Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Tuesday, July 7, 2026 · 6:49 PM EDT

Key developments

GIZMODO

Judge approves $46.75 million 23andMe breach settlement

Gizmodo's Ece Yildirim reported that a bankruptcy judge approved a $46.75 million settlement for users affected by 23andMe's 2023 breach, which exposed profile and genetic data for nearly 7 million people. About $14.29 million has already been paid, and the order authorizes another $32.46 million in distributions. The company filed for bankruptcy in March 2025 and was later sold to a nonprofit led by Anne Wojcicki; California Attorney General Rob Bonta is separately suing Chrome Holding Co. over alleged security failures and misleading breach statements.

Why it matters

The approval moves one of the largest genetic-privacy breach cases from litigation into payouts while separate state enforcement remains unresolved.

Sources & driving stories

GIZMODO · Ece Yildirim

Gizmodo coverage
THE PHILADELPHIA INQUIRER

Blank Rome sued over client data exposure

The Philadelphia Inquirer and Above the Law's Joe Patrice reported that two proposed class actions filed Monday in the Eastern District of Pennsylvania accuse Blank Rome of failing to protect information for 57,554 current and former clients and others. Complaints say a third party impersonated IT on May 21 and induced a lawyer to upload files to an external Google Drive; potentially exposed data included names, Social Security numbers, addresses, birthdates, driver's license and passport numbers, medical information, and health insurance information. Blank Rome says one attorney was involved, its network was not breached, files were deleted within two hours, law enforcement was notified, and credit monitoring was offered.

Why it matters

The suits test how law firms may be held accountable when social engineering exposes highly sensitive client and health-related information without a network intrusion.

Sources & driving stories

THE PHILADELPHIA INQUIRER

The Philadelphia Inquirer coverage

ABOVE THE LAW · Joe Patrice

Above the Law coverage

ABAJOURNAL · John O'Brien

Abajournal coverage
THE HILL

Judge quashes DOJ election-worker data subpoena

The Hill's Sarah Davis reported that U.S. District Judge William Ray on Tuesday denied the DOJ's grand jury subpoena seeking names, job titles, residential and email addresses, and personal cell numbers for Fulton County, Georgia, 2020 election workers. Ray called the April request "staggering" and said the government could not use a grand jury subpoena to obtain private information without a legitimate law enforcement purpose. Fulton County officials said the demand could cover thousands of employees and volunteers.

Why it matters

The ruling limits government access to sensitive personal data in election-related investigations and frames such requests as a privacy risk even outside commercial breach settings.

Sources & driving stories

THE HILL · Sarah Davis

The Hill coverage

Worth noting

WORTH NOTING

Texas app age-verification proceeds

The Record's Suzanne Smalley and CNET's Katelyn Chedraoui report that the Supreme Court declined to block Texas's app-store age verification law while challenges continue, leaving under-18 age checks and parental-consent requirements in force ahead of Fifth Circuit arguments in August.

WORTH NOTING

Lemonade settlement claims open

Cleveland's Claudia Dimuro reports Lemonade agreed to a $10.5 million class settlement affecting about 198,000 people, with documented breach-related losses eligible for up to $10,000 and claims due Sept. 8.

WORTH NOTING

Bandai teen arrest raises AI-abuse questions

TechNadu's Lore Apostol reports Tokyo police arrested a 15-year-old suspected of exploiting Bandai Channel in November 2025, allegedly canceling 46,812 subscriptions and accessing up to 1,366,000 email and username records after using ChatGPT to build a malicious script.

Still unclear

OPEN QUESTION

Will age checks create new data honeypots?

Texas's law advances while challengers argue age verification can require sensitive identity disclosures, raising the question of whether child-safety mandates increase privacy exposure.

OPEN QUESTION

Can social-engineering cases reset breach liability?

Blank Rome's defense emphasizes no network breach and rapid containment, but plaintiffs are pressing privacy and security claims based on training, safeguards, and delayed notice.