State-Level Legal Action Targets Temu Over Privacy and Cybersecurity

August 22, 2025 by
Frank Calviño

In mid-2025, multiple U.S. states, including Kentucky, Nebraska, Arkansas, Illinois, and New York, filed lawsuits against the Chinese-owned e-commerce platform Temu, alleging widespread data privacy violations, malware-based surveillance, and intellectual property theft. These cases represent a significant shift in cybersecurity enforcement, with state attorneys general stepping into territory traditionally managed by federal agencies.

Who’s Leading the Legal Front?

Kentucky Attorney General Russell Coleman filed a lawsuit on July 17, 2025, accusing Temu of unlawfully collecting user data (Wi-Fi, GPS, camera), sharing it with the Chinese government, and infringing on iconic Kentucky brands, including Buffalo Trace Distillery and Churchill Downs.

Nebraska AG Michael Hilgers filed a suit on June 12, 2025, alleging Temu installs malware that extracts personal data (including from minors), employs deceptive marketing tactics, and supports counterfeit product listings. The lawsuit argues Nebraska consumers lose control over their data once they install the Temu app.

Arkansas Attorney General Tim Griffin previously sued Temu, calling its app “dangerous malware” and accusing it of bypassing device controls to harvest personal data and contact information from Temu users’ phones.

Other states, such as Illinois and New York, have filed similar complaints, echoing allegations of privacy violations and cybersecurity threats.

Core Allegations Against Temu

Malware & Data Exfiltration

Lawsuits claim that Temu’s app contains hidden code that functions like spyware, recording location, communications, camera activity, and even contact lists without user consent. Experts warn it may evade detection by security tools.

Foreign Data Access Risks

By design or regulation under Chinese law, Temu’s parent company PDD Holdings may allow the Chinese government access to sensitive user data. Kentucky’s suit specifically emphasizes unauthorized data transmission to Chinese authorities.

Counterfeit & IP Violations

Kentucky’s complaint also alleges Temu sells counterfeit versions of famous state brands. Nebraska’s lawsuit includes claims of copycat products and deceptive marketing that harm local creators and businesses.

Broader Implications & Context

State Governments Assume National Cyber Roles

These cases mark a crucial shift: U.S. states are assuming enforcement responsibilities historically held by federal cybersecurity and intelligence agencies. Experts note that while some states lack forensic and legal resources for high-level cyber threats, the trend is clear.

Response from Temu

Temu categorically denies the allegations, calling them misinformation, often tied to short-seller reports. It has attempted to counter concerns by relocating its principal executive office to Dublin and signing data hosting deals with U.S. providers like Oracle, Google, and Microsoft to store user data domestically.

TikTok Parallel

Temu’s crisis echoes that of TikTok—another Chinese app under scrutiny for data sharing with Beijing. While Temu’s Oracle cloud deal is seen as a privacy-preservation effort, critics say such strategies have done little to appease regulators in TikTok’s case.

What This Means for Consumers & Businesses

  • Consumers: If allegations hold, users may face unauthorized surveillance, loss of privacy, and data misuse.
  • State Legislatures: These enforcement actions could accelerate new data protection laws or tighten consumer privacy statutes at state level.
  • E-commerce Brands: Sellers using Temu or similar platforms may face increased compliance scrutiny and liability risks.
  • Companies with China Ties: All foreign-owned apps must now consider deeper transparency and domestic data storage strategies to maintain trust and regulatory goodwill.

Legal actions in Kentucky, Nebraska, and Arkansas, along with emerging filings in Illinois and New York, spotlight Temu as a focal point in U.S. cybersecurity law. Key allegations include the use of surreptitious malware, unauthorized data transfers to China, and counterfeit product practices. These suits illustrate how state-level enforcement is evolving — with significant implications for digital privacy, regulatory policy, and e-commerce operations.

Shiprocket IPO Draws Strong Demand on Final Day of Bidding
India’s e-commerce enablement company Shiprocket has entered the final day of its initial public offering with strong investor demand, putting one of the country’s best-known logistics technology companies on course...
August 14, 2026
Amazon signs global warehouse automation agreement with AutoStore
Amazon has signed a global strategic supply agreement with warehouse automation specialist AutoStore, establishing a framework that could allow the e-commerce giant to deploy AutoStore technology across its international fulfillment...
August 13, 2026
Oman completes nearly 87% of national E-Commerce Plan as digital trade push accelerates
Oman has completed nearly 87% of its National E-Commerce Plan 2022–2027, marking another major step in the Sultanate’s efforts to strengthen its digital economy and establish itself as a regional...
August 10, 2026
Top crossmenu

By continuing to use the site, you agree to the use of cookies. more information

The cookie settings on this website are set to "allow cookies" to give you the best browsing experience possible. If you continue to use this website without changing your cookie settings or you click "Accept" below then you are consenting to this.

Close