View as Webpage

Volume 7, Issue 5

Welcome


Welcome to our fifth issue of 2026 of Decoded -- our technology law insights e-newsletter.


During the summer months, our firm is pleased to host a talented group of law students, who get the opportunity to research and write, shadow our attorneys, and learn about the practice of law in a firm setting. As young professionals still deeply involved in higher education, our Summer Associates will be contributing to our summer publications and sharing their perspectives as both students and future legal practitioners. Please join us in welcoming Jessica Blevins, Charlie Long and Nathan Ellis to the Decoded team for this summer edition.

 

Spilman’s SuperVision Labor & Employment Symposium, Charleston, WV, June 18

2026 Workplace Masterclass: L&E Compliance, AI, & the Brave New Employment Landscape: A fast-moving, high-impact seminar for employers navigating the modern workplace. Join Spilman attorneys for our full-day SuperVision Symposium, designed to inspire confidence in navigating complex employment decisions. This complimentary symposium is tailored for business owners, C-suite executives, HR professionals, and anyone who manages employees. Dive into a day of valuable insights on employment topics such as AI, investigations, litigation, immigration, labor law, accommodations, and much more. Spend the day with us and leave armed with strategies and solutions to tackle the ever-changing world of labor and employment law. Please click here to learn more and register.


As always, thank you for reading.


Nicholas P. Mooney II, Co-Editor of Decoded; Chair of Spilman's Technology Practice Group; Co-Chair of the Cybersecurity & Data Protection Practice Group; and Co-Chair of the Artificial Intelligence Law Practice Group


and


Alexander L. Turner, Co-Editor of Decoded and Co-Chair of the Cybersecurity & Data Protection Practice Group

Two Years Ago vs Today: Looking at Crypto Regulation in the US

“U.S. crypto regulation is becoming more defined, with the GENIUS Act, advancing Senate legislation and closer SEC-CFTC coordination replacing the earlier enforcement-first approach.”

 

Why this is important: U.S. cryptocurrency regulation has evolved from a period of significant uncertainty to one of increasing clarity, creating a more favorable environment for institutional adoption and corporate use of digital assets.

 

A few years ago, crypto companies operated under a regulatory framework largely defined by enforcement actions rather than formal rules. Regulators often relied on lawsuits and settlements to establish boundaries, leaving businesses uncertain about compliance obligations. For CFOs and treasury teams, this uncertainty created risks related to accounting treatment, banking access, disclosures, and future regulatory liabilities, discouraging deeper involvement with crypto assets.

 

Now, the regulatory environment is more predictable. A key regulatory milestone was the passage of the GENIUS Act in 2025, which created the first federal legislative framework focused on stablecoins. The proposed Clarity Act would further define when digital assets are regulated as securities, commodities, or under separate oversight regimes while imposing anti-money-laundering requirements and standards for decentralization claims.

 

Additional policy changes have reduced barriers to adoption. The SEC rescinded accounting guidance that had made crypto custody more costly for banks and public companies, while the SEC and CFTC have increased coordination through joint guidance and formal cooperation agreements.

 

Ultimately, crypto’s primary challenge has shifted. Previously, the industry struggled with uncertainty about whether clear rules existed. Today, the issue is navigating multiple emerging regulatory frameworks that may differ across products, markets, and regulators. Continued adoption will depend on achieving greater consistency and interoperability among those rules. --- Shane P. Riley

Frequency and Severity of Hacks of Medical Devices Increasing

“Adoption of AI-enabled and AI-assisted medical devices is increasing, despite serious concerns about the cybersecurity risks associated with the devices, and legacy devices continue to be used past end-of-support, despite those devices containing known and unpatched vulnerabilities.”

 

Why this is important: This is important as the use of AI-enabled medical devices continues to rise. However, confidence in the ability to mitigate the cybersecurity risks has not. Outside counsel and in-house attorneys must be vigilant in dealing with the review of these devices and paying close attention to the changing legal landscape surrounding their use. In modern healthcare, cybersecurity is now a huge part of patient safety, and AI technology continues to change at a rapid rate. A single breach in an AI medical device is not just a data leak; it is a potential clinical shutdown that delays patient care. This is why healthcare leaders must integrate legal and compliance into the beginning of the procurement process to ensure that risks are translated into clear leadership decisions. --- Sara E. Chapman

FBI Warns About PhaaS Platform Used to Access Microsoft 365 Environments

“Device code phishing enabled hackers to bypass multifactor authentication without credentials.”


Why this is important: The attack works by sending the victim an email that looks like it comes from a trusted service, such as Microsoft or a file-sharing platform. The email instructs the recipient to visit a real Microsoft website and type in a short code included in the message. This step seems routine and even reassuring because the website is genuinely Microsoft's. What the victim does not realize is that entering the code hands the attacker a digital key to the account. From that point forward, the attacker can read email, access files, and participate in Teams conversations, all without ever knowing the victim's password and without triggering the usual MFA prompt.


The Kali365 service makes this attack available to criminals who lack technical sophistication. It provides ready-made deceptive emails, automated tools, and tracking dashboards, functioning much like a subscription software product, except that its only purpose is enabling account takeovers. Researchers found active campaigns using this method against organizations in manufacturing, education, insurance, financial and legal services, healthcare, and government across the U.S., Canada, Australia, New Zealand, and Germany.


This threat is not theoretical to us. In the past month, our managed detection and response (MDR) provider, a security service that monitors our systems around the clock, alerted our team to an active account takeover attempt in real time. That alert meant nothing without someone willing to act on it immediately. Enterprise Systems Manager Jason Dunkle did exactly that, responding at 2 AM to shut the threat down before any harm occurred. In doing so, Jason embodied two principles at the heart of the Spilman Way: we promise to be exceedingly prompt and responsive, and we always strive to exceed expectations. Nobody expects someone to leave a warm bed in the middle of the night to protect the firm and its clients. Jason did it without hesitation, and our firm is better for it.



The broader lesson is that a single security control, no matter how good, is never enough on its own. Think of security like the locks, alarm system, and security guard at a bank. Removing any one of them makes the whole system weaker. In our case, the layers worked together: our email security flagged suspicious activity, our MDR provider detected the session takeover in progress, and a skilled team member was ready and willing to act on that information immediately. The goal is never to find the one perfect control that stops everything. The goal is to build enough overlapping layers that when one is defeated, another catches what slipped through. --- James E. Dunlap, Chief Information Officer, Spilman Thomas & Battle

Centers for Medicare and Medicaid Services Exposes Doctors’ Social Security Numbers

“The exposure is linked to a CMS provider directory data intended to help improve accuracy of insurer networks.”

 

Why this is important: The Centers for Medicare and Medicaid Services (CMS) recently took the National Provider Directory offline after the Trump administration inadvertently exposed Social Security numbers of at least 100 health providers in a downloadable data file in a part of the directory that is primarily intended for insurers and researchers. Launched in July 2025, the National Provider Directory is a database accessible by the public that allows beneficiaries to find providers who accept Medicare and Medicaid. CMS blamed user error on the part of healthcare providers for the Social Security numbers being entered in the wrong place. CMS assures the public that the inadvertent disclosure is being addressed internally and that patients using an online search tool likely would not have been able to access this sensitive information, while also acknowledging that there are areas where data integrity processes could be strengthened. Some privacy officials are sounding the alarms that privacy safeguards need to be bolstered to avoid such inadvertent disclosures. --- Jennifer A. Baker

OnlyFans Mega Leak Reveals 340M User Records, Hackers Claim

“The alleged leak could expose real identities of OnlyFans creators and subscribers who value anonymity on the platform.”

 

Why this is important: A threat actor claims to be selling 340 million OnlyFans user records, including emails, usernames, and account activity metrics, according to a post on a popular data leak forum. OnlyFans has not confirmed the leak and claimed these reports are false. However, security researchers have analyzed samples of the alleged data attached to the post and confirmed it could expose the identities of creators and subscribers who value anonymity on the platform known for hosting explicit content.

 

The attackers claim that there was no direct breach or scraping of OnlyFans systems. Instead, the database for sale is a compilation of data from previous leaks, public sources, and other platform data breaches. By utilizing external data points, threat actors can cross-reference common identifiers—like a single email address—to link a user's private online persona with public profiles or mainstream services, ultimately exposing the user’s real-world identity. The weaponization of aggregated data to strip away digital anonymity highlights a growing cybercrime trend that focuses on data correlation over system exploitation. Threat actors do not need to execute a sophisticated network intrusion, but can produce a similarly devastating privacy breach and inflict equivalent harm to companies and users by simply connecting the dots between available information.

 

The incident forces a reevaluation of what it means for a platform to protect its users, and exposes a significant responsibility gap within the current regulatory framework. Because data privacy laws are triggered by a specific security incident, such as an unauthorized intrusion into a company's network or direct data scraping, there is a regulatory blind spot when it comes to the weaponization of aggregated data. When a platform can factually claim that no direct breach occurred, it effectively evades statutory penalties and notification requirements, leaving affected users exposed to the privacy fallout without any clear legal recourse. --- Alison M. Sacriponte

Canvas Owner Reaches ‘Agreement’ with Threat Actors After Data Breach

“Cybersecurity experts suggest that Instructure appears to have made a ransomware payment, which the FBI highly discourages.”

 

Why this is important: Instructure, the parent company of cloud-based learning management system Canvas, announced that it had reached an agreement with a threat actor following a significant cybersecurity breach affecting colleges and schools nationwide. The breach, attributed to the cybergang ShinyHunters, involved multiple intrusions into Canvas systems, from which the attackers claimed to have exfiltrated massive amounts of data from millions of users, including usernames, email addresses, user communications, and enrollment information across thousands of institutions worldwide. Instructure stated that in accordance with the agreement, the stolen data was returned, and Instructure received digital confirmation of its deletion, commonly referred to as “shred logs.” The company also reported that the threat actor agreed not to pursue further extortion against affected institutions or individuals. Several class action lawsuits have already been filed against Instructure in federal district courts over the data breach.



Cybersecurity experts suggest the "agreement" with threat actors was a ransomware payment, although Instructure did not explicitly confirm paying a ransom. Law enforcement agencies, including the FBI, strongly discourage ransomware payments due to concerns that they incentivize further criminal activity and offer no guarantee of data destruction. Even with assurances from threat actors, organizations cannot verify that all copies of compromised data have been permanently deleted or that the affected institutions or individuals will not be targeted.

 

The incident highlights ongoing legal and compliance risks, including potential liability exposure, data privacy concerns, and the limits of contractual-style resolutions with threat actors and cybercriminals. This incident also underscores a broader systemic challenge within the education sector, which has grown increasingly vulnerable to attacks, particularly as recent shifts in federal funding have dismantled key technical assistance and threat-monitoring frameworks. When systemic state and federal support structures are lacking, companies face immense pressure to settle with cybercriminals. This incident underscores the difficult legal and strategic calculus that organizations face in ransomware scenarios—balancing fiduciary duties, regulatory risk, and stakeholder harm against public policy discouraging payment and the inherent uncertainty of dealing with threat actors. --- Alison M. Sacriponte

What’s Next for Data Centers in PA? State Lawmakers are Split on How to Regulate Them.

“The Pennsylvania House has passed bills in recent months aimed at regulating the massive data center projects popping up across the state.”

 

Why this is important: Data center advocates are lobbying Pennsylvania legislators so that the unfettered free enterprise of data center development may continue in exchange for the promises of jobs and access to advanced technology. Advocates for natural resources argue that data centers can and will create strains on water sources, energy grids, create noise pollution, and other long-term complications that do not rise to the level of the purported benefits. In the middle is the Pennsylvania General Assembly, which is split on how best to approach the data center revolution. Taxes, annual reporting, permits, and mandated open discourse with local communities are a few suggestions currently being considered. If legislative red tape makes the profits untenable, the investments will not come to Pennsylvania. However, if nothing is done to ensure sustainable development and the protection of wildlife and local community resources, then the result may be a community best suited for data centers, not civilians. Whether the best solutions are state laws, local ordinances, cooperative agreements, trust, or a combination, only time will tell. What is immediately understood is that there is a bipartisan, bicameral race in Pennsylvania to get ahead of the curve to guide the development of data centers towards a healthy, mutually profitable, community-enriching future. --- Sophia L. Hines

Ohio Lawmakers are Creating Bipartisan Data Center Committee that will Start Meeting This Month

“Ohio has about 200 data centers, the fifth-highest state in the country.”

 

Why this is important: It’s official – Ohio lawmakers have formed a bipartisan data center committee that will bring together workers, companies, and residents to testify on the impacts of data centers in Ohio. Companies are especially eager to have the opportunity to address concerns.

 

Data centers are on the rise throughout the United States. The electricity used by data centers is expected to rise to 9 percent of all U.S. electricity by 2030. This is unsurprising, as a large data center can use as much electricity as 100,000 homes. Furthermore, Ohio is on the cutting edge of the data center boom, as the state has about 200 data centers, making it the fifth-highest state in the country.

 

The rise of data centers has not been without pushback – a group of Ohioans is trying to get a data center ban on the state’s November ballot. Additionally, 11 other states have introduced legislation to temporarily ban data centers. However, given Ohio’s data center prevalence, other states may soon follow suit with similar bipartisan committee arrangements. --- Charlie C. Long, Summer Associate

AI Data Center Boom is Rewriting Construction Economics for Owners Nationwide

“Hyperscale developers are drawing electricians, HVAC specialists and project managers away from traditional builds, tightening labor supply and raising subcontractor pricing.”

 

Why this is important: Before the current data center boom, extensive labor commitments were required for commercial and public construction projects such as large manufacturing facilities, hospitals, university campus improvements, infrastructure renovations, utility generation facilities and mega commercial warehouses. While the demand for construction labor remains high for these commercial and public construction projects, the “newest kids on the block” – AI-driven data centers – are beginning to impact certain aspects of traditional commercial projects in certain geographic areas of the country. While this is not surprising in light of the billions of dollars flowing into AI-data center projects, the boom has led to what this article describes as a “two-tier construction economy.” What does that mean, and why is it important to non-data-center commercial and public owners with significant construction projects planned near areas of AI-data center development?

 

The “two-tier construction economy” refers to the current situation where trades needed to construct AI data centers – HVAC, electrical, welders and project managers – are offered higher wages than they may have made on “traditional” commercial and public projects. Naturally, the higher wages can draw some of these crucial tradespeople to the AI datacenter work and away from the “traditional” projects. In response, owners of hospitals, universities, infrastructure projects and the like facing this competition may have to raise wages or scout for subcontractors farther away from their project sites to secure sufficient manpower. Having a workforce more remotely located from the job site can impact construction schedules, require remote housing near the site, and mandate changes to supply sourcing, among other things.

 

Owners on “traditional” commercial and public projects need to consider impacts of AI data center construction near in time and location to their planned projects. This is particularly true in areas most affected by AI infrastructure growth – Northern Virginia, Ohio, Texas and Arizona. Among other planning factors, owners should consider pre-construction labor market analyses; conduct outreach with required contractors and key subcontractors to secure commitments; consider alternative, less impacted construction sites if possible; evaluate earlier procurement and storage of necessary materials; develop contracts with larger contingency allocations; and evaluate project costs that account for potentially more remote workers. Finally, to the extent necessary and reasonable, outreach to the AI data center owner regarding its project schedule can assist with a more collaborative and workable planning process that facilitates construction of both the data center and the “traditional” project in a timely manner. --- Stephanie U. Eaton

Texas County Halts Rural Data Center Expansion for One Year

“Hill County commissioners have voted to temporarily halt new data center construction in unincorporated parts of the county, marking a significant escalation in the debate over digital infrastructure growth in rural Texas.”

 

Why this is important: As the demand for data centers continues to grow, rural communities are increasingly being asked to accommodate large-scale facilities that place significant demand on local resources. Regulating data center development is important because these facilities consume substantial amounts of electricity and water. Effective regulations help ensure that economic benefits from technological growth are balanced with environmental sustainability and the host community’s needs. For construction owners and developers, moratoriums such as these highlight the importance of closely monitoring evolving laws and regulations to ensure that projects remain compliant and aligned with community expectations. --- Jessica Blevins, Summer Associate

You Can’t Just Plug in a Data Center

“To meet booming AI-driven energy demand, utilities and regulators must adopt better rules, better forecasts, and better commitments.”

 

Why this is important: Data centers are not the first industrial customers to require greater power outputs than the average household; however, the speculative nature of the technology, the legislative delay in passing national regulations, and the reality that most utility sources must invest in additional transformers, substations, and transmission upgrades without complete guarantees are creating real concerns as addressed in this article. Forecasting for a data center's power usage can be exaggerated when only one party, the utility company (through its captive customer base), is footing the bill associated with the expansion effort. Large-load tariffs may help to compensate and incentivize utility providers and cover the broad range of contingencies, but the flexibility of service may become a factor as homes or businesses naturally cycle through peaks in energy usage. Regardless, the power grid is a rigid asset that must be managed with competence and care. The burden that data centers create throughout the U.S. can be mitigated to some degree, but the enthusiasm of a few investors and corporations must be carefully balanced with the necessity of planning, mutual investment, cooperative strategy, and long-term fee-bearing contracts. --- Sophia L. Hines

Google in Talks with SpaceX for Suncatcher Orbital Data Center Project

“Developing its space-based ​orbital data ⁠centers is one of the major drivers behind SpaceX's IPO plans, as the endeavor is ​expected to be highly capital intensive and technologically ​challenging.”

 

Why this is important: Alphabet Inc.’s Google recently announced Project Suncatcher. The article explains that this project is a research effort to network solar-powered satellites equipped with Google’s Tensor Processing Units into an orbital AI cloud. The prototype launch is set for 2027 and will be a partnership between Google and Elon Musk’s SpaceX. Google is also collaborating with Planet Labs, launching two prototype satellites by around 2027. This development will be highly capital-intensive and technologically challenging, which will be a major driver behind SpaceX’s IPO plans. --- Taiesha K. Morgan

Amid Heavy AI Use, Workers Say Their Skills are Atrophying

“As worker sentiment sours on the technology, clearer guidelines surrounding its usage may be even more critical.”

 

Why this is important: Recent workforce data highlights the growing tension between the rapid expansion of artificial intelligence across the workplace and employee capability metrics. As AI has become more widespread in day-to-day operations, employees report that their reliance on technology has weakened their foundational professional skills and confidence in their proficiency within their respective careers. A recent study showed that nearly half of employees believe they are overly dependent on AI tools, with many reporting declines in critical thinking, confidence, and long-term skill development. These findings are significant as they illustrate AI’s impact in the workforce, extending far beyond efficiency, raising questions about employee training, professional development, and oversight as many businesses continue to integrate AI into their operations. --- Nathan T. Ellis, Summer Associate

X Share This Email
LinkedIn Share This Email

This is an attorney advertisement. Your receipt and/or use of this material does not constitute or create an attorney-client relationship between you and Spilman Thomas & Battle, PLLC or any attorney associated with the firm. This e-mail publication is distributed with the understanding that the author, publisher and distributor are not rendering legal or other professional advice on specific facts or matters and, accordingly, assume no liability whatsoever in connection with its use.



Responsible Attorney: Michael J. Basile, 800-967-8251