Texas Attorney General Ken Paxton has warned businesses and nonprofit organizations about a surge in scam demand letters falsely alleging website privacy violations under California law.
The letters allege violations of the California Invasion of Privacy Act based on the use of common website technologies such as cookies, pixels, analytics tools, and search bars. Senders may claim these tools constitute unlawful "wiretapping" and demand immediate payment to avoid litigation. The letters may include screenshots of the recipient's website and a draft complaint.
Paxton urged organizations receiving such letters to exercise caution and seek legal guidance before responding or paying. "We have been made aware of suspicious letters demanding payment from Texas businesses for alleged website privacy violations under California law," the office quoted Paxton as saying.
The office noted that one serial plaintiff, Vivek Shah, who has sent numerous demand letters alleging privacy violations, was declared a vexatious litigant. He is barred from filing new actions asserting privacy claims in the U.S. District Court for the Central District of California without the court's permission.
Entities receiving such letters should consult with legal counsel before taking action. Those believing they have received fraudulent demand letters can report them to the Texas Attorney General's Consumer Protection Division by calling 1-800-621-0508 or filing an online complaint.
