CRANDALL CONSULTING
HomePrivacy Laws Risk Scanner › Federal Wiretap Act

The Federal Wiretap Act & Website Tracking Litigation

Published by Crandall Consulting · Informational litigation intelligence · Last intelligence update: August 31, 2026

73/100
Risk Guideline
High
Risk Level
96%
Evidence Confidence
rising
Trend
50
Tracked Lawsuits
1
Tracked Matters
0
Tracked Demand Letters
0
Reported Claims

Lawsuits, demand letters, tracked matters, and reported claims are counted separately and are not interchangeable. Last intelligence update: August 31, 2026.

Risk scores, classifications, statistics, and technical findings are informational guidelines based on observed website behavior and publicly available litigation activity, statutes, court decisions, legal commentary, and other public sources. They are not legal advice, legal opinions, or determinations of liability.

What the Federal Wiretap Act Is

The Federal Wiretap Act (Title III of the Omnibus Crime Control and Safe Streets Act, 18 U.S.C. § 2510 et seq.), as amended by the Electronic Communications Privacy Act (ECPA), generally restricts the intentional interception of wire, oral, and electronic communications and provides a civil cause of action with statutory damages. Because it is federal law, litigants may raise it regardless of state, which is why federal theories can be potentially relevant to websites nationally.

How It Is Being Applied to Website Tracking

Courts and litigants are increasingly examining whether modern website technologies — session replay tools, advertising pixels, chat widgets, and analytics that transmit visitor activity to third parties — can constitute an "interception" of electronic communications under the Act. Key contested questions in public decisions include whether the third party is a direct "party" to the communication, whether consent was obtained, and whether the intercepted information includes "contents" of a communication. The legal landscape remains unsettled and outcomes vary by circuit and by facts.

Current Landscape

Federal litigation activity is elevated: your dataset tracks 50 federal lawsuits and one other matter, with no tracked demand letters. Recent filings and reported complaints repeatedly focus on website and web-app integration with third-party trackers and ad-tech components, including pixels (TikTok, Meta), ad platforms (Google Ads, DoubleClick, Microsoft/Bing), third-party tracking cookies, and device-identifier techniques such as device fingerprinting and mobile advertising IDs. Several matters also identify collection of addressing information (IP addresses, HTTP request information), cookie IDs, and other technical identifiers.

Courts are examining a range of procedural and substantive issues in these matters. At the pleading stage, some district courts have dismissed putative class actions for lack of Article III standing where the alleged collection and sharing of non-sensitive browsing or device data was not found to allege a concrete injury (see Torres v. SeatGeek, Inc.; Crano v. Sojern, Inc.). Other courts have permitted certain privacy-related theories to survive motions to dismiss, including a decision treating software processes that record addressing information as potentially analogous to pen registers under CIPA at the pleading stage (Fregosa v. Mashable Inc.). Several recent complaints also assert Wiretap Act and ECPA theories and challenge consent- and cookie-management implementations (examples include complaints reported against Pfizer and Brooklinen, and the Planned Parenthood filing in SDNY).

Tracked Federal Cases & Matters

Torres v. SeatGeek, Inc.

United States District Court for the Northern District of California (Magistrate Judge Laurel Beeler) · 2026-05-22 · lawsuit · defense-favorable

A Northern District of California magistrate judge granted a Rule 12 motion to dismiss Torres v. SeatGeek for lack of Article III standing, holding that routine metadata collected via tracking pixels (IP, device/browser metadata, cookie IDs) did not constitute a concrete injury under the Popa framework. The court found aggregation across three recipients and receipt of targeted ads insufficient to transform the non-sensitive technical data into a cognizable privacy injury.

Caldwell v. InMobi Pte. Ltd.

United States District Court, Northern District of California · 2026-04-29 · lawsuit · plaintiff-favorable

The Northern District of California denied InMobi’s motion to dismiss a putative class action alleging CIPA pen register violations and California privacy torts, holding the pleading sufficiently alleges modern tracking technologies can satisfy CIPA’s definitions and that privacy claims survive at the pleading stage. The court left factual questions (e.g., consent, app identity, linkage to real-world identity) for later stages of the case.

Paul Nakamura v. Pfizer Inc.

United States District Court for the Southern District of New York · lawsuit

Privado AI reports that a proposed class action filed May 12, 2026 alleges Pfizer's website continued to transmit visitor data to Google tracking tools after users selected 'Decline All' on a consent banner. The complaint asserts claims under the federal Wiretap Act and several California statutes and was filed in the Southern District of New York; Pfizer was reportedly served May 18, 2026 and an answer date was noted.

Fregosa v. Mashable Inc.

United States District Court for the Northern District of California · 2025-10-09 · lawsuit · plaintiff-favorable

A federal district court in the Northern District of California denied Mashable’s motion to dismiss a Second Amended Complaint alleging that third-party web trackers installed on Mashable’s site recorded IP addresses and device identifiers in violation of CIPA’s pen-register provisions. The court concluded the statute’s text and precedent permit treating software processes that record addressing information as pen registers at the pleading stage, and the case remains pending.

Crano v. Sojern, Inc.

United States District Court for the Northern District of California · 2026-06-09 · lawsuit · defense-favorable

A California federal judge dismissed the Second Amended Complaint in Crano v. Sojern, Inc. for lack of Article III standing, finding the plaintiff failed to allege a concrete injury. The court rejected theories based on intangible privacy harms from collection of technical identifiers and an unjust-enrichment economic harm theory, relying on Ninth Circuit precedent and distinguishing In re Facebook.

Laura Gilbert v. Brooklinen, Inc.

United States District Court for the Eastern District of New York · lawsuit

This is a putative class-action complaint filed June 18, 2026, in the Eastern District of New York alleging that Brooklinen’s website deployed third‑party tracking technologies (pixels, cookies, analytics) despite users rejecting non‑essential cookies, and asserting the Wiretap Act, California privacy and consumer-protection statutes, and common-law claims. The complaint seeks class relief and damages and identifies specific tracking vendors and technologies observed on the site. The case is a filed complaint (litigation pending).

E.H. et al v. Lifelong Adoptions, Inc.

United States District Court for the Eastern District of California · 2026-07-24 · lawsuit

The federal district court granted LifeLong’s motion to dismiss in part and denied it in part on July 24, 2026. Several claims were dismissed (some with leave to amend, others without), while multiple privacy-related claims under California common law, the California Constitution, CIPA, and the federal ECPA survived the pleading challenge and will proceed subject to further amendment or litigation.

C.B. v. Planned Parenthood Federation of America, Inc.

U.S. District Court for the Southern District of New York · lawsuit

A proposed class action filed June 19, 2026 in SDNY alleges Planned Parenthood and regional affiliates transmitted appointment-booking selections and related details to third parties (notably Google) via embedded trackers and that tracking continued into a MyChart patient portal. The complaint asserts multiple state and federal statutory claims and seeks a nationwide class and several subclasses; defendants had not responded at time of reporting.

FTC v Kochava, Inc.

Court not identified · tracked matter

This is an FTC Legal Library page titled "FTC v Kochava, Inc." (page date 2026-06-26). The extracted content contains only site navigation and header material and does not include any substantive details about filings, claims, allegations, or the matter's status.

Vivek Shah v. Crain Communications, Inc.

U.S. District Court for the Central District of California · 2026-07-20 · lawsuit · defense-favorable

A federal district court in the Central District of California declared Vivek Shah a vexatious litigant on July 20, 2026 and entered a pre-filing order requiring leave of court before Shah may file new CIPA or related digital privacy suits in that district. The court based its decision on a record of repeated, materially identical filings and voluntary dismissals, and limited the order to the Central District and to specified claim types.

Vivek Shah

California federal court · lawsuit · defense-favorable

The provided page text is largely site navigation and practice-area links. The page title states that a California federal court declared serial CIPA plaintiff Vivek Shah a vexatious litigant, but the article body and case details are not present in the supplied text.

Adair, et al. v. Cigna Corporate Services, LLC and the Cigna Group

Court not identified · lawsuit · defense-favorable

A Klein Moynihan Turco blog post summarizes a Pennsylvania federal judge's dismissal of plaintiffs' ECPA, WESCA, and invasion of privacy claims against Cigna on the ground that plaintiffs consented to use of third-party tracking technologies by agreeing to Cigna's Terms of Use and incorporated Privacy Notice. The post highlights that the court found post-loading consent could be sufficient for dismissal and notes a trend of courts scrutinizing whether tracking software supports wiretapping claims.

Relevant Federal Statutes

Historical Risk Guideline

August 8, 2026: 38/100August 10, 2026: 58/100August 11, 2026: 60/100August 12, 2026: 62/100August 12, 2026: 62/100August 14, 2026: 64/100August 15, 2026: 64/100August 16, 2026: 64/100August 17, 2026: 68/100August 18, 2026: 69/100August 18, 2026: 69/100August 19, 2026: 69/100August 20, 2026: 71/100August 21, 2026: 71/100August 22, 2026: 71/100August 23, 2026: 73/100August 24, 2026: 73/100August 25, 2026: 73/100August 26, 2026: 73/100August 27, 2026: 73/100August 28, 2026: 73/100August 30, 2026: 73/100August 31, 2026: 73/100
DateRisk GuidelineLevelConfidenceTracked Lawsuits
August 19, 202669High96%36
August 20, 202671High96%37
August 21, 202671High96%37
August 22, 202671High96%41
August 23, 202673High96%44
August 24, 202673High96%45
August 25, 202673High96%47
August 26, 202673High96%48
August 27, 202673High96%49
August 28, 202673High96%50
August 30, 202673High96%50
August 31, 202673High96%50

Methodology & Limitations

Statistics on this page are generated by the Crandall Consulting litigation intelligence engine. Publicly available sources (court and government materials, recognized legal press, professional analysis, and industry reports) are discovered through automated web research, classified into a tiered source hierarchy, and reduced to structured facts with full source provenance. Risk guidelines and evidence-confidence scores are computed by a deterministic formula from those stored facts — never by an AI model directly (AI explains findings; it never assigns a score). Counts labeled "tracked" reflect matters identified in our source set and are not official court statistics.

The overall risk guideline is composed of six deterministically weighted components: statutory structure (25%), current litigation activity (25%), prior precedent (18%), GPC / universal opt-out posture (15%), regulatory enforcement (9%), and the forward-looking 24-month horizon (8%). When a state's GPC status is limited data, that component is excluded and the remaining weights are renormalized — limited data never reads as lower exposure. Current litigation activity is measured over recent windows (velocity), not lifetime volume, so a jurisdiction with high historical activity but declining current filings reflects that decline. Litigation activity (volume) and precedential risk (authority of decisions) are measured separately. Full details are on the methodology page.

Sources

All State Pages

Is Your Website Creating Hidden Tracking Risk?

Scan your site for third-party tracking and potential wiretap exposure. Free, no account required.

Scan My Website