
In mid-2025, multiple U.S. states, including Kentucky, Nebraska, Arkansas, Illinois, and New York, filed lawsuits against the Chinese-owned e-commerce platform Temu, alleging widespread data privacy violations, malware-based surveillance, and intellectual property theft. These cases represent a significant shift in cybersecurity enforcement, with state attorneys general stepping into territory traditionally managed by federal agencies.
Kentucky Attorney General Russell Coleman filed a lawsuit on July 17, 2025, accusing Temu of unlawfully collecting user data (Wi-Fi, GPS, camera), sharing it with the Chinese government, and infringing on iconic Kentucky brands, including Buffalo Trace Distillery and Churchill Downs.
Nebraska AG Michael Hilgers filed a suit on June 12, 2025, alleging Temu installs malware that extracts personal data (including from minors), employs deceptive marketing tactics, and supports counterfeit product listings. The lawsuit argues Nebraska consumers lose control over their data once they install the Temu app.
Arkansas Attorney General Tim Griffin previously sued Temu, calling its app “dangerous malware” and accusing it of bypassing device controls to harvest personal data and contact information from Temu users’ phones.
Other states, such as Illinois and New York, have filed similar complaints, echoing allegations of privacy violations and cybersecurity threats.
Lawsuits claim that Temu’s app contains hidden code that functions like spyware, recording location, communications, camera activity, and even contact lists without user consent. Experts warn it may evade detection by security tools.
By design or regulation under Chinese law, Temu’s parent company PDD Holdings may allow the Chinese government access to sensitive user data. Kentucky’s suit specifically emphasizes unauthorized data transmission to Chinese authorities.
Kentucky’s complaint also alleges Temu sells counterfeit versions of famous state brands. Nebraska’s lawsuit includes claims of copycat products and deceptive marketing that harm local creators and businesses.
These cases mark a crucial shift: U.S. states are assuming enforcement responsibilities historically held by federal cybersecurity and intelligence agencies. Experts note that while some states lack forensic and legal resources for high-level cyber threats, the trend is clear.
Temu categorically denies the allegations, calling them misinformation, often tied to short-seller reports. It has attempted to counter concerns by relocating its principal executive office to Dublin and signing data hosting deals with U.S. providers like Oracle, Google, and Microsoft to store user data domestically.
Temu’s crisis echoes that of TikTok—another Chinese app under scrutiny for data sharing with Beijing. While Temu’s Oracle cloud deal is seen as a privacy-preservation effort, critics say such strategies have done little to appease regulators in TikTok’s case.
Legal actions in Kentucky, Nebraska, and Arkansas, along with emerging filings in Illinois and New York, spotlight Temu as a focal point in U.S. cybersecurity law. Key allegations include the use of surreptitious malware, unauthorized data transfers to China, and counterfeit product practices. These suits illustrate how state-level enforcement is evolving — with significant implications for digital privacy, regulatory policy, and e-commerce operations.
By continuing to use the site, you agree to the use of cookies. more information
The cookie settings on this website are set to "allow cookies" to give you the best browsing experience possible. If you continue to use this website without changing your cookie settings or you click "Accept" below then you are consenting to this.