The U.S. Supreme Court ruled 8-1 that the Federal Communications Commission lawfully imposed nearly $200 million in penalties on major wireless carriers for improperly sharing customers’ location data. The decision upheld FCC forfeiture orders issued against AT&T, Verizon, and T-Mobile/Sprint, rejecting the companies’ argument that the agency’s penalty process violated their Seventh Amendment right to a jury trial. The Court agreed that FCC fine decisions are not final punishments on their own and can be enforced through the courts.
The case stemmed from findings that carriers sold access to sensitive location information to aggregators and failed to obtain valid customer consent or adequately safeguard the data. Investigators said the information was later misused by third parties, including bounty hunters, a rogue sheriff, and a government contractor that allegedly built a self-service tool allowing law enforcement agencies to obtain phone location data nationwide without a court order. The ruling preserves the FCC’s authority to investigate telecom privacy violations and pursue penalties over unlawful handling of subscriber location data.

See the reporting duties and controls this puts on the clock.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-06-04, the U.S. Supreme Court ruled 8-1 that the FCC lawfully imposed the fines against the telecommunications companies. The decision rejected arguments that the FCC forfeiture process violated the carriers’ Seventh Amendment right to a jury trial and preserved the agency’s authority to investigate carriers and seek court enforcement of penalties.
In April 2024, the FCC imposed nearly $200 million in penalties on AT&T, Verizon, and T-Mobile/Sprint for sharing consumers’ location data without proper consent. The FCC said the carriers failed to obtain valid customer consent, did not adequately protect the data, and sold access to aggregators that passed it to third-party data brokers.
A Senate investigation led by Sen. Ron Wyden found that a government contractor used purchased location data to build a self-service website that let law enforcement obtain phone location data nationwide without a court order. The investigation helped expose how telecom location data was being resold through aggregators and brokers.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
techdirt.com
Open sourcearstechnica.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.