The B2B Podcast Index
Index
All categories
MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
MethodologySubmit
Best of:MarketingSalesSaaSFinanceHROpsLeadershipCustomer SuccessAI & DataProductStartups & FoundersRevOpsEngineering & DevTools
An independent project byFame
SearchBest episodesGuestsInsightsMethodologySubmit a podcast
Index/Legal & Privacy Brief
Legal & Privacy Brief artwork

2026-06-20: Google and AdMob agreed to pay $8.25 million to settle children's privacy claims related to Google

Legal & Privacy Brief · 2026-06-20 · 12 min

0:00--:--

Key moments - from our scoring

Substance score

26 / 100

Five dimensions, 20 points each

Insight Density7 / 20
Originality4 / 20
Guest Caliber2 / 20
Specificity & Evidence11 / 20
Conversational Craft2 / 20

Google and AdMob will pay $8.25 million to settle children's privacy claims centered on Google Play Store policies, specifically allegations of data collection and monetization from minors without proper parental consent under COPPA. The settlement highlights a critical compliance area for app operators: implementing robust age-gating, documented consent mechanisms, and parental authorization before collecting personal information from users under 13. Beyond child privacy, this brief covers emerging enforcement trends across consumer protection - including class actions against Steve Madden for dark pattern email marketing, Garmin for body composition accuracy claims, and Performance Golf for unauthorized subscription enrollment. The episode also examines regulatory shifts like UK Information Commissioner John Edwards' resignation following workplace conduct issues, Anthropic's forced shutdown of its Fable AI model after US export control classification as a munition, and significant cybersecurity enforcement including the international disruption of the SOC Golish botnet linked to Evil Corp. For compliance officers, operations leaders, and product teams, key takeaways include strengthening COPPA audits, implementing out-of-band verification for payment changes to combat $3+ billion in annual business email compromise losses, ensuring subscription programs obtain explicit affirmative consent, and reviewing AI export control implications before international deployment.

Key takeaways

  • →Google and AdMob must pay $8.25 million for collecting children's data without proper parental consent, requiring companies to audit age-gating mechanisms and ensure COPPA compliance before collecting personal information from users under 13.
  • →Business Email Compromise attacks caused $3.47 billion in losses in 2025, making out-of-band verification and verbal confirmation of payment instructions critical controls for finance and HR teams.
  • →Multiple class actions challenge subscription enrollment practices, requiring companies to obtain affirmative consent through separate checkboxes and provide clear cancellation mechanisms compliant with state automatic renewal laws.
  • →The US government's classification of Anthropic's Fable AI model as a dangerous munition under export controls demonstrates that organizations developing advanced AI must consult export control regulations before international releases.
  • →The SOC Golish botnet disruption affected 15,000 compromised WordPress sites, underscoring the need for immediate updates to WordPress core, themes, plugins, and implementation of file integrity monitoring.

In this episode

  1. 1Google and AdMob $8.25 Million Children's Privacy Settlement
  2. 2Enforcement Actions and Class Action Litigation Updates
  3. 3Supreme Court Decisions on Gun Possession and Federal Jurisdiction
  4. 4Senate Advances Supreme Court Camera Legislation
  5. 5Business Email Compromise and Cybercrime Risk Mitigation
  6. 6UK Information Commissioner Resignation and Regulatory Impact
  7. 7Anthropic Fable AI Model Shutdown Due to Export Controls
  8. 8International Cybercrime Disruptions and WordPress Security Threats

Mentioned

GoogleAdMobAnthropicGoogle Play StoreFableSteve MaddenGarminPerformance GolfJohn EdwardsEvil CorpTelegramWordPress

Topics in this episode

Business Email Compromise (BEC)Google Play StoreAdMobCOPPA (Children's Online Privacy Protection Act)Steve MaddenGarmin Index S2Performance Golf Scratch ClubAnthropic Fable AIExport Control AuthoritySOC Golish malware

Questions this episode answers

What did Google and AdMob settle for regarding children's privacy violations?

Google and AdMob agreed to pay $8.25 million to resolve a class action lawsuit alleging they collected and monetized data from children without proper parental consent or compliance with the Children's Online Privacy Protection Act (COPPA) through Google Play Store policies. Class members who made Google Play purchases during the applicable class period may be eligible for compensation.

Why did Anthropic shut down its Fable AI model?

The US Government classified Anthropic's Fable AI model as a dangerous munition under Export Control Authority and banned foreign nationals from accessing it on June 12, 2026, just three days after its release. Unable to differentiate between American and foreign users, Anthropic shut off access entirely.

What was the SOC Golish botnet and what happened to it?

SOC Golish is a botnet active since 2017 linked to Russia's Evil Corp cybercrime group that spreads through fake browser update prompts. Law enforcement from the Netherlands, Canada, the United States, and Germany disrupted the network in June 2026, seizing over 100 servers and disinfecting nearly 15,000 hacked websites.

How much did business email compromise attacks cost in 2025 according to the FBI?

Business email compromise attacks accounted for 24,768 complaints and $3.47 billion in losses in 2025, making it the second-largest cybercrime by total loss after investment fraud, with phishing remaining the most frequently reported crime overall.

What are the common business email compromise schemes highlighted in the brief?

Common BEC schemes include senior executive fraud using voice or video deepfakes, vendor payment redirection through compromised accounts or lookalike domains, M&A transaction interception during deal closings, and payroll diversion through fraudulent direct deposit changes.

What our scoring noted

Our reviewer’s read on each dimension, with quotes from the episode.

Insight Density

7 / 20

The episode packs in a reasonable number of factual news items and compliance action items per minute, but the 'insights' are almost entirely surface-level reporting or obvious recommendations ('implement MFA', 'ensure parental consent'). The Fable AI munition classification and the ICO investigation drop are genuinely interesting data points, but there is no analytical depth beyond restating the news.

AI related fraud captured 22,300 364 complaints and $893 million in losses
regulatory investigations drop from over 2,000 in 2019 to just over 200 in 2025, with more than 3,000 potential cases unassigned

Originality

4 / 20

This is pure news aggregation with boilerplate compliance checklists appended to each story. There is no contrarian framing, no first-principles reasoning, and no original analysis - just a structured summary of third-party reporting with generic takeaways recycled across every legal/privacy newsletter in the space.

Compliance Audit Subscription enrollment flows to ensure affirmative consent before charging recurring fees
Implement multifactor authentication on all email accounts

Guest Caliber

2 / 20

There is a single, unnamed speaker reading a news digest with no guests, practitioners, or experts of any kind. The source entity 'Carolina Clear Tech' is unknown, and no credentials or experience are established. This cannot score above the floor on this dimension.

He here's the full breakdown of today's top legal and privacy stories
Speaker A: Legal and Privacy Brief for June 20, 2026

Specificity & Evidence

11 / 20

The episode is genuinely above average on this dimension: it cites named cases, dollar figures, complaint counts, dates, and attributed sources throughout. Weaknesses include lack of any deeper interpretation of those numbers and occasional garbled data ('22,300 364 complaints').

Business email compromise Beck attacks accounted for 24,768 complaints and $3.47 billion in losses
seizing more than 100 servers and disinfecting nearly 15,000 hacked websites

Conversational Craft

2 / 20

There is no conversation whatsoever - this is a single speaker reading a scripted news brief with zero host-guest dynamic, no questions, no follow-ups, and no pushback. The format structurally precludes any conversational craft, earning only minimal credit for clean segmentation.

Next Section Enforcement Actions
Next Section Litigation Updates

Conversation analysis

Computed from the transcript - who did the talking, and the words that came up most.

Most-used words

class12privacy11court9children8claims8state8june7google7information7consent7anthropic6fable6export6actions6mechanisms6justice6

Full transcript

12 min

Transcribed and scored by The B2B Podcast Index.

Speaker A: Legal and Privacy Brief for June 20, 2026 Google and AdMob agreed to pay $8.25 million to settle children's privacy claims related to Google Play Store policies. Anthropic shut down its Fable AI model after the US Government classified it as a dangerous munition and banned foreign access under Export Control Authority. UK Information Commissioner John Edwards resigned over workplace conduct involving inappropriate humor. He here's the full breakdown of today's top legal and privacy stories. Legal and Privacy Brief June 20, 20206 Next Section Enforcement Actions Google Play Children's Privacy Settlement Google and Admob agreed to pay $8.25 million to resolve a class action lawsuit alleging violations of children's privacy laws through Google Play Store policies. The settlement addresses claims that the companies collected and monetized data from children without proper parental consent or or compliance with the Children's Online Privacy Protection Act. Class members who made Google Play purchases between the applicable class period may be eligible for compensation. Review your app store practices if you operate apps available to children under 13. Ensure parental consent mechanisms comply with COPPA before collecting any personal information, document age gating mechanisms and data collection practices for minors. Source Top Class Actions Next Section Litigation Updates Steve Madden Email Marketing Class Action A new class action lawsuit filed in Washington State alleges Steve Madden uses deceptive false time scarcity tactics in marketing emails to manipulate consumers into rushed purchases. The complaint claims the retailer creates artificial urgency through countdown timers and limited time offers that violate state consumer protection laws. This follows increasing scrutiny of dark patterns in digital marketing. Top Class Actions Garmin's Smart Scale Accuracy Claims A class action lawsuit alleges Garmin falsely advertises that its index S2 smart scales accurately measure body composition metrics, including body fat percentage, muscle mass, and bone density. The complaint challenges the scientific validity of bioelectrical impedance analysis in consumer devices and whether Garmin's marketing claims constitute deceptive advertising under state consumer protection statutes. Top Class Actions Performance Golf Unwanted Subscription Enrollment Performance Golf faces a class action lawsuit alleging the company enrolled consumers into its Scratch Club subscription program without consent. The complaint claims customers who made one time purchases were automatically charged recurring fees without clear disclosure or authorization, violating state laws governing negative option billing and automatic renewal practices. Compliance Audit Subscription enrollment flows to ensure affirmative consent before charging recurring fees. State laws increasingly require clear disclosure, separate consent checkboxes, and easy cancellation mechanisms for auto renewal programs. Top Class Actions Supreme Court Decisions on Gun Possession Sentence Appeals and Federal Court Jurisdiction the Supreme Court issued three decisions on June 19th in United States v. Himani the court held that prosecuting Ali Hemani for possessing a gun while being an unlawful marijuana user approximately every other day violates the Second Amendment, with Justice Gorsuch writing for a unanimous court with multiple concurrences. In Hunter v. United States, Justice Kagan wrote for the majority that agreements not to appeal a sentence are unenforceable when they would result in a miscarriage of justice Remanding to reconsider under that standard. Justice Thomas dissented. In T M v. University of Maryland Medical System Corp. The court held 5:4 that the Rucker Feldman doctrine applies to state court judgments still subject to state appellate review, not just final decisions. Justice Sotomayor wrote for the majority, with Justice Barrett dissenting, joined by Roberts, Kagan and Gorsuch. Skadu? S Blog Next Section Regulatory Guidance Senate Committee Advances Supreme Court Camera Legislation the Senate Judiciary Committee advanced legislation with bipartisan support to televise Supreme Court proceedings. The bill would require the justices to accept cameras unless a majority determines video coverage would interfere with due process rights of a party to a case, Bloomberg reports. The committee approved similar bills four times in previous Congresses, but none came to a full Senate vote. Legislation remains in committee and faces uncertain prospects for floor consideration. Skatu? S Blog Business Email Compromise risk mitigation the FBI's 2025 Internet Crime Report shows Business email compromise Beck attacks accounted for 24,768 complaints and $3.47 billion in losses, second only to investment fraud by total loss. Phishing remained the most frequently reported crime, with 191,561 complaints. AI related fraud captured 22,300 364 complaints and $893 million in losses. Coalition's 2025 Cyber Claims Report found BEC and funds transfer Fraud accounted for 60% of total claims in 2024, with nearly 30% of BEC incidents escalating to funds transfer fraud. Common schemes include senior executive fraud using voice or video deepfakes, vendor payment redirection through compromised accounts or lookalike domains, um M&A transaction interception during deal closings and payroll diversion through fraudulent direct deposit changes. Implement multifactor authentication on all email accounts. Establish out of band verification procedures for payment instructions, especially wire transfers above threshold amounts. Train finance and HR staff to recognize spoof domains and compromised account indicators. Require verbal confirmation using known phone numbers for any changes to vendor payment details or or employee direct deposit information. Debavoice Data Blog Next section Privacy Developments UK Information Commissioner resigns UK Information Commissioner John Edwards formally resigned on June 19 after stepping back from duties in February during a workplace investigation, Edwards acknowledged exercising poor judgment and making inappropriate attempts at humor that caused offense. Edwards, who served as New Zealand's Privacy Commissioner from 2014 to 2021 before his UK appointment in January 2022, had continued drawing his 200,000 pounds annual salary while in New Zealand. During the investigation, Deputy Chief Executive Paul Arnold assumed statutory functions as temporary acting accounting officer. The Department for Science, Innovation and Technology will determine next steps, including the search for a successor. The ICO the Information Commissioner's office transitioned to ah. A new information Commission structure has stalled and regulatory investigations drop from over 2,000 in 2019 to just over 200 in 2025, with more than 3,000 potential cases unassigned. Source the Record Next section Policy Changes Anthropic shuts down fable AI model after US export controls the US government classified Anthropic's fable generative AI model as a dangerous munition on June 12, three days after its June 9 release, using export Control Authority to prohibit foreign nationals from accessing it. Unable to differentiate between Americans and foreigners, Anthropic shut off access for everyone. Fable is a constrained version of Mythos, which Anthropic claimed in April was dangerous due to its ability to find and exploit code vulnerabilities. The model is described as relentlessly proactive and capable of finding novel and unexpected ways to satisfy goals and including loopholes and constraints. Open source developers have since replicated similar capabilities using smaller models with sophisticated harnesses. Prague company matched Anthropic's cybersecurity capabilities with cheaper models, and other groups demonstrated that multiple cheaper models harnessed together can match Fable's performance. Schneier on security UK social media age restrictions exceed Australia's approach the UK is examining steps to prevent children from circumventing a social media ban for users under 16, with measures going further than Australia's policy. The Financial Times and BMJ report the government is considering technical enforcement mechanisms beyond simple age verification. The Everything in Moderation newsletter covered split screen reactions to the UK ban, with trust and safety professionals debating implementation, feasibility and civil liberties implications. Tech Dirt International law enforcement disrupts SOC Galish malware network Police from the Netherlands, Canada, the United States and Germany disrupted the Soc Golish botnet linked to Russia's Evil Corp cybercrime group, seizing more than 100 servers and disinfecting nearly 15,000 hacked websites. Dutch police removed malware and backdoors from thousands of infected WordPress sites and notified owners. SOC Golish, active since 2017, spreads through fake browser update prompts on legitimate sites. The FBI stated the malware establishes an initial foothold for ransomware campaigns and espionage. Evil Corp. Was sanctioned by the US in 2019 for developing Dridex banking malware, which caused over $100 million in losses. Researchers at Infoblox identified Sock Golish as an entry point for Doppel Paymer, Wastedlocker, Hades, Lockbit, and Ransom Hub ransomware groups. Audit WordPress installations for outdated plugins and weak credentials. Implement website integrity monitoring to detect unauthorized changes. Review Web application firewall rules to block common injection vectors. Consider website malware scanning services if you operate public facing WordPress sites. The record India temporarily blocks Telegram India blocked the Telegram messaging app until June 22, according to government announcements. The temporary restriction follows ongoing tensions between technology platforms and regulatory authorities over content moderation and lawful intercept requirements. Tech Dirt Next Compliance Takeaways Children's privacy compliance if your apps or services are available to users under 13 audit data collection practices for COPPA compliance. The $8.25 million Google Play settlement underscores regulatory focus on age appropriate consent mechanisms and parental controls. BEC prevention Protocols with bec losses exceeding $3 billion in 2025 and AI enabled impersonation attacks rising. Implement out of band verification for all payment instruction changes. Require verbal confirmation using known phone numbers for wire transfers, vendor payment updates, and direct deposit changes. Subscription billing disclosures Multiple class actions challenge auto enrollment and negative option billing practices. Ensure subscription programs obtain affirmative consent through separate checkboxes, provide clear disclosure of recurring charges, and offer straightforward cancellation mechanisms compliant with state automatic renewal laws. WordPress security hardening the SOC Golish takedown affecting 15,000 compromised sites highlights ongoing risks to outdated CMS installations. Update WordPress core themes and plugins immediately, enable automatic security updates and implement file integrity monitoring to detect backdoor injection Export control awareness for AI tools the Fable classification as a munition demonstrates expanding U.S. export controls on advanced AI capabilities. Organizations developing or deploying cutting edge AI models should consult export control before international releases, particularly for models with dual use, cybersecurity or adversarial capabilities. That concludes today's legal and privacy brief from Carolina Clear Tech for informational purposes only, not legal advice.

Related episodes across the Index

Other episodes covering the same guests and topics, from across The B2B Podcast Index.

  • D2C Without a Tax Degree: How to Sell On a Web Shop Without Becoming a Tax ExpertGrowth Stage by FastSpring · on Google Play Store84 / 100
  • Chris Pogue: Digital Forensics in the Modern Threat LandscapeKitecast · on Business Email Compromise (BEC)82 / 100
  • Denise Incandela, EVP of Walmart Fashion: How Walmart Became a True Fashion DestinationThe Retail Pilot · on Steve Madden78 / 100
  • Inside Email Security: Phishing, Hackers, and Harmony CheckpointThe Audit · on Business Email Compromise (BEC)74 / 100
  • S1 EP12: How to Grow Subscribers Through SMS Marketing30 Minutes of Growth · on Steve Madden68 / 100
  • Navigating the Cybersecurity Maze, with Geoff MooreIT Matters · on Business Email Compromise (BEC)67 / 100

More from Legal & Privacy Brief

All episodes →
  • 2026-07-11: The FTC struck a 10-year settlement with John Deere requiring the company to provide farmers and63 / 100
  • 2026-06-19: Labcorp settles a 2018-2019 data breach class action for $35 million51 / 100
  • 2026-06-18: Section 702 surveillance authority expired after Trump tied renewal to his election bill49 / 100
  • 2026-07-10: The House passed the KIDS Act mandating age verification online
  • 2026-07-09: Cash App's owner Block, Inc
All Legal & Privacy Brief episodes →