
U.S. state governments began stepping into roles traditionally held by federal agencies in the area of cybersecurity enforcement.
State attorneys general from Kentucky, Nebraska, Arkansas, Illinois, and New York have launched lawsuits against the Chinese-linked e-commerce app Temu, accusing it of data harvesting, malware deployment, and unauthorized data transfers to China. These cases signal a significant shift in responsibility from federal bodies to state-level enforcement.
Under the current administration, federal agencies—including the Federal Trade Commission and the Consumer Protection Branch of the Department of Justice—have scaled back enforcement activities, especially in consumer protection and cybersecurity. This has opened a gap that state attorneys general are now working to fill through legal action under state unfair and deceptive practices statutes as well as privacy laws.
A March 2025 executive order calls for states and local governments to take on greater responsibility in resilience planning and cybercrime enforcement. State AG offices have cited this executive order as support for their investigations, including actions related to Temu.
Recent legal actions, new cyber reporting laws (such as those in New York), and multi-state collaboration represent a turning point: U.S. states are now assuming prominent cybersecurity roles. Whether they have sufficient resources or surveillance infrastructure remains in question—but the trend reflects a clear shift in the national enforcement landscape.
By continuing to use the site, you agree to the use of cookies. more information
The cookie settings on this website are set to "allow cookies" to give you the best browsing experience possible. If you continue to use this website without changing your cookie settings or you click "Accept" below then you are consenting to this.