Back to news
Cybersecurity Alert
September 18, 2026 by EmailMeNow IT Consulting

Paxton Warns Texas Businesses About CIPA Privacy Demand Letters

Texas AG Ken Paxton warned of suspicious California CIPA demand letters sent to Texas businesses. Audits (ideal 100%): uscourts.gov 67%, texasbar.com 60%, cacd.uscourts.gov 54%, texasattorneygeneral.gov 37%.

Source: Texas Attorney General Ken Paxton

NewsPrivacyTexasPhishingMFAYubiKeyAuthenticator AppsCybersecurity
Desk with a sealed envelope, a printed demand letter, and a laptop showing a generic website cookie banner

Attorney General Ken Paxton issued a consumer alert on September 17, 2026: Texas businesses and nonprofits are seeing a surge of demand letters that allege website privacy violations under California’s Invasion of Privacy Act (CIPA). The letters target ordinary tools — cookies, pixels, analytics, and search bars — call them “wiretapping,” and demand immediate payment to avoid a lawsuit. Some attach screenshots of the recipient’s site and a draft complaint.

This is not a finding that every CIPA claim is fake, and it is not a data-breach notice. CIPA is a real statute. Paxton’s office says this wave of letters may exaggerate or misrepresent a violation, and that recipients should not pay or reply until they talk to qualified counsel.

We scanned uscourts.gov, cacd.uscourts.gov, texasbar.com, and texasattorneygeneral.gov. 100% is the ideal overall domain-security score. None reach it.

Desk with a sealed envelope, a printed demand letter, and a laptop showing a generic website cookie banner

Snapshot

FieldDetail
AlertTexas OAG · Sept 17, 2026
Claim in lettersCIPA “wiretapping” via cookies / pixels / analytics / search bars
Named exampleVivek Shah — C.D. Cal. vexatious litigant (prefiling order)
DocketShah v. Crain Communications · 2:26-cv-03070 · filed Mar 18, 2026
OrderDkt 34 · July 20, 2026 · Judge R. Gary Klausner
Report suspected fraudOAG complaint · 1-800-621-0508

What the letters claim — and what they do not settle

Paxton’s office says senders may treat common website technology as unlawful interception under California law and demand payment now. A letter with a screenshot and a draft complaint can look like a filed case. It is often still a pre-suit demand.

Keep two facts in view:

  1. Some CIPA tracking-pixel suits are real litigation. Our Adidas coverage post flags California CIPA / pixel dockets as a different theory from that vendor-credential story. Do not treat this alert as a ruling on those cases.
  2. A demand letter is not a judgment. Paxton: letters of this type may exaggerate or misrepresent a potential violation. Baker Donelson’s July 24 write-up on the Shah order makes the same split: the prefiling bar is leverage, not a merits decision that analytics never violate CIPA.

CIPA’s $5,000 per-violation damages are what make a cookie-and-pixel letter scary. That number is not an invoice you are required to pay from the letterhead.

The Shah example — and its limits

Paxton names Vivek Shah as a serial CIPA plaintiff who has sent demand letters and who is barred from filing new CIPA or related digital-privacy actions in the Central District of California without the court’s permission.

CourtListener confirms the docket Paxton is pointing at:

ItemRecord
CaseVivek Shah v. Crain Communications, Inc.
CourtC.D. Cal. 2:26-cv-03070 · filed March 18, 2026
OrderDkt 34, July 20, 2026 — declares Shah a vexatious litigant; prefiling order for new CIPA / related digital-privacy cases in that district
AppealNotice of appeal July 23, 2026 (Dkt 37) · 9th Cir. 26-4739

The order denies a security-of-costs bond in the Crain case itself. It does not stop demand letters. It does not apply automatically in Texas state court, other federal districts, or to other plaintiffs. Shah voluntarily dismissed the Crain complaint with prejudice the same week (Dkt 36).

Other 2026 C.D. Cal. Shah rows (Imprint, Udemy, Lofty Inc. v. Shah, Wild Alaskan, and more) show the volume. We did not find a matching Texas federal CIPA cookie/pixel docket tied to this alert. Shah v. Agarwal (S.D. Tex. 4:26-cv-01209) is a contract caption — do not treat it as this CIPA wave.

Laptop showing a generic pay-now legal-demand email beside a handwritten card to type the official attorney general URL

What to do if a letter lands

Paxton’s three steps, in plain language:

  1. Call a lawyer who does privacy / website-tracking work before you answer. The State Bar of Texas Find a Lawyer directory is the resource the alert points to. Type that host yourself.
  2. With counsel, inventory pixels, cookies, analytics, session replay, chat widgets, and search tools on your site. That is a privileged review, not a reason to wire money from the letter.
  3. Watch the law. CIPA application to analytics is unsettled. A C.D. Cal. prefiling order is not a Texas privacy statute.

If you believe the letter is fraudulent, abusive, or deceptive, report it to the Consumer Protection Division: 1-800-621-0508 or the online complaint portal. Use the General form for scam / deceptive-practice facts. Do not paste SSNs, dates of birth, or account numbers into the complaint. OAG complaints are public. The office does not recover your money as your private lawyer.

Also:

  • Type texasattorneygeneral.gov yourself. A “pay the AG / CIPA settlement portal” link in the same envelope is hostile until that official host says so.
  • Do not click a PACER or “Central District” payment page from the letter. Type uscourts.gov or cacd.uscourts.gov yourself.
  • Treat wire / crypto / gift-card “settlement” instructions as a scam pattern, even when the PDF looks like a complaint.

This post is not legal advice.

MFA: YubiKey and Google Authenticator

A CIPA letter does not need your second factor. A follow-on phishing page that harvests the mailbox or My Bar login does. Grades match our MFA directory.

GradeMeaning
FailSMS, voice, or email OTP — or no public MFA path
PassSelf-serve Google Authenticator-style open TOTP
StrongFIDO2 / YubiKey-class security key for sign-in
PlatformGradeYubiKeyAuthenticator
Texas OAG site loginFailNoNo
State Bar of Texas My BarFailNoNo

OAG’s public login is username and password. The consumer-complaint FAQ describes a confirmation email, not YubiKey or Google Authenticator enrollment.

My Bar login is bar number and password. Password-reset help is email (or a phone call if the address is stale). We found no public YubiKey or open-TOTP path.

Directory: MFA support directory · Business Apps.

Use these on the mailbox that will receive the letter — not as a CIPA legal defense.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
Proton PassPasskeys + authenticator-style TOTPProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key and phone authenticator beside a username-and-password login

Independent cybersecurity audits

We audited the AG, State Bar, and court hosts on September 18, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not score whether a CIPA letter is meritorious.

OrganizationDomainOverallvs 100%
U.S. Courtsuscourts.gov67%−33
State Bar of Texastexasbar.com60%−40
C.D. Cal.cacd.uscourts.gov54%−46
Texas Attorney Generaltexasattorneygeneral.gov37%−63
DomainIdentityTransportWebsite
uscourts.gov50%15%87%
texasbar.com70%15%37%
cacd.uscourts.gov50%15%43%
texasattorneygeneral.gov10%15%40%

Audit links: uscourts.gov · texasbar.com · cacd.uscourts.gov · texasattorneygeneral.gov

texasattorneygeneral.gov at 37% with Identity 10% is the weakest of the four — the same AG host scored 37% in our July 23andMe settlement post. Transport 15% on every row is a mail-transport gap. That is why a spoofed “Office of the Attorney General / pay now” message is easier to dress up, not proof that this alert is itself a lure.

Four padlocks stop short of a complete finish line, illustrating domain audits that miss the ideal score

Illustration only — scores are in the tables above, not in the artwork.

Website stack note

Passive website-tech probes on September 18, 2026:

DomainStack signal
texasattorneygeneral.govStack undetected; Sectigo TLS expires 2026-12-09
texasbar.comASP.NET (X-Powered-By exposed); Google Trust Services TLS expires 2026-12-01
uscourts.govDrupal 10 (probe compares to current 11.x); DigiCert TLS expires 2027-03-26
cacd.uscourts.govDrupal 10 (probe compares to current 11.x); DigiCert TLS expires 2026-12-03

Point-in-time only. A CMS version on a court or AG host is not a CIPA finding. Watch the December 2026 leaf dates on the AG, Bar, and C.D. Cal. hosts.

Blacklist, lookalikes, CourtListener

Email blacklist checks (public DoH, September 18, 2026): all four domains were clear on mail/domain lists we can query. texasattorneygeneral.gov showed informational SPFBL notes on web/CDN IPs. That is not mail reputation. Do not lead as “the AG is blacklisted.”

DNS lookalike scans (BEC profile, registered signals only):

Brand scannedTo reviewLikely ownedBEC staging
texasattorneygeneral.gov110
uscourts.gov822
texasbar.com910

High-interest registered names (investigate; not proof this alert’s senders used them):

LookalikeTechniqueNote
uscourts.comtld-swapBEC staging (NS + MX)
uscourts.apptld-swapBEC staging (NS + MX)
texasattorneygeneral.orgtld-swapRegistered — not the .gov alert host
texasbar.orgtld-swapRegistered — not the Find-a-Lawyer host

texasattorneygeneral.com redirected to the .gov. uscourts.biz / uscourts.info looked brand-owned. Type the .gov and texasbar.com yourself. Continuous monitoring: Cybersquat Domain Monitoring.


Run a free audit at audit.emailmenow.com or contact EmailMeNow for pixel inventories, phishing-resistant mail, and domain monitoring aimed at the 100% ideal.


Sources: Texas OAG consumer alert (Sept 17, 2026) · File a consumer complaint · Complaint FAQ · State Bar Find a Lawyer · My Bar login · Shah v. Crain C.D. Cal. 2:26-cv-03070 Dkt 34 (July 20, 2026) · Baker Donelson (July 24, 2026) · Shumaker. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 18, 2026. Domain scores: audit.emailmenow.com only. This alert is not a court finding that analytics violate (or do not violate) CIPA. Not legal advice.