"Your website unlawfully intercepted my communications. A draft complaint is attached. Resolve this within 14 days for $7,500, or I file."
Tasha read it twice at 11 p.m., standing behind the counter of her bakery after close. She sells cakes. Her website has a menu, an order form, a little search box and the Meta pixel her nephew installed so her Instagram ads would work.
The email had screenshots. Her homepage. Her search bar. A line of code with her pixel ID circled in red. Then twelve pages of something that looked exactly like a lawsuit, with her LLC's name typed in the caption.
It cited a California law. Tasha has never been to California.
The letter threatened a large per-violation amount. The math underneath it said every visit could count. By midnight she had her card out and a payment link open.
Tasha is a composite. The letters aren't. On September 17, Texas Attorney General Ken Paxton warned of a "recent surge" of what his office called scam demand letters hitting businesses and nonprofits. They claim that ordinary website tools, like cookies, pixels, analytics and search bars, count as illegal "wiretapping" under the California Invasion of Privacy Act, a 1967 eavesdropping law. The AG says the letters may come with screenshots of your own site and a draft complaint, and they push for immediate payment to avoid a lawsuit.
Here's the twist. Some of these letters are real legal claims, and some are pure pressure. From the outside they look the same. That's the whole trick: there's no way to know which one you got, so you're tempted to pay just to make it stop.
The AG's alert says letters like these "may exaggerate or misrepresent" a violation. One serial sender has been declared a vexatious litigant by a federal court in California. A July order bars him from filing new website-privacy cases in that court without a judge's permission first. A law firm that has handled more than a dozen of these says thousands of businesses have received them since fall 2025, many with no real connection to California.
And the law itself is unsettled. California courts are split on whether this old wiretap law even covers a pixel, and two appeals are pending.
Red flags
- "Pay in 14 days or we file." The deadline comes from the sender, not a court. A demand letter isn't a court order, and you don't have to pay on the spot.
- Screenshots of your own site plus a "draft complaint." The Texas AG names both as features of these letters. Your site is public, so anyone can screenshot it in a minute.
- A tiny business, a huge number. The letter threatens a large per-violation amount and suggests every visit counts. That math is the pressure.
- A state you don't do business in. A neighborhood bakery that has never shipped a cake out of state getting a California wiretap claim is exactly the pattern.
- A payment link or a "quick settlement" before anyone has looked at your site. Real disputes get reviewed. Shakedowns get paid.
What to do
- Don't pay, and don't reply yourself. The Texas AG says not to respond to the sender or pay without first getting qualified legal advice, if you can.
- Don't ignore it either. Save the email, every attachment and the date it arrived.
- Freeze a snapshot of your site before you change anything. Screenshot the homepage, any form, your cookie banner and your privacy policy, with the date showing. Then check which pixels, chat widgets and analytics tags load before a visitor clicks "accept."
- Get privacy help. Look for a privacy or website-tracking attorney (your state bar can help you find one), and ask your insurer whether a cyber or liability policy covers it.
- Fix it going forward. With that help, set nonessential trackers to load only after a visitor agrees.
- Report it. If you think a letter is fraudulent or abusive, report it to your state attorney general (find yours at naag.org) and at ReportFraud.FTC.gov. In Texas, the AG's Consumer Protection Division takes reports at 1-800-621-0508.
Tasha closed the payment tab. The pixel's still on her site. Now it waits for a yes.
Sources:
- Texas Attorney General, Consumer alert on scam demand letters alleging website privacy violations (Sept. 17, 2026): https://www.texasattorneygeneral.gov/news/releases/consumer-alert-attorney-general-ken-paxton-warns-texans-scam-demand-letters-alleging-website-privacy
- Tucker Ellis LLP, The CIPA Demand Letter Tsunami (July 2026), on the July 20, 2026 vexatious-litigant order and the split in California courts: https://www.tuckerellis.com/alerts/the-cipa-demand-letter-tsunami-what-you-need-to-know-and-what-you-can-do-about-it/
- FTC, Scams and Your Small Business: https://www.ftc.gov/business-guidance/resources/scams-your-small-business-guide-business
- National Association of Attorneys General, find your state AG: https://www.naag.org/find-my-ag/