TL;DR: As of October 1, 2025, a lapse in government funding has shuttered key federal agencies, allowing the Cybersecurity Information Sharing Act to expire and taking the FTC offline, creating a dangerous vacuum in the nation's cybersecurity and consumer protection infrastructure.

What changed (August 6, 2026): The 43-day shutdown ended in November 2025, and Congress revived CISA 2015 through January 30, 2026 as part of the funding bill. A subsequent Consolidated Appropriations Act in early February 2026 pushed the sunset to September 30, 2026, but the long-term reauthorization fight is still unresolved and a separate DHS funding lapse in spring 2026 again stressed CISA operations before funding was restored.

What changed (September 7, 2026): The House passed a continuing resolution on September 1, 2026 that pushes CISA 2015, the Federal Cybersecurity Enhancement Act, and the Technology Modernization Fund through "early December" 2026, the third stopgap extension of the information-sharing law since the original 10-year sunset. The FTC, meanwhile, has been actively enforcing: it sued Amazon with 22 state attorneys general on August 31, settled with payment processor Nuvei for $4.85 million on September 4, finalized a $930,000 Cox Media Group "Active Listening" order on August 27, and announced new National Do Not Call Registry fees for FY 2027 effective October 1, 2026. Both signals matter: the CR keeps the underlying information-sharing framework alive for another quarter, and the FTC docket shows the agency is no longer operating in the "muted" mode this article first warned about.

A Void in Washington

As of October 1, 2025, a lapse in government funding has shuttered key federal agencies, creating a dangerous vacuum in the nation's cybersecurity and consumer protection infrastructure. The shutdown has not only paused routine operations but has also allowed a critical piece of cyber-defense legislation to expire and taken the primary consumer protection agency offline, leaving both private industry and the public exposed.

The CISA Lifeline is Cut, Leaving Industry in the Dark

A cornerstone of public-private cybersecurity cooperation, the Cybersecurity Information Sharing Act of 2015 (CISA 2015), expired on October 1 amid the shutdown.[1, 2] This law was instrumental in fostering a collective defense against cyber threats by providing legal liability protections to companies that voluntarily shared threat intelligence with the government and each other. These safeguards encouraged the timely exchange of information about new attack methods and vulnerabilities, allowing defenders to learn from each other in near real-time.

With the law's expiration, these legal protections have vanished. A coalition of over 50 industry groups had warned Congress that such a lapse would dramatically decrease information sharing, leading to a "more complex and dangerous" security environment.[1] Without this framework, private entities are now isolated, hesitant to share critical data for fear of lawsuits. This creates a significant advantage for malicious actors, who thrive when their targets are unable to coordinate a defense.

The FTC Goes Dark, Muting Consumer Protection

Simultaneously, the Federal Trade Commission (FTC), the nation's chief consumer protection watchdog, has effectively closed its doors.[3, 4] The shutdown has rendered its most important public-facing services unavailable. Critical resources for citizens, including ReportFraud.ftc.gov, IdentityTheft.gov, and the National Do Not Call Registry, are all offline.[4]

While the FTC's Consumer Sentinel Network, a database of consumer complaints, remains technically available to law enforcement, no new complaint data will be entered until the government reopens.[4] This effectively freezes the nation's primary repository of consumer fraud data, blinding authorities to emerging scams and leaving victims with no official channel to report harm. The federal government's withdrawal from the field signals a systemic weakness that invites other actors (both regulatory and criminal) to fill the void.

National Security and Economic Implications

The simultaneous lapse of CISA and closure of the FTC creates a perfect storm of vulnerability. At a time when cyber threats are increasingly sophisticated and consumer fraud is rampant, the United States has effectively disarmed two of its primary defense mechanisms. The timing could not be worse, as threat actors worldwide are likely to view this period as an opportune moment to launch attacks or scams with reduced risk of detection or consequence. Federal contractors are already a target: a ransomware crew hit a contractor serving ICE, DHS, and CISA.

For businesses, the absence of legal protections for information sharing means that critical threat intelligence may not reach those who need it most. A vulnerability discovered by one company may not be shared with others in the same sector, allowing attackers to exploit the same weakness across multiple targets, the same dynamic that drives supply chain attacks through third-party vendors. This fragmentation of the cybersecurity ecosystem undermines years of progress in building collaborative defense strategies.

For consumers, the closure of the FTC means that fraud victims have nowhere to turn. Scammers know that reports will not be processed, investigations will not be initiated, and enforcement actions will not be taken. This creates a lawless digital environment where bad actors can operate with near impunity.

What You Can Do

While the federal government is unable to provide protection, individuals and organizations can take proactive steps to defend themselves during this period of vulnerability.

For Individuals: Heighten Your Vigilance

Be extra cautious of phishing attempts, unsolicited calls, and unusual requests for personal information. Verify the identity of anyone claiming to be from a government agency or financial institution by calling them back at a known, legitimate number.

For Businesses: Strengthen Internal Sharing

Even without CISA protections, continue to share threat intelligence within your industry through trusted channels. Consider joining private sector information sharing and analysis centers (ISACs) that operate independently of government frameworks.

Document Everything

If you are a victim of fraud or a cybersecurity incident, document everything thoroughly. Once the FTC reopens, you may still be able to file a retroactive complaint. Keep records of dates, communications, and financial losses.

Use Alternative Reporting Channels

While the FTC is offline, you can still report fraud to your state's Attorney General office, local law enforcement, or the FBI's Internet Crime Complaint Center (IC3) at ic3.gov.

A Self-Inflicted Wound

This government shutdown is not a natural disaster or an external attack. It is a self-inflicted wound that has left the nation more vulnerable to both cyber threats and consumer fraud. The expiration of CISA and the closure of the FTC demonstrate how political dysfunction can have immediate and tangible consequences for national security and economic stability. As this crisis continues, the burden of protection has shifted entirely to individuals, businesses, and state governments, none of whom have the resources or legal authorities that federal agencies possess.

Update (August 6, 2026): CISA 2015 revived, then pushed to September 30, 2026

The 43-day shutdown ended when President Trump signed H.R. 5371, a continuing resolution that Cybersecurity Dive reported on November 13, 2025 also temporarily revived CISA 2015 through January 30, 2026.[5] The FTC's National Do Not Call Registry came back online the same day; the agency reported that "all Do Not Call services are fully active" and that enforcement had resumed.[6] On December 22, 2025, the FTC moved to reopen and set aside the 2024 Rytr final consent order under the Trump administration's AI Action Plan, the first publicly visible signal that the agency's privacy enforcement docket was unstuck.[7]

The CISA 2015 sunset was then pushed out again by the Consolidated Appropriations Act, 2026, enacted in early February 2026, which extended the statute through September 30, 2026 without amending any of the substantive cyber-information-sharing provisions.[8] A long-term reauthorization remains unresolved: Senator Rand Paul, who chairs the Senate Homeland Security Committee, has blocked multi-year extensions demanding CISA be barred from "disinformation" work, and the path to a permanent fix is still "murky" according to Federal News Network's congressional staff reporting.[9]

A separate DHS funding lapse in spring 2026 again stressed CISA operations. By April 2026, CISA Acting Director Nick Andersen was publicly warning House appropriators that the agency's resources were "more limited than I would like" and that many "preparatory activities within the environment, a lot of the outreach that we'd typically be able to do" were not permitted during the ongoing DHS shutdown.[11] DHS had been unfunded for about two months due to a partisan stalemate over immigration enforcement reforms, employees were called back to the office using funds from the One Big Beautiful Bill Act, and CISA had cancelled plans to onboard summer interns in the CyberCorps scholarship program.[11] The September 30, 2026 sunset is now the next hard deadline for both CISA 2015 and the broader information-sharing legal protections this article originally warned were lost.

Update (September 7, 2026): CISA 2015 gets a third stopgap, FTC docket stays open

Two new developments in the last month change the picture this article first painted in October 2025. The CISA 2015 sunset is no longer the next hard deadline; the FTC is no longer muted. Both shifts land in the same week and matter for the same reason: the original TL;DR's "dangerous vacuum" was the product of two separate lapses happening at the same time, and the September 2026 window closes the immediate vacuum while keeping the long-term reauthorization fight unresolved.

On the cyber side, Federal News Network's Justin Doubleday reported on September 1, 2026 that the House had passed a continuing resolution the previous day that would extend CISA 2015, the Federal Cybersecurity Enhancement Act, and the Technology Modernization Fund "through the stopgap funding period into early December" 2026, the third short-term extension of the information-sharing law since its original 10-year sunset in September 2025.[12] The Senate had already passed the measure, so it headed to President Trump's desk. The article's framing is the one this article has tracked since November 2025: Congress is "kicking the can down the road again" on long-term reauthorization, and the path to a permanent fix remains blocked by Senate Homeland Security and Governmental Affairs Committee Chairman Rand Paul, who wants CISA barred from "disinformation" work folded into any multi-year extension. The same article surfaces the new pressure point: the Treasury Department's AI-enabled cybersecurity clearinghouse, GOLD EAGLE, "depends on the protections CISA 2015 provides," so a lapse would not only break the underlying information-sharing flow but also cut the legal floor out from under the vulnerability-coordination program the White House launched on July 14, 2026.[12] The Operational Technology Cybersecurity Coalition's executive director Tatyana Bolton put the industry position on the record on July 31, 2026: "We can no longer keep doing minor extensions of CISA 2015. We must have long-term authority to keep CISA 2015 operational."[12] A July 17, 2026 multi-association letter to House leaders argued the same point and warned that a lapse "would be especially ill-timed," because it would also break the GOLD EAGLE initiative the administration is building on top of CISA 2015.[12] The next hard deadline is now early December 2026, not September 30, and the substantive question for that deadline is the same one this article has been tracking since the November 2025 revival: whether a long-term reauthorization finally clears the Senate.

On the consumer-protection side, the FTC's press-release log shows the agency has been actively enforcing through August and into early September 2026, not operating in the "muted" mode this article first warned about. The substantive August 2026 actions include the finalized $930,000 Cox Media Group "Active Listening" order on August 27, 2026, the $4 million Manchester City Nissan deceptive-fees settlement on August 19, 2026, the $2.1 million Doxo misleading-search-ads settlement on August 17, 2026, and more than $23.8 million in refunds to drivers and diners harmed by Grubhub's deceptive earnings claims on August 12, 2026.[13] The substantive September 2026 actions are the FTC and 22 state attorneys general suing Amazon on August 31, 2026 for allegedly inflating prices in its online marketplace, and the $4.85 million settlement with payment processor Nuvei on September 4, 2026 for opening and maintaining accounts for merchants it knew or should have known were engaged in fraud.[13] The agency also published new fees for telemarketers accessing the National Do Not Call Registry for Fiscal Year 2027, effective October 1, 2026, the same date the September 30, 2026 CISA 2015 sunset was set to hit before the September 1 CR.[13] The combination is the same "two prongs at once" pattern this article's TL;DR framed as the danger: when both the cyber information-sharing law and the consumer-protection agency are operating, the surveillance and privacy picture looks fundamentally different than when they are both closed. The FTC docket is now visibly unstuck on a wide range of consumer-protection actions, the CISA 2015 framework is still alive for at least another quarter, and the next time the "dangerous vacuum" framing applies it will be because Congress let the early-December sunset lapse, not because a shutdown closed the agencies.

See the September 1, 2026 daily briefing and the September 7, 2026 daily briefing for the broader context on the CISA 2015 stopgap and the FTC enforcement pace.

Sources for this update: Federal News Network, Justin Doubleday. "CR extends cyber info sharing law through December." September 1, 2026; Federal Trade Commission. Press Releases. August 17, 2026 onward.

References

  1. The Times of India. "US government shutdown: One of the biggest American cybersecurity law expires leaving industry anxious and worried."
  2. World Economic Forum. "A key US cyber law has expired amid a government shutdown."
  3. The Times of India. "US government shutdown: FTC has important notice for Americans on fraud, says they cannot..."
  4. Federal Trade Commission. "Status of FTC Online Services During 2025 Lapse in Funding."
  5. Cybersecurity Dive. "Government funding bill temporarily revives cybersecurity information-sharing law through Jan. 30, 2026."
  6. MS Law Group. "FTC's National Do Not Call Registry Back Online Following Government Shutdown."
  7. Federal Trade Commission. "FTC Reopens and Sets Aside Rytr Final Order in Response to the Trump Administration's AI Action Plan."
  8. Hunton Andrews Kurth. "Congress Extends Cybersecurity Information Sharing Act of 2015 Through September 2026."
  9. Federal News Network. "Congress extends CISA 2015, but path to long-term reauthorization remains murky."
  10. Wikipedia. "2026 United States federal government shutdowns." [tertiary, unlinked]
  11. Nextgov. "CISA resources 'more limited than I would like' amid shutdown, top official says."
  12. Federal News Network, Justin Doubleday. "CR extends cyber info sharing law through December." September 1, 2026
  13. Federal Trade Commission. Press Releases, August 17, 2026 onward (Cox Media Group $930,000 "Active Listening" order, Manchester City Nissan $4M deceptive-fees settlement, Doxo $2.1M search-ads settlement, Grubhub $23.8M in refunds, Amazon + 22 state AGs price-inflation suit, Nuvei $4.85M payment-processor settlement, FY 2027 National Do Not Call Registry fees)