State-Level Legal Action Targets Temu Over Privacy and Cybersecurity

August 22, 2025 by
Frank Calviño

In mid-2025, multiple U.S. states, including Kentucky, Nebraska, Arkansas, Illinois, and New York, filed lawsuits against the Chinese-owned e-commerce platform Temu, alleging widespread data privacy violations, malware-based surveillance, and intellectual property theft. These cases represent a significant shift in cybersecurity enforcement, with state attorneys general stepping into territory traditionally managed by federal agencies.

Who’s Leading the Legal Front?

Kentucky Attorney General Russell Coleman filed a lawsuit on July 17, 2025, accusing Temu of unlawfully collecting user data (Wi-Fi, GPS, camera), sharing it with the Chinese government, and infringing on iconic Kentucky brands, including Buffalo Trace Distillery and Churchill Downs.

Nebraska AG Michael Hilgers filed a suit on June 12, 2025, alleging Temu installs malware that extracts personal data (including from minors), employs deceptive marketing tactics, and supports counterfeit product listings. The lawsuit argues Nebraska consumers lose control over their data once they install the Temu app.

Arkansas Attorney General Tim Griffin previously sued Temu, calling its app “dangerous malware” and accusing it of bypassing device controls to harvest personal data and contact information from Temu users’ phones.

Other states, such as Illinois and New York, have filed similar complaints, echoing allegations of privacy violations and cybersecurity threats.

Core Allegations Against Temu

Malware & Data Exfiltration

Lawsuits claim that Temu’s app contains hidden code that functions like spyware, recording location, communications, camera activity, and even contact lists without user consent. Experts warn it may evade detection by security tools.

Foreign Data Access Risks

By design or regulation under Chinese law, Temu’s parent company PDD Holdings may allow the Chinese government access to sensitive user data. Kentucky’s suit specifically emphasizes unauthorized data transmission to Chinese authorities.

Counterfeit & IP Violations

Kentucky’s complaint also alleges Temu sells counterfeit versions of famous state brands. Nebraska’s lawsuit includes claims of copycat products and deceptive marketing that harm local creators and businesses.

Broader Implications & Context

State Governments Assume National Cyber Roles

These cases mark a crucial shift: U.S. states are assuming enforcement responsibilities historically held by federal cybersecurity and intelligence agencies. Experts note that while some states lack forensic and legal resources for high-level cyber threats, the trend is clear.

Response from Temu

Temu categorically denies the allegations, calling them misinformation, often tied to short-seller reports. It has attempted to counter concerns by relocating its principal executive office to Dublin and signing data hosting deals with U.S. providers like Oracle, Google, and Microsoft to store user data domestically.

TikTok Parallel

Temu’s crisis echoes that of TikTok—another Chinese app under scrutiny for data sharing with Beijing. While Temu’s Oracle cloud deal is seen as a privacy-preservation effort, critics say such strategies have done little to appease regulators in TikTok’s case.

What This Means for Consumers & Businesses

  • Consumers: If allegations hold, users may face unauthorized surveillance, loss of privacy, and data misuse.
  • State Legislatures: These enforcement actions could accelerate new data protection laws or tighten consumer privacy statutes at state level.
  • E-commerce Brands: Sellers using Temu or similar platforms may face increased compliance scrutiny and liability risks.
  • Companies with China Ties: All foreign-owned apps must now consider deeper transparency and domestic data storage strategies to maintain trust and regulatory goodwill.

Legal actions in Kentucky, Nebraska, and Arkansas, along with emerging filings in Illinois and New York, spotlight Temu as a focal point in U.S. cybersecurity law. Key allegations include the use of surreptitious malware, unauthorized data transfers to China, and counterfeit product practices. These suits illustrate how state-level enforcement is evolving — with significant implications for digital privacy, regulatory policy, and e-commerce operations.

Shein falls into the red ahead of its Hong Kong IPO
Shein has reported a quarterly net loss as the fast-fashion e-commerce giant prepares for its long-awaited initial public offering in Hong Kong. The Singapore-headquartered retailer recorded a net loss of...
July 27, 2026
Notino reaches €1.76 billion as European cross-border growth accelerates
Czech beauty retailer Notino generated €1.76 billion in revenue during its latest financial year, reinforcing its position as one of Europe’s most successful cross-border e-commerce businesses. The Brno-based company closed...
July 24, 2026
Kord raises £6.4 million to unify onboarding, compliance and payments
UK fintech company Kord has raised £6.4 million in Series A funding to expand its platform for customer onboarding, regulatory compliance and payment processing. The round was led by Guinness...
July 21, 2026
Top crossmenu

By continuing to use the site, you agree to the use of cookies. more information

The cookie settings on this website are set to "allow cookies" to give you the best browsing experience possible. If you continue to use this website without changing your cookie settings or you click "Accept" below then you are consenting to this.

Close