a robust privacy program.
$12.8M
The California Privacy Protection Agency sent a letter to Congress opposing the SECURE Data Act, a federal bill that would preempt state privacy laws like the CCPA and Delete Act. The letter argues the bill would eliminate rights for 40 million Californians, including the DROP platform and opt-out preference signal requirements, and urges Congress to set a floor rather than a ceiling on privacy protections.
The FTC filed a complaint and obtained a temporary restraining order against six defendants operating a deceptive health care scheme that impersonated government and insurance carriers to sell fake comprehensive health plans. The defendants allegedly charged consumers without express informed consent, failed to disclose material terms including cancellation processes, and misled consumers into paying for inadequate coverage that left many with substantial medical debt. The FTC seeks refunds for affected consumers and alleges violations of the FTC Act, Telemarketing Sales Rule, Impersonation Rule, and Gramm-Leach-Bliley Act.
The FTC filed a complaint against Innovative Partners in April 2026, alleging the operators impersonate the government and large insurance carriers to deceive consumers seeking health insurance into buying supposedly comprehensive PPO plans that do not offer the coverage they seek.
The FTC settled with Humor Rainbow, Inc. (operator of OkCupid) and Match Group Americas over allegations that OkCupid deceived users by sharing personal data including photos and location information with an unauthorized third party, contrary to its privacy policy promises to inform users and provide opt-out opportunities. The settlement permanently prohibits the companies from misrepresenting their data collection, use, disclosure, and privacy control practices. No monetary penalty was imposed.
Consumer fraud enforcement action where the FTC settled with Air AI for misleading entrepreneurs with false earnings and refund guarantees. The company will be banned from marketing business opportunities and pay a suspended $18 million judgment with $50,000 for consumer relief. Violations included failure to provide required disclosures and false claims under the Telemarketing Sales Rule and Business Opportunity Rule.
$18.0M
Consumer protection and civil rights lawsuit filed by Oregon AG and 20 other states against the U.S. Department of Agriculture over unlawful funding conditions that coerce states into complying with policies unrelated to nutrition programs. The conditions relate to immigration, DEI, and gender identity, and are alleged to violate the Spending Clause and Administrative Procedure Act. The suit seeks to block these conditions to protect billions in funding for programs like SNAP, WIC, and school lunches that serve vulnerable populations.
Consumer fraud enforcement action where the FTC settled with Xponential Fitness for violating the Franchise Rule by misrepresenting key information to franchisees, including time to open and costs. The settlement includes a $17 million monetary judgment for redress and prohibits future misrepresentations.
$17.0M
Privacy enforcement action where Oregon AG and a coalition of 16 other states sue the Trump Administration to stop the Department of Education's new IPEDS data reporting requirements, arguing they jeopardize student privacy, lack proper definitions, and risk data errors and identification.
Connecticut Attorney General William Tong, joined by 17 other attorneys general, filed a lawsuit against the U.S. Department of Education to block new IPEDS data reporting requirements that demand student information disaggregated by race and sex. The coalition argues the rushed implementation is unlawful, invades student privacy, and risks unreliable data and baseless investigations. They seek an injunction to halt the data collection and protect student privacy.
The California Privacy Protection Agency settled with PlayOn Sports for $1.10 million over CCPA violations, including failing to provide adequate opt-out mechanisms and improperly tracking users, particularly students. The company must implement proper opt-out methods, improve disclosures, and comply with children's data consent requirements.
$1.1M
The FTC and 11 states settled with Walmart for $100 million over deceptive earnings claims in its Spark Driver gig worker app, where drivers were misled about base pay, tips, and incentives. The settlement also addressed GLBA violations for failing to provide proper notice regarding the handling of drivers' financial information. Walmart must implement an earnings verification program and is banned from misrepresenting driver earnings.
$100.0M
Texas Attorney General Ken Paxton reached an agreement with Samsung Electronics America, Inc. to stop collecting Automated Content Recognition (ACR) data from smart TVs without consumers' express consent. Samsung must update its smart TVs to provide clear and conspicuous disclosures and obtain consent before any data collection, ensuring Texans are informed and in control of their viewing data.
The FTC issued a policy statement announcing it will not enforce COPPA against operators that collect age verification data under specific conditions. The policy aims to encourage the use of age verification technologies to protect children online. Operators must limit data use, ensure security, provide notice, and use accurate verification methods.
CalPrivacy sponsored AB 2021, the Whistleblower Protection and Privacy Act, introduced by Assemblymember Pilar Schiavo. The bill establishes whistleblower protections under the CCPA, including an award program and anti-retaliation provisions, to encourage insiders to report privacy violations.
Consumer fraud enforcement action where the FTC is distributing $23 million in refunds to investors defrauded by the Sanctuary Belize and Kanantik real estate schemes. The defendants deceived consumers about luxury amenities and resale potential, resulting in losses of over $100 million. This is the second round of refunds following a court judgment.
$22.9M
Consumer fraud case where the FTC sued JustAnswer LLC for deceiving consumers into enrolling in a costly recurring monthly subscription by falsely claiming low one-time fees. The company did not obtain affirmative consent or clearly disclose subscription terms, violating ROSCA and the FTC Act. The FTC seeks an injunction, consumer refunds, and civil penalties.
Consumer fraud investigation where the FTC is seeking information from 20 universities about whether sports agents are complying with the Sports Agent Responsibility and Trust Act (SPARTA), which requires disclosures to student athletes and notification to schools. The inquiry aims to ensure student athletes are protected from deceptive practices by agents.
New York Attorney General Letitia James sent a letter to Instacart demanding information about its use of algorithmic pricing, after a study found users were charged up to 23% more for identical products. The AG warned that Instacart’s pricing disclosures are non-compliant with New York’s Algorithmic Pricing Disclosure Act, which requires prominent notices near product prices when personal data is used to set prices. Instacart must provide details on its pricing experiments, automated tools, and compliance efforts with the state’s disclosure requirements.
The FTC settled with Disney for violating the COPPA Rule by mislabeling videos on YouTube, which allowed the collection of children's personal data without parental consent. Disney must pay a $10 million civil penalty and implement measures to ensure proper video labeling and compliance with COPPA.
$10.0M
Connecticut Attorney General William Tong, leading a coalition of 35 attorneys general, urged Meta to enforce its policies against misleading AI-generated weight loss ads on Instagram and Facebook. The ads promote non-FDA approved GLP-1 drugs without disclosing risks and use fake AI content. The coalition demands Meta restrict such ads, require clear risk disclosures, and label AI-generated content.
Environmental and consumer protection enforcement action where Mercedes-Benz USA agreed to a nearly $150 million settlement for installing emissions defeat devices in diesel vehicles and misleading consumers about their environmental compliance. The settlement includes significant consumer relief and practice reforms.
$149.7M
Attorney General William Tong led a coalition of 15 attorneys general in submitting a comment letter to the EPA opposing the Trump Administration's proposal to roll back PFAS reporting requirements under the Toxic Substances Control Act. The coalition argues that the exemptions would shield most manufacturers from reporting critical information about PFAS chemicals, hindering efforts to protect public health and the environment.
Texas Attorney General Ken Paxton filed a lawsuit against Sony, Samsung, LG, Hisense, and TCL Technology Group for using Automated Content Recognition (ACR) technology to collect Texans' viewing data without proper consent. A temporary restraining order was secured against Hisense to halt all data collection and sharing. The AG issued a consumer alert with instructions to disable ACR on smart TVs.
Texas Attorney General Ken Paxton filed a lawsuit against five major TV manufacturers—Sony, Samsung, LG, Hisense, and TCL—for illegally collecting consumers' viewing data through Automated Content Recognition (ACR) technology without knowledge or consent. The companies capture screenshots and monitor TV usage in real-time, then sell the data for targeted advertising, risking sensitive information. The suit seeks to halt these invasive practices and protect Texans' privacy.
Connecticut Attorney General William Tong, along with the FTC and 21 other states and counties, filed a lawsuit against Uber Technologies, LLC and Uber USA, LLC for deceptive practices related to their Uber One subscription service. The lawsuit alleges Uber used negative option marketing, misled consumers about savings, made cancellation difficult, and charged consumers prematurely. The action seeks restitution, penalties, and an injunction under the Connecticut Unfair Trade Practices Act and the Restore Online Shoppers' Confidence Act.
Texas Attorney General Ken Paxton has filed lawsuits against five major TV manufacturers—Sony, Samsung, LG, Hisense, and TCL—for unlawfully collecting Texans' viewing data using Automated Content Recognition (ACR) technology without their knowledge or consent. The ACR software captures screenshots of TV displays every 500 milliseconds and transmits the data to the companies, which then sell it for targeted advertising. The AG's office alleges these practices violate Texas privacy laws and seeks to enjoin the companies from continuing the surveillance.
Connecticut Attorney General William Tong led a multistate coalition in sending inquiry letters to six major BNPL providers—Affirm, Afterpay, Klarna, PayPal, Sezzle, and Zip—seeking detailed information on their pricing, fees, disclosures, and consumer assessment practices to evaluate compliance with consumer protection laws, following the rescission of federal Truth in Lending Act rules for BNPL.
Consumer protection and advertising enforcement action. Oregon Attorney General secured a settlement with meal-kit company HelloFresh for misleading consumers with deceptive 'free meal,' 'free shipping,' and 'free gift' offers that required hundreds of dollars in purchases to obtain. The company must pay $106,000 and implement comprehensive advertising reforms.
$106K
California Attorney General Rob Bonta, joined by Connecticut and New York Attorneys General, secured a $5.1 million multistate settlement with edtech company Illuminate Education, Inc. over a 2021 data breach that exposed sensitive personal and medical information of millions of students, including over 434,000 California students. The investigation found Illuminate failed to implement basic security measures, including failing to terminate former employee credentials, lacking suspicious activity monitoring, and unsecured backup databases, as well as making false statements in its privacy policy. Illuminate must pay $3.25 million to California, implement enhanced security practices, and notify the CA DOJ of future student data breaches.
$5.1M
Connecticut Attorney General William Tong filed an expanded complaint against Altice/Optimum Online for deceptive advertising and hidden 'Network Enhancement' fees that collected at least $39.1 million from consumers. The company allegedly misled customers with 'price for life' deals while burying fees in fine print and targeting Spanish speakers with English-only disclosures. The complaint seeks penalties and disgorgement under the Connecticut Unfair Trade Practices Act.
Connecticut Attorney General secured a $1 million multistate settlement with TFG Holding, Inc. for deceptive VIP membership program marketing and billing practices. The company must improve disclosures, obtain explicit consent, provide easy cancellation, and offer restitution to affected consumers.
$1.0M
Florida Attorney General James Uthmeier filed a civil enforcement action against Roku, Inc. for violating the Florida Digital Bill of Rights (FDBOR) and Florida Deceptive and Unfair Trade Practices Act (FDUTPA). The complaint alleges Roku collected, sold, and enabled reidentification of children’s sensitive personal data, including viewing habits and voice recordings, without parental consent or meaningful notice to consumers. The state seeks civil penalties, injunctive relief, and requirements for Roku to implement transparent disclosures, lawful parental controls, and cease unauthorized processing of children’s data.
The Texas Attorney General opened an investigation into TP-Link Systems Inc. for potentially allowing the Chinese government to access Texans' consumer data through back doors in networking equipment. The investigation will examine whether TP Link violated Texas privacy law by misleading consumers about its independence and improperly collecting or disclosing data. This follows a prior privacy notice violation issued to the company.
The California Privacy Protection Agency (CPPA) settled with Tractor Supply Company for $1.35 million over violations of the California Consumer Privacy Act (CCPA). The violations included failing to maintain a proper privacy policy, not notifying job applicants of their rights, lacking an effective opt-out mechanism, and sharing personal information without adequate contracts. Tractor Supply must pay the fine and implement remedial measures such as scanning digital properties and annual compliance certification.
$1.4M
The FTC and 19 states settled with Kars-R-Us.com, Inc. and its operators for deceptive charity fundraising claims, where only 0.28% of over $45 million raised was used for breast cancer screenings. Operators face permanent fundraising bans and a $3.88 million monetary judgment.
$3.9M
The FTC secured a $2.5 billion settlement with Amazon, including a $1 billion civil penalty and $1.5 billion in consumer refunds, for enrolling millions of consumers in Prime subscriptions without proper consent and designing a deliberately difficult cancellation process. The order requires Amazon to implement clear enrollment disclosures, an easy cancellation method, and cease the unlawful practices.
$1.0B
The FTC issued 6(b) orders to seven technology companies to investigate the safety and privacy practices of their AI chatbots, particularly regarding impacts on children and teens. The inquiry focuses on compliance with children's privacy laws, data handling, and disclosures, requiring companies to provide information on these aspects.
The FTC settled allegations against Apitor Technology for violating COPPA by allowing a third party to collect geolocation data from children without parental consent. Apitor must pay a $500,000 suspended fine, delete improperly collected data, and implement measures to comply with COPPA, including obtaining parental consent and notifying parents.
$500K
Florida Attorney General James Uthmeier issued a subpoena to Lorex as part of an ongoing consumer protection and data privacy investigation. The probe examines Lorex’s ties to Dahua Technology and potential foreign spying risks, including unauthorized access to children’s data, and whether the company misled consumers about the privacy and security of its camera products and apps. The subpoena seeks documents related to corporate structure, third-party contracts, software update origins, data center locations, security vulnerabilities, and marketing claims about privacy and security.
Texas Attorney General Ken Paxton opened an investigation into Meta and Character.AI via Civil Investigative Demands, alleging deceptive trade practices including misrepresenting AI chatbots as confidential mental health tools while harvesting user data for targeted advertising. The probe assesses potential violations of Texas consumer protection laws and the SCOPE Act, particularly regarding privacy misrepresentations, concealment of data usage, and harms to children. This builds on prior investigations into Character.AI for SCOPE Act compliance.
Texas Attorney General Ken Paxton has opened an investigation into Meta AI Studio and Character.AI for deceptive practices in marketing AI chatbots as mental health services to children. The platforms are accused of impersonating licensed professionals, fabricating qualifications, and exploiting user data for advertising without proper disclosure. Civil Investigative Demands have been issued to examine violations of Texas consumer protection laws and the SCOPE Act.
Massachusetts Attorney General settled with Earnest Operations LLC for $2.5 million over allegations that the student loan lender's use of AI underwriting models led to disparate impact on Black, Hispanic, and non-citizen applicants. The company failed to test its AI models for bias, used discriminatory variables like Cohort Default Rate, and sent inaccurate adverse action notices. Earnest must pay the fine, discontinue problematic practices, and implement compliance measures.
$2.5M
Connecticut Attorney General William Tong announced a settlement with TicketNetwork, Inc. for violating the Connecticut Data Privacy Act by maintaining an unreadable privacy notice and non-functional consumer rights mechanisms. TicketNetwork agreed to comply with CTDPA requirements, maintain metrics for consumer rights requests, report to the AG, and pay $85,000.
$85K
California Attorney General Rob Bonta announced a $1.55 million settlement with health information website publisher Healthline Media LLC, resolving allegations that the company violated the CCPA and Unfair Competition Law. Violations included failing to honor consumer opt-out requests, sharing sensitive health data with third parties without required privacy protections, and using deceptive consent banners that did not disable tracking cookies. The settlement imposes injunctive terms, compliance requirements, and a civil penalty, marking the largest CCPA settlement to date.
$1.6M
Florida Attorney General James Uthmeier issued subpoenas to Contec, a Chinese medical device manufacturer, and Epsimed, a Miami-based reseller, over allegations that their patient monitors contain backdoors and automatically transmit patient data to China without consent. The companies are accused of violating Florida's Deceptive and Unfair Trade Practices Act by omitting material security vulnerabilities andmaking false representations about FDA approval and product quality. The AG may seek damages, civil penalties, and injunctive relief in future enforcement.
New York Attorney General Letitia James, joined by 27 other state attorneys general and the District of Columbia, filed a lawsuit against 23andMe to block the company’s planned sale of 15 million customers’ genetic and health data without their consent or knowledge. The coalition argues 23andMe must comply with state laws requiring express informed consent for the sale or transfer of sensitive genetic data. The lawsuit seeks to prevent misuse, exposure in future breaches, and unauthorized use of customers’ private genetic information.
The FTC settled charges against GoDaddy Inc. and GoDaddy.com, LLC for misleading customers about their data security protections and failing to adequately secure their website hosting services. The company allegedly did not implement reasonable security measures, leaving customer websites vulnerable to attacks that could harm both the customers and visitors to those sites. The case resulted in a consent order requiring GoDaddy to improve its security practices.
The FTC settled charges against GoDaddy Inc. and GoDaddy.com, LLC for misleading customers about their data security protections and failing to adequately secure their website hosting services. The company's security failures left customers' and website visitors' data vulnerable to attacks. The final order requires GoDaddy to implement comprehensive data security measures.
The California Privacy Protection Agency (CPPA) opened a formal public comment period on modifications to proposed regulations for CCPA updates, cybersecurity audits, risk assessments, Automated Decisionmaking Technology (ADMT), and insurance companies. The modifications were approved unanimously during the May 1 Board Meeting, and comments are accepted until June 2, 2025.
Texas Attorney General Ken Paxton has notified several Chinese companies, including TP-Link, Alibaba, and CapCut, that they are violating the Texas Data Privacy and Security Act (TDPSA). The companies must comply with TDPSA requirements to disclose data processing, allow consumer opt-outs, and enable data deletion within 30 days. Failure to comply will result in further legal action.
Texas Attorney General Ken Paxton has issued notices to several Chinese companies, including TP-Link, Alibaba, and CapCut, for violating the Texas Data Privacy and Security Act (TDPSA). The companies must comply with TDPSA's requirements to disclose data processing, allow opt-outs, and enable data deletion within 30 days, or face further legal action.
Texas Attorney General Ken Paxton issued a 30-day compliance notice to TP-Link, Alibaba, CapCut, and other CCP-affiliated Chinese companies for violating the Texas Data Privacy and Security Act (TDPSA). The companies are accused of failing to disclose consumer data processing activities, allow opt-out of data collection, and enable consumer data deletion as required by Texas law. If the companies do not comply within 30 days, the Attorney General's office will pursue additional legal action.
Texas Attorney General Ken Paxton announced legal action against several Chinese companies, including TP-Link, Alibaba, and CapCut, for violating the Texas Data Privacy and Security Act (TDPSA). The companies have been given 30 days to comply with requirements to disclose data processing, allow consumers to opt out of data collection, and enable data deletion. Failure to comply will result in further legal action to protect Texans' privacy rights and prevent data from being accessed by the Chinese Communist Party.
Florida Attorney General James Uthmeier filed a lawsuit against Snap, Inc., operator of Snapchat, for violating Florida’s HB3 child social media protection law and the Florida Deceptive and Unfair Trade Practices Act (FDUTPA). The suit alleges Snap knowingly allowed children under 13 to create accounts, failed to obtain parental consent for 14-15 year old users, deployed addictive dark pattern design features to children, and deceived parents about platform risks including predator access, drug sales, and harmful content. The legal action seeks to hold Snap accountable for noncompliance with Florida child safety and privacy laws.