A proposed US privacy class action alleges Lenovo.com embedded extensive advertising and analytics tracking that enabled bulk transfers of Americans’ sensitive identifiers and browsing context to entities tied to China, potentially violating the Justice Department’s Data Security Program and its Bulk Sensitive Data Transfer Rule (28 C.F.R. Part 202). The complaint—filed in the US District Court for the Northern District of California by Almeida Law Group on behalf of a San Francisco resident—claims Lenovo’s web infrastructure used pixels, scripts, cookies, and real-time bidding components to collect persistent identifiers (e.g., IP addresses, advertising IDs/cookies) and “full-string URLs” that can reveal detailed user behavior.
The suit argues the DOJ framework was designed to prevent adversarial countries from acquiring large-scale behavioral data usable for surveillance or exploitation, and it cites thresholds and categories for “covered personal identifiers” (including device identifiers such as IMEI/MAC/SIM and advertising IDs). It alleges Lenovo’s site loaded numerous first- and third-party trackers from major ad-tech/analytics providers (including TikTok, Meta/Facebook, Microsoft, and Google) and that Lenovo knowingly permitted access to, or transfer of, bulk US sensitive personal data to “covered persons,” including entities allegedly under Chinese jurisdiction such as Lenovo’s foreign parent structure—claims Lenovo has not been shown to concede in the cited reporting.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
In response to reporting on the lawsuit, Lenovo said it does not improperly share customer data and that its practices are lawful, transparent, and compliant with applicable U.S. and global privacy and data protection requirements.
Almeida Law Group filed a proposed class action in the Northern District of California on behalf of San Francisco resident Spencer Christy, alleging Lenovo's website tracking and advertising technology enabled prohibited bulk transfers of Americans' data to China-linked entities in violation of DOJ Data Security Program rules and other privacy laws.
The proposed class action defines the class period as communications intercepted or used on Lenovo.com on or after April 8, 2025, alleging the site used pixels, cookies, scripts, and ad-tech components to collect identifiers and browsing context from U.S. visitors.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
tomshardware.com
Open sourcecybersecuritynews.com
Open sourcego.theregister.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.