
On November 7, 2025, failed actor and convicted felon Vivek Shah, a California resident, visited the website of Drexel Chemicals, an agrichemical wholesaler in Memphis. Five days later, Shah served Drexel a letter alleging the company wiretapped him in violation of Section 631(a) of the California Invasion of Privacy Act, threatening to sue if the company did not pay him a settlement.
Shah – aliases Ray Amin and Rohan Gill – was convicted in 2012 for threatening to kill families of the wealthy and famous if they did not make extortion payments, for which he set up an offshore account in Cyprus. Post-prison, Shah’s occupation appears to be extorting settlements from legitimate businesses for their dastardly act of operating websites. Shah alone is estimated to have sent letters to thousands of retailers and other businesses claiming “wiretapping.”
He is not alone in this scam. Over 5,300 lawsuits currently are pending, claiming that ubiquitous internet tools – cookies, pixels, chatbots, marketing software, even collection of IP addresses so a website may return information to the consumer – violate wiretapping or pen register laws. Litigants claim use of these universal internet tools constitute recording of a conversation without their consent, breaching laws written decades before the internet.
Over 5,300 lawsuits currently are pending, claiming that ubiquitous internet tools such as cookies and pixels violate wiretapping or pen register laws.
These lawsuits plague retailers, other businesses, and nonprofits throughout the country, from the largest companies to flower shops, restaurants, hospitals, shoe stores, roofers, plumbers – even a cheerleading team. One individual appears as the plaintiff in more than 100 cases. One California law firm has filed over 1,000 such lawsuits.
Among the serial plaintiffs:
– Alondra Gutierrez concocted 24 suits against home furnishings companies, sporting goods stores, a mattress company, a maker of body washes, and for some reason, a fishing gear company.
– Anna Orr filed 20 lawsuits against a restaurant development company, Levi’s, a Caterpillar equipment dealer, PeachyBbies Slime Shop, an engineering company, and a film maker. Remarkable range.
– Anne Heiting goes for bigger fish. She’s filed 38 suits against Rocket Mortgage, Marriott, HP, Lulu’s, Frontier Airlines, Guess, Andersen Windows, and Williams Sonoma, among others.
We could go on and on, and we’re not even out of the “A’s.”
Evidence suggests at least one law firm is advertising for plaintiffs on social media, selling abusive “wiretapping” lawsuits as a way to make a quick buck.
As thousands of retailers have learned, companies well beyond California are at risk, and not just under California law. Twelve States have “two-party consent” wiretapping laws, requiring both parties to a conversation to consent to recording. Over 600 suits have been filed in Florida. Many cases allege federal theories under the Electronic Communications Privacy Act (ECPA). Even though ECPA is not violated so long as one party consents to “recording,” it has a crime/tort exception. Plaintiffs allege that a website collecting information constitutes invasion of privacy, a tort, and thus federal law is an available remedy even though one party (the business) obviously consented.
Retailers are major targets.
A shoe store owner in Chicago that has been targeted under California wiretapping law said, “It’s like an extortion ring aimed at small businesses with websites. We would literally have to shutter our website to avoid these attacks. We have robust privacy policies with opt ins and opt outs, but that doesn’t deter them.”
A Chicago shoe store owner that has been targeted under California wiretapping law said, “It’s like an extortion ring aimed at small businesses with websites.”
“They create fear, consume valuable time, force owners to seek legal or technical guidance, and distract us from running our businesses,” an Atlanta retailer said. A Charlotte-based company added, “It has the feel of a coordinated shakedown — one that extracts money from small businesses for the benefit of the law firms driving it. We desperately need congressional support to help pass reform in this area.”
Cookies and chatbots aren’t “wiretapping” – they’re standard e-commerce, subject to the requirements of State privacy laws in the states that have them. So why aren’t these serial plaintiffs suing under California’s or other states’ privacy laws?
First, because every State privacy law, including California’s, allows cookies, pixels, chatbots, and other internet tools as perfectly legal means to learn who is visiting a website and how to serve them better. The free internet would not exist without this functionality.
Second, money. State privacy laws do not include a private right of action; the wiretapping laws do. California law subjects defendants to up to $5,000 in penalties per violation, which under the outrageous plaintiffs’ theories occurs every time someone connects to a website. Big potential payday for shady law firms, bet-the-company risk for businesses.
Pending cases have ballooned by roughly 1,000 just since earlier this year. Twenty-plus cases are being filed each week, not to mention the thousands of demand letters, settlements for which have knocked some small retailers out of business.
Congress must act this year. It must block wiretapping and pen register laws from being misapplied to the internet and end this egregious tax on the economy.
David French is the Executive Vice President of Government Relations at the National Retail Federation.




