Attorney General Ken Paxton issued a consumer alert on September 17, 2026: Texas businesses and nonprofits are seeing a surge of demand letters that allege website privacy violations under California’s Invasion of Privacy Act (CIPA). The letters target ordinary tools — cookies, pixels, analytics, and search bars — call them “wiretapping,” and demand immediate payment to avoid a lawsuit. Some attach screenshots of the recipient’s site and a draft complaint.
This is not a finding that every CIPA claim is fake, and it is not a data-breach notice. CIPA is a real statute. Paxton’s office says this wave of letters may exaggerate or misrepresent a violation, and that recipients should not pay or reply until they talk to qualified counsel.
We scanned uscourts.gov, cacd.uscourts.gov, texasbar.com, and texasattorneygeneral.gov. 100% is the ideal overall domain-security score. None reach it.

Snapshot
| Field | Detail |
|---|---|
| Alert | Texas OAG · Sept 17, 2026 |
| Claim in letters | CIPA “wiretapping” via cookies / pixels / analytics / search bars |
| Named example | Vivek Shah — C.D. Cal. vexatious litigant (prefiling order) |
| Docket | Shah v. Crain Communications · 2:26-cv-03070 · filed Mar 18, 2026 |
| Order | Dkt 34 · July 20, 2026 · Judge R. Gary Klausner |
| Report suspected fraud | OAG complaint · 1-800-621-0508 |
What the letters claim — and what they do not settle
Paxton’s office says senders may treat common website technology as unlawful interception under California law and demand payment now. A letter with a screenshot and a draft complaint can look like a filed case. It is often still a pre-suit demand.
Keep two facts in view:
- Some CIPA tracking-pixel suits are real litigation. Our Adidas coverage post flags California CIPA / pixel dockets as a different theory from that vendor-credential story. Do not treat this alert as a ruling on those cases.
- A demand letter is not a judgment. Paxton: letters of this type may exaggerate or misrepresent a potential violation. Baker Donelson’s July 24 write-up on the Shah order makes the same split: the prefiling bar is leverage, not a merits decision that analytics never violate CIPA.
CIPA’s $5,000 per-violation damages are what make a cookie-and-pixel letter scary. That number is not an invoice you are required to pay from the letterhead.
The Shah example — and its limits
Paxton names Vivek Shah as a serial CIPA plaintiff who has sent demand letters and who is barred from filing new CIPA or related digital-privacy actions in the Central District of California without the court’s permission.
CourtListener confirms the docket Paxton is pointing at:
| Item | Record |
|---|---|
| Case | Vivek Shah v. Crain Communications, Inc. |
| Court | C.D. Cal. 2:26-cv-03070 · filed March 18, 2026 |
| Order | Dkt 34, July 20, 2026 — declares Shah a vexatious litigant; prefiling order for new CIPA / related digital-privacy cases in that district |
| Appeal | Notice of appeal July 23, 2026 (Dkt 37) · 9th Cir. 26-4739 |
The order denies a security-of-costs bond in the Crain case itself. It does not stop demand letters. It does not apply automatically in Texas state court, other federal districts, or to other plaintiffs. Shah voluntarily dismissed the Crain complaint with prejudice the same week (Dkt 36).
Other 2026 C.D. Cal. Shah rows (Imprint, Udemy, Lofty Inc. v. Shah, Wild Alaskan, and more) show the volume. We did not find a matching Texas federal CIPA cookie/pixel docket tied to this alert. Shah v. Agarwal (S.D. Tex. 4:26-cv-01209) is a contract caption — do not treat it as this CIPA wave.

What to do if a letter lands
Paxton’s three steps, in plain language:
- Call a lawyer who does privacy / website-tracking work before you answer. The State Bar of Texas Find a Lawyer directory is the resource the alert points to. Type that host yourself.
- With counsel, inventory pixels, cookies, analytics, session replay, chat widgets, and search tools on your site. That is a privileged review, not a reason to wire money from the letter.
- Watch the law. CIPA application to analytics is unsettled. A C.D. Cal. prefiling order is not a Texas privacy statute.
If you believe the letter is fraudulent, abusive, or deceptive, report it to the Consumer Protection Division: 1-800-621-0508 or the online complaint portal. Use the General form for scam / deceptive-practice facts. Do not paste SSNs, dates of birth, or account numbers into the complaint. OAG complaints are public. The office does not recover your money as your private lawyer.
Also:
- Type texasattorneygeneral.gov yourself. A “pay the AG / CIPA settlement portal” link in the same envelope is hostile until that official host says so.
- Do not click a PACER or “Central District” payment page from the letter. Type uscourts.gov or cacd.uscourts.gov yourself.
- Treat wire / crypto / gift-card “settlement” instructions as a scam pattern, even when the PDF looks like a complaint.
This post is not legal advice.
MFA: YubiKey and Google Authenticator
A CIPA letter does not need your second factor. A follow-on phishing page that harvests the mailbox or My Bar login does. Grades match our MFA directory.
| Grade | Meaning |
|---|---|
| Fail | SMS, voice, or email OTP — or no public MFA path |
| Pass | Self-serve Google Authenticator-style open TOTP |
| Strong | FIDO2 / YubiKey-class security key for sign-in |
| Platform | Grade | YubiKey | Authenticator |
|---|---|---|---|
| Texas OAG site login | Fail | No | No |
| State Bar of Texas My Bar | Fail | No | No |
OAG’s public login is username and password. The consumer-complaint FAQ describes a confirmation email, not YubiKey or Google Authenticator enrollment.
My Bar login is bar number and password. Password-reset help is email (or a phone call if the address is stale). We found no public YubiKey or open-TOTP path.
Directory: MFA support directory · Business Apps.
Recommended MFA tools
Use these on the mailbox that will receive the letter — not as a CIPA legal defense.
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
We audited the AG, State Bar, and court hosts on September 18, 2026. 100% is the ideal — none reach it. These scores are public email / transport / website posture. They do not score whether a CIPA letter is meritorious.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| U.S. Courts | uscourts.gov | 67% | −33 |
| State Bar of Texas | texasbar.com | 60% | −40 |
| C.D. Cal. | cacd.uscourts.gov | 54% | −46 |
| Texas Attorney General | texasattorneygeneral.gov | 37% | −63 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| uscourts.gov | 50% | 15% | 87% |
| texasbar.com | 70% | 15% | 37% |
| cacd.uscourts.gov | 50% | 15% | 43% |
| texasattorneygeneral.gov | 10% | 15% | 40% |
Audit links: uscourts.gov · texasbar.com · cacd.uscourts.gov · texasattorneygeneral.gov
texasattorneygeneral.gov at 37% with Identity 10% is the weakest of the four — the same AG host scored 37% in our July 23andMe settlement post. Transport 15% on every row is a mail-transport gap. That is why a spoofed “Office of the Attorney General / pay now” message is easier to dress up, not proof that this alert is itself a lure.

Illustration only — scores are in the tables above, not in the artwork.
Website stack note
Passive website-tech probes on September 18, 2026:
| Domain | Stack signal |
|---|---|
| texasattorneygeneral.gov | Stack undetected; Sectigo TLS expires 2026-12-09 |
| texasbar.com | ASP.NET (X-Powered-By exposed); Google Trust Services TLS expires 2026-12-01 |
| uscourts.gov | Drupal 10 (probe compares to current 11.x); DigiCert TLS expires 2027-03-26 |
| cacd.uscourts.gov | Drupal 10 (probe compares to current 11.x); DigiCert TLS expires 2026-12-03 |
Point-in-time only. A CMS version on a court or AG host is not a CIPA finding. Watch the December 2026 leaf dates on the AG, Bar, and C.D. Cal. hosts.
Blacklist, lookalikes, CourtListener
Email blacklist checks (public DoH, September 18, 2026): all four domains were clear on mail/domain lists we can query. texasattorneygeneral.gov showed informational SPFBL notes on web/CDN IPs. That is not mail reputation. Do not lead as “the AG is blacklisted.”
DNS lookalike scans (BEC profile, registered signals only):
| Brand scanned | To review | Likely owned | BEC staging |
|---|---|---|---|
| texasattorneygeneral.gov | 1 | 1 | 0 |
| uscourts.gov | 8 | 2 | 2 |
| texasbar.com | 9 | 1 | 0 |
High-interest registered names (investigate; not proof this alert’s senders used them):
| Lookalike | Technique | Note |
|---|---|---|
| uscourts.com | tld-swap | BEC staging (NS + MX) |
| uscourts.app | tld-swap | BEC staging (NS + MX) |
| texasattorneygeneral.org | tld-swap | Registered — not the .gov alert host |
| texasbar.org | tld-swap | Registered — not the Find-a-Lawyer host |
texasattorneygeneral.com redirected to the .gov. uscourts.biz / uscourts.info looked brand-owned. Type the .gov and texasbar.com yourself. Continuous monitoring: Cybersquat Domain Monitoring.
Related coverage
- Adidas / Alta coverage suit — do not mix with CIPA pixel dockets
- Paxton 23andMe settlement
- Chase card-hold SMS scam
- MFA support directory
Run a free audit at audit.emailmenow.com or contact EmailMeNow for pixel inventories, phishing-resistant mail, and domain monitoring aimed at the 100% ideal.
Sources: Texas OAG consumer alert (Sept 17, 2026) · File a consumer complaint · Complaint FAQ · State Bar Find a Lawyer · My Bar login · Shah v. Crain C.D. Cal. 2:26-cv-03070 Dkt 34 (July 20, 2026) · Baker Donelson (July 24, 2026) · Shumaker. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches September 18, 2026. Domain scores: audit.emailmenow.com only. This alert is not a court finding that analytics violate (or do not violate) CIPA. Not legal advice.