Field Notes

source

Verizon and Its Cloud Vendor Must Face Lawsuit for Reporting “CSAM” That Wasn’t

Lawshe v. Verizon

Riana Pfefferkorn’s guest post on Eric Goldman’s Technology & Marketing Law Blog (March 2025, updated February 2026) analyzes Lawshe v. Verizon, the first lawsuit to survive a motion to dismiss against providers for filing a false CSAM report. The preserved post (raw response) explains the statutory frame: 18 U.S.C. § 2258A obliges providers to report “apparent violations” once they have actual knowledge, § 2258B immunizes mistaken reports, and an SCA exception permits disclosing content to NCMEC. Verizon’s vendor Synchronoss auto-reported two hash matches against legal adult pornography without human review; the court held the “apparent CSAM“-tagged match immunized but let defamation and SCA claims proceed on the “unconfirmed CSAM“-tagged match, distinguishing mistaken reports (immunized) from unfounded ones (not).

The February 2026 update records that the parties settled and the court vacated the order, restoring robust § 2258B immunity as a practical matter. The post also states the structural point this wiki reuses: § 2258A is a reporting duty without a monitoring duty, yet its incentives push providers to over-report — nearly 36 million CyberTips in 2023, 85 percent of them from Meta — because false reports cost the provider nothing while missed ones risk massive fines.

This grounds the legal-mechanism sections of CSAM scanning externalizes error costs and Automated CSAM detection. Limitations: the analyzed order was vacated, so it binds no one; the author is a leading academic specialist writing analysis, not neutral description, though her characterization of the vacatur favors the defense side.

Built on 1 source (1 external).

Working out connections…