Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
privacy-surveillance-policyenforcement-actioncybersecurity-regulationidentity-impersonation-fraud

Regulatory and legal scrutiny of online platforms over child safety, age verification, and gambling-like mechanics

Updated 2d agoFirst seen Feb 27, 20268 sources

New York Attorney General Letitia James filed suit against Valve, alleging Steam’s loot boxes and the broader skin economy enable “illegal gambling,” including through third-party sites that let users resell in-game items for cash and use Steam inventories as virtual chips for gambling. The complaint argues Valve has only “sporadically enforced” rules against skin-gambling sites and seeks changes to or elimination of loot boxes plus consumer restitution/disgorgement; the reporting also notes prior (dismissed) parent lawsuits and earlier pressure from Washington state to crack down on skin gambling.

Separate legal and policy actions focused on child safety and age assurance across major platforms. Los Angeles County sued Roblox, alleging the platform misled parents about safety while exposing children to grooming and explicit content, and highlighting historical gaps in messaging controls and weak age verification; the suit also points to Roblox’s more recent use of third-party Persona facial age checks to access chat features. Court filings in a multidistrict litigation against Meta/Instagram surfaced internal discussions (including then-CISO Guy Rosen) indicating executives were aware as early as 2018 that adults could message minors with explicit content; Instagram’s client-side classifier that blurs explicit images for teens reportedly did not roll out until 2024. In parallel, Discord paused and reworked a planned global age-verification policy after backlash, delaying rollout to the second half of 2026 and committing to additional verification options (beyond government ID/video selfies), vendor transparency, and a technical explanation of its “age determination systems.”

Share:
Regulatory and legal scrutiny of online platforms over child safety, age verification, and gambling-like mechanics
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

11 events from the most recent confirmed update back to the earliest known activity.

11 EVENTS
Mar 25, 20263mo ago

New Mexico jury orders Meta to pay $375 million over child exploitation claims

On 2026-03-25, a New Mexico civil jury ordered Meta to pay $375 million after finding it compromised user safety and facilitated the sexual exploitation of minors on its platforms. Meta said it disagrees with the verdict and plans to appeal; the case stemmed from a 2023 lawsuit brought by New Mexico Attorney General Raúl Torrez.

Nuevo M�xico condena a Meta a pagar 375 millones de d�lares por facilitar la explotaci�n sexual de menores en sus redes | Empresas
Feb 26, 20264mo ago

New York sues Valve over loot boxes and illegal gambling claims

Ars Technica reported on February 26, 2026 that New York sued Valve, alleging it enabled illegal gambling through loot boxes. No further details were provided in the supplied reference synopsis, but the lawsuit itself is a distinct legal action.

Newly unsealed filings detail Meta's delayed teen protections

By February 26, 2026, newly unsealed court documents in MDL No. 3047 revealed Meta's prior internal knowledge of explicit messages to minors, delayed deployment of image blurring, and undisclosed survey data on teen exposure to harmful content. The filings intensified public scrutiny of Instagram's child-safety practices.

Feb 25, 20264mo ago

Discord pauses and revises age verification rollout

On February 25, 2026, Discord said it would postpone the global rollout of its age verification policy until the second half of 2026 after backlash. The company also said it would add more verification options, increase transparency about vendors, and publish technical details on how its systems work.

Feb 19, 20264mo ago

Los Angeles County sues Roblox over child-safety practices

On February 19, 2026, Los Angeles County filed a lawsuit alleging Roblox misled parents about child safety while exposing children to predators and sexually explicit content. The complaint alleges violations of California's Unfair Competition Law and False Advertising Law and seeks penalties and injunctive relief.

Feb 1, 20265mo ago

Discord introduces new age verification policy

Discord introduced an age verification policy in early February 2026 that relied on methods such as government ID and video selfies for some users. The policy triggered weeks of user backlash after its announcement.

Jan 1, 20251y ago

Independent audit challenges Meta teen-safety claims

A 2025 independent audit reportedly found that many publicly promoted Meta teen-safety features did not work as described. The audit added to ongoing criticism reflected in later court filings and whistleblower testimony.

Sep 1, 20242y ago

Meta launches private-by-default teen accounts

The filings say Meta did not implement private-by-default teen account settings until September 2024. The delayed rollout is presented as part of broader scrutiny over Instagram's teen-safety measures.

Jan 1, 20242y ago

Meta deploys image blurring for explicit images sent to teens

Court documents allege Meta took about six years after identifying the problem to launch an Instagram feature that automatically blurs explicit images sent to teens in direct messages. The article contrasts the delayed rollout with Meta's earlier internal awareness in 2018.

Jan 1, 20198y ago

Meta considers private-by-default teen accounts but delays rollout

Related court filings allege Meta considered making teen Instagram accounts private by default in 2019. The change was allegedly delayed for years because of engagement concerns.

Jan 1, 20189y ago

Instagram internally flags explicit DMs to minors

Newly unsealed court documents allege Meta was aware in 2018 that adults were finding and messaging minors on Instagram and sending explicit images. An email thread cited in a deposition described these risks and more severe child-safety harm scenarios.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

19 LINKEDOpen in app
Affected products
6 linked
InstagramDiscordFacebookFacebook MessengerWhatsappZoom
Organizations
13 linked
DiscordMeta PlatformsRobloxPersonaMalwarebytesTikTokBritish Broadcasting CorporationSnapForbesGoogleHindenburg ResearchSocial Media Victims Law CenterProdigy
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.