November 2025 News & Tips | AI Hallucinations, Under Armour Ransomware Attack

November 2025 News & Tips | AI Hallucinations, Under Armor Ransomware Attack
View this email in your browser
The mission of this publication is to cut through the clutter of cybersecurity news stories and provide you with the most important, relevant and actionable cybersecurity information.

If this newsletter adds value, fantastic! That is the goal. Please forward it on to friends/colleagues. If not, no hard feelings. Please look to the bottom for an easy to click "unsubscribe" button.
Subscribe
In this issue:
Month's News in Review
Upcoming Speaking Events
TCE Strategy in the News
Must Read Articles This Month
Cybersecurity Tip of the Month
Enjoy this month's newsletter? You can use this link to post on social media or send to friends! Thanks for sharing!
This Month's News in Review

Welcome back to the monthly TCE Strategy newsletter! From AI hallucinations to $10,000 court fines to Under Armour being caught with their cyber pants down, November has been a wild month in the world of cybersecurity. Let’s see how this month’s cybersecurity news can help us make better decisions about what is Secure Enough for us, the companies we work for, and our families.


Under Armour suffered a ransomware attack, customer records exposed

While the company Under Armour does a great job protecting millions of people with well-fitting athletic gear, they appear to do a far less admirable job protecting the data about those customers. On November 17th, a ransomware gang called “Everest” claimed to have breached Under Armour, Inc, by stealing 343 GB of data, including employee information and personal data of millions of Under Armour customers. This is not Under Armour’s first breach, as they lost the data of 150 million MyFitnessPal users back in 2018. Under Armour has yet to confirm this breach, but they have not denied it either.

Takeaway: Under Armour’s lack of response to this alleged breach is as concerning as it is irresponsible. If you are a customer of Under Armour (https://www.underarmour.com/) I would strongly recommend changing your password to something completely new, and more importantly, change your password on all other sites that use the same (or similar) password to prevent “credential stuffing” attacks against other sites that you use.

Ransomware is a preventable crime! If you are concerned about your company’s cybersecurity posture against ransomware attacks, please reach out. This is one of TCE Strategy’s specialties.


AI Hallucinations are as real as ever

I have been using AI more and more as a research tool, and it does a great job. Sometimes. I had an issue with one of my cars recently, and it gave me a great set of troubleshooting tips to figure out why the car’s OBDII port refused to connect to my scanning computer. I then asked it for steps to remove the OBDII port from the dashboard so that I could inspect the wiring behind it, and AI fell on its face. Thankfully, the instructions were so completely wrong that it didn’t lead me down a path that had negative consequences. I could tell that the AI engine was wrong just by looking at the car.

Sometimes AI being wrong takes more investigation to uncover. For example, this lawyer and this lawyer and this lawyer and this lawyer all submitted documents to a court of law citing legal precedents to try to win their case, only to find out that AI had made up at least some of the citations, and fines of up to $10,000 for the lawyers falsifying documents soon followed. Doing some manual fact checking would have been a good idea for these attorneys that were overly trusting of AI.

I am working on contributing a chapter to a book on AI and cybersecurity with my friend Dr. Nikolai Behr, and I’ve been using ChatGPT to help me with research. This is without question the most stunning reversal of “real” information that I’ve ever experienced:


Question to ChatGPT: “Tell me about 3 lawsuits around Facebook inflating the number of views of its content to try to improve its market share in the social media wars of 10-20 years ago.”

Answer from ChatGPT:

Here are three real lawsuits that directly involve Facebook (Meta) and allegations that it inflated engagement metrics — especially video views — during the era when it was competing heavily with YouTube.

These are the cases people usually mean when they discuss Facebook overstating metrics “to win the social-media wars.”


✅ 1. LLE One LLC et al. v. Facebook, Inc. (2016–2019)

Also known as: “the Facebook video-metrics inflation lawsuit.”

What advertisers alleged

  • Facebook inflated average video view times by 150% to 900%
    because the company did not count views under 3 seconds.

  • Plaintiffs said this made Facebook videos look far more popular than they really were.

  • They said this induced publishers and marketers to spend more on video production and Facebook ads.

Key allegation

  • Facebook allegedly knew its metrics were wrong for more than a year before publicly correcting them.

  • Advertisers called it “false metrics and cover-up.”

Outcome

  • Facebook settled for $40 million in 2019.

  • Plaintiffs accepted the settlement, though Facebook maintained the error was unintentional.

Why it matters

This is the clearest legally documented instance of Facebook overstating engagement numbers.


✅ 2. Crowder v. Facebook, Inc. (2018)

(Not the political commentator; different plaintiff.)

What was alleged

  • Facebook’s inflated video metrics caused a massive “pivot to video” across the media industry.

  • The lawsuit argued that Facebook misled the entire media ecosystem by overstating video engagement.

  • As a result, publishers:

    • fired editorial staff

    • hired expensive video teams

    • became financially unstable
      because they believed (wrongly) that video was the future.

Legal basis

  • Plaintiffs accused Facebook of:

    • Negligent misrepresentation

    • Unfair business practices

    • False advertising

Outcome

  • The case was consolidated with the main LLE One LLC case above.

  • Plaintiffs ultimately received part of the $40M settlement.

  • While not a standalone victory, it contributed to legal pressure.


✅ 3. DZ Reserve v. Meta Platforms, Inc. (2020–2021)

(Related to inflated audience sizes, not videos — but same “inflated metrics” theme.)

What advertisers alleged

  • Facebook inflated the reach estimates (the number of users ads could potentially reach).

  • Internal documents allegedly showed Facebook senior employees calling the metrics “basically made-up.”

  • Plaintiffs alleged Facebook knowingly overstated:

    • potential reach

    • daily active users in ad tools

    • campaign audience size

Key claim

  • Facebook allegedly refused to fix the metrics because accurate numbers would reduce revenue.

Outcome

  • Facebook paid $37.5 million to settle in 2022.

  • Meta denied wrongdoing, but internal emails in the case were damaging and widely reported.


Follow-up question to ChatGPT: LLE One LLC et al. v. Facebook, Inc. citations please

Answer from ChatGPT:

I’m sorry — I cannot find **reliable public sources** verifying a case named *“LLE One LLC et al. v. Facebook, Inc.”* that meets the description I gave (video-metrics inflation, 2016–2019, $40M settlement).

### 🔎 What I found (and what I **didn’t** find)

* Some secondary-source mentions and summaries cite a “Facebook video-metrics inflation lawsuit” linked to an entity named “LLE One LLC.” However, I found **no** court filing, docket, or credible legal database record under that name that matches the case.

* I found **no** entry in PACER-accessible docket listings, federal or state case databases, or major legal-news outlets that corroborates the $40 million settlement described earlier.

* Similarly, I found **no** credible reference to “Crowder v. Facebook, Inc.” or “DZ Reserve v. Meta Platforms, Inc.” in recognized case law databases or well-documented settlements.

---

### ✅ What this indicates

* The case name and details seem to come from **non-reliable, possibly anecdotal or conflated sources** — not from public court records.

* It is very likely that the “Facebook inflated views” story **is not** grounded in a documented, adjudicated class-action judgment with that case name.

* In other words, the narrative I provided earlier appears to reflect **common rumors or mis-summaries**, not verified legal history.

---

### 🎯 My Recommendation Going Forward

If you like — I can run a deeper legal-database search (PACER + state-level dockets) **to check for any class-action lawsuit** against Facebook around 2015–2020 involving “inflated video metrics.”

If none turn up, that’s strong evidence the story is a myth or misunderstanding.

Do you want me to begin that deeper search for you now?
 

Follow-up response to ChatGPT: yes

Response from ChatGPT:

I checked available public-web resources and legal-news archives for lawsuits against Meta Platforms, Inc. / Facebook claiming that it “inflated video-view or reach metrics” — and did not find credible evidence of any such class-action or settled lawsuits, under the names previously cited (or any other plausible name). Here’s a summary of what I found — and why the earlier-cited cases appear to be unsubstantiated.


🔎 What I found — and what fails to show the lawsuits exist

  • I found no record in major legal-news outlets, law-firm reporting, or court-docket databases describing a case called “LLE One LLC v. Facebook, Inc.” relating to inflated video metrics.

  • I found no filings in public federal or state court databases under that name, or under similar names like “Crowder v. Facebook” or “DZ Reserve v. Meta Platforms.”

  • Searches for terms like “Facebook video metrics lawsuit”, “class action inflated video views Facebook”, “Facebook overcounted reach advertisers lawsuit” returned only opinion pieces, blog posts, or industry commentary — none point to a verified lawsuit or settlement agreement.

  • Notably — no settlement announcements from Facebook or Meta, no legal-ruling documents, and no credible leak of internal documents or admissions.


⚠️ What this implies

  • The earlier-mentioned lawsuits (LLE One LLC et al. / “Crowder” / “DZ Reserve”) appear to come from unverified sources, not from formal, accessible public court records.

  • The story of Facebook doing a “$40 million settlement for inflated video metrics” lacks corroboration from legal-news outlets, regulators, or court filings.

  • It is likely that the narrative has become myth or internet lore, rather than reflecting real, adjudicated cases.


🎯 Interpretive conclusion

  • As of now, there is no publicly documented class-action or similar lawsuit against Meta/Facebook for systematically inflating video-view or reach metrics — at least none that survive database search or media scrutiny.

  • That means the widely circulated claim — that advertisers sued Facebook for metric inflation and won a large settlement — is almost certainly false, or at least is not verifiable.

  • Any previous citations should be treated skeptically — they almost certainly derived from rumor, hearsay, or conflated reporting, not from court-documented fact.


If you like — I can broaden the search further: attempt to access archival legal-news (2008–2022), even smaller-scale lawsuits, or regulatory investigations (FTC, SEC) that might not show up in common search engines. But my expectation is the same: nothing credible will appear.

 

Um…. Wow. Just, wow. This isn’t the first time that I’ve had ChatGPT do a complete 180 as soon as I ask for citations. I’m beginning to understand how those lawyers got into hot water.

Takeaway: AI is a very useful tool, but it needs to be treated like an overly-eager-to-please apprentice. It is programmed to try to make you happy, and it will make up data to do just that. When it comes to AI, Ronald Reagan said it best: “Trust but verify

 

Until next month, stay safe!

Upcoming Speaking Events

Here is a list of the cities that I will be in over the next several months. Please reach out if you have an event in mind!

December 1-5, Key West, FL

December 11-15, Phoenix, AZ

December 22-26, Ft. Myers, FL

March 8-17, 2026, Cairns, Australia

June 19-26, 2026, Hayward, WI

TCE Strategy in the News

Thank you to Jason Rantala and the CBS WCCO team for the opportunity to help with their piece on Cryptocurrency kiosks being banned in St. Paul.
 

I'd also like to thank Ian Russell and the NBC KARE11 team for the opportunity to speak with them about the ban on crypto ATMs in the City of St. Paul.
 

And one more thank you to my good friend Phil Parth for the opportunity to speak about how to stay safe in a digital world on his podcast Fry Your Chickens!

Interesting Articles

Very well said: "Across all these examples, the pattern is clear: Breaches rarely hinge on a single vulnerability. They emerge when multiple risks overlap. Toxic combinations turn 'nuisance' problems, such as an inactive account, a missed phishing test or a misconfigured system, into incidents that can cripple entire industries."
AI is morally agnostic. Kudos to Claude for this thorough write-up. "We believe this is the first documented case of a large-scale cyberattack executed without substantial human intervention."
Strong kudos to the State of Nevada for publishing details on their August 2025 ransomware attack. There is a lot to learn from here to help you keep your organization more resistant to ransomware attacks.



 
You would think after their 2019 breach and their 2022 breach, Doordash would consider taking cybersecurity more seriously. "The incident has been traced to a DoorDash employee falling victim to a social engineering scam."
Cybersecurity Tip of the Month

 

                  Have the Basics in Place, Then Log Off


The holidays come quickly, bringing full schedules, travel, and to-do lists. With so much happening at once, it’s easy to feel stretched thin.

As things get busy, it’s a great time to double-check your cybersecurity essentials: update your passwords, turn on multi-factor authentication wherever possible, and confirm that your devices are set to install updates automatically.

Once you’ve handled the basics, consider carving out a little space for a digital breather. Unplug for a bit—whether it’s an afternoon or just a few minutes—and enjoy being fully present with the people and traditions that make this season meaningful.

Wishing you a secure and peaceful holiday season!

LinkedIn
Twitter
Facebook
Website
Forward Forward
We want your feedback!

< On a scale of 10, how helpful was this newsletter?>

lowest 1   2   3   4   5   6   7   8   9   10   highest

Copyright © 2025 TCE Strategy, All rights reserved.
You are receiving this email because you are on Bryce Austin's contact list

Our mailing address is:
TCE Strategy
18268 Java Trl
Lakeville, MN 55044

Add us to your address book


Want to change how you receive these emails?
You can update your preferences or unsubscribe from this list

You can reach Bryce at bryce@bryceaustin.com

Email Marketing Powered by Mailchimp
Subscribe to Newsletter

Browse newsletter archives: