NZXT agrees to let customers keep their rental PCs in class-action settlement

The complaint also claimed that the plaintiff received a desktop with an RTX 4090 instead of the expected RTX 4080 Super. Further, it alleged that a Fragile representative told a plaintiff that he could buy the PC after renting. This is despite a NZXT representative previously confirming via Reddit that Flex isn’t a rent-to-own program.

Settlement agreement

In lieu of a trial, on April 7, NZXT and Fragile reached a settlement agreement [PDF] for a class of 19,322 customers [PDF], as first spotted by Gamers Nexus. The terms of the agreement are pending approval from a judge.

The agreement would allow some customers to own the PCs that they rented if they meet certain requirements, including having signed up for Flex on or before 2024 and never received an upgraded PC, or if “their accounts are more than 90 days delinquent as of March 30, 2026 and they signed up for the NZXT Flex Program between October 29, 2024, and June 1, 2025.” The value of the PCs that users may keep is “approximately” $1,216,129.02, the agreement says.

The rest of the proposed settlement consists of a $923,117.92 debt forgiveness pool that will provide up to $5,000 to members who are 90 days past due on payments, plus a $1,450,000 settlement cash fund.

Finally, NZXT agreed to change its business practices by trying to “prohibit social media influencer advertisement campaigns from making statements that customers have an ownership interest in NZXT Flex PCs,” using different brand names for its rental PCs and PCs that can be owned (something that NZXT has done since December 2024).

The PC company also committed to providing “accurate specifications and performance statistics” for its rental PCs and requiring customers to confirm that they know Flex isn’t a rent-to-own program before subscribing.

Finally, NZXT will update Flex’s website to “prominently” inform customers that they can use software to transfer their data from one rental PC to another rental PC for free.

NZXT agreed to maintain these practices until December 31, 2027.

Ars Technica reached out to NZXT for comment, but did not hear back before publication. We’ll update the story if we receive a response.

https://arstechnica.com/gadgets/2026/04/nzxt-agrees-to-3-45-million-settlement-over-controversial-rental-pc-program/




Your tech support company runs scams. Stop—or disguise with more fraud?

Payment processors aren’t idiots, and a huge number of new charges was likely to arouse suspicion. (Indeed, one processor suspected that Tech Live Connect was using “friendly” charges as early as 2018.) To make the charges look legitimate, Tech Live Connect processed them using real customer data, including names and addresses.

Once Tech Live Connect got its chargeback ratio low enough, it used this data to get more merchant accounts, allowing it to stay in business longer and for people there to scam new targets. Cotter eventually admitted that, by keeping his company open using this scheme, he defrauded Americans of an additional $8 million or so.

The scheme ran for four years, and it had to be managed every month. In March 2018, for instance, Cotter’s team realized that it needed 27,000 more “good” transactions that month to outweigh all the bad ones, so it spent $140,000 to acquire 3,000 virtual debit cards, which it then charged through six different payment gateways.

For a plan that involved giving money to yourself, this one proved surprisingly costly. By the time Tech Live Connect acquired the cards in bulk, which required third-party vendors, and then paid all processing charges, half of the money charged was gone.

Still, it was worth a few million dollars to keep the company in business. Tech Live Connect made significant cash—more than $13 million during the four years this system was in operation.

Payment processors grew suspicious despite Cotter’s tricks, and by 2020 the US Postal Inspection Service had launched an investigation. Cotter was charged later that year and by December 2020 had been hit with an injunction ordering him to stop “selling technical-support services or software via telemarketing or websites.”

The legal case dragged on for years, until Cotter finally pleaded guilty in January 2026 to one count of conspiracy to commit bank fraud. Last week, the 64-year-old Cotter was sentenced to 28 months in prison.

https://arstechnica.com/tech-policy/2026/04/your-tech-support-company-runs-scams-stop-or-disguise-with-more-fraud/




IBM folds to Trump anti-DEI push, admits no misconduct but pays $17M penalty

While companies often enter settlements without admitting to alleged misdeeds, this settlement says IBM ended conduct that it denies having ever engaged in. In one sentence, the settlement agreement says that “the cooperation IBM provided included… taking voluntary remedial measures, including the termination and/or modification of various programs, policies, or other activities described in the Covered Conduct.” Two sentences later, the settlement states that “IBM denies that it engaged in the Covered Conduct.”

Trump admin’s aggressive push against DEI

IBM agreed to pay $17,077,043 to the government within 14 days of the settlement being signed. The amount includes civil penalties and $8.2 million in restitution to the government.

“Racial discrimination is illegal, and government contractors cannot evade the law by repackaging it as DEI,” Acting Attorney General Todd Blanche said. “The department launched the Civil Rights Fraud Initiative to root out this misconduct, hold offenders accountable, and end this practice for good.”

The Trump administration has taken an aggressive stance against DEI programs that were implemented to help historically underrepresented groups. President Trump has issued several executive orders on DEI, including one last month that targets federal contractors.

In addition to ending DEI policies within the government, the Trump administration uses multiple legal and regulatory tools to pressure private companies. For example, the Federal Communications Commission chairman has refused to approve mergers unless the merging companies end DEI initiatives.

“IBM is pleased to have resolved this matter,” the company said in a statement provided to Ars. “Our workforce strategy is driven by a single principle: having the right people with the right skills that our clients depend on.”

The Justice Department credited IBM for cooperating in its investigation and for ending DEI programs. “IBM made early disclosures of facts relevant to the government’s investigation gathered during IBM’s independent investigation, including information to assist in the calculation of damages and penalties,” the department’s press release said. “The company also undertook voluntary remedial measures, including the termination and/or modification of various programs and practices at issue.”

https://arstechnica.com/tech-policy/2026/04/ibm-folds-to-trump-anti-dei-push-admits-no-misconduct-but-pays-17m-penalty/




Californians sue over AI tool that records doctor visits

Several Californians sued Sutter Health and MemorialCare this week over allegations that an AI transcription tool was used to record them without their consent, in violation of state and federal law.

The proposed class-action lawsuit, filed on Wednesday in federal court in San Francisco, states that, within the past six months, the plaintiffs received medical care at various Sutter and MemorialCare facilities.

During those visits, medical staff used Abridge AI. According to the complaint, this system “captured and processed their confidential physician-patient communications. Plaintiffs did not receive clear notice that their medical conversations would be recorded by an artificial intelligence platform, transmitted outside the clinical setting, or processed through third-party systems.”

The complaint adds that these recordings “contained individually identifiable medical information, including but not limited to medical histories, symptoms, diagnoses, medications, treatment discussions, and other sensitive health disclosures communicated during confidential medical consultations.”

In recent years, Abridge’s software and AI service have been rapidly deployed across major health care providers nationwide, including Kaiser Permanente, the Mayo Clinic, Duke Health, and many more.

https://arstechnica.com/tech-policy/2026/04/californians-sue-over-ai-tool-that-records-doctor-visits/




Report: US demands Reddit unmask ICE critic, summons firm to grand jury

But on March 31, “Reddit received another message from the feds,” The Intercept reported. “This time, instead of requesting information on an individual user, the government ordered Reddit itself to appear before a grand jury—not in California, but in Washington.”

The subpoena was issued by prosecutors from the US Attorney’s office in DC, and the “records sought spanned a period roughly three times longer than what ICE had originally requested,” the article said. The US Attorney for the District of Columbia is Jeanine Pirro. The grand jury subpoena is a new tactic being used by the Trump administration after it repeatedly lost attempts to subpoena information in court, The Intercept was told by CLDC Executive Director Lauren Regan.

Grand jury proceedings are not public. Grand juries may issue indictments after assessing evidence presented by prosecutors to determine whether there is probable cause that someone committed a crime. Witnesses may be called to give testimony. If an indictment is issued, the accused would be put on trial.

“The only valid use of a grand jury is to investigate federal crimes,” Regan told The Intercept. It’s unclear how Doe’s Reddit posts are evidence of a crime, and the administration is “able to hide what they are doing under the guise of a federal grand jury,” she said.

While the now-withdrawn summons is public, we do not have a copy of the subpoena. The CLDC told Ars today that it has no further comment on the case and noted that grand jury subpoenas are issued in secret.

Reddit: “We do not voluntarily share information with any government”

David Greene, senior counsel for the Electronic Frontier Foundation, “knew of no examples during the recent wave of immigration enforcement-related investigations in which a leading tech company has been called to appear before one of the secret panels,” The Intercept article said. “Free speech protections are at their weakest in the context of a grand jury, he explained: The proceedings are not adversarial; their purpose is to permit a prosecutor to file charges.”

https://arstechnica.com/tech-policy/2026/04/trump-admin-hounds-reddit-to-reveal-identity-of-user-who-criticized-ice/




Dad stuck in support nightmare after teen lied about age on Discord

“We’re not rookies on technology,” he said.

After receiving the data dump on his daughter’s Discord account, a couple of things stuck out immediately as odd to Frey.

“There’s no age recorded at signup, but there’s something worth flagging: her data includes an age_group field set to ’13–17,’ confirming Discord’s system knows she’s a teen,” Frey told Ars.

According to the data, Discord updated this field on March 9, about nine days before the account was hacked on March 18.

“They changed the age on their side, even though we can’t change the age on ours,” Frey said.

Additionally, Frey noticed that a separate field, “is_underage,” was set to “false.” He told Ars that he thinks that “discrepancy matters because the underage flag likely controls whether stricter ad protections” for kids are “applied.”

Since his daughter set up the account with an 18+ setting, it’s possible that the field corresponded to her self-reported age. But Frey could see that Discord updated the setting twice: once two days after the hack, and again after her account was restored. Each time, she was marked as not underage, despite support forum messages that repeatedly informed Discord she was 13.

Seemingly, that meant that the platform could create “a detailed behavioral ad profile” on the teen, even though its internal system had categorized her in the 13–17 age group, Frey said.

Samantha Baldwin, a policy and research staff technologist for the Electronic Frontier Foundation (EFF), told Ars that Discord’s hesitancy to formally update the age setting is telling. Frey’s case shows why privacy advocates believe that age verification laws aren’t about “protecting children” but about “surveillance and censorship,” she said.

“That they would not recategorize a minor’s account demonstrates this clearly,” Baldwin said. “Discord is in the business of making money by selling their users’ personal data. They are implementing ‘age verification’ to meet regulatory compliance and to collect more data about their customers, not protect children.”

https://arstechnica.com/tech-policy/2026/04/dad-stuck-in-support-nightmare-after-teen-lied-about-age-on-discord/




Trump-appointed judges refuse to block Trump blacklisting of Anthropic AI tech

The department’s “relationship with Anthropic has deteriorated to the extent that Anthropic’s CEO has publicly described the Department’s statements regarding the controversy as ‘completely false’ and ‘just straight up lies,’” the court said. “Under these circumstances, requiring the Department to prolong its use of Anthropic’s AI technology, whether directly or through contractors, strikes us as a substantial judicial imposition on military operations. And, of course, we do not lightly override the Department’s judgments on matters involving national security.”

While the court said the balance of equities favors the government in determining whether to issue a stay, it acknowledged that Anthropic raised substantial questions that should be addressed quickly.

“In our view, the equitable balance here cuts in favor of the government,” the court said. “On one side is a relatively contained risk of financial harm to a single private company. On the other side is judicial management of how, and through whom, the Department of War secures vital AI technology during an active military conflict. For that reason, we deny Anthropic’s motion for a stay pending review on the merits. Nonetheless, because Anthropic raises substantial challenges to the determination and will likely suffer some irreparable harm during the pendency of this litigation, we agree with Anthropic that substantial expedition is warranted.”

The Computer & Communications Industry Association (CCIA), a trade group that filed briefs in both cases, said that tech companies are concerned about the “Pentagon’s means of blacklisting Anthropic without following typical procurement procedures,” and that the appeals court “denial will prolong ambiguities regarding whether political considerations can drive federal procurement.”

“Designating a company as a supply chain risk is a tool normally reserved for foreign adversaries, and should be used with discretion and proper procedure,” CCIA CEO Matt Schruers said. “It is risky to US innovation and competition to allow the government to unfairly discourage doing business with a US AI company as it competes with foreign AI companies.”

https://arstechnica.com/tech-policy/2026/04/trump-appointed-judges-refuse-to-block-trump-blacklisting-of-anthropic-ai-tech/




Police corporal created AI porn from driver’s license pics

A corporal in the Pennsylvania state police yesterday pleaded guilty to a mind-boggling set of crimes that include going through his co-workers’ underwear, possessing a stolen gun, having child sexual abuse material on his hard drives, and using AI tools to create over 3,000 pornographic “deepfakes.”

One of the deepfakes involved a district court judge, while many of the others were created based on photos downloaded illicitly from state databases, including driver’s license photos.

Some of the imagery was even created at police barracks, using state-owned devices.

Deepfakes from driver’s licenses

Stephen Kamnik, 39, was arrested last year and charged with nine felonies and six misdemeanors. According to the Pennsylvania attorney general, “For years, Kamnik allegedly misused Commonwealth computer resources for his own personal sexual gratification, including the creation of AI-generated pornography of numerous female citizens of Pennsylvania.”

The Philadelphia Inquirer notes that the investigation began back in 2024 after police officials “noticed that the computer assigned to [Kamnik] had been using an unusually high amount of Internet bandwidth” and that an external hard drive had been repeatedly attached to it.

This aroused suspicion and eventually led to searches of Kamnik’s phone, computer, and external hard drive, which revealed a massive trove of illicit material. This material included thousands of pornographic deepfakes that Kamnik had generated using AI tools.

The attorney general said yesterday that Kamnik got material for this process through several methods, such as “secretly filming and photographing individuals, including coworkers.” Investigators even found “an unlawfully recorded video of a Montgomery County magisterial district judge during a court proceeding which Kamnik also edited for apparent lewd purposes.”

But many of the AI deepfakes were generated using the faces of women pulled from state databases. Kamnik’s devices showed that he had used “a secured database, JNET, to obtain hundreds of photographs of females—in violation of JNET usage policies,” the attorney general said. One of the rules JNET users must agree to before searching is “that personal use of JNET is strictly prohibited.”

https://arstechnica.com/tech-policy/2026/04/state-police-corporal-created-porn-deepfakes-from-drivers-license-photos/




First man convicted under Take It Down Act kept making AI nudes after arrest

Man kept making AI nudes after arrest

The Take It Down Act was passed in May 2025, and Strahler was arrested on federal charges by June.

The Federal Bureau of Investigation was called in after Strahler’s phone was seized in April, after one of his victims called local police. Confronted by the local cops, Strahler admitted to creating and sending the images, then was arrested and jailed.

Once the FBI got involved, an analysis of his device showed that he had “similarly harassed two ex-girlfriends and their mothers,” The New York Times reported. The FBI also found images of two boys on the phone.

That arrest was not enough to stop Strahler from creating more images, though. While he was on pre-trial release in the first case, another Ohio police department arrested him in June after he continued sending fake nudes to harass one of his victims. A search of his new phone uncovered more than 2,400 images and videos “depicting nudity, child sexual abuse material, or violence,” the press release said.

Celebrating Strahler’s conviction, the US Attorney in the Southern District of Ohio, Dominick S. Gerace II, said that his office is “committed to using every tool at our disposal to hold accountable offenders like Strahler, who seek to intimidate and harass others by creating and circulating this disturbing content.”

“We believe Strahler is the first person in the United States to be convicted under the Take It Down Act,” Gerace said. “We will not tolerate the abhorrent practice of posting and publicizing AI-generated intimate images of real individuals without consent.”

On X, Melania Trump also claimed the conviction as a win after championing the Take It Down Act and joining Donald Trump in signing it into law. On Tuesday, she praised Gerace’s team for putting an end to Strahler’s harassment and “protecting Americans from cybercrimes in this new digital age.”

https://arstechnica.com/tech-policy/2026/04/first-man-convicted-under-take-it-down-act-kept-making-ai-nudes-after-arrest/




LinkedIn scanning users’ browser extensions sparks controversy and two lawsuits

We contacted Teamfluence today and will update this article if it provides a response.

“Unfortunately, this is a case of an individual who lost in the court of law, but is seeking to re-litigate in the court of public opinion without regard for accuracy,” LinkedIn said.

Lawyer: LinkedIn “does not meaningfully deny” allegation

It’s not uncommon for lawyers to file class action lawsuits shortly after explosive claims are made by media outlets or advocacy groups. The Farrell lawsuit against LinkedIn extensively quotes the BrowserGate report and describes Fairlinked as a “European advocacy group” without mentioning its ties to Teamfluence. We contacted the lawyers who filed the lawsuit and will update this article if we get a response.

The Ganan lawsuit doesn’t mention the BrowserGate report but makes similar allegations. J.R. Howell, the Santa Monica attorney who filed the complaint, told Ars today that the suit’s allegations “were based on the firm’s own review and analysis of LinkedIn’s client-side code and related technical behavior, as well as the applicable US and California legal framework.”

Howell told Ars that LinkedIn’s response to the claims does not refute the central allegation regarding lack of consent.

“LinkedIn’s public response does not meaningfully deny the core conduct alleged in the complaint,” Howell told Ars. “The real question is not whether LinkedIn says it was fighting abuse of the terms of service. The question is whether users were actually informed, in any clear and meaningful way, that LinkedIn would secretly probe their browsers for installed extensions, extract session-linked data, and make that data available to undisclosed third parties whose own uses could extend beyond a one-time compliance check.”

Howell argues that a “reasonable user does not consent to mass browser surveillance and third-party data exploitation through vague references to security, cookies, add-ons, or abuse prevention.”

Both lawsuits allege that LinkedIn violated the California Constitution’s protection against invasion of privacy and the California Comprehensive Computer Data Access and Fraud Act. The Ganan lawsuit also alleges that LinkedIn violated the federal Electronic Communications Privacy Act. Both lawsuits seek financial damages and an injunction forcing the company to change its data-collection and disclosure practices.

https://arstechnica.com/tech-policy/2026/04/linkedin-scanning-users-browser-extensions-sparks-controversy-and-two-lawsuits/