<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
    <channel>
      <title>Peter&#x27;s Path - Privacy</title>
      <link>https://peterspath.net</link>
      <description>Peter&#x27;s Path is my personal endeavour to live a life of purpose through hiking, reading, and embracing the beauty of nature, faith, and ideas.</description>
      <generator>Zola</generator>
      <language>en</language>
      <atom:link href="https://peterspath.net/categories/privacy/rss.xml" rel="self" type="application/rss+xml"/>
      <lastBuildDate>Thu, 04 Jun 2026 15:00:00 +0000</lastBuildDate>
      <item>
          <title>Privacy Roundup #0238 • May 2026</title>
          <pubDate>Thu, 04 Jun 2026 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0238/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0238/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0238/">&lt;!-- Covered month: May 2026 (2026-05-01 to 2026-05-31) --&gt;
&lt;p&gt;May 2026 brought a wave of mass data breaches, fresh fights over encryption backdoors and age checks, and a landmark order against a location data broker.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-ftc-bans-kochava-from-selling-sensitive-location-data&quot;&gt;1. FTC bans Kochava from selling sensitive location data&lt;&#x2F;h3&gt;
&lt;p&gt;The Federal Trade Commission ordered the data broker Kochava to stop selling location data that can trace people to clinics, places of worship and shelters. The firm must also delete the records it gathered without clear consent.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2026&#x2F;05&#x2F;ftc-ban-kochava-subsidiary-selling-sensitive-location-data-settle-charges-they-sold-location-data&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-nyc-health-and-hospitals-breach-exposes-1-8-million-patients&quot;&gt;2. NYC Health and Hospitals breach exposes 1.8 million patients&lt;&#x2F;h3&gt;
&lt;p&gt;A third party vendor was breached, exposing medical records and biometric scans, including fingerprints, for at least 1.8 million people. It is one of the largest health breaches of the year so far.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2026&#x2F;05&#x2F;18&#x2F;nyc-health-and-hospitals-says-hackers-stole-medical-data-and-fingerprints-during-breach-affecting-at-least-1-8-million-people&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-hotel-check-in-system-left-a-million-passports-open-to-anyone&quot;&gt;3. Hotel check-in system left a million passports open to anyone&lt;&#x2F;h3&gt;
&lt;p&gt;An unsecured cloud storage bucket run by the Japanese hotel system Tabiq exposed around a million passports and driving licences. Anyone who found the link could read the documents without any password.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2026&#x2F;05&#x2F;15&#x2F;a-hotel-check-in-system-left-a-million-passports-and-drivers-licenses-open-for-anyone-to-see&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-charter-confirms-breach-after-shinyhunters-extortion-threat&quot;&gt;4. Charter confirms breach after ShinyHunters extortion threat&lt;&#x2F;h3&gt;
&lt;p&gt;The cable provider Charter Communications confirmed a breach after the ShinyHunters gang claimed to hold more than 40 million records. The stolen data included customer names, addresses, phone numbers and account details.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;charter-confirms-data-breach-after-shinyhunters-extortion-threat&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-carnival-cruise-breach-affects-nearly-6-million-people&quot;&gt;5. Carnival Cruise breach affects nearly 6 million people&lt;&#x2F;h3&gt;
&lt;p&gt;Carnival Cruise confirmed a breach that exposed the names, birthdays and email addresses of almost 6 million customers. Loyalty programme details were also taken in the incident.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;carnival-cruise-confirms-data-breach-affecting-nearly-6-million-people&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-instructure-confirms-canvas-breach-claimed-by-shinyhunters&quot;&gt;6. Instructure confirms Canvas breach claimed by ShinyHunters&lt;&#x2F;h3&gt;
&lt;p&gt;Instructure confirmed a breach of its Canvas learning platform after ShinyHunters claimed to have stolen vast numbers of records. The data spanned thousands of schools and other education providers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;instructure-confirms-data-breach-shinyhunters-claims-attack&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-age-verification-is-a-privacy-nightmare-eff-warns&quot;&gt;7. Age verification is a privacy nightmare, EFF warns&lt;&#x2F;h3&gt;
&lt;p&gt;The Electronic Frontier Foundation argued that online age checks force everyone to hand sensitive identity data to third parties. Storing that data in one place creates a tempting target for thieves and a tool for surveillance.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;05&#x2F;age-verification-privacy-nightmare&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-canada-s-bill-c-22-revives-the-encryption-backdoor-fight&quot;&gt;8. Canada&#x27;s Bill C-22 revives the encryption backdoor fight&lt;&#x2F;h3&gt;
&lt;p&gt;Canada brought back a surveillance bill that would let the government demand backdoors into encrypted services and a year of retained metadata. Both Apple and Meta have come out against the plan.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;05&#x2F;canadas-bill-c-22-repackaged-version-last-years-surveillance-nightmare&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-the-secure-data-act-is-not-serious-privacy-law-says-eff&quot;&gt;9. The SECURE Data Act is not serious privacy law, says EFF&lt;&#x2F;h3&gt;
&lt;p&gt;The EFF criticised the SECURE Data Act for wiping out stronger state privacy laws while offering little in return. The bill has no private right of action and no real curb on behavioural advertising.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;05&#x2F;secure-data-act-not-serious-piece-privacy-legislation&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-uk-visa-portal-spilled-applicants-passports-and-selfies-online&quot;&gt;10. UK visa portal spilled applicants&#x27; passports and selfies online&lt;&#x2F;h3&gt;
&lt;p&gt;A UK visa portal exposed at least 100,000 documents, including passports and applicant photos. The leak remained open when the report was published.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2026&#x2F;05&#x2F;26&#x2F;uk-visa-portal-spilled-thousands-of-applicants-passports-and-selfies-online-and-hasnt-fixed-the-leak&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-pay-tel-prison-phone-service-exposed-300-000-callers-licences&quot;&gt;11. Pay Tel prison phone service exposed 300,000 callers&#x27; licences&lt;&#x2F;h3&gt;
&lt;p&gt;A misconfigured cloud server at the prison phone firm Pay Tel exposed more than 300,000 driving licences. The same lapse also laid bare recordings of inmate communications.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2026&#x2F;05&#x2F;28&#x2F;a-security-lapse-at-prison-payphone-service-pay-tel-publicly-exposed-over-300000-callers-drivers-licenses&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-trump-mobile-confirms-it-exposed-customer-data&quot;&gt;12. Trump Mobile confirms it exposed customer data&lt;&#x2F;h3&gt;
&lt;p&gt;Trump Mobile admitted it had exposed customer details, including phone numbers and home addresses, through a third party platform. The company had stayed quiet about earlier reports of the leak.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2026&#x2F;05&#x2F;22&#x2F;trump-mobile-confirms-it-exposed-customers-personal-data-including-phone-numbers-and-home-addresses&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-7-eleven-breach-exposes-data-on-185-000-people&quot;&gt;13. 7-Eleven breach exposes data on 185,000 people&lt;&#x2F;h3&gt;
&lt;p&gt;7-Eleven confirmed that the ShinyHunters gang stole personal data on about 185,000 customers. The records included names, birthdays and contact details.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;7-eleven-data-breach-exposes-personal-information-of-185-000-people&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-vimeo-breach-exposes-data-on-119-000-users&quot;&gt;14. Vimeo breach exposes data on 119,000 users&lt;&#x2F;h3&gt;
&lt;p&gt;Vimeo disclosed that ShinyHunters had taken personal information belonging to more than 119,000 people. The company said login credentials and financial details were not affected.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;vimeo-data-breach-exposes-personal-information-of-119-000-people&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-trellix-discloses-breach-after-source-code-repository-hack&quot;&gt;15. Trellix discloses breach after source code repository hack&lt;&#x2F;h3&gt;
&lt;p&gt;The security firm Trellix said attackers reached part of its source code repository. The company could not yet confirm whether customer data had been taken.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;trellix-discloses-data-breach-after-source-code-repository-hack&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-hundreds-of-hotels-caught-up-in-booking-scams&quot;&gt;16. Hundreds of hotels caught up in booking scams&lt;&#x2F;h3&gt;
&lt;p&gt;WIRED reported that guest data from more than 350 hotels around the world may have been accessed. Criminals used the stolen details to run convincing booking scams against travellers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.wired.com&#x2F;story&#x2F;hundreds-of-hotels-caught-up-in-vacation-booking-scams&#x2F;&quot;&gt;www.wired.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-microsoft-shared-dutch-officials-emails-without-gdpr-redactions&quot;&gt;17. Microsoft shared Dutch officials&#x27; emails without GDPR redactions&lt;&#x2F;h3&gt;
&lt;p&gt;Reports said Microsoft passed on Dutch civil servants&#x27; emails without the redactions that GDPR requires. The case renewed concern about how cloud providers handle European public sector data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;cybernews.com&#x2F;tech&#x2F;microsoft-dutch-data&#x2F;&quot;&gt;cybernews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-your-privacy-should-not-be-a-corporate-decision-argues-eff&quot;&gt;18. Your privacy should not be a corporate decision, argues EFF&lt;&#x2F;h3&gt;
&lt;p&gt;The EFF warned that firms such as Meta, Google and Palantir keep treating user privacy as a business choice rather than a right. It pointed to face recognition plans and broken promises about disclosing government requests.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;05&#x2F;your-privacy-shouldnt-be-corporate-decision&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-london-police-deploy-live-facial-recognition-at-a-protest-for-the-first-time&quot;&gt;19. London police deploy live facial recognition at a protest for the first time&lt;&#x2F;h3&gt;
&lt;p&gt;The Metropolitan Police scanned the faces of people near a large central London march against a watch list, the first such use at a protest. The Biometrics and Surveillance Camera Commissioner warned that forces could face court action over the practice.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.biometricupdate.com&#x2F;202605&#x2F;uk-watchdog-warns-of-legal-risks-as-london-police-deploy-lfr-at-protest&quot;&gt;www.biometricupdate.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-we-must-not-normalise-digital-surveillance-abuses-says-eff&quot;&gt;20. We must not normalise digital surveillance abuses, says EFF&lt;&#x2F;h3&gt;
&lt;p&gt;The EFF published a guide on concrete steps people can take to resist creeping digital surveillance. It urged the public not to accept invasive tools as a normal part of daily life.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;05&#x2F;we-must-not-normalize-digital-surveillance-abuses-effs-new-guide-underlines&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0237 • April 2026</title>
          <pubDate>Thu, 07 May 2026 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0237/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0237/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0237/">&lt;!-- Covered month: April 2026 (2026-04-01 to 2026-04-30) --&gt;
&lt;p&gt;April brought a hacked FBI wiretap system, fresh fights over government location buying, and a wave of breaches and fines across Europe and the United States.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-suspected-chinese-breach-of-fbi-system-exposed-surveillance-targets-phone-numbers&quot;&gt;1. Suspected Chinese breach of FBI system exposed surveillance targets&#x27; phone numbers&lt;&#x2F;h3&gt;
&lt;p&gt;The FBI told Congress that intruders reached an unclassified system holding pen register and wiretap data. The bureau called it a major incident and pointed to a China linked group.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.nextgov.com&#x2F;cybersecurity&#x2F;2026&#x2F;04&#x2F;suspected-chinese-breach-fbi-system-exposed-surveillance-targets-phone-numbers&#x2F;412612&#x2F;&quot;&gt;www.nextgov.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-france-confirms-data-breach-at-government-agency-that-manages-citizens-ids&quot;&gt;2. France confirms data breach at government agency that manages citizens&#x27; IDs&lt;&#x2F;h3&gt;
&lt;p&gt;France confirmed that hackers broke into ANTS, the agency that issues passports, ID cards and driving licences. A criminal offered millions of records, including names, dates of birth and contact details, for sale.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2026&#x2F;04&#x2F;22&#x2F;france-confirms-data-breach-at-government-agency-that-manages-citizens-ids&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-mercor-a-10-billion-ai-startup-confirms-it-was-the-victim-of-a-major-cybersecurity-breach&quot;&gt;3. Mercor, a $10 billion AI startup, confirms it was the victim of a major cybersecurity breach&lt;&#x2F;h3&gt;
&lt;p&gt;The AI data firm Mercor said attackers stole information after they poisoned the open source LiteLLM library. Criminals claimed terabytes of source code and internal records, and some contractors later sued over their exposed data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;fortune.com&#x2F;2026&#x2F;04&#x2F;02&#x2F;mercor-ai-startup-security-incident-10-billion&#x2F;&quot;&gt;fortune.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-hackers-steal-and-leak-sensitive-lapd-police-documents&quot;&gt;4. Hackers steal and leak sensitive LAPD police documents&lt;&#x2F;h3&gt;
&lt;p&gt;A group broke into a file sharing tool at the Los Angeles City Attorney&#x27;s Office and took hundreds of thousands of files. The leak held witness names, medical details and unredacted complaints tied to police cases.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2026&#x2F;04&#x2F;08&#x2F;hackers-steal-and-leak-sensitive-lapd-police-documents&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-new-mexico-s-meta-ruling-and-encryption&quot;&gt;5. New Mexico&#x27;s Meta Ruling and Encryption&lt;&#x2F;h3&gt;
&lt;p&gt;Bruce Schneier warned that a New Mexico ruling against Meta treated end to end encryption as a liability. He argued the case could push platforms toward more monitoring and weaker protection for everyone.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2026&#x2F;04&#x2F;new-mexicos-meta-ruling-and-encryption.html&quot;&gt;www.schneier.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-fisa-section-702-congress-passes-short-term-surveillance-program-extension-just-before-deadline&quot;&gt;6. FISA Section 702: Congress passes short-term surveillance program extension just before deadline&lt;&#x2F;h3&gt;
&lt;p&gt;With the spying power about to lapse, Congress passed short patches to keep Section 702 alive. Lawmakers extended the authority without adding a warrant rule for searches of Americans&#x27; data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cnbc.com&#x2F;2026&#x2F;04&#x2F;30&#x2F;fisa-section-702-congress-extension.html&quot;&gt;www.cnbc.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-congress-must-reject-new-insufficient-702-reauthorization-bill&quot;&gt;7. Congress Must Reject New Insufficient 702 Reauthorization Bill&lt;&#x2F;h3&gt;
&lt;p&gt;The Electronic Frontier Foundation urged Congress to reject a reauthorisation bill that lacked a real warrant requirement. It said the measure left the FBI free to search Americans&#x27; messages without a judge.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;04&#x2F;congress-must-reject-new-insufficient-702-reauthorization-bill&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-dhs-is-buying-access-to-real-time-location-data-the-latest-expansion-of-its-surveillance-technology&quot;&gt;8. DHS is buying access to real-time location data, the latest expansion of its surveillance technology&lt;&#x2F;h3&gt;
&lt;p&gt;The Department of Homeland Security signed a fresh contract with Penlink for a tool that tracks phones in real time. Civil liberties groups said the deal let agents follow people without a warrant.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;prismreports.org&#x2F;2026&#x2F;04&#x2F;29&#x2F;dhs-surveillance-location-data-penlink-plx&#x2F;&quot;&gt;prismreports.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-open-records-laws-reveal-alprs-sprawling-surveillance-now-states-want-to-block-what-the-public-sees&quot;&gt;9. Open Records Laws Reveal ALPRs&#x27; Sprawling Surveillance. Now States Want to Block What the Public Sees&lt;&#x2F;h3&gt;
&lt;p&gt;Several states moved to exempt licence plate reader data from public records laws. The EFF warned that the change would hide how police use and share this mass surveillance.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;04&#x2F;open-records-laws-reveal-alprs-sprawling-surveillance-now-states-want-block-what&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-how-push-notifications-can-betray-your-privacy-and-what-to-do-about-it&quot;&gt;10. How Push Notifications Can Betray Your Privacy (and What to Do About It)&lt;&#x2F;h3&gt;
&lt;p&gt;The EFF explained how push notifications leak data to Apple, Google and, through them, to police. It set out practical steps people can take to limit what their phones reveal.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;04&#x2F;how-push-notifications-can-betray-your-privacy-and-what-do-about-it&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-apple-rolls-out-ios-26-4-2-to-fix-a-flaw-that-allowed-the-fbi-to-access-push-notifications&quot;&gt;11. Apple rolls out iOS 26.4.2 to fix a flaw that allowed the FBI to access push notifications&lt;&#x2F;h3&gt;
&lt;p&gt;Apple shipped an update after reports that deleted notifications stayed in a database police could read. The fix stops the phone from keeping notifications that the user has cleared.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.engadget.com&#x2F;cybersecurity&#x2F;apple-rolls-out-ios-2642-to-fix-a-flaw-that-allowed-the-fbi-to-access-push-notifications-201153603.html&quot;&gt;www.engadget.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-mexican-surveillance-company&quot;&gt;12. Mexican Surveillance Company&lt;&#x2F;h3&gt;
&lt;p&gt;Schneier flagged the spread of Grupo Seguritech, a Mexican surveillance firm now moving into the United States. He used the case to warn that each gain in monitoring power costs civil liberties.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2026&#x2F;04&#x2F;mexican-surveillance-company.html&quot;&gt;www.schneier.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-sen-sanders-talks-to-claude-about-ai-and-privacy&quot;&gt;13. Sen. Sanders Talks to Claude About AI and Privacy&lt;&#x2F;h3&gt;
&lt;p&gt;Schneier highlighted a video of Senator Bernie Sanders questioning an AI assistant about privacy and big tech. Readers debated whether the model gave honest answers or simply told the senator what he wanted to hear.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2026&#x2F;04&#x2F;sen-sanders-talks-to-claude-about-ai-and-privacy.html&quot;&gt;www.schneier.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-supreme-court-finds-for-tiktok-in-dispute-with-data-protection-commission&quot;&gt;14. Supreme Court finds for TikTok in dispute with Data Protection Commission&lt;&#x2F;h3&gt;
&lt;p&gt;Ireland&#x27;s Supreme Court backed TikTok in a procedural fight with the data regulator. A stay on the 530 million euro fine and the order to halt China transfers stays in place while the case continues.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.irishtimes.com&#x2F;crime-law&#x2F;courts&#x2F;2026&#x2F;04&#x2F;30&#x2F;supreme-court-finds-for-tiktok-in-dispute-with-data-protection-commission&#x2F;&quot;&gt;www.irishtimes.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-italy-s-data-protection-regulator-fined-intesa-sanpaolo-eur31-8-million-over-insider-data-breach&quot;&gt;15. Italy&#x27;s data protection regulator fined Intesa Sanpaolo €31.8 million over insider data breach&lt;&#x2F;h3&gt;
&lt;p&gt;Italy&#x27;s Garante fined the bank Intesa Sanpaolo after one worker snooped on thousands of customer accounts. The regulator said weak controls let the abuse run for two years before anyone noticed.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;databreaches.net&#x2F;2026&#x2F;04&#x2F;03&#x2F;italys-data-protection-regulator-fined-intesa-sanpaolo-e31-8-million-over-insider-data-breach&#x2F;&quot;&gt;databreaches.net&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-russia-hacked-routers-to-steal-microsoft-office-tokens&quot;&gt;16. Russia Hacked Routers to Steal Microsoft Office Tokens&lt;&#x2F;h3&gt;
&lt;p&gt;Krebs reported a Russian campaign that compromised home and office routers to grab Microsoft sign in tokens. The stolen tokens let attackers read email and files without a password.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2026&#x2F;04&#x2F;russia-hacked-routers-to-steal-microsoft-office-tokens&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab&quot;&gt;17. Germany Doxes &quot;UNKN,&quot; Head of RU Ransomware Gangs REvil, GandCrab&lt;&#x2F;h3&gt;
&lt;p&gt;German investigators named the alleged leader of the REvil and GandCrab ransomware crews. The gangs stole and leaked vast amounts of personal data during years of attacks.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2026&#x2F;04&#x2F;germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-scattered-spider-member-tylerb-pleads-guilty&quot;&gt;18. &#x27;Scattered Spider&#x27; Member &#x27;Tylerb&#x27; Pleads Guilty&lt;&#x2F;h3&gt;
&lt;p&gt;A member of the Scattered Spider crew pleaded guilty over a string of intrusions and extortion plots. The group used phone scams and SIM swaps to break into firms and steal sensitive records.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2026&#x2F;04&#x2F;scattered-spider-member-tylerb-pleads-guilty&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-committees-introduce-pair-of-privacy-bills-to-establish-comprehensive-data-protections-for-all-americans&quot;&gt;19. Committees Introduce Pair of Privacy Bills to Establish Comprehensive Data Protections for All Americans&lt;&#x2F;h3&gt;
&lt;p&gt;House Republicans introduced the SECURE Data Act to set a single national privacy standard. The bill would give people rights to access and delete data and to opt out of targeted advertising.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;energycommerce.house.gov&#x2F;posts&#x2F;committees-on-energy-and-commerce-and-financial-services-introduce-pair-of-privacy-bills-to-establish-comprehensive-data-protections-for-all-americans&quot;&gt;energycommerce.house.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-why-america-s-biggest-companies-gave-up-the-fight-against-utah-s-app-store-law-protecting-kids&quot;&gt;20. Why America&#x27;s biggest companies gave up the fight against Utah&#x27;s app store law protecting kids&lt;&#x2F;h3&gt;
&lt;p&gt;A trade group for Apple, Google, Meta and Amazon dropped its lawsuit against Utah&#x27;s age verification law for app stores. The measure forces stores to check ages and seek parental consent before minors can download apps, and privacy groups warn that such checks push everyone towards handing over identity data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.deseret.com&#x2F;politics&#x2F;2026&#x2F;04&#x2F;27&#x2F;apple-meta-google-drop-lawsuit-against-utah-app-store-verification-act-after-winning-lawsuit-against-similar-law-in-texas&#x2F;&quot;&gt;www.deseret.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0236 • March 2026</title>
          <pubDate>Thu, 02 Apr 2026 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0236/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0236/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0236/">&lt;!-- Covered month: March 2026 (2026-03-01 to 2026-03-31) --&gt;
&lt;p&gt;March brought huge healthcare and supply-chain breaches, a wave of GDPR court rulings, and fresh proof that the government buys location data from the advertising industry.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-french-health-software-firm-cegedim-leaks-15-8-million-patient-records&quot;&gt;1. French health software firm Cegedim leaks 15.8 million patient records&lt;&#x2F;h3&gt;
&lt;p&gt;Attackers stole personal details on up to 15.8 million French patients from Cegedim Santé, one of the largest healthcare leaks in European history. The data included names, contact details and sensitive medical notes for some patients, and the regulator CNIL was notified.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2026&#x2F;03&#x2F;03&#x2F;french_medical_leak&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-fbi-confirms-it-buys-americans-location-data-to-track-citizens&quot;&gt;2. FBI confirms it buys Americans&#x27; location data to track citizens&lt;&#x2F;h3&gt;
&lt;p&gt;Under questioning from Senator Ron Wyden, FBI Director Kash Patel told the Senate that the bureau purchases commercially available location data. It was the first time since 2023 that the FBI admitted buying data that brokers harvest from ordinary phone apps.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2026&#x2F;03&#x2F;18&#x2F;fbi-is-buying-location-data-to-track-us-citizens-kash-patel-wyden&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-uk-companies-house-confirms-flaw-exposed-five-million-firms-data&quot;&gt;3. UK Companies House confirms flaw exposed five million firms&#x27; data&lt;&#x2F;h3&gt;
&lt;p&gt;A bug in the WebFiling service let any logged-in user view the dashboard of any of the five million registered companies, exposing directors&#x27; home addresses and dates of birth. The flaw had been live since an October 2025 update, and the service was taken offline until a fix was confirmed.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;uks-companies-house-confirms-security-flaw-exposed-business-data&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-luxembourg-court-annuls-amazon-s-eur746-million-gdpr-fine&quot;&gt;4. Luxembourg court annuls Amazon&#x27;s €746 million GDPR fine&lt;&#x2F;h3&gt;
&lt;p&gt;Luxembourg&#x27;s Administrative Court threw out the record €746 million fine against Amazon because the regulator skipped two legally required steps. The court upheld most of the underlying violations and sent the case back to the watchdog to begin those analyses again.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.mlex.com&#x2F;mlex&#x2F;articles&#x2F;2452693&#x2F;amazon-sees-luxembourg-appeals-court-annul-746-million-gdpr-fine&quot;&gt;www.mlex.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-france-s-top-court-upholds-criteo-s-eur40-million-gdpr-fine&quot;&gt;5. France&#x27;s top court upholds Criteo&#x27;s €40 million GDPR fine&lt;&#x2F;h3&gt;
&lt;p&gt;The Conseil d&#x27;État rejected the ad-tech firm Criteo&#x27;s appeal and confirmed the full €40 million penalty from the CNIL. The regulator found that Criteo could not prove it had valid consent for its tracking cookies and failed to honour erasure requests.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;noyb.eu&#x2F;en&#x2F;conseil-detat-upholds-criteos-eu40m-gdpr-fine&quot;&gt;noyb.eu&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-cbp-bought-phone-location-data-from-the-online-advertising-system&quot;&gt;6. CBP bought phone location data from the online advertising system&lt;&#x2F;h3&gt;
&lt;p&gt;An internal document obtained by 404 Media shows Customs and Border Protection tracked phones using location data drawn from real-time advertising bids. It is the first time the agency has admitted that the data it buys comes from the same system that serves ordinary online adverts.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.404media.co&#x2F;cbp-tapped-into-the-online-advertising-ecosystem-to-track-peoples-movements&#x2F;&quot;&gt;www.404media.co&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-proton-mail-payment-data-helped-the-fbi-unmask-a-protester&quot;&gt;7. Proton Mail payment data helped the FBI unmask a protester&lt;&#x2F;h3&gt;
&lt;p&gt;Court records show Proton Mail handed Swiss authorities payment data tied to a Stop Cop City email account, which was then shared with the FBI. The email itself stayed encrypted, but the credit card identifier was enough to trace the account holder.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.404media.co&#x2F;proton-mail-helped-fbi-unmask-anonymous-stop-cop-city-protestor&#x2F;&quot;&gt;www.404media.co&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-ftc-acts-against-match-and-okcupid-over-secret-data-sharing&quot;&gt;8. FTC acts against Match and OkCupid over secret data sharing&lt;&#x2F;h3&gt;
&lt;p&gt;The Federal Trade Commission said OkCupid quietly gave nearly three million user photos and location data to an unrelated startup in which its founders had invested. The settlement bars Match and OkCupid from misrepresenting their privacy promises in future.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2026&#x2F;03&#x2F;ftc-takes-action-against-match-okcupid-deceiving-users-sharing-personal-data-third-party&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-eff-weighs-the-safe-act-as-section-702-nears-its-deadline&quot;&gt;9. EFF weighs the SAFE Act as Section 702 nears its deadline&lt;&#x2F;h3&gt;
&lt;p&gt;With the warrantless surveillance power Section 702 due to expire, the EFF examined the bipartisan SAFE Act and called it an imperfect vehicle for real reform. The bill would require a warrant before the FBI reads Americans&#x27; messages, but the group warned it still leaves gaps.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;03&#x2F;safe-act-imperfect-vehicle-real-section-702-reform&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-anthropic-and-the-pentagon-clash-over-surveillance-use&quot;&gt;10. Anthropic and the Pentagon clash over surveillance use&lt;&#x2F;h3&gt;
&lt;p&gt;The military ended a contract after Anthropic refused to let its technology be used for mass surveillance of people in the United States. The EFF welcomed the stance but argued that privacy should rest on law, not on the goodwill of a few company bosses.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;03&#x2F;anthropic-dod-conflict-privacy-protections-shouldnt-depend-decisions-few-powerful&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-ameriprise-financial-breach-exposes-data-on-48-000-customers&quot;&gt;11. Ameriprise Financial breach exposes data on 48,000 customers&lt;&#x2F;h3&gt;
&lt;p&gt;The wealth manager disclosed a breach that exposed names, addresses, account numbers, dates of birth and Social Security numbers for about 48,000 customers. The firm detected the intrusion in March and offered affected people credit and identity monitoring.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;cyberguy.com&#x2F;security&#x2F;ameriprise-data-breach-hits-48000-customers&#x2F;&quot;&gt;cyberguy.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-hackers-expose-millions-of-anonymous-crime-and-school-tips&quot;&gt;12. Hackers expose millions of anonymous crime and school tips&lt;&#x2F;h3&gt;
&lt;p&gt;A hacker claims to have taken more than eight million records from P3 Global Intel, the platform behind many Crime Stoppers programmes and thousands of US schools. The leaked files held names, addresses and other details, and the data was reportedly stored in plain text despite claims of encryption.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.malwarebytes.com&#x2F;blog&#x2F;news&#x2F;2026&#x2F;03&#x2F;hackers-claim-to-have-accessed-data-tied-to-millions-of-crime-tipsters&quot;&gt;www.malwarebytes.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-foster-city-declares-emergency-after-ransomware-attack&quot;&gt;13. Foster City declares emergency after ransomware attack&lt;&#x2F;h3&gt;
&lt;p&gt;Ransomware knocked out nearly all municipal services in Foster City, California, and the council declared a local state of emergency. Emergency lines stayed open, but the attack showed how small towns holding resident data lack the budgets to defend it.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cbsnews.com&#x2F;sanfrancisco&#x2F;news&#x2F;foster-city-california-ransomware-cyberattack-state-of-emergency&#x2F;&quot;&gt;www.cbsnews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-judge-rules-flock-camera-images-are-public-records&quot;&gt;14. Judge rules Flock camera images are public records&lt;&#x2F;h3&gt;
&lt;p&gt;A Washington court held that images from Flock automatic licence plate readers are public records that anyone can request. The ruling found the cameras serve a government purpose and are paid for with public money, prompting some cities to pause their systems.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.404media.co&#x2F;judge-rules-flock-surveillance-images-are-public-records-that-can-be-requested-by-anyone&#x2F;&quot;&gt;www.404media.co&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-marquis-ransomware-breach-hits-more-than-672-000-people&quot;&gt;15. Marquis ransomware breach hits more than 672,000 people&lt;&#x2F;h3&gt;
&lt;p&gt;The Texas fintech firm Marquis told regulators that a 2025 ransomware attack stole personal and financial data on over 672,000 people. The stolen files included bank account numbers, card details and Social Security numbers, and the attack disrupted dozens of banks.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2026&#x2F;03&#x2F;18&#x2F;marquis-says-over-672000-people-had-personal-and-financial-data-stolen-in-ransomware-attack&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-telus-digital-confirms-breach-after-claim-of-one-petabyte-theft&quot;&gt;16. Telus Digital confirms breach after claim of one petabyte theft&lt;&#x2F;h3&gt;
&lt;p&gt;The outsourcing giant Telus Digital confirmed a breach after the ShinyHunters group claimed to have taken close to one petabyte of data. The stolen material reportedly spans customer records, voice recordings and call data across many of the firm&#x27;s clients.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;telus-digital-confirms-breach-after-hacker-claims-1-petabyte-data-theft&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-european-commission-confirms-data-breach-after-europa-eu-hack&quot;&gt;17. European Commission confirms data breach after Europa.eu hack&lt;&#x2F;h3&gt;
&lt;p&gt;The European Commission confirmed that data had been taken from its Europa.eu platform after the ShinyHunters group claimed to have stolen more than 350 gigabytes from a cloud account. The Commission said it was notifying the Union entities that might be affected, while insisting its internal systems stayed intact.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;european-commission-confirms-data-breach-after-europaeu-hack&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-jury-finds-meta-and-google-negligent-over-app-design&quot;&gt;18. Jury finds Meta and Google negligent over app design&lt;&#x2F;h3&gt;
&lt;p&gt;A California jury found Meta and Google negligent in the design of their apps and awarded a young plaintiff six million dollars in damages. The verdict was the first to hold the companies to account for the structure of their products rather than for hosted content.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.npr.org&#x2F;2026&#x2F;03&#x2F;25&#x2F;nx-s1-5746125&#x2F;meta-youtube-social-media-trial-verdict&quot;&gt;www.npr.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-meta-ordered-to-pay-375-million-in-new-mexico-child-safety-case&quot;&gt;19. Meta ordered to pay $375 million in New Mexico child-safety case&lt;&#x2F;h3&gt;
&lt;p&gt;A separate jury found Meta liable for failing to protect children and for misleading users about safety, ordering it to pay 375 million dollars. The two verdicts together may shape thousands of pending lawsuits against social media firms.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.nbcnews.com&#x2F;tech&#x2F;tech-news&#x2F;verdict-reached-landmark-social-media-addiction-trial-rcna263421&quot;&gt;www.nbcnews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-uk-regulators-promise-action-on-weak-age-checks&quot;&gt;20. UK regulators promise action on weak age checks&lt;&#x2F;h3&gt;
&lt;p&gt;The ICO and Ofcom said together that they would act against online services that fail to enforce minimum ages with proper age assurance. Critics warned that the checks, which can demand ID or biometric data, raise their own privacy risks if the data is exposed.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.twobirds.com&#x2F;en&#x2F;insights&#x2F;2026&#x2F;uk&#x2F;uk-childrens-safety-the-age-gates-are-coming--why-all-internet-services-should-be-acting-now&quot;&gt;www.twobirds.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0235 • February 2026</title>
          <pubDate>Thu, 05 Mar 2026 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0235/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0235/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0235/">&lt;!-- Covered month: February 2026 (2026-02-01 to 2026-02-28) --&gt;
&lt;p&gt;February brought a wave of vishing-driven breaches, fresh fights over police cameras and ICE surveillance, and regulators leaning on data brokers.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-hackers-publish-data-stolen-from-harvard-and-upenn-breaches&quot;&gt;1. Hackers publish data stolen from Harvard and UPenn breaches&lt;&#x2F;h3&gt;
&lt;p&gt;The ShinyHunters group leaked about 2.2 million records taken from Harvard and the University of Pennsylvania after both refused to pay a ransom. The files held alumni names, addresses, phone numbers and donation details drawn from fundraising systems.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2026&#x2F;02&#x2F;04&#x2F;hackers-publish-personal-information-stolen-during-harvard-upenn-data-breaches&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-breach-at-french-bank-registry-exposes-1-2-million-accounts&quot;&gt;2. Breach at French bank registry exposes 1.2 million accounts&lt;&#x2F;h3&gt;
&lt;p&gt;An attacker used a civil servant&#x27;s stolen credentials to reach FICOBA, the national registry of every bank account opened in France. The exposed data included account numbers, holder names, addresses and, in some cases, tax identifiers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;data-breach-at-french-bank-registry-impacts-12-million-accounts&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-odido-breach-exposes-6-2-million-dutch-customers&quot;&gt;3. Odido breach exposes 6.2 million Dutch customers&lt;&#x2F;h3&gt;
&lt;p&gt;The Dutch telecommunications firm Odido confirmed one of the largest European telecom breaches of early 2026. Attackers reached personal details of about 6.2 million customers after the firm detected the intrusion in early February.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;odido-data-breach-exposes-personal-info-of-62-million-customers&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-fintech-firm-figure-breach-affects-nearly-1-million-accounts&quot;&gt;4. Fintech firm Figure breach affects nearly 1 million accounts&lt;&#x2F;h3&gt;
&lt;p&gt;Blockchain lender Figure Technology Solutions said an employee fell for a social engineering attack that exposed roughly 967,000 user records. The stolen files held names, dates of birth, email addresses, postal addresses and phone numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;data-breach-at-fintech-firm-figure-affects-nearly-1-million-accounts&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-ad-tech-firm-optimizely-confirms-breach-after-vishing-attack&quot;&gt;5. Ad tech firm Optimizely confirms breach after vishing attack&lt;&#x2F;h3&gt;
&lt;p&gt;Optimizely said attackers reached internal business systems through a voice phishing call on 11 February. The firm reported no evidence that customer or personal data was taken, but it warned the roughly 10,000 companies that use its tools.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;ad-tech-firm-optimizely-confirms-data-breach-after-vishing-attack&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-coinbase-confirms-insider-breach-linked-to-leaked-support-tool-screenshots&quot;&gt;6. Coinbase confirms insider breach linked to leaked support tool screenshots&lt;&#x2F;h3&gt;
&lt;p&gt;Coinbase said a contractor had improperly reached the records of about 30 customers after screenshots of an internal support tool surfaced online. The exposed details included names, dates of birth, phone numbers, identity verification data, wallet balances and transaction histories.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;coinbase-confirms-insider-breach-linked-to-leaked-support-tool-screenshots&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-ico-fines-reddit-14-47-million-pounds-for-children-s-privacy-failures&quot;&gt;7. ICO fines Reddit 14.47 million pounds for children&#x27;s privacy failures&lt;&#x2F;h3&gt;
&lt;p&gt;The Information Commissioner&#x27;s Office fined Reddit 14.47 million pounds for processing the data of children under 13 without any effective age checks. The regulator warned that relying on users to declare their own age is not enough to protect young people.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;ico.org.uk&#x2F;about-the-ico&#x2F;media-centre&#x2F;news-and-blogs&#x2F;2026&#x2F;02&#x2F;reddit-issued-with-1447m-fine-for-children-s-privacy-failures&#x2F;&quot;&gt;ico.org.uk&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-ftc-reminds-data-brokers-of-their-duties-under-padfaa&quot;&gt;8. FTC reminds data brokers of their duties under PADFAA&lt;&#x2F;h3&gt;
&lt;p&gt;The Federal Trade Commission sent letters to 13 data brokers on 9 February warning them not to sell sensitive American data to foreign adversaries. The agency flagged firms that had offered information tied to members of the armed forces.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.alstonprivacy.com&#x2F;ftc-sends-letters-reminding-data-brokers-of-their-obligations-under-padfaa&#x2F;&quot;&gt;www.alstonprivacy.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-data-broker-kochava-reaches-privacy-deal-with-the-ftc&quot;&gt;9. Data broker Kochava reaches privacy deal with the FTC&lt;&#x2F;h3&gt;
&lt;p&gt;Kochava agreed to settle long-running FTC claims that it sold precise location data revealing visits to clinics and places of worship. The deal would force the firm to block raw location data linked to sensitive sites for at least two years.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.mediapost.com&#x2F;publications&#x2F;article&#x2F;413112&#x2F;data-broker-kochava-reaches-privacy-deal-with-ftc.html&quot;&gt;www.mediapost.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-tenth-circuit-limits-sweeping-searches-of-a-protester-s-devices&quot;&gt;10. Tenth Circuit limits sweeping searches of a protester&#x27;s devices&lt;&#x2F;h3&gt;
&lt;p&gt;The appeals court ruled that the Fourth Amendment does not support broad warrants to comb through a protester&#x27;s phone, photos and messages. The judges held that the particularity requirement applies with special force to digital devices.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;02&#x2F;victory-tenth-circuit-finds-fourth-amendment-doesnt-support-broad-search-0&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-california-reaches-record-2-75-million-dollar-privacy-settlement-with-disney&quot;&gt;11. California reaches record 2.75 million dollar privacy settlement with Disney&lt;&#x2F;h3&gt;
&lt;p&gt;California Attorney General Rob Bonta announced a 2.75 million dollar settlement with Disney over its failure to honour opt-out requests under the state privacy law. The company let users switch off data sharing on single devices only, while continuing to share information with third-party advertising firms across the rest of an account.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;oag.ca.gov&#x2F;news&#x2F;press-releases&#x2F;california-wont-let-it-go-attorney-general-bonta-announces-275-million&quot;&gt;oag.ca.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-eff-and-aclu-tell-big-tech-to-resist-lawless-dhs-subpoenas&quot;&gt;12. EFF and ACLU tell Big Tech to resist lawless DHS subpoenas&lt;&#x2F;h3&gt;
&lt;p&gt;The two groups urged Amazon, Apple, Google, Meta and others to demand court review before handing over user identities to the Department of Homeland Security. They warned that the agency had used subpoenas to unmask people who documented or criticised ICE.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;02&#x2F;open-letter-tech-companies-protect-your-users-lawless-dhs-subpoenas&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-dhs-watchdog-opens-inquiry-into-ice-surveillance-tools&quot;&gt;13. DHS watchdog opens inquiry into ICE surveillance tools&lt;&#x2F;h3&gt;
&lt;p&gt;The Inspector General began an audit of whether ICE&#x27;s surveillance and biometric programmes follow privacy law. Senators Mark Warner and Tim Kaine pushed for the review over contracts with firms such as Palantir, Clearview AI and Flock.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.404media.co&#x2F;inspector-general-investigating-whether-ices-surveillance-tech-breaks-the-law&#x2F;&quot;&gt;www.404media.co&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-eff-warns-that-free-surveillance-tech-carries-a-high-cost&quot;&gt;14. EFF warns that &quot;free&quot; surveillance tech carries a high cost&lt;&#x2F;h3&gt;
&lt;p&gt;The group described how vendors, federal agencies and wealthy donors give police free surveillance gear that bypasses local oversight. It argued that the hidden price is paid in lost privacy and weaker public control.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;02&#x2F;free-surveillance-tech-still-comes-high-and-dangerous-cost&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-eff-op-ed-urges-san-jose-to-drop-its-flock-system&quot;&gt;15. EFF op-ed urges San Jose to drop its Flock system&lt;&#x2F;h3&gt;
&lt;p&gt;The piece argued that automated licence plate readers can be turned against immigrants, dissidents and other targets. It called on local leaders to end the city&#x27;s contract and protect their communities.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;02&#x2F;op-ed-san-jose-can-protect-immigrants-ending-flock-surveillance-system&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-with-ring-consumers-built-a-surveillance-dragnet&quot;&gt;16. With Ring, consumers built a surveillance dragnet&lt;&#x2F;h3&gt;
&lt;p&gt;A Ring Super Bowl advert for an AI feature that scans neighbourhood cameras to find a lost dog drew sharp privacy criticism. Reporters and lawmakers warned the same tool could be turned on people deemed suspicious.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.404media.co&#x2F;with-ring-american-consumers-built-a-surveillance-dragnet&#x2F;&quot;&gt;www.404media.co&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-why-some-cities-are-cancelling-flock-camera-contracts&quot;&gt;17. Why some cities are cancelling Flock camera contracts&lt;&#x2F;h3&gt;
&lt;p&gt;NPR reported that a growing number of cities are dropping Flock licence plate readers over fears the data could feed immigration enforcement. Local officials cited the lack of control over who can search the footage.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.npr.org&#x2F;2026&#x2F;02&#x2F;17&#x2F;nx-s1-5612825&#x2F;flock-contracts-canceled-immigration-survillance-concerns&quot;&gt;www.npr.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-whatsapp-encryption-a-lawsuit-and-a-lot-of-noise&quot;&gt;18. WhatsApp encryption, a lawsuit, and a lot of noise&lt;&#x2F;h3&gt;
&lt;p&gt;Cryptographer Matthew Green examined claims that Meta could read end-to-end encrypted WhatsApp messages. He explained that the real risks sit around the protocol, in cloud backups, business messaging and internal access systems.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;blog.cryptographyengineering.com&#x2F;2026&#x2F;02&#x2F;02&#x2F;whatsapp-encryption-a-lawsuit-and-a-lot-of-noise&#x2F;&quot;&gt;blog.cryptographyengineering.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-age-verification-laws-face-mixed-prospects-in-2026&quot;&gt;19. Age verification laws face mixed prospects in 2026&lt;&#x2F;h3&gt;
&lt;p&gt;Experts told Route Fifty that the spread of age verification rules raises real privacy and anonymity concerns. Courts have blocked some measures while others move ahead, leaving a patchwork across the states.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.route-fifty.com&#x2F;digital-government&#x2F;2026&#x2F;02&#x2F;age-verification-laws-face-mixed-prospects-experts-say&#x2F;411492&#x2F;&quot;&gt;www.route-fifty.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-ten-dutch-municipalities-fined-over-secret-probes-into-muslim-residents&quot;&gt;20. Ten Dutch municipalities fined over secret probes into Muslim residents&lt;&#x2F;h3&gt;
&lt;p&gt;The Dutch data protection authority fined ten councils a total of 250,000 euros for collecting sensitive files on Muslim residents without their knowledge. The councils logged people&#x27;s religion and political views and shared the reports with national bodies.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;nltimes.nl&#x2F;2026&#x2F;02&#x2F;05&#x2F;ten-municipalities-fined-privacy-violations-secret-probes-muslim-community&quot;&gt;nltimes.nl&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0234 • January 2026</title>
          <pubDate>Thu, 05 Feb 2026 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0234/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0234/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0234/">&lt;!-- Covered month: January 2026 (2026-01-01 to 2026-01-31) --&gt;
&lt;p&gt;January brought a wave of government surveillance deals, fresh data broker fines, large corporate breaches and a renewed fight over encryption.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-ice-is-going-on-a-surveillance-shopping-spree&quot;&gt;1. ICE Is Going on a Surveillance Shopping Spree&lt;&#x2F;h3&gt;
&lt;p&gt;The EFF set out how ICE signed new contracts for phone tracking, social media monitoring, face surveillance and spyware. The agency now spends ten times its old budget on these tools, building one of the largest domestic surveillance systems in history.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;01&#x2F;ice-going-surveillance-shopping-spree&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-inside-ice-s-tool-to-monitor-phones-in-entire-neighbourhoods&quot;&gt;2. Inside ICE&#x27;s Tool to Monitor Phones in Entire Neighbourhoods&lt;&#x2F;h3&gt;
&lt;p&gt;404 Media revealed Webloc, a tool that lets ICE watch a city block for phones and trace each device home and to work. The data comes from hundreds of millions of phones and can be queried without a warrant.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.404media.co&#x2F;inside-ices-tool-to-monitor-phones-in-entire-neighborhoods&#x2F;&quot;&gt;www.404media.co&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-eff-calls-on-tech-companies-to-encrypt-it-already&quot;&gt;3. EFF Calls on Tech Companies to Encrypt It Already&lt;&#x2F;h3&gt;
&lt;p&gt;The EFF asked Meta, Apple, Google, Bluesky, Telegram and Amazon Ring to keep their promises on end to end encryption. The campaign wants default encryption for group chats, backups and home cameras.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2026&#x2F;01&#x2F;introducing-encrypt-it-already&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-calprivacy-brings-new-enforcement-actions-against-data-brokers&quot;&gt;4. CalPrivacy Brings New Enforcement Actions Against Data Brokers&lt;&#x2F;h3&gt;
&lt;p&gt;California fined Datamasters, run by Rickenbacher Data LLC, and S&amp;amp;P Global for failing to register under the Delete Act. Datamasters had resold lists of people grouped by health condition, age and perceived race.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;privacy.ca.gov&#x2F;2026&#x2F;01&#x2F;calprivacy-brings-new-round-of-enforcement-actions-against-data-brokers&#x2F;&quot;&gt;privacy.ca.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-worried-about-surveillance-states-enact-privacy-laws-and-restrict-licence-plate-readers&quot;&gt;5. Worried About Surveillance, States Enact Privacy Laws and Restrict Licence Plate Readers&lt;&#x2F;h3&gt;
&lt;p&gt;States across the political spectrum moved to curb licence plate readers, and several blocked ICE from reaching their driver record databases. Democratic led cities also dropped contracts with Flock Safety, the largest supplier of the cameras, over fears the scans fed federal surveillance.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;stateline.org&#x2F;2026&#x2F;01&#x2F;08&#x2F;worried-about-surveillance-states-enact-privacy-laws-and-restrict-license-plate-readers&#x2F;&quot;&gt;stateline.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-crunchbase-confirms-data-breach-after-hacking-claims&quot;&gt;6. Crunchbase Confirms Data Breach After Hacking Claims&lt;&#x2F;h3&gt;
&lt;p&gt;Crunchbase confirmed a breach after the group ShinyHunters published stolen records. The attackers used voice phishing to steal an employee single sign on credential and claimed to take more than two million records.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.securityweek.com&#x2F;crunchbase-confirms-data-breach-after-hacking-claims&#x2F;&quot;&gt;www.securityweek.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-target-s-dev-server-offline-after-hackers-claim-to-steal-source-code&quot;&gt;7. Target&#x27;s Dev Server Offline After Hackers Claim to Steal Source Code&lt;&#x2F;h3&gt;
&lt;p&gt;Around 860 gigabytes of Target source code and developer documents appeared online, and staff confirmed the files were real. The theft began with an infostealer on an employee workstation that held wide internal access.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;targets-dev-server-offline-after-hackers-claim-to-steal-source-code&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-data-thieves-borrow-nike-s-just-do-it-mantra-claim-they-ran-off-with-1-4tb&quot;&gt;8. Data Thieves Borrow Nike&#x27;s &#x27;Just Do It&#x27; Mantra, Claim They Ran Off With 1.4TB&lt;&#x2F;h3&gt;
&lt;p&gt;A group calling itself WorldLeaks published what it said was 1.4 terabytes of internal Nike data. The files covered product design, factory training and manufacturing processes, though they did not appear to hold customer records.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2026&#x2F;01&#x2F;26&#x2F;data_thieves_claim_nike_data_haul&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-blue-shield-of-california-notifies-members-of-potential-privacy-breach&quot;&gt;9. Blue Shield of California Notifies Members of Potential Privacy Breach&lt;&#x2F;h3&gt;
&lt;p&gt;A record merge fault let some Blue Shield members view another member&#x27;s details in the portal. The exposed data included names, diagnoses, medications and claims information.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;news.blueshieldca.com&#x2F;january-5-2026-blue-shield-of-california-notifies-members-of-potential-data-breach&quot;&gt;news.blueshieldca.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-who-operates-the-badbox-2-0-botnet&quot;&gt;10. Who Operates the Badbox 2.0 Botnet?&lt;&#x2F;h3&gt;
&lt;p&gt;Krebs traced how a disclosed vulnerability was used to build a vast botnet running on cheap Android television boxes. The person in control launched denial of service attacks, doxing and a swatting raid against the researcher and reporter.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2026&#x2F;01&#x2F;who-operates-the-badbox-2-0-botnet&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-patch-tuesday-january-2026-edition&quot;&gt;11. Patch Tuesday, January 2026 Edition&lt;&#x2F;h3&gt;
&lt;p&gt;Microsoft fixed at least 113 flaws, with eight rated critical and one already under attack. Two Office bugs could run code just from viewing a message in the preview pane.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2026&#x2F;01&#x2F;patch-tuesday-january-2026-edition&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-cnil-fines-free-mobile-and-free-42-million-euros&quot;&gt;12. CNIL Fines Free Mobile and Free 42 Million Euros&lt;&#x2F;h3&gt;
&lt;p&gt;The French regulator fined the two telecoms firms over weak security after an attacker reached data on 24 million subscriber contracts. The breach exposed bank account numbers for customers of both companies.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cnil.fr&#x2F;en&#x2F;sanction-free-2026&quot;&gt;www.cnil.fr&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-illinois-state-agency-exposed-personal-data-of-700-000-people&quot;&gt;13. Illinois State Agency Exposed Personal Data of 700,000 People&lt;&#x2F;h3&gt;
&lt;p&gt;The Illinois Department of Human Services revealed that it had posted the records of more than 700,000 residents on public mapping platforms. The data, which included addresses and benefits status, stayed open to view for years before staff took it down.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;illinois-agency-exposed-data&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-ice-takes-aim-at-data-held-by-advertising-and-tech-firms&quot;&gt;14. ICE Takes Aim at Data Held by Advertising and Tech Firms&lt;&#x2F;h3&gt;
&lt;p&gt;ICE published a request for information to learn how ad tech and big data providers could feed its investigations. Privacy experts warned the move could let the agency buy its way around warrant rules.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2026&#x2F;01&#x2F;27&#x2F;ice_data_advertising_tech_firms&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-ai-and-the-rise-of-bulk-spying&quot;&gt;15. AI and the Rise of Bulk Spying&lt;&#x2F;h3&gt;
&lt;p&gt;Bruce Schneier argued that artificial intelligence lets governments and firms move from targeted watching to mass surveillance. He warned that cheap analysis removes the old limits that once protected privacy.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.schneier.com&#x2F;news&#x2F;archives&#x2F;2026&#x2F;01&#x2F;ai-and-the-rise-of-bulk-spying.html&quot;&gt;www.schneier.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-instagram-denies-breach-amid-claims-of-17-million-account-data-leak&quot;&gt;16. Instagram Denies Breach Amid Claims of 17 Million Account Data Leak&lt;&#x2F;h3&gt;
&lt;p&gt;A dataset said to hold records on more than 17 million Instagram accounts appeared on a hacking forum, listing names, emails, phone numbers and addresses. Meta denied any breach of its systems and said it had fixed a bug that let attackers mass request password reset emails.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;instagram-denies-breach-amid-claims-of-17-million-account-data-leak&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-coalition-urges-congress-to-block-funding-for-ice-surveillance&quot;&gt;17. Coalition Urges Congress to Block Funding for ICE Surveillance&lt;&#x2F;h3&gt;
&lt;p&gt;Forty four groups asked lawmakers to cut funding for what they called an ICE surveillance panopticon. They warned that the spending threatened the rights of citizens and immigrants alike.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.commondreams.org&#x2F;news&#x2F;ice-surveillance-technology-funding&quot;&gt;www.commondreams.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-ice-and-activists-clash-over-doxing-and-privacy&quot;&gt;18. ICE and Activists Clash Over Doxing and Privacy&lt;&#x2F;h3&gt;
&lt;p&gt;The Washington Post reported on court and street fights as ICE used surveillance tools against protesters. Civil rights groups said the agency was infringing the privacy and speech rights of citizens.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.washingtonpost.com&#x2F;technology&#x2F;2026&#x2F;01&#x2F;15&#x2F;ice-activists-doxing&#x2F;&quot;&gt;www.washingtonpost.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-france-travail-fined-5-million-euros-over-job-seeker-data&quot;&gt;19. France Travail Fined 5 Million Euros Over Job Seeker Data&lt;&#x2F;h3&gt;
&lt;p&gt;The CNIL fined the French employment agency for failing to secure the data of job seekers. The penalty added to a busy month of European enforcement against poor data protection.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cnil.fr&#x2F;en&#x2F;data-breach-5million-fine-france-travail&quot;&gt;www.cnil.fr&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match&quot;&gt;20. Match Group Breach Exposes Data From Hinge, Tinder, OkCupid, and Match&lt;&#x2F;h3&gt;
&lt;p&gt;The group ShinyHunters leaked about 1.7 gigabytes of files said to hold roughly ten million records from the dating apps run by Match Group. The attackers reached the data through a social engineering attack that captured company single sign on credentials.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;match-group-breach-exposes-data-from-hinge-tinder-okcupid-and-match&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0233 • December 2025</title>
          <pubDate>Thu, 01 Jan 2026 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0233/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0233/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0233/">&lt;!-- Covered month: December 2025 (2025-12-01 to 2025-12-31) --&gt;
&lt;p&gt;December closed the year with fresh fights over message scanning, the first big fine under the EU platform rules, and a run of large breaches and data broker reckonings.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-eu-chat-control-nears-its-final-hurdle&quot;&gt;1. EU Chat Control nears its final hurdle&lt;&#x2F;h3&gt;
&lt;p&gt;The EU Council pushed again to scan private messages, and public pressure forced the Danish presidency to drop the demand to scan encrypted chats. The plan still allows so called voluntary scanning of messages that are not end to end encrypted, so the danger to privacy has not gone away.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;12&#x2F;after-years-controversy-eus-chat-control-nears-its-final-hurdle-what-know&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-european-commission-fines-x-120-million-euros-under-the-digital-services-act&quot;&gt;2. European Commission fines X 120 million euros under the Digital Services Act&lt;&#x2F;h3&gt;
&lt;p&gt;The Commission issued its first non compliance fine under the Digital Services Act, penalising X for a deceptive blue checkmark, a poor advertising archive, and blocking researcher access to public data. X was given strict deadlines to set out how it will fix each failure.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;digital-strategy.ec.europa.eu&#x2F;en&#x2F;news&#x2F;commission-fines-x-eu120-million-under-digital-services-act&quot;&gt;digital-strategy.ec.europa.eu&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-top-eu-court-makes-marketplaces-responsible-for-users-ads&quot;&gt;3. Top EU court makes marketplaces responsible for users&#x27; ads&lt;&#x2F;h3&gt;
&lt;p&gt;The Court of Justice ruled that online marketplace operators count as data controllers for personal data in user posted adverts, even when they did not write the content. Operators must now verify identities and check consent before publishing adverts that contain sensitive data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.insideprivacy.com&#x2F;eu-data-protection&#x2F;cjeu-clarifies-responsibilities-of-online-marketplace-operators&#x2F;&quot;&gt;www.insideprivacy.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-ftc-acts-against-illuminate-education-over-a-breach-hitting-10-million-students&quot;&gt;4. FTC acts against Illuminate Education over a breach hitting 10 million students&lt;&#x2F;h3&gt;
&lt;p&gt;The FTC required the education technology firm to build a security programme and delete data it no longer needs after a hacker reached the records of more than 10 million students. Regulators said the company stored data in plain text and waited nearly two years to warn some districts.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2025&#x2F;12&#x2F;ftc-takes-action-against-education-technology-provider-failing-secure-students-personal-data&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-ftc-orders-illusory-systems-to-repay-victims-of-a-186-million-dollar-hack&quot;&gt;5. FTC orders Illusory Systems to repay victims of a 186 million dollar hack&lt;&#x2F;h3&gt;
&lt;p&gt;The maker of the Nomad crypto bridge marketed itself as security first, yet shipped untested code that let thieves drain 186 million dollars. Under the settlement the firm must return recovered money and run an independent security programme.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2025&#x2F;12&#x2F;ftc-will-require-illusory-systems-return-money-stolen-hackers-implement-information-security-program&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-prosper-breach-exposes-data-on-13-1-million-people&quot;&gt;6. Prosper breach exposes data on 13.1 million people&lt;&#x2F;h3&gt;
&lt;p&gt;The lending marketplace began telling customers in December that attackers had queried its databases and taken names, Social Security numbers, bank details, and more. The firm said account funds were untouched and offered two years of credit monitoring.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;data-breaches-affecting-20-million-prosper-700credit&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-aflac-says-hackers-stole-personal-and-health-data-of-22-6-million-people&quot;&gt;7. Aflac says hackers stole personal and health data of 22.6 million people&lt;&#x2F;h3&gt;
&lt;p&gt;The insurance giant told state regulators in December that a summer intrusion had reached the records of about 22.65 million people. The haul covered names, dates of birth, addresses, Social Security numbers, government identity numbers, and medical and health insurance details.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;12&#x2F;23&#x2F;us-insurance-giant-aflac-says-hackers-stole-personal-and-health-data-of-22-6-million-people&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-flock-left-its-ai-cameras-open-on-the-internet&quot;&gt;8. Flock left its AI cameras open on the internet&lt;&#x2F;h3&gt;
&lt;p&gt;Researchers found at least 60 of Flock&#x27;s Condor cameras live streaming on the open internet with no password and no encryption, letting anyone watch and download weeks of footage. The cameras filmed children at play, shoppers, and drivers before Flock called it a limited misconfiguration.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.404media.co&#x2F;flock-exposed-its-ai-powered-cameras-to-the-internet-we-tracked-ourselves&#x2F;&quot;&gt;www.404media.co&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-schneier-weighs-a-new-anonymous-phone-service&quot;&gt;9. Schneier weighs a new anonymous phone service&lt;&#x2F;h3&gt;
&lt;p&gt;A carrier called Phreeli lets people sign up with nothing but a postcode, which is legal in all fifty states yet offered by none of the big players. Schneier warned that the parent network still holds location data, so the promise of true anonymity is thin.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2025&#x2F;12&#x2F;new-anonymous-phone-service.html&quot;&gt;www.schneier.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-ring-rolls-out-ai-facial-recognition-to-its-video-doorbells&quot;&gt;10. Ring rolls out AI facial recognition to its video doorbells&lt;&#x2F;h3&gt;
&lt;p&gt;Amazon&#x27;s Ring switched on a feature called Familiar Faces that lets owners catalogue up to fifty people and get named alerts when the doorbell spots them. EFF and Senator Ed Markey urged the firm to drop the tool, warning that a home camera network could become a way to track people across whole neighbourhoods.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;12&#x2F;09&#x2F;amazons-ring-rolls-out-controversial-ai-powered-facial-recognition-feature-to-video-doorbells&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-to-catch-a-predator-leak-exposes-the-inner-workings-of-intellexa-s-spyware&quot;&gt;11. To Catch a Predator: leak exposes the inner workings of Intellexa&#x27;s spyware&lt;&#x2F;h3&gt;
&lt;p&gt;Amnesty International verified leaked files showing how the Predator spyware infects phones, including a method that hides the attack inside ordinary mobile adverts. The documents proved the firm kept direct access to live customer systems and tied the tool to fresh abuses against a human rights lawyer in Pakistan.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;securitylab.amnesty.org&#x2F;latest&#x2F;2025&#x2F;12&#x2F;intellexa-leaks-predator-spyware-operations-exposed&#x2F;&quot;&gt;securitylab.amnesty.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-freedom-mobile-discloses-a-breach-exposing-customer-data&quot;&gt;12. Freedom Mobile discloses a breach exposing customer data&lt;&#x2F;h3&gt;
&lt;p&gt;Canada&#x27;s fourth largest carrier said attackers used a subcontractor&#x27;s account to reach the personal details of a limited number of customers. The exposed records held names, home addresses, dates of birth, phone numbers, and Freedom Mobile account numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;freedom-mobile-discloses-data-breach-exposing-customer-data&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-microsoft-fixes-a-zero-day-in-its-december-patch-round&quot;&gt;13. Microsoft fixes a zero-day in its December patch round&lt;&#x2F;h3&gt;
&lt;p&gt;Microsoft shipped fixes for at least 56 flaws, including one already used in attacks and two that had been disclosed in public. The release closed out a year in which the company patched more than 1,100 vulnerabilities.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;12&#x2F;microsoft-patch-tuesday-december-2025-edition&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-federal-judge-blocks-the-texas-app-store-age-verification-law&quot;&gt;14. Federal judge blocks the Texas app store age verification law&lt;&#x2F;h3&gt;
&lt;p&gt;A judge granted an injunction against Senate Bill 2420, ruling that forcing age checks to download apps likely breaks the First Amendment. The law had been set to take effect in January 2026.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.jurist.org&#x2F;news&#x2F;2025&#x2F;12&#x2F;us-federal-court-blocks-texas-app-store-age-verification-law&#x2F;&quot;&gt;www.jurist.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-austria-supreme-court-rules-meta-s-personalised-ads-unlawful&quot;&gt;15. Austria supreme court rules Meta&#x27;s personalised ads unlawful&lt;&#x2F;h3&gt;
&lt;p&gt;Austria&#x27;s highest court held that Meta cannot lean on contractual necessity to process user data for targeted advertising without consent, since the adverts are a way to make money rather than a core service. The ruling, enforceable across the EU, also barred Meta from handling sensitive data such as health or political views without an explicit opt in.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.jurist.org&#x2F;news&#x2F;2025&#x2F;12&#x2F;austrian-supreme-court-rules-metas-personalized-ads-unlawful&#x2F;&quot;&gt;www.jurist.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-lastpass-hammered-with-ps1-2m-fine-for-2022-breach-fiasco&quot;&gt;16. LastPass hammered with £1.2M fine for 2022 breach fiasco&lt;&#x2F;h3&gt;
&lt;p&gt;The UK Information Commissioner&#x27;s Office fined LastPass 1.2 million pounds after a 2022 attack reached a backup database holding the data of up to 1.6 million British users. Regulators said the firm let senior staff use the same master password for personal and business accounts, which let one breach feed the next.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;12&#x2F;11&#x2F;lastpass_ico_fine&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-hacker-claims-to-leak-wired-database-with-2-3-million-records&quot;&gt;17. Hacker claims to leak WIRED database with 2.3 million records&lt;&#x2F;h3&gt;
&lt;p&gt;A thief posted what they said was a Condé Nast database of more than 2.3 million WIRED subscriber records, listing email addresses, names, postal addresses, phone numbers, and birthdays. BleepingComputer checked a sample of the records and confirmed they belonged to genuine subscribers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;hacker-claims-to-leak-wired-database-with-23-million-records&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-court-approves-disney-s-10-million-dollar-coppa-settlement&quot;&gt;18. Court approves Disney&#x27;s 10 million dollar COPPA settlement&lt;&#x2F;h3&gt;
&lt;p&gt;A federal court signed off on an order making Disney pay 10 million dollars to settle FTC claims that it let firms harvest data from children watching its YouTube videos. Disney had set audience labels at the channel level rather than per video, so some child directed clips escaped the made for kids tag and fed targeted advertising.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2025&#x2F;12&#x2F;court-approves-order-requiring-disney-pay-10-million-settle-ftc-allegations-firm-enabled-unlawful&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-france-s-cnil-fines-nexpublica-1-7-million-euros-over-a-data-leak&quot;&gt;19. France&#x27;s CNIL fines Nexpublica 1.7 million euros over a data leak&lt;&#x2F;h3&gt;
&lt;p&gt;The French regulator penalised the maker of social care software after a flaw let users open other people&#x27;s documents through its online portal. The CNIL said the firm had ignored basic security practice and left known weaknesses unfixed for years before the breach came to light.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;thecyberexpress.com&#x2F;gdpr-fine-on-nexpublica-france&#x2F;&quot;&gt;thecyberexpress.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-ofcom-fines-an-adult-site-under-the-online-safety-act&quot;&gt;20. Ofcom fines an adult site under the Online Safety Act&lt;&#x2F;h3&gt;
&lt;p&gt;The UK regulator issued a 1 million pound fine against AVS Group over age checks it judged were not highly effective across the firm&#x27;s 18 adult websites. Ofcom added a further 50,000 pound penalty after the company failed to answer its repeated requests for information.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ofcom.org.uk&#x2F;online-safety&#x2F;protecting-children&#x2F;ofcom-fines-porn-company-1million-for-not-having-robust-age-checks&quot;&gt;www.ofcom.org.uk&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0232 • November 2025</title>
          <pubDate>Thu, 04 Dec 2025 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0232/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0232/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0232/">&lt;!-- Covered month: November 2025 (2025-11-01 to 2025-11-30) --&gt;
&lt;p&gt;November brought a wave of vendor breaches, fresh fights over surveillance and encryption, and large fines that showed regulators are not slowing down.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-coupang-says-33-7-million-customer-accounts-were-breached&quot;&gt;1. Coupang says 33.7 million customer accounts were breached&lt;&#x2F;h3&gt;
&lt;p&gt;The South Korean retailer admitted that a former employee accessed the personal data of 33.7 million users over several months. Names, addresses, phone numbers and order histories were taken, and the chief executive resigned over the failure.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cnbc.com&#x2F;2025&#x2F;11&#x2F;30&#x2F;top-south-korean-e-commerce-firm-coupang-says-33point7-million-customer-accounts-breached.html&quot;&gt;www.cnbc.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-washington-post-confirms-data-breach-linked-to-oracle-hacks&quot;&gt;2. Washington Post confirms data breach linked to Oracle hacks&lt;&#x2F;h3&gt;
&lt;p&gt;The newspaper said nearly 10,000 staff and contractors were caught up in the wider attack on Oracle E-Business Suite. The Cl0p group exploited a zero-day flaw and stole records that included bank account numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;11&#x2F;07&#x2F;washington-post-confirms-data-breach-linked-to-oracle-hacks&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-doordash-confirms-data-breach-affecting-users-phone-numbers-and-addresses&quot;&gt;3. DoorDash confirms data breach affecting users&#x27; phone numbers and addresses&lt;&#x2F;h3&gt;
&lt;p&gt;A social engineering attack on a staff member let intruders reach customer, driver and merchant records. The exposed data included names, email addresses, phone numbers and physical addresses.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;11&#x2F;17&#x2F;doordash-confirms-data-breach-impacting-users-phone-numbers-and-physical-addresses&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-openai-discloses-customer-data-breach-through-mixpanel-vendor-hack&quot;&gt;4. OpenAI discloses customer data breach through Mixpanel vendor hack&lt;&#x2F;h3&gt;
&lt;p&gt;An SMS phishing attack on the analytics firm Mixpanel exposed names, email addresses and location metadata for some OpenAI API users. OpenAI ended its relationship with the vendor and began a wider review of its suppliers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;openai-discloses-api-customer-data-breach-via-mixpanel-vendor-hack&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-salesforce-says-customer-data-was-accessed-after-gainsight-breach&quot;&gt;5. Salesforce says customer data was accessed after Gainsight breach&lt;&#x2F;h3&gt;
&lt;p&gt;Stolen access tokens linked to the Gainsight app let attackers reach data belonging to hundreds of Salesforce customers. The ShinyHunters group claimed it pulled records from close to a thousand organisations.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;11&#x2F;20&#x2F;salesforce-says-some-of-its-customers-data-was-accessed-after-gainsight-breach&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-situsamc-confirms-breach-of-client-data-after-cyberattack&quot;&gt;6. SitusAMC confirms breach of client data after cyberattack&lt;&#x2F;h3&gt;
&lt;p&gt;The real-estate finance firm said attackers took accounting records and legal agreements tied to its banking clients. JPMorgan Chase, Citi and Morgan Stanley were among the lenders told that customer data might be exposed.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;11&#x2F;24&#x2F;situsamc_breach&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-researchers-find-a-shockingly-large-amount-of-satellite-traffic-is-unencrypted&quot;&gt;7. Researchers find a shockingly large amount of satellite traffic is unencrypted&lt;&#x2F;h3&gt;
&lt;p&gt;Academics using about 800 dollars of kit intercepted phone calls, texts and military feeds sent in the clear over satellites. Half of the links they observed carried no encryption at all.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.npr.org&#x2F;2025&#x2F;11&#x2F;04&#x2F;nx-s1-5588502&#x2F;researchers-uncover-security-gap-while-studying-satellite-communications&quot;&gt;www.npr.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-the-uk-has-it-wrong-on-digital-id-here-s-why&quot;&gt;8. The UK Has It Wrong on Digital ID. Here&#x27;s Why.&lt;&#x2F;h3&gt;
&lt;p&gt;EFF warned that the planned national digital ID scheme would build a centralised database that hands the state new power over access to everyday services. It cautioned that such systems risk shutting out people without a smartphone, a passport or reliable internet.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;11&#x2F;uk-has-it-wrong-digital-id-heres-why&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-police-searched-plate-logs-with-racist-terms-against-romani-people&quot;&gt;9. Police searched plate logs with racist terms against Romani people&lt;&#x2F;h3&gt;
&lt;p&gt;EFF found more than 80 agencies ran searches of the Flock network using slurs and stereotypes aimed at Romani people. Many of those searches listed no suspected crime at all.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;11&#x2F;license-plate-surveillance-logs-reveal-racist-policing-against-romani-people&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-rights-organizations-demand-halt-to-mobile-fortify-ice-s-handheld-face-recognition-program&quot;&gt;10. Rights Organizations Demand Halt to Mobile Fortify, ICE&#x27;s Handheld Face Recognition Program&lt;&#x2F;h3&gt;
&lt;p&gt;A coalition of civil liberties groups told the Department of Homeland Security to switch off Mobile Fortify, the handheld app that lets agents scan faces in the field. They also asked the agency to release its privacy analyses and explain its policy on face recognition.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;11&#x2F;rights-organizations-demand-halt-mobile-fortify-ices-handheld-face-recognition&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-ice-gains-new-tools-to-track-and-identify-people&quot;&gt;11. ICE gains new tools to track and identify people&lt;&#x2F;h3&gt;
&lt;p&gt;Immigration agents now use facial recognition, phone location databases and spyware to find and name people. Civil liberties groups warn that much of this tracking happens without a warrant.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.npr.org&#x2F;2025&#x2F;11&#x2F;08&#x2F;nx-s1-5585691&#x2F;ice-facial-recognition-immigration-tracking-spyware&quot;&gt;www.npr.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-meta-hit-with-479-million-euro-fine-in-spain-over-privacy-violations&quot;&gt;12. Meta hit with 479 million euro fine in Spain over privacy violations&lt;&#x2F;h3&gt;
&lt;p&gt;A Madrid court ordered Meta to pay damages to 81 Spanish press publishers over its data practices. The ruling showed how privacy law can underpin large claims beyond the usual regulators.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;euroweeklynews.com&#x2F;2025&#x2F;11&#x2F;21&#x2F;meta-hit-with-e479m-fine-in-spain-over-privacy-violations&#x2F;&quot;&gt;euroweeklynews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-logitech-confirms-data-breach-from-a-third-party-zero-day-flaw&quot;&gt;13. Logitech confirms data breach from a third-party zero-day flaw&lt;&#x2F;h3&gt;
&lt;p&gt;The hardware maker told regulators that intruders copied data from its internal systems through a flaw in a supplier&#x27;s software. The records likely held limited information about employees, customers and suppliers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.sec.gov&#x2F;Archives&#x2F;edgar&#x2F;data&#x2F;0001032975&#x2F;000103297525000085&#x2F;logi-20251114.htm&quot;&gt;www.sec.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-google-ai-can-access-some-content-from-gmail-and-chats-here-s-how-to-opt-out&quot;&gt;14. Google AI can access some content from Gmail and chats. Here&#x27;s how to opt out&lt;&#x2F;h3&gt;
&lt;p&gt;A widely shared video claimed Google had quietly opted everyone into using their email to train Gemini. Google denied training the model on Gmail, though its smart features still read message content.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.snopes.com&#x2F;news&#x2F;2025&#x2F;11&#x2F;21&#x2F;google-ai-emails-chats&#x2F;&quot;&gt;www.snopes.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-court-ends-dragnet-electricity-surveillance-programme-in-sacramento&quot;&gt;15. Court ends dragnet electricity surveillance programme in Sacramento&lt;&#x2F;h3&gt;
&lt;p&gt;A California court ruled that the utility SMUD broke state privacy law by sifting through residents&#x27; smart meter data and passing more than 33,000 tips to police without any suspicion. The judgment found that suspicionless searches of whole postcodes worth of energy records are not a lawful investigation.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;11&#x2F;victory-court-end-dragnet-electricity-surveillance-program-sacramento&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-berkeley-debates-whether-to-keep-its-flock-surveillance-cameras&quot;&gt;16. Berkeley debates whether to keep its Flock surveillance cameras&lt;&#x2F;h3&gt;
&lt;p&gt;The city weighed its contract with Flock Safety as residents pressed it to cut ties over privacy fears. At least 30 places have switched off or cancelled their Flock cameras during the year.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.berkeleyside.org&#x2F;2025&#x2F;11&#x2F;24&#x2F;flock-safety-cameras-berkeley-license-plate-readers&quot;&gt;www.berkeleyside.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-attorney-general-bonta-secures-1-4-million-settlement-with-mobile-app-gaming-company-for-violating-california-s-nation-leading-privacy-law&quot;&gt;17. Attorney General Bonta Secures $1.4 Million Settlement with Mobile App Gaming Company for Violating California&#x27;s Nation-Leading Privacy Law&lt;&#x2F;h3&gt;
&lt;p&gt;California&#x27;s attorney general fined the game maker Jam City for failing to offer opt-out controls across its 21 mobile apps. The company had also shared or sold the data of children aged 13 to 16 without the affirmative consent that state law demands.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;oag.ca.gov&#x2F;news&#x2F;press-releases&#x2F;attorney-general-bonta-secures-14-million-settlement-mobile-app-gaming-company&quot;&gt;oag.ca.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-the-legal-case-against-ring-s-face-recognition-feature&quot;&gt;18. The Legal Case Against Ring&#x27;s Face Recognition Feature&lt;&#x2F;h3&gt;
&lt;p&gt;EFF argued that Amazon Ring&#x27;s new Familiar Faces tool scans everyone who approaches a camera, including neighbours and passers-by who never agreed to a face scan. Amazon plans to switch the feature off in Illinois and Texas, a sign that it would not survive the biometric privacy laws there.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;11&#x2F;legal-case-against-rings-face-recognition-feature&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-princeton-university-discloses-data-breach-affecting-donors-alumni&quot;&gt;19. Princeton University discloses data breach affecting donors, alumni&lt;&#x2F;h3&gt;
&lt;p&gt;Princeton said attackers reached a fundraising database through a phishing attack on a staff member, exposing names, email addresses, phone numbers and home and business addresses for alumni, donors, students and staff. The records did not hold passwords, financial details or Social Security numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;princeton-university-discloses-data-breach-affecting-donors-alumni&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-checkout-com-snubs-hackers-after-data-breach-to-donate-ransom-instead&quot;&gt;20. Checkout.com snubs hackers after data breach, to donate ransom instead&lt;&#x2F;h3&gt;
&lt;p&gt;The payments firm said the ShinyHunters group reached a legacy cloud store that had sat unused since 2020 and held onboarding records for about a quarter of its merchants. Rather than pay the ransom, Checkout.com pledged the sum to security research at Carnegie Mellon and Oxford.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;checkoutcom-snubs-shinyhunters-hackers-to-donate-ransom-instead&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0231 • October 2025</title>
          <pubDate>Thu, 06 Nov 2025 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0231/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0231/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0231/">&lt;!-- Covered month: October 2025 (2025-10-01 to 2025-10-31) --&gt;
&lt;p&gt;October 2025 brought a wave of supply chain extortion, fresh attacks on encryption, and a hard look at the surveillance camera networks now woven through everyday life.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-surveillance-secrets-exposes-first-wap-s-global-phone-tracking&quot;&gt;1. Surveillance Secrets exposes First Wap&#x27;s global phone tracking&lt;&#x2F;h3&gt;
&lt;p&gt;A reporting team traced a hidden archive of more than a million tracking attempts to First Wap, a firm that locates phones worldwide through the ageing SS7 telecom protocol. The records showed journalists, dissidents, and business figures tracked in over 160 countries without their knowledge.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.lighthousereports.com&#x2F;investigation&#x2F;surveillance-secrets&#x2F;&quot;&gt;www.lighthousereports.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-simonmed-says-1-2-million-patients-hit-in-data-breach&quot;&gt;2. SimonMed says 1.2 million patients hit in data breach&lt;&#x2F;h3&gt;
&lt;p&gt;The imaging provider told more than 1.2 million people that intruders had reached their records earlier in the year. The Medusa gang claimed it took 212GB of files, including identity scans, payment details, and medical reports.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;simonmed-says-12-million-patients-impacted-in-january-data-breach&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-hackers-steal-70-000-id-photos-from-discord-support-system&quot;&gt;3. Hackers steal 70,000 ID photos from Discord support system&lt;&#x2F;h3&gt;
&lt;p&gt;Attackers broke into a third party support provider and took around 70,000 images of government identity documents that users had handed over for age checks. The theft showed how age verification rules force people to surrender the very data that most needs protecting.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.nbcnews.com&#x2F;tech&#x2F;tech-news&#x2F;70000-government-id-photos-exposed-discord-user-hack-rcna236714&quot;&gt;www.nbcnews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-red-hat-consulting-repositories-breached-by-crimson-collective&quot;&gt;4. Red Hat consulting repositories breached by Crimson Collective&lt;&#x2F;h3&gt;
&lt;p&gt;A group calling itself Crimson Collective claimed it took 570GB of data from a Red Hat consulting GitLab server covering around 28,000 repositories. The files reportedly held engagement reports for customers including the US Navy and Congress.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.404media.co&#x2F;red-hat-investigating-breach-impacting-as-many-as-28-000-customers-including-the-navy-and-congress&#x2F;&quot;&gt;www.404media.co&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-italy-orders-the-clothoff-deepfake-app-to-stop&quot;&gt;5. Italy orders the Clothoff deepfake app to stop&lt;&#x2F;h3&gt;
&lt;p&gt;Italy&#x27;s data protection authority ordered the deepfake nudity app Clothoff to stop processing the data of Italian users. The regulator opened a wider inquiry into apps that strip people in images without consent.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ansa.it&#x2F;sito&#x2F;notizie&#x2F;cronaca&#x2F;2025&#x2F;10&#x2F;03&#x2F;garante-stop-a-clothoff-lapp-che-spoglia-le-persone_eab1588d-6a0e-4aba-8660-613f5cd093b9.html&quot;&gt;www.ansa.it&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-hacking-group-claims-theft-of-1-billion-records-from-salesforce-customer-databases&quot;&gt;6. Hacking group claims theft of 1 billion records from Salesforce customer databases&lt;&#x2F;h3&gt;
&lt;p&gt;A group calling itself Scattered Lapsus$ Hunters opened a dark web leak site listing dozens of companies whose Salesforce data had been stolen through compromised Salesloft Drift tokens. The attackers threatened to publish around a billion records, and Salesforce told customers it would not pay any ransom.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;10&#x2F;03&#x2F;hacking-group-claims-theft-of-1-billion-records-from-salesforce-customer-databases&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-flock-s-gunshot-microphones-will-start-listening-for-human-voices&quot;&gt;7. Flock&#x27;s gunshot microphones will start listening for human voices&lt;&#x2F;h3&gt;
&lt;p&gt;Flock revealed that its acoustic sensors would expand from gunfire to detect sounds of human distress such as screaming. EFF warned that always listening microphones over public streets raise serious questions under state eavesdropping laws.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;10&#x2F;flocks-gunshot-detection-microphones-will-start-listening-human-voices&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-sonicwall-says-every-cloud-backup-was-exposed&quot;&gt;8. SonicWall says every cloud backup was exposed&lt;&#x2F;h3&gt;
&lt;p&gt;SonicWall admitted that an attacker reached the firewall configuration backups of all customers who used its cloud backup service. Those files reveal network layouts, access rules, and credentials that help attackers plan further intrusions.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;cyberscoop.com&#x2F;sonicwall-customer-firewall-configurations-exposed&#x2F;&quot;&gt;cyberscoop.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-california-signs-the-defending-californians-data-act&quot;&gt;9. California signs the Defending Californians&#x27; Data Act&lt;&#x2F;h3&gt;
&lt;p&gt;Governor Newsom signed SB 361, which forces data brokers to disclose whether they sell information to foreign actors, government bodies, or AI developers. The law also doubles the daily fine for brokers that ignore deletion requests.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;sd13.senate.ca.gov&#x2F;news&#x2F;press-release&#x2F;october-9-2025&#x2F;governor-signs-landmark-defending-californians-data-act&quot;&gt;sd13.senate.ca.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-virginia-police-tap-surveillance-cameras-for-immigration-cases&quot;&gt;10. Virginia police tap surveillance cameras for immigration cases&lt;&#x2F;h3&gt;
&lt;p&gt;Reporting found that Virginia&#x27;s Flock camera network was searched nearly 3,000 times for immigration enforcement over a year. Local cameras sold to fight car theft were feeding a federal deportation effort.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.vpm.org&#x2F;news&#x2F;2025-10-09&#x2F;flock-safety-cameras-alprs-federal-immigration-enforcement-lehmann-kochis&quot;&gt;www.vpm.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-eu-pulls-the-chat-control-vote-after-germany-objects&quot;&gt;11. EU pulls the Chat Control vote after Germany objects&lt;&#x2F;h3&gt;
&lt;p&gt;The EU Council shelved its planned vote on the message scanning rule once Germany joined the opposition and formed a blocking minority. The proposal that would have forced scanning of private messages was held back yet again.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.govinfosecurity.com&#x2F;europe-postpones-chat-control-vote-a-29718&quot;&gt;www.govinfosecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-california-requires-device-level-age-signals&quot;&gt;12. California requires device level age signals&lt;&#x2F;h3&gt;
&lt;p&gt;Governor Newsom signed AB 1043, which makes operating system makers pass an age bracket signal to apps at account setup. Supporters say it avoids identity uploads, while critics warn it pushes age checks onto every device and platform.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.alstonprivacy.com&#x2F;california-enacts-digital-age-verification-law&#x2F;&quot;&gt;www.alstonprivacy.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-capita-fined-ps14m-over-its-2023-ransomware-breach&quot;&gt;13. Capita fined £14m over its 2023 ransomware breach&lt;&#x2F;h3&gt;
&lt;p&gt;The UK Information Commissioner fined the outsourcing firm Capita £14m after a breach exposed data on more than six million people. Investigators found the company took 58 hours to isolate an infected device despite an early alert.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;10&#x2F;15&#x2F;ico_fines_capita_14m&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-f5-says-nation-state-hackers-stole-big-ip-source-code&quot;&gt;14. F5 says nation state hackers stole BIG-IP source code&lt;&#x2F;h3&gt;
&lt;p&gt;F5 disclosed that attackers held long term access to its development systems and took source code and details of undisclosed flaws in its BIG-IP products. US authorities ordered federal agencies to patch at once given how widely the products are deployed.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.helpnetsecurity.com&#x2F;2025&#x2F;10&#x2F;15&#x2F;f5-big-ip-data-breach&#x2F;&quot;&gt;www.helpnetsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-ring-agrees-to-share-doorbell-footage-with-flock&quot;&gt;15. Ring agrees to share doorbell footage with Flock&lt;&#x2F;h3&gt;
&lt;p&gt;Amazon&#x27;s Ring announced a deal letting police using Flock request video from home doorbells. On the same day reporting showed that immigration agents, the Secret Service, and the Navy could already search Flock&#x27;s network.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;10&#x2F;16&#x2F;amazons-ring-to-partner-with-flock-a-network-of-ai-cameras-used-by-ice-feds-and-police&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-qantas-data-appears-on-the-dark-web&quot;&gt;16. Qantas data appears on the dark web&lt;&#x2F;h3&gt;
&lt;p&gt;Hackers published the records of more than five million Qantas customers after the airline declined to pay a ransom. The leaked files held names, email addresses, phone numbers, and dates of birth.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.euronews.com&#x2F;travel&#x2F;2025&#x2F;10&#x2F;14&#x2F;qantas-data-leak-over-5-million-customers-affected-as-personal-information-shared-on-the-d&quot;&gt;www.euronews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-ec-finds-meta-and-tiktok-breached-transparency-rules-under-dsa&quot;&gt;17. EC finds Meta and TikTok breached transparency rules under DSA&lt;&#x2F;h3&gt;
&lt;p&gt;The European Commission found that Meta and TikTok had failed to give researchers adequate access to public data as the Digital Services Act requires. It also said Meta did not offer users on Instagram and Facebook a simple way to report illegal content, with possible fines of up to six per cent of global revenue.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;10&#x2F;24&#x2F;ec-finds-meta-and-tiktok-breached-transparency-rules-under-dsa&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-judge-bars-nso-from-targeting-whatsapp-users-with-spyware-reduces-damages-in-landmark-case&quot;&gt;18. Judge bars NSO from targeting WhatsApp users with spyware, reduces damages in landmark case&lt;&#x2F;h3&gt;
&lt;p&gt;A US federal judge ordered the spyware maker NSO Group to stop targeting WhatsApp with its Pegasus tool, ruling that the conduct caused irreparable harm. The court let the injunction stand but cut the earlier jury award from 168 million dollars to 4 million dollars.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;judge-bars-nso-from-targeting-whatsapp-users-lowers-damages&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-conduent-data-breach-impacts-over-10-5-million-individuals&quot;&gt;19. Conduent data breach impacts over 10.5 million individuals&lt;&#x2F;h3&gt;
&lt;p&gt;The business services firm Conduent told regulators that a ransomware attack exposed the data of more than 10.5 million people across the United States. The stolen files held names, Social Security numbers, dates of birth, and medical and health insurance details.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.infosecurity-magazine.com&#x2F;news&#x2F;conduent-data-breach-10-million&#x2F;&quot;&gt;www.infosecurity-magazine.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-draftkings-warns-of-account-takeovers-from-reused-passwords&quot;&gt;20. DraftKings warns of account takeovers from reused passwords&lt;&#x2F;h3&gt;
&lt;p&gt;DraftKings told customers that attackers had broken into accounts using passwords stolen from other sites. The exposed details included names, addresses, phone numbers, and the last digits of payment cards.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;draftkings-warns-of-account-breaches-in-credential-stuffing-attacks&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0230 • September 2025</title>
          <pubDate>Thu, 02 Oct 2025 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0230/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0230/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0230/">&lt;!-- Covered month: September 2025 (2025-09-01 to 2025-09-30) --&gt;
&lt;p&gt;September 2025 brought record privacy fines, a string of supply chain breaches, and fresh fights over surveillance and encryption.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-google-must-pay-425-million-in-privacy-lawsuit-jury-rules&quot;&gt;1. Google must pay $425 million in privacy lawsuit, jury rules&lt;&#x2F;h3&gt;
&lt;p&gt;A San Francisco jury ordered Google to pay 425.7 million dollars for tracking phone activity after users had switched the setting off. The case covered about 98 million devices, and Google said it would appeal.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cbsnews.com&#x2F;news&#x2F;google-ordered-pay-425-million-privacy-tracking-case&#x2F;&quot;&gt;www.cbsnews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-cookies-placed-without-consent-shein-fined-150-million-euros-by-the-cnil&quot;&gt;2. Cookies placed without consent: SHEIN fined 150 million euros by the CNIL&lt;&#x2F;h3&gt;
&lt;p&gt;France&#x27;s data regulator fined Shein&#x27;s Irish subsidiary 150 million euros for dropping advertising cookies before users could choose. On the same day the CNIL fined Google 325 million euros for similar consent failures.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cnil.fr&#x2F;en&#x2F;cookies-placed-without-consent-shein-fined-150-million-euros-cnil&quot;&gt;www.cnil.fr&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-jaguar-land-rover-extends-production-delay-following-cyberattack&quot;&gt;3. Jaguar Land Rover extends production delay following cyberattack&lt;&#x2F;h3&gt;
&lt;p&gt;A cyberattack forced Jaguar Land Rover to shut down its systems and halt production at its main British plants. Attackers leaked internal data, and the firm confirmed customer information had been taken.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cybersecuritydive.com&#x2F;news&#x2F;jaguar-land-rover-production-delay-cyberattack&#x2F;760254&#x2F;&quot;&gt;www.cybersecuritydive.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-stellantis-says-a-third-party-vendor-spilled-customer-data&quot;&gt;4. Stellantis says a third-party vendor spilled customer data&lt;&#x2F;h3&gt;
&lt;p&gt;Stellantis confirmed that attackers reached customer data through a third-party platform serving its North American operations. The carmaker said the exposed records were limited to names and email addresses.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;09&#x2F;22&#x2F;stellantis_breach&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-the-ongoing-fallout-from-a-breach-at-ai-chatbot-maker-salesloft&quot;&gt;5. The Ongoing Fallout from a Breach at AI Chatbot Maker Salesloft&lt;&#x2F;h3&gt;
&lt;p&gt;Hackers stole authentication tokens from Salesloft&#x27;s Drift chatbot and used them to raid hundreds of connected Salesforce accounts. Google&#x27;s researchers urged firms to revoke every token tied to the integration.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;09&#x2F;the-ongoing-fallout-from-a-breach-at-ai-chatbot-maker-salesloft&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-plex-urges-users-to-change-passwords-after-data-breach&quot;&gt;6. Plex urges users to change passwords after data breach&lt;&#x2F;h3&gt;
&lt;p&gt;Plex told users to reset their passwords after an intruder reached a database holding emails, usernames, and hashed passwords. The streaming firm forced a reset and advised people to switch on two-factor authentication.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;09&#x2F;09&#x2F;plex-urges-users-to-change-passwords-after-data-breach&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-wealthsimple-data-breach-exposes-sensitive-client-information&quot;&gt;7. Wealthsimple Data Breach Exposes Sensitive Client Information&lt;&#x2F;h3&gt;
&lt;p&gt;The Canadian investment platform said a compromised third-party software package exposed data on less than one percent of its clients. The leaked records included contact details, government IDs, account numbers, and social insurance numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.crowdfundinsider.com&#x2F;2025&#x2F;09&#x2F;250491-wealthsimple-data-breach-exposes-sensitive-client-information&#x2F;&quot;&gt;www.crowdfundinsider.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-ftc-launches-inquiry-into-ai-chatbots-acting-as-companions&quot;&gt;8. FTC Launches Inquiry into AI Chatbots Acting as Companions&lt;&#x2F;h3&gt;
&lt;p&gt;The Federal Trade Commission ordered seven firms, including OpenAI, Meta, and Google, to explain how their chatbots affect children and teenagers. The agency asked what steps each company takes to limit harm and to warn parents.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2025&#x2F;09&#x2F;ftc-launches-inquiry-ai-chatbots-acting-companions&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-mexican-allies-raise-alarms-about-new-mass-surveillance-laws-call-for-international-support&quot;&gt;9. Mexican Allies Raise Alarms About New Mass Surveillance Laws, Call for International Support&lt;&#x2F;h3&gt;
&lt;p&gt;Mexican civil society groups warned that new laws force every person to enrol in a biometric ID system and hand officials wide access to personal data. The digital rights group R3D challenged the measures in court and sought international backing.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;09&#x2F;mexican-allies-raise-alarms-about-new-mass-surveillance-laws-call-international&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-what-whatsapp-s-advanced-chat-privacy-really-does&quot;&gt;10. What WhatsApp&#x27;s &quot;Advanced Chat Privacy&quot; Really Does&lt;&#x2F;h3&gt;
&lt;p&gt;The Electronic Frontier Foundation pushed back on a viral claim that Meta AI reads private chats unless a setting is switched on. It explained that the AI only sees a message when a user invokes it, though WhatsApp still gathers metadata.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;09&#x2F;what-whatsapps-advanced-chat-privacy-really-does&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-tile-trackers-leak-unencrypted-bluetooth-data-say-boffins&quot;&gt;11. Tile trackers leak unencrypted Bluetooth data, say boffins&lt;&#x2F;h3&gt;
&lt;p&gt;Researchers at Georgia Tech found that Tile trackers broadcast their data without encryption, so anyone with the right gear can follow a tag. The flaw lets both the company and stalkers track a device over time.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;09&#x2F;30&#x2F;tile_trackers_unencrypted_info&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-california-privacy-protection-agency-issues-record-1-35-million-fine-against-tractor-supply-company&quot;&gt;12. California Privacy Protection Agency issues record $1.35 million fine against Tractor Supply Company&lt;&#x2F;h3&gt;
&lt;p&gt;California&#x27;s privacy agency reached a 1.35 million dollar settlement with Tractor Supply, its largest penalty so far. Regulators said the retailer failed to honour opt-out requests and lacked proper service provider contracts.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.whitecase.com&#x2F;insight-alert&#x2F;california-privacy-protection-agency-issues-record-135-million-fine-against-tractor&quot;&gt;www.whitecase.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-california-finalizes-regulations-to-strengthen-consumers-privacy&quot;&gt;13. California Finalizes Regulations to Strengthen Consumers&#x27; Privacy&lt;&#x2F;h3&gt;
&lt;p&gt;California finalised rules on automated decision-making, risk assessments, and cybersecurity audits under the state privacy law. The rules take effect in January 2026, with phased deadlines stretching through the decade.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;cppa.ca.gov&#x2F;announcements&#x2F;2025&#x2F;20250923.html&quot;&gt;cppa.ca.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-ice-to-buy-tool-that-tracks-locations-of-hundreds-of-millions-of-phones-every-day&quot;&gt;14. ICE to Buy Tool that Tracks Locations of Hundreds of Millions of Phones Every Day&lt;&#x2F;h3&gt;
&lt;p&gt;Documents showed that ICE planned to buy a surveillance tool that maps billions of daily location signals from hundreds of millions of phones. An internal legal note said the agency could query the data without a warrant.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.404media.co&#x2F;ice-to-buy-tool-that-tracks-locations-of-hundreds-of-millions-of-phones-every-day&#x2F;&quot;&gt;www.404media.co&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-volvo-na-staff-data-stolen-in-third-party-ransomware-attack&quot;&gt;15. Volvo NA staff data stolen in third-party ransomware attack&lt;&#x2F;h3&gt;
&lt;p&gt;Volvo North America confirmed that a ransomware attack on its software supplier Miljodata exposed staff data, including names and social security numbers. The attack hit much of Sweden&#x27;s public sector and many large firms.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;09&#x2F;26&#x2F;volvo_north_america_confirms_staff&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-430k-customers-affected-in-harrods-latest-breach&quot;&gt;16. 430k customers affected in Harrods&#x27; latest breach&lt;&#x2F;h3&gt;
&lt;p&gt;The luxury retailer Harrods said attackers reached around 430,000 customer records through a third-party supplier. The exposed data covered names and contact details, and the firm refused to deal with the attackers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;09&#x2F;29&#x2F;harrods_blames_thirdparty_supplier_after&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-what-we-know-about-the-cyberattack-that-hit-major-european-airports&quot;&gt;17. What we know about the cyberattack that hit major European airports&lt;&#x2F;h3&gt;
&lt;p&gt;A ransomware attack on Collins Aerospace check-in software disrupted Heathrow, Brussels, and Berlin airports for days. Staff fell back on manual processing, which led to long delays and many cancelled flights.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cnbc.com&#x2F;2025&#x2F;09&#x2F;21&#x2F;what-we-know-about-the-cyberattack-that-hit-major-european-airports.html&quot;&gt;www.cnbc.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-texas-expands-and-modifies-data-broker-registration-law&quot;&gt;18. Texas Expands and Modifies Data Broker Registration Law&lt;&#x2F;h3&gt;
&lt;p&gt;Amendments to the Texas Data Broker Act took effect on the first of the month, widening the definition of a data broker and changing who must register. The update reflects a broader push by states to track and limit the trade in personal data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.wilmerhale.com&#x2F;en&#x2F;insights&#x2F;blogs&#x2F;wilmerhale-privacy-and-cybersecurity-law&#x2F;20250904-texas-expands-and-modifies-data-broker-registration-law&quot;&gt;www.wilmerhale.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-microsoft-patch-tuesday-september-2025-edition&quot;&gt;19. Microsoft Patch Tuesday, September 2025 Edition&lt;&#x2F;h3&gt;
&lt;p&gt;Microsoft shipped fixes for more than 80 flaws, including several that attackers could use to seize control of a system. Prompt patching matters for privacy, since such bugs often open the door to data theft.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;09&#x2F;microsoft-patch-tuesday-september-2025-edition&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-farmers-insurance-data-breach-affects-1-1-million-customers&quot;&gt;20. Farmers Insurance Data Breach Affects 1.1 Million Customers&lt;&#x2F;h3&gt;
&lt;p&gt;Farmers Insurance said attackers reached the records of more than 1.1 million customers through its Salesforce platform rather than its own network. The breach was part of a wider wave of thefts that hit firms using the same cloud service.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;scamicide.com&#x2F;2025&#x2F;09&#x2F;21&#x2F;scam-of-the-day-september-22-2025-farmers-insurance-data-breach-affects-1-1-million-customers&#x2F;&quot;&gt;scamicide.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0229 • August 2025</title>
          <pubDate>Thu, 04 Sep 2025 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0229/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0229/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0229/">&lt;!-- Covered month: August 2025 (2025-08-01 to 2025-08-31) --&gt;
&lt;p&gt;August 2025 was dominated by a wave of Salesforce supply chain breaches, fresh fights over encryption and age checks, and court wins against intrusive data collection.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-google-confirms-data-theft-in-salesforce-attacks&quot;&gt;1. Google confirms data theft in Salesforce attacks&lt;&#x2F;h3&gt;
&lt;p&gt;Google said one of its Salesforce systems was breached by the ShinyHunters group, which tricked staff into handing over access. The stolen records held contact details for small and medium business customers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;google-suffers-data-breach-in-ongoing-salesforce-data-theft-attacks&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-transunion-breach-hits-4-4-million-people&quot;&gt;2. TransUnion breach hits 4.4 million people&lt;&#x2F;h3&gt;
&lt;p&gt;The credit reporting firm said hackers took names, addresses, dates of birth and Social Security numbers from its Salesforce account. No credit reports or core credit data were touched.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;08&#x2F;28&#x2F;transunion-says-hackers-stole-4-4-million-customers-personal-information&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-torture-victim-s-landmark-hacking-lawsuit-against-spyware-maker-can-proceed-judge-rules&quot;&gt;3. Torture Victim&#x27;s Landmark Hacking Lawsuit Against Spyware Maker Can Proceed, Judge Rules&lt;&#x2F;h3&gt;
&lt;p&gt;A federal judge in Oregon ruled that a Saudi activist may sue the spyware firm DarkMatter and three former executives for hacking her iPhone. The court let her claims proceed under the Computer Fraud and Abuse Act, the first time such a human rights case has gone this far.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;press&#x2F;releases&#x2F;torture-victims-landmark-hacking-lawsuit-against-spyware-maker-can-proceed-judge&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-workday-discloses-breach-after-salesforce-attacks&quot;&gt;4. Workday discloses breach after Salesforce attacks&lt;&#x2F;h3&gt;
&lt;p&gt;The HR software firm said attackers posing as IT staff tricked employees and reached a third party customer system. The thieves took business contact details such as names, email addresses and phone numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;hr-giant-workday-discloses-data-breach-amid-salesforce-attacks&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-salesloft-drift-breach-hits-more-than-700-firms&quot;&gt;5. Salesloft Drift breach hits more than 700 firms&lt;&#x2F;h3&gt;
&lt;p&gt;Google warned that stolen tokens for the Salesloft Drift tool let attackers raid Salesforce data at hundreds of organisations. The thieves searched the haul for passwords and cloud keys to reach further systems.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;thehackernews.com&#x2F;2025&#x2F;08&#x2F;google-warns-salesloft-oauth-breach.html&quot;&gt;thehackernews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-pandora-confirms-customer-data-breach&quot;&gt;6. Pandora confirms customer data breach&lt;&#x2F;h3&gt;
&lt;p&gt;The jewellery firm said names, dates of birth and email addresses were taken from its Salesforce database. The breach formed part of the same campaign of social engineering against support staff.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;pandora-confirms-data-breach-amid-ongoing-salesforce-data-theft-attacks&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-bouygues-telecom-breach-exposes-6-4-million&quot;&gt;7. Bouygues Telecom breach exposes 6.4 million&lt;&#x2F;h3&gt;
&lt;p&gt;The French operator said attackers reached the data of 6.4 million accounts, including contact details and bank account numbers. Card numbers and account passwords were not part of the theft.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;08&#x2F;07&#x2F;data-breach-at-french-telecom-giant-bouygues-affects-millions-of-customers&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-orange-belgium-breach-affects-850-000&quot;&gt;8. Orange Belgium breach affects 850,000&lt;&#x2F;h3&gt;
&lt;p&gt;The carrier said attackers took names, phone numbers, SIM card numbers and PUK codes from 850,000 customers. The exposed SIM and PUK data raised fears of SIM swap fraud.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.securityweek.com&#x2F;orange-belgium-data-breach-impacts-850000-customers&#x2F;&quot;&gt;www.securityweek.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-air-france-and-klm-disclose-customer-breach&quot;&gt;9. Air France and KLM disclose customer breach&lt;&#x2F;h3&gt;
&lt;p&gt;The airlines said attackers reached a third party support platform and took names, contact details and loyalty numbers. Passwords, passports and card data were not affected.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;air-france-and-klm-disclose-data-breaches-impacting-customers&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-farmers-insurance-breach-impacts-1-1-million&quot;&gt;10. Farmers Insurance breach impacts 1.1 million&lt;&#x2F;h3&gt;
&lt;p&gt;The insurer began notifying 1.1 million customers after a third party database tied to Salesforce was breached. The stolen data held names, dates of birth, driving licence numbers and partial Social Security numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;farmers-insurance-data-breach-impacts-11m-people-after-salesforce-attack&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-columbia-university-breach-hits-870-000-people&quot;&gt;11. Columbia University breach hits 870,000 people&lt;&#x2F;h3&gt;
&lt;p&gt;The university said a politically driven attacker took Social Security numbers, financial aid records and some health data. The breach reached students, applicants, alumni and staff.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.insidehighered.com&#x2F;news&#x2F;tech-innovation&#x2F;administrative-tech&#x2F;2025&#x2F;08&#x2F;12&#x2F;hack-columbia-university-hits-870k-people&quot;&gt;www.insidehighered.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-connex-credit-union-breach-exposes-172-000&quot;&gt;12. Connex Credit Union breach exposes 172,000&lt;&#x2F;h3&gt;
&lt;p&gt;The Connecticut lender said attackers reached files holding names, account numbers, Social Security numbers and government identity details. Members were told two months after the intrusion.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.infosecurity-magazine.com&#x2F;news&#x2F;connex-credit-union-breach&#x2F;&quot;&gt;www.infosecurity-magazine.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-pennsylvania-attorney-general-confirms-ransomware-breach&quot;&gt;13. Pennsylvania Attorney General confirms ransomware breach&lt;&#x2F;h3&gt;
&lt;p&gt;The office said a ransomware attack exposed Social Security numbers and medical information. The attack knocked out email, phones and case systems for about three weeks.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;pennsylvania-attorney-general-office-data-breach-ssns&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-women-sue-tea-app-after-data-leak&quot;&gt;14. Women sue Tea app after data leak&lt;&#x2F;h3&gt;
&lt;p&gt;Users of the women only dating safety app filed class actions after a breach spilled photos, identity documents and private chats. The leaked records led to online harassment of the women involved.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.washingtonpost.com&#x2F;nation&#x2F;2025&#x2F;08&#x2F;06&#x2F;tea-dating-advice-app-hack-lawsuits&#x2F;&quot;&gt;www.washingtonpost.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-jury-finds-meta-broke-california-privacy-law-over-flo&quot;&gt;15. Jury finds Meta broke California privacy law over Flo&lt;&#x2F;h3&gt;
&lt;p&gt;A federal jury ruled that Meta unlawfully collected reproductive health data from users of the Flo period tracking app. The jury found Meta had no consent to gather the sensitive information for advertising.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;08&#x2F;05&#x2F;jury-rules-meta-violated-california-privacy-laws-by-collecting-menstrual-health-data-from-flo&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-uk-drops-its-apple-encryption-backdoor-demand&quot;&gt;16. UK drops its Apple encryption backdoor demand&lt;&#x2F;h3&gt;
&lt;p&gt;US officials said Britain agreed to abandon its secret order for Apple to provide access to encrypted files. The deal protects American users, though questions remained about UK customers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.nextgov.com&#x2F;cybersecurity&#x2F;2025&#x2F;08&#x2F;uk-agreed-drop-backdoor-encryption-demand-apple-dni-says&#x2F;407556&#x2F;&quot;&gt;www.nextgov.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-ftc-warns-firms-not-to-weaken-encryption-for-foreign-powers&quot;&gt;17. FTC warns firms not to weaken encryption for foreign powers&lt;&#x2F;h3&gt;
&lt;p&gt;The FTC chairman wrote to more than a dozen technology firms warning against censoring speech or breaking encryption to satisfy foreign laws. The letters named the UK Online Safety Act and Investigatory Powers Act as risks.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;ftc-warns-tech-giants-not-to-bow-to-foreign-pressure-on-encryption&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-security-researcher-maps-hundreds-of-teslamate-servers-spilling-tesla-vehicle-data&quot;&gt;18. Security researcher maps hundreds of TeslaMate servers spilling Tesla vehicle data&lt;&#x2F;h3&gt;
&lt;p&gt;A researcher found more than 1,300 self hosted TeslaMate dashboards exposed online without any password. The open servers leaked owners&#x27; location histories, charging habits and recent trips for anyone to read.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;08&#x2F;26&#x2F;security-researcher-maps-hundreds-of-teslamate-servers-spilling-tesla-vehicle-data&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-russian-government-hackers-said-to-be-behind-us-federal-court-filing-system-hack-report&quot;&gt;19. Russian government hackers said to be behind US federal court filing system hack: Report&lt;&#x2F;h3&gt;
&lt;p&gt;Reports said Russian state hackers breached the federal courts PACER and case filing systems and read sealed criminal records. The stolen files may have exposed the identities of confidential informants and other protected documents.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;08&#x2F;12&#x2F;russian-government-hackers-said-to-be-behind-us-federal-court-filing-system-hack-report&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-eu-chat-control-plan-heads-for-a-decisive-vote&quot;&gt;20. EU Chat Control plan heads for a decisive vote&lt;&#x2F;h3&gt;
&lt;p&gt;A Polish compromise to ease the deadlock over the EU message scanning law failed, leaving the proposal heading towards a Council vote. Critics warned that the plan still threatened encryption and mass surveillance.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;euperspectives.eu&#x2F;2025&#x2F;08&#x2F;eu-chat-control-heads-for-a-decisive-vote&#x2F;&quot;&gt;euperspectives.eu&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0228 • July 2025</title>
          <pubDate>Thu, 07 Aug 2025 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0228/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0228/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0228/">&lt;!-- Covered month: July 2025 (2025-07-01 to 2025-07-31) --&gt;
&lt;p&gt;July 2025 brought mass breaches, fresh age checks, and a clearer look at how governments and firms hoard our data.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-qantas-data-breach-could-affect-6-million-customers&quot;&gt;1. Qantas data breach could affect 6 million customers&lt;&#x2F;h3&gt;
&lt;p&gt;Qantas said attackers reached customer records through a third party platform used by one of its call centres. Names, email addresses, phone numbers and frequent flyer numbers were exposed for millions of people.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.helpnetsecurity.com&#x2F;2025&#x2F;07&#x2F;02&#x2F;qantas-cyber-incident-data-breach&#x2F;&quot;&gt;www.helpnetsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-weak-passwords-expose-data-on-tens-of-millions-of-mcdonald-s-job-seekers&quot;&gt;2. Weak passwords expose data on tens of millions of McDonald&#x27;s job seekers&lt;&#x2F;h3&gt;
&lt;p&gt;Researchers guessed the login for McDonald&#x27;s hiring chatbot and reached the records of about sixty four million applicants. The maker, Paradox.ai, had left a default username and password of &quot;123456&quot; in place.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;07&#x2F;poor-passwords-tattle-on-ai-hiring-bot-maker-paradox-ai&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-women-s-safety-app-tea-leaks-selfies-and-id-photos&quot;&gt;3. Women&#x27;s safety app Tea leaks selfies and ID photos&lt;&#x2F;h3&gt;
&lt;p&gt;A poorly secured store left about seventy two thousand images open, including selfies and government identity documents. The files spread to public forums, putting users at risk of harassment and fraud.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;chicago.suntimes.com&#x2F;technology&#x2F;2025&#x2F;07&#x2F;28&#x2F;womens-dating-safety-app-tea-data-breach-impacting-thousands-photos&quot;&gt;chicago.suntimes.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-uk-age-checks-for-adult-sites-begin-under-the-online-safety-act&quot;&gt;4. UK age checks for adult sites begin under the Online Safety Act&lt;&#x2F;h3&gt;
&lt;p&gt;From 25 July, sites serving adult content in the United Kingdom had to confirm that visitors are over eighteen. Critics warned that credit card and selfie checks force people to hand sensitive data to verification firms.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.thepinknews.com&#x2F;2025&#x2F;07&#x2F;24&#x2F;uk-online-safety-act-what-to-know-age-verification&#x2F;&quot;&gt;www.thepinknews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-meta-board-settles-cambridge-analytica-claims-for-190-million-dollars&quot;&gt;5. Meta board settles Cambridge Analytica claims for 190 million dollars&lt;&#x2F;h3&gt;
&lt;p&gt;Shareholders accused Mark Zuckerberg and other leaders of letting the firm break a privacy order with regulators. The two sides settled on the second day of trial, so the executives avoided giving evidence.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.npr.org&#x2F;2025&#x2F;07&#x2F;17&#x2F;nx-s1-5471574&#x2F;settlement-reached-in-investors-lawsuit-against-meta-ceo-mark-zuckerberg-and-other-company-leaders&quot;&gt;www.npr.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-eff-exposes-a-power-meter-mass-surveillance-scheme-in-sacramento&quot;&gt;6. EFF exposes a power meter mass surveillance scheme in Sacramento&lt;&#x2F;h3&gt;
&lt;p&gt;The local utility searched every customer&#x27;s energy data and passed more than thirty three thousand tips to police. EFF called the decade long programme an illegal search of private household records.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;07&#x2F;when-your-power-meter-becomes-tool-mass-surveillance&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-amazon-ring-revives-direct-police-requests-for-home-camera-footage&quot;&gt;7. Amazon Ring revives direct police requests for home camera footage&lt;&#x2F;h3&gt;
&lt;p&gt;Ring said police could again ask users for video and even request live access to home cameras. EFF warned this undoes earlier reforms and widens a network of private surveillance across neighbourhoods.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;07&#x2F;amazon-ring-cashes-techno-authoritarianism-and-mass-surveillance&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-police-arrest-the-suspected-administrator-of-the-xss-cybercrime-forum&quot;&gt;8. Police arrest the suspected administrator of the XSS cybercrime forum&lt;&#x2F;h3&gt;
&lt;p&gt;Ukrainian and French officers, backed by Europol, detained a man accused of running a forum with more than fifty thousand members. The site sold stolen data, malware and access to hacked systems.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.europol.europa.eu&#x2F;media-press&#x2F;newsroom&#x2F;news&#x2F;key-figure-behind-major-russian-speaking-cybercrime-forum-targeted-in-ukraine&quot;&gt;www.europol.europa.eu&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-schneier-weighs-encryption-backdoors-against-the-fourth-amendment&quot;&gt;9. Schneier weighs encryption backdoors against the Fourth Amendment&lt;&#x2F;h3&gt;
&lt;p&gt;Bruce Schneier reviewed a paper on the Dual_EC backdoor that the NSA pushed into security products. He asked whether secretly weakening encryption breaks the constitutional rule against unreasonable searches.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2025&#x2F;07&#x2F;encryption-backdoors-and-the-fourth-amendment.html&quot;&gt;www.schneier.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-a-doge-staffer-leaks-a-private-xai-key-from-a-sensitive-system&quot;&gt;10. A DOGE staffer leaks a private xAI key from a sensitive system&lt;&#x2F;h3&gt;
&lt;p&gt;Marko Elez, who held access to Treasury and Social Security data, published a working xAI key on a code site. The slip raised fresh doubts about how DOGE handles the personal records of Americans.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;07&#x2F;doge-denizen-marko-elez-leaked-api-key-for-xai&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-eff-urges-an-appeals-court-to-protect-taxpayer-privacy&quot;&gt;11. EFF urges an appeals court to protect taxpayer privacy&lt;&#x2F;h3&gt;
&lt;p&gt;EFF filed a brief against an arrangement that let the tax agency share protected records with immigration enforcement. It argued the deal breaks long standing limits on the use of tax data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;07&#x2F;eff-us-court-appeals-protect-taxpayer-privacy&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-eff-vows-to-fight-on-against-online-age-mandates&quot;&gt;12. EFF vows to fight on against online age mandates&lt;&#x2F;h3&gt;
&lt;p&gt;After the Supreme Court upheld a Texas age check law, EFF set out its plan to resist broader mandates. It warned that such rules strip away the right to read and speak without proving who you are.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;07&#x2F;despite-supreme-court-setback-eff-fights-against-online-age-mandates&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-investigation-maps-the-firm-behind-the-clothoff-nudify-app&quot;&gt;13. Investigation maps the firm behind the Clothoff nudify app&lt;&#x2F;h3&gt;
&lt;p&gt;A whistleblower told Der Spiegel that Clothoff runs a network of apps that turn ordinary photos into fake nudes. The operators hide their identity, even using AI to fake the face of the company chief.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;gigazine.net&#x2F;gsc_news&#x2F;en&#x2F;20250704-clothoff-nudify&#x2F;&quot;&gt;gigazine.net&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-schneier-collects-warnings-on-surveillance-in-his-july-newsletter&quot;&gt;14. Schneier collects warnings on surveillance in his July newsletter&lt;&#x2F;h3&gt;
&lt;p&gt;The Crypto-Gram issue gathered work on the near impossibility of human spying under constant digital tracking. It also noted that large language models could open a new front of intimate surveillance.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.schneier.com&#x2F;crypto-gram&#x2F;archives&#x2F;2025&#x2F;0715.html&quot;&gt;www.schneier.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-uk-police-charge-four-over-the-scattered-spider-ransom-group&quot;&gt;15. UK police charge four over the Scattered Spider ransom group&lt;&#x2F;h3&gt;
&lt;p&gt;British authorities charged four people tied to a crew blamed for attacks on major retailers. The group is known for tricking staff and stealing data to extort large payments.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;07&#x2F;uk-charges-four-in-scattered-spider-ransom-group&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-eff-cautions-that-zero-knowledge-proofs-cannot-save-digital-id&quot;&gt;16. EFF cautions that zero knowledge proofs cannot save digital ID&lt;&#x2F;h3&gt;
&lt;p&gt;The group argued that clever cryptography does not fix the risks built into mandatory digital identity. Age and identity checks still push people to share more data and lose the chance to stay anonymous.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;07&#x2F;zero-knowledge-proofs-alone-are-not-digital-id-solution-protecting-user-privacy&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-eff-says-dating-apps-must-learn-how-consent-works&quot;&gt;17. EFF says dating apps must learn how consent works&lt;&#x2F;h3&gt;
&lt;p&gt;EFF criticised dating services that feed personal profiles and messages into AI tools without asking users. It pressed firms to seek clear consent before mining the most private details of their members.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;07&#x2F;dating-apps-need-learn-how-consent-works&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-phishers-target-aviation-executives-to-scam-their-customers&quot;&gt;18. Phishers target aviation executives to scam their customers&lt;&#x2F;h3&gt;
&lt;p&gt;Krebs reported a scheme that hijacks executive email accounts in the aviation trade. The attackers then use that trust to redirect payments and steal money from suppliers and clients.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;07&#x2F;phishers-target-aviation-execs-to-scam-customers&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-microsoft-rushes-a-fix-for-attacks-on-a-sharepoint-zero-day&quot;&gt;19. Microsoft rushes a fix for attacks on a SharePoint zero day&lt;&#x2F;h3&gt;
&lt;p&gt;Microsoft released an emergency patch after attackers exploited a flaw in on premises SharePoint servers. The hole let intruders run code and reach data held inside many organisations.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;07&#x2F;microsoft-fix-targets-attacks-on-sharepoint-zero-day&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-big-tech-gives-a-mixed-response-to-treasury-sanctions&quot;&gt;20. Big Tech gives a mixed response to Treasury sanctions&lt;&#x2F;h3&gt;
&lt;p&gt;The government sanctioned a network that hosted scam and cybercrime operations abroad. Krebs found that major technology firms were slow and uneven in cutting off the named bad actors.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;07&#x2F;big-techs-mixed-response-to-u-s-treasury-sanctions&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0227 • June 2025</title>
          <pubDate>Thu, 03 Jul 2025 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0227/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0227/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0227/">&lt;!-- Covered month: June 2025 (2025-06-01 to 2025-06-30) --&gt;
&lt;p&gt;June 2025 brought record credential leaks, fresh spyware findings and a wave of state and court decisions that pushed surveillance deeper into everyday life.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-researchers-find-16-billion-login-records-exposed-online&quot;&gt;1. Researchers find 16 billion login records exposed online&lt;&#x2F;h3&gt;
&lt;p&gt;Cybernews reported thirty exposed datasets holding about 16 billion username and password pairs, most of them gathered by infostealer malware. The files covered accounts at Apple, Google, Facebook and many government services, though much of the data was recycled from older leaks.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;cybernews.com&#x2F;security&#x2F;billions-credentials-exposed-infostealers-data-leak&#x2F;&quot;&gt;cybernews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-meta-and-yandex-caught-tracking-android-users-through-localhost&quot;&gt;2. Meta and Yandex caught tracking Android users through localhost&lt;&#x2F;h3&gt;
&lt;p&gt;Researchers showed that Facebook, Instagram and Yandex apps quietly listened on local ports to link people&#x27;s web browsing to their real identities. Meta paused the technique within days of the disclosure, even during private browsing.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;06&#x2F;03&#x2F;meta_pauses_android_tracking_tech&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-supreme-court-upholds-texas-age-verification-law&quot;&gt;3. Supreme Court upholds Texas age verification law&lt;&#x2F;h3&gt;
&lt;p&gt;On 27 June the court ruled six to three that Texas may force adult websites to verify the age of every visitor. Critics warned that the decision burdens lawful speech and pushes people to hand over identity documents to access content.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;06&#x2F;todays-supreme-court-decision-age-verification-tramples-free-speech-and-undermines&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-ice-buys-a-tool-that-tracks-phones-across-whole-neighbourhoods&quot;&gt;4. ICE buys a tool that tracks phones across whole neighbourhoods&lt;&#x2F;h3&gt;
&lt;p&gt;Documents reviewed by 404 Media showed that Immigration and Customs Enforcement bought access to commercial location data drawn from hundreds of millions of phones. An internal legal analysis stated the agency could query the data without a warrant.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.404media.co&#x2F;inside-ices-tool-to-monitor-phones-in-entire-neighborhoods&#x2F;&quot;&gt;www.404media.co&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-citizen-lab-confirms-paragon-spyware-on-journalists-phones&quot;&gt;5. Citizen Lab confirms Paragon spyware on journalists&#x27; phones&lt;&#x2F;h3&gt;
&lt;p&gt;Forensic analysis confirmed that Paragon&#x27;s Graphite spyware infected the iPhones of an Italian reporter and another European journalist through a zero click attack. Apple had patched the flaw, which it tracked as CVE-2025-43200, in iOS 18.3.1.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;citizenlab.ca&#x2F;research&#x2F;first-forensic-confirmation-of-paragons-ios-mercenary-spyware-finds-journalists-targeted&#x2F;&quot;&gt;citizenlab.ca&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-court-approves-sale-of-23andme-and-its-dna-database&quot;&gt;6. Court approves sale of 23andMe and its DNA database&lt;&#x2F;h3&gt;
&lt;p&gt;A bankruptcy judge cleared the sale of 23andMe, including the genetic data of more than thirteen million customers, to a nonprofit led by founder Anne Wojcicki. More than two dozen states had sued to block the deal, arguing that genetic data is not ordinary property.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.npr.org&#x2F;2025&#x2F;06&#x2F;30&#x2F;nx-s1-5451398&#x2F;23andme-sale-approved-dna-data&quot;&gt;www.npr.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-cyberattack-on-unfi-empties-whole-foods-shelves&quot;&gt;7. Cyberattack on UNFI empties Whole Foods shelves&lt;&#x2F;h3&gt;
&lt;p&gt;United Natural Foods, the main distributor for Whole Foods and thousands of grocers, took systems offline after detecting an intrusion on 5 June. The outage disrupted deliveries for days and forced the company to warn of product shortages.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;06&#x2F;11&#x2F;whole-foods-tells-staff-cyberattack-at-its-primary-distributor-unfi-will-affect-product-availability&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-aflac-discloses-breach-in-wave-of-attacks-on-insurers&quot;&gt;8. Aflac discloses breach in wave of attacks on insurers&lt;&#x2F;h3&gt;
&lt;p&gt;Aflac said on 20 June that intruders had reached its United States network on 12 June and may have taken personal and health data. Investigators tied the social engineering attack to the broader campaign against American insurers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;aflac-discloses-breach-amidst-scattered-spider-insurance-attacks&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-eff-warns-the-eu-encryption-roadmap-makes-everyone-less-safe&quot;&gt;9. EFF warns the EU encryption roadmap makes everyone less safe&lt;&#x2F;h3&gt;
&lt;p&gt;The European Commission set out a plan to give police a way to read encrypted communications by 2030, part of its ProtectEU strategy. More than eighty groups and experts signed a letter saying any backdoor weakens security for all users.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;06&#x2F;eus-encryption-roadmap-makes-everyone-less-safe&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-germany-fines-vodafone-45-million-euros-over-data-failings&quot;&gt;10. Germany fines Vodafone 45 million euros over data failings&lt;&#x2F;h3&gt;
&lt;p&gt;The federal data protection regulator imposed two fines on Vodafone on 3 June for poor oversight of sales agents and weak customer verification. The penalties followed fraud cases and security flaws in the company&#x27;s online portal and hotline.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bfdi.bund.de&#x2F;SharedDocs&#x2F;Pressemitteilungen&#x2F;EN&#x2F;2025&#x2F;06_Geldbu%C3%9Fe-Vodafone.html&quot;&gt;www.bfdi.bund.de&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-predator-spyware-rebuilds-its-hidden-infrastructure&quot;&gt;11. Predator spyware rebuilds its hidden infrastructure&lt;&#x2F;h3&gt;
&lt;p&gt;Insikt Group reported on 12 June that operators of Predator spyware had expanded their network to five layers to hide its origin. The researchers also found a previously unknown customer in Mozambique, despite earlier sanctions on the makers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;new-predator-spyware-infrastructure-identified&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-meta-brings-targeted-advertisements-to-whatsapp&quot;&gt;12. Meta brings targeted advertisements to WhatsApp&lt;&#x2F;h3&gt;
&lt;p&gt;On 16 June Meta said it would place ads in the Updates tab of WhatsApp, using data such as location, language and channels followed. Privacy groups said any advertising built on personal data is a problem, even in an encrypted app.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.washingtonpost.com&#x2F;politics&#x2F;2025&#x2F;06&#x2F;17&#x2F;meta-whatsapp-ads-privacy-antitrust&#x2F;&quot;&gt;www.washingtonpost.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-health-firm-episource-reports-breach-affecting-5-4-million&quot;&gt;13. Health firm Episource reports breach affecting 5.4 million&lt;&#x2F;h3&gt;
&lt;p&gt;Episource, which handles medical coding and risk work for health plans, disclosed that intruders took the records of about 5.4 million people. The stolen files included names, Social Security numbers, diagnoses and treatment details.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.securityweek.com&#x2F;data-breach-at-healthcare-services-firm-episource-impacts-5-4-million-people&#x2F;&quot;&gt;www.securityweek.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-zoomcar-breach-exposes-8-4-million-users&quot;&gt;14. Zoomcar breach exposes 8.4 million users&lt;&#x2F;h3&gt;
&lt;p&gt;The car sharing firm told the United States Securities and Exchange Commission on 17 June that an intruder had reached the data of about 8.4 million users. The exposed records held names, phone numbers, addresses and car registration details.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;zoomcar-discloses-security-breach-impacting-84-million-users&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-privacy-groups-find-data-brokers-skip-state-registration&quot;&gt;15. Privacy groups find data brokers skip state registration&lt;&#x2F;h3&gt;
&lt;p&gt;A joint study by EFF and Privacy Rights Clearinghouse found that hundreds of data brokers registered in one state but not in others. The groups urged regulators to check whether the gaps point to widespread non compliance.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;06&#x2F;why-are-hundreds-data-brokers-not-registering-states&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-nso-group-appeals-the-168-million-dollar-whatsapp-award&quot;&gt;16. NSO Group appeals the 168 million dollar WhatsApp award&lt;&#x2F;h3&gt;
&lt;p&gt;The spyware maker asked the court to cut the damages or grant a new trial after a jury found it liable for hacking 1,400 WhatsApp users. NSO argued it could not pay the punitive award handed down in May.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;nso-group-appeals-jury-award-168million-&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-eff-says-flock-safety-updates-cannot-make-plate-readers-safe&quot;&gt;17. EFF says Flock Safety updates cannot make plate readers safe&lt;&#x2F;h3&gt;
&lt;p&gt;Flock Safety promised new privacy controls for its number plate cameras after public pressure. EFF argued that the firm&#x27;s national, linked surveillance network is the real problem, and no setting can fix it.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;06&#x2F;flock-safetys-feature-updates-cannot-make-automated-license-plate-readers-safe&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-ransomware-attack-at-mclaren-health-care-hits-743-000-people&quot;&gt;18. Ransomware attack at McLaren Health Care hits 743,000 people&lt;&#x2F;h3&gt;
&lt;p&gt;The Michigan health system began notifying about 743,000 patients on 20 June about a breach traced to a 2024 ransomware attack. The stolen files held names, Social Security numbers, driving licence numbers and medical details.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;06&#x2F;23&#x2F;second_suspected_ransomware_attack_on&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-android-16-adds-an-advanced-protection-mode&quot;&gt;19. Android 16 adds an Advanced Protection mode&lt;&#x2F;h3&gt;
&lt;p&gt;Google shipped Android 16 with a single setting that gathers its strongest security and privacy tools in one place. EFF said people at higher risk, such as journalists and activists, should consider turning it on.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;06&#x2F;googles-advanced-protection-arrives-android-should-you-use-it&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-eff-publishes-its-2025-who-has-your-back-report&quot;&gt;20. EFF publishes its 2025 Who Has Your Back report&lt;&#x2F;h3&gt;
&lt;p&gt;The annual report graded twenty four companies on how well they tell users about government data requests and disclose retention policies. Nine firms, among them Apple, Adobe and Dropbox, earned a star in every category open to them.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;press&#x2F;releases&#x2F;eff-report-charts-companies-next-frontier-user-privacy&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0226 • May 2025</title>
          <pubDate>Thu, 05 Jun 2025 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0226/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0226/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0226/">&lt;!-- Covered month: May 2025 (2025-05-01 to 2025-05-31) --&gt;
&lt;p&gt;May 2025 brought record fines, insider breaches and government surveillance contracts that showed how data brokers, Big Tech and encryption sit at the centre of the privacy fight.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-ireland-fines-tiktok-530-million-euro-for-sending-eu-data-to-china&quot;&gt;1. Ireland fines TikTok 530 million euro for sending EU data to China&lt;&#x2F;h3&gt;
&lt;p&gt;The Irish Data Protection Commission imposed a 530 million euro penalty on TikTok for unlawfully transferring European user data to servers in China and for failing to tell users where their data went. The regulator also ordered the company to bring its processing into line within six months.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cnbc.com&#x2F;2025&#x2F;05&#x2F;02&#x2F;ireland-fines-tiktok-530-million-for-sending-eu-user-data-to-china.html&quot;&gt;www.cnbc.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-telemessage-a-modified-signal-clone-used-by-us-officials-is-hacked&quot;&gt;2. TeleMessage, a modified Signal clone used by US officials, is hacked&lt;&#x2F;h3&gt;
&lt;p&gt;A hacker breached TeleMessage, the modified Signal app used by former national security adviser Mike Waltz, and extracted archived messages, contact details and login credentials. The breach showed that the archived chats were not end-to-end encrypted, contradicting the company&#x27;s marketing.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;05&#x2F;05&#x2F;telemessage-a-modified-signal-clone-used-by-us-government-officials-has-been-hacked&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-google-agrees-to-pay-texas-1-375-billion-dollars-over-tracking-claims&quot;&gt;3. Google agrees to pay Texas 1.375 billion dollars over tracking claims&lt;&#x2F;h3&gt;
&lt;p&gt;Google settled two lawsuits brought by the Texas attorney general for 1.375 billion dollars, the largest such state settlement to date. The suits accused the company of tracking users&#x27; location, incognito searches and biometric data without consent.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;05&#x2F;10&#x2F;google-will-pay-texas-1-4-billion-to-settle-privacy-lawsuits&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-coinbase-refuses-20-million-dollar-ransom-after-insider-breach&quot;&gt;4. Coinbase refuses 20 million dollar ransom after insider breach&lt;&#x2F;h3&gt;
&lt;p&gt;Coinbase disclosed that bribed overseas support contractors copied the data of nearly 70,000 customers, including names, contact details and partial identity documents. The company refused a 20 million dollar extortion demand and offered the same sum as a reward for information on the attackers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.coinbase.com&#x2F;blog&#x2F;protecting-our-customers-standing-up-to-extortionists&quot;&gt;www.coinbase.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-marks-and-spencer-confirms-customer-data-stolen-in-cyber-attack&quot;&gt;5. Marks and Spencer confirms customer data stolen in cyber-attack&lt;&#x2F;h3&gt;
&lt;p&gt;Marks and Spencer confirmed that attackers, linked to the Scattered Spider group, had stolen customer data during an attack that crippled its online operations. The exposed records included names, addresses, dates of birth and order histories, though the retailer said no usable payment details were held on its systems.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.infosecurity-magazine.com&#x2F;news&#x2F;ms-customer-data-stolen-attack&#x2F;&quot;&gt;www.infosecurity-magazine.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-trump-signs-the-take-it-down-act-into-law&quot;&gt;6. Trump signs the TAKE IT DOWN Act into law&lt;&#x2F;h3&gt;
&lt;p&gt;President Trump signed the TAKE IT DOWN Act, which criminalises nonconsensual intimate imagery and forces platforms to remove flagged content within 48 hours. Digital rights groups warned that the vague language and tight deadline could pressure providers to over-remove content and weaken end-to-end encryption.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cnn.com&#x2F;2025&#x2F;05&#x2F;19&#x2F;tech&#x2F;ai-explicit-deepfakes-trump-sign-take-it-down-act&quot;&gt;www.cnn.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-regeneron-wins-bid-to-buy-23andme-and-its-dna-trove&quot;&gt;7. Regeneron wins bid to buy 23andMe and its DNA trove&lt;&#x2F;h3&gt;
&lt;p&gt;Drugmaker Regeneron agreed to buy bankrupt 23andMe for 256 million dollars, gaining access to the genetic data of more than 15 million customers. The sale raised fresh concern about what happens to deeply sensitive DNA records when a company collapses.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cnn.com&#x2F;2025&#x2F;05&#x2F;19&#x2F;business&#x2F;regeneron-23-and-me&quot;&gt;www.cnn.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-lexisnexis-says-breach-exposed-data-of-364-000-people&quot;&gt;8. LexisNexis says breach exposed data of 364,000 people&lt;&#x2F;h3&gt;
&lt;p&gt;Data broker LexisNexis Risk Solutions disclosed that an attacker had accessed a GitHub account and exposed the records of more than 364,000 individuals. The stolen data included names, dates of birth, addresses, Social Security numbers and driver licence numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;05&#x2F;28&#x2F;data-broker-giant-lexisnexis-says-breach-exposed-personal-information-of-over-364000-people&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-signal-blocks-microsoft-recall-from-screenshotting-chats&quot;&gt;9. Signal blocks Microsoft Recall from screenshotting chats&lt;&#x2F;h3&gt;
&lt;p&gt;Signal added a screen security setting to its Windows desktop app that uses digital rights management flags to stop Microsoft Recall from capturing conversations. The company said Recall still placed content from privacy apps at risk despite a year of Microsoft adjustments.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;05&#x2F;22&#x2F;signal_microsoft_recall&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-meta-begins-training-ai-on-public-posts-from-eu-users&quot;&gt;10. Meta begins training AI on public posts from EU users&lt;&#x2F;h3&gt;
&lt;p&gt;Meta started using public posts and comments from adult European users to train its AI systems after the Irish regulator allowed the plan to proceed. Privacy advocates in several countries criticised the move and the opt-out mechanism offered to users.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;04&#x2F;15&#x2F;meta_resume_ai_training_eu_user_posts&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-uk-legal-aid-agency-breach-exposes-years-of-applicant-data&quot;&gt;11. UK Legal Aid Agency breach exposes years of applicant data&lt;&#x2F;h3&gt;
&lt;p&gt;The UK Legal Aid Agency revealed that attackers had downloaded a large volume of data on people who applied for legal aid between 2007 and May 2025. The exposed records may have included contact details, criminal history, national identity numbers and financial information.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.gov.uk&#x2F;government&#x2F;news&#x2F;legal-aid-agency-data-breach&quot;&gt;www.gov.uk&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-ascension-notifies-437-000-patients-of-a-third-party-breach&quot;&gt;12. Ascension notifies 437,000 patients of a third-party breach&lt;&#x2F;h3&gt;
&lt;p&gt;Ascension told more than 437,000 patients that their data had likely been stolen through a hacked former business partner. The exposed information included names, Social Security numbers, health insurance details and clinical records.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.securityweek.com&#x2F;437000-impacted-by-ascension-health-data-breach&#x2F;&quot;&gt;www.securityweek.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-adidas-discloses-breach-through-a-customer-service-provider&quot;&gt;13. Adidas discloses breach through a customer service provider&lt;&#x2F;h3&gt;
&lt;p&gt;Adidas disclosed that an unauthorised party had obtained consumer data through a third-party customer service provider. The affected records included names, email addresses, phone numbers, postal addresses and dates of birth, though no payment data was involved.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.computerweekly.com&#x2F;news&#x2F;366624963&#x2F;Adidas-confirms-customer-data-was-accessed-during-cyber-attack&quot;&gt;www.computerweekly.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-dior-discloses-cyberattack-and-warns-customers-of-data-breach&quot;&gt;14. Dior discloses cyberattack and warns customers of data breach&lt;&#x2F;h3&gt;
&lt;p&gt;Fashion house Dior disclosed that attackers had accessed a database holding customer contact details, postal addresses and purchase histories. The company said no passwords or payment information were exposed and began notifying affected customers in China and South Korea.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;fashion-giant-dior-discloses-cyberattack-warns-of-data-breach&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-krebsonsecurity-hit-with-near-record-6-3-terabit-ddos&quot;&gt;15. KrebsOnSecurity hit with near-record 6.3 terabit DDoS&lt;&#x2F;h3&gt;
&lt;p&gt;Security writer Brian Krebs reported that his site had been struck by a 6.3 terabit per second denial-of-service attack, the largest Google had ever handled. The traffic came from the Aisuru botnet, which assembles compromised home and Internet of Things devices.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;05&#x2F;krebsonsecurity-hit-with-near-record-6-3-tbps-ddos&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-xai-developer-leaks-api-key-for-private-spacex-and-tesla-models&quot;&gt;16. xAI developer leaks API key for private SpaceX and Tesla models&lt;&#x2F;h3&gt;
&lt;p&gt;An xAI developer exposed a private API key on GitHub that granted access to dozens of fine-tuned models trained on internal data from SpaceX, Tesla and X. The key stayed live for about two months despite an early warning, raising fresh concerns about how Musk&#x27;s companies handle sensitive data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;05&#x2F;xai-dev-leaks-api-key-for-private-spacex-tesla-llms&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-ftc-finalises-order-against-godaddy-over-data-security-failures&quot;&gt;17. FTC finalises order against GoDaddy over data security failures&lt;&#x2F;h3&gt;
&lt;p&gt;The Federal Trade Commission finalised a consent order requiring GoDaddy to build a proper information security programme after years of weak protections led to several breaches. The order also bars the company from misrepresenting its security to customers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2025&#x2F;05&#x2F;ftc-finalizes-order-godaddy-over-data-security-failures&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-montana-becomes-first-state-to-close-the-data-broker-loophole&quot;&gt;18. Montana becomes first state to close the data broker loophole&lt;&#x2F;h3&gt;
&lt;p&gt;Montana enacted a law that bars law enforcement from buying sensitive personal data, including location and communications records, from data brokers. Police must now obtain a warrant, consent or a subpoena to access the kinds of data they could previously simply purchase.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;05&#x2F;montana-becomes-first-state-close-law-enforcement-data-broker-loophole&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-german-court-refuses-to-halt-meta-ai-training-on-user-data&quot;&gt;19. German court refuses to halt Meta AI training on user data&lt;&#x2F;h3&gt;
&lt;p&gt;The Higher Regional Court of Cologne dismissed a consumer group&#x27;s request for an injunction against Meta over the use of public posts to train its AI models. The court found that Meta&#x27;s interest in processing the data outweighed the interests of the users affected.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.taylorwessing.com&#x2F;en&#x2F;insights-and-events&#x2F;insights&#x2F;2025&#x2F;05&#x2F;meta-vs-verbraucherzentrale-nrw&quot;&gt;www.taylorwessing.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-jury-orders-nso-group-to-pay-168-million-dollars-over-whatsapp-hacks&quot;&gt;20. Jury orders NSO Group to pay 168 million dollars over WhatsApp hacks&lt;&#x2F;h3&gt;
&lt;p&gt;A California jury ordered spyware maker NSO Group to pay Meta about 168 million dollars for enabling Pegasus attacks on roughly 1,400 WhatsApp users. The verdict was a rare courtroom defeat for the commercial spyware industry, which has long shielded itself from accountability.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;05&#x2F;06&#x2F;nso_group_meta_verdict&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0225 • April 2025</title>
          <pubDate>Thu, 01 May 2025 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0225/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0225/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0225/">&lt;!-- Covered month: April 2025 (2025-04-01 to 2025-04-30) --&gt;
&lt;p&gt;April 2025 saw Europe land its first Digital Markets Act fines on Apple and Meta, a run of large health and corporate breaches, and fresh fights over encryption, location tracking and government access to data.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-european-commission-fines-apple-500-million-euros-under-the-digital-markets-act&quot;&gt;1. European Commission fines Apple 500 million euros under the Digital Markets Act&lt;&#x2F;h3&gt;
&lt;p&gt;On 23 April the Commission found that Apple breached its anti-steering obligation by stopping developers from telling users about cheaper offers outside the App Store. It was the first fine ever issued under the Digital Markets Act and gave Apple sixty days to comply.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;digital-markets-act.ec.europa.eu&#x2F;commission-finds-apple-and-meta-breach-digital-markets-act-2025-04-23_en&quot;&gt;digital-markets-act.ec.europa.eu&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-meta-fined-200-million-euros-over-its-pay-or-consent-advertising-model&quot;&gt;2. Meta fined 200 million euros over its pay-or-consent advertising model&lt;&#x2F;h3&gt;
&lt;p&gt;The same day, the Commission ruled that Meta&#x27;s &quot;consent or pay&quot; choice did not give users a genuine option to refuse the combination of their personal data across services. Meta was ordered to change the model or face further penalties of up to five per cent of daily turnover.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.taylorwessing.com&#x2F;en&#x2F;insights-and-events&#x2F;insights&#x2F;2025&#x2F;04&#x2F;meta-fined-200-million-euro-by-eu-under-digital-markets-act&quot;&gt;www.taylorwessing.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-uk-tribunal-blocks-government-attempt-to-keep-the-apple-encryption-case-secret&quot;&gt;3. UK tribunal blocks government attempt to keep the Apple encryption case secret&lt;&#x2F;h3&gt;
&lt;p&gt;On 7 April the Investigatory Powers Tribunal refused the Home Office request to hold its case against Apple entirely behind closed doors. The judges called the secrecy bid a fundamental interference with the principle of open justice.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.computerweekly.com&#x2F;news&#x2F;366622253&#x2F;Court-rejects-Home-Office-bid-for-blanket-secrecy-in-hearings-over-Apple-encryption-case&quot;&gt;www.computerweekly.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-blue-shield-of-california-shared-the-health-data-of-4-7-million-members-with-google&quot;&gt;4. Blue Shield of California shared the health data of 4.7 million members with Google&lt;&#x2F;h3&gt;
&lt;p&gt;The insurer disclosed that a Google Analytics misconfiguration had leaked member information to Google Ads from April 2021 until January 2024. The exposed details included plan types, doctor searches, postal codes and account identifiers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;04&#x2F;23&#x2F;blue-shield-of-california-shared-the-private-health-data-of-millions-with-google-for-years&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-davita-confirms-a-ransomware-attack-on-its-dialysis-network&quot;&gt;5. DaVita confirms a ransomware attack on its dialysis network&lt;&#x2F;h3&gt;
&lt;p&gt;The kidney care provider detected and contained the intrusion on 12 April after attackers encrypted part of its systems and stole data. The breach later turned out to affect about 2.7 million people, including names, Social Security numbers and clinical records.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.healthcare-brew.com&#x2F;stories&#x2F;2025&#x2F;04&#x2F;29&#x2F;davita-hack-patient-care-exposed-data&quot;&gt;www.healthcare-brew.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-hertz-discloses-a-breach-tied-to-flaws-in-cleo-file-transfer-software&quot;&gt;6. Hertz discloses a breach tied to flaws in Cleo file transfer software&lt;&#x2F;h3&gt;
&lt;p&gt;On 14 April Hertz began notifying customers across its Hertz, Dollar and Thrifty brands that their data had been taken through vulnerabilities in a vendor platform. Exposed records included names, contact details, driving licences and, for some, Social Security and passport numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.securityweek.com&#x2F;hertz-discloses-data-breach-linked-to-cleo-hack&#x2F;&quot;&gt;www.securityweek.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-4chan-taken-offline-after-a-major-hack-leaks-source-code-and-moderator-emails&quot;&gt;7. 4chan taken offline after a major hack leaks source code and moderator emails&lt;&#x2F;h3&gt;
&lt;p&gt;On 15 April the imageboard went dark after attackers from a rival forum claimed to have lived inside its systems for over a year. The leak exposed the site&#x27;s PHP source code, internal admin panels and the email addresses of roughly 218 moderators and staff.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;04&#x2F;15&#x2F;notorious-image-board-4chan-hacked-and-internal-data-leaked&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-whistleblower-says-doge-siphoned-sensitive-case-data-from-the-labour-board&quot;&gt;8. Whistleblower says DOGE siphoned sensitive case data from the labour board&lt;&#x2F;h3&gt;
&lt;p&gt;A security architect told Congress that he watched gigabytes of data leave the National Labor Relations Board after DOGE staff demanded top-level access. The records can hold confidential information about union organisers and proprietary business data, and the outflows coincided with login attempts from a Russian address.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;04&#x2F;whistleblower-doge-siphoned-nlrb-case-data&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-florida-advances-a-social-media-bill-demanding-an-encryption-backdoor&quot;&gt;9. Florida advances a social media bill demanding an encryption backdoor&lt;&#x2F;h3&gt;
&lt;p&gt;Florida&#x27;s SB 868 would force platforms to decrypt minors&#x27; messages on receipt of a subpoena, saying the quiet part out loud about breaking end-to-end encryption. The EFF warned that there is no way to build such access without leaving everyone less safe.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;04&#x2F;floridas-new-social-media-bill-says-quiet-part-out-loud-and-demands-encryption&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-google-abandons-its-plan-to-phase-out-third-party-cookies-in-chrome&quot;&gt;10. Google abandons its plan to phase out third-party cookies in Chrome&lt;&#x2F;h3&gt;
&lt;p&gt;On 22 April Google said it would not even show users a choice prompt and would keep third-party cookies working as they do now. The reversal ended a five-year effort that had already slipped past several deadlines.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.onetrust.com&#x2F;blog&#x2F;google-drops-plans-for-third-party-cookie-choice-prompt-in-chrome&#x2F;&quot;&gt;www.onetrust.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-eff-tells-congress-what-a-strong-federal-privacy-law-should-contain&quot;&gt;11. EFF tells Congress what a strong federal privacy law should contain&lt;&#x2F;h3&gt;
&lt;p&gt;Responding to a House working group, the EFF set out priorities including data minimisation, opt-in consent and a ban on behavioural advertising. It put a private right of action at the top of the list, arguing that people must be able to sue companies that abuse their data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;04&#x2F;eff-congress-heres-what-strong-privacy-law-looks&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-states-move-to-shield-location-data-from-surveillance&quot;&gt;12. States move to shield location data from surveillance&lt;&#x2F;h3&gt;
&lt;p&gt;The EFF mapped how California, Massachusetts, Illinois and other states are passing laws to limit tracking of people&#x27;s movements. The piece highlighted tools such as Locate X that can follow a phone as its owner travels to seek reproductive healthcare.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;04&#x2F;privacy-map-how-states-are-fighting-location-surveillance&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-cisa-warns-of-credential-risk-after-a-legacy-oracle-cloud-breach&quot;&gt;13. CISA warns of credential risk after a legacy Oracle cloud breach&lt;&#x2F;h3&gt;
&lt;p&gt;On 16 April the US cyber agency issued guidance after a hacker stole old login credentials from a legacy Oracle environment. Oracle had publicly played down the incident even as it privately told customers their data was taken.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cisa.gov&#x2F;news-events&#x2F;alerts&#x2F;2025&#x2F;04&#x2F;16&#x2F;cisa-releases-guidance-credential-risks-associated-potential-legacy-oracle-cloud-compromise&quot;&gt;www.cisa.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-texas-court-dismisses-the-state-privacy-case-against-allstate-and-arity&quot;&gt;14. Texas court dismisses the state privacy case against Allstate and Arity&lt;&#x2F;h3&gt;
&lt;p&gt;On 10 April a judge ruled that Texas lacked jurisdiction over Allstate and its analytics subsidiary Arity. The state had accused them of turning ordinary phone apps into covert trackers that logged the driving routes of millions of people.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.mlex.com&#x2F;mlex&#x2F;articles&#x2F;2326565&#x2F;texas-court-lacks-jurisdiction-over-allstate-subsidiary-judge-says-in-location-privacy-suit&quot;&gt;www.mlex.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-marks-spencer-confirms-a-ransomware-attack-that-stole-customer-data&quot;&gt;15. Marks &amp;amp; Spencer confirms a ransomware attack that stole customer data&lt;&#x2F;h3&gt;
&lt;p&gt;The retailer admitted that attackers had used social engineering against a contractor before launching ransomware that crippled its systems. Stolen information included names, addresses and order histories, and the firm warned the disruption would cost it hundreds of millions of pounds.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cybersecuritydive.com&#x2F;news&#x2F;ms-hackers-customer-data-cyberattack&#x2F;747956&#x2F;&quot;&gt;www.cybersecuritydive.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-eight-state-regulators-form-a-bipartisan-privacy-enforcement-consortium&quot;&gt;16. Eight state regulators form a bipartisan privacy enforcement consortium&lt;&#x2F;h3&gt;
&lt;p&gt;On 16 April California&#x27;s privacy agency and seven state attorneys general announced a memorandum to coordinate investigations and share resources. The Consortium of Privacy Regulators marks a shift towards joined-up enforcement of state privacy laws.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.maynardnexsen.com&#x2F;publication-seven-state-ags-and-cppa-form-privacy-regulatory-consortium&quot;&gt;www.maynardnexsen.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-photo-shows-a-senior-official-using-a-modified-signal-clone-that-archives-messages&quot;&gt;17. Photo shows a senior official using a modified Signal clone that archives messages&lt;&#x2F;h3&gt;
&lt;p&gt;A Reuters photograph from a 30 April cabinet meeting appeared to show national security adviser Mike Waltz using TeleMessage, an app that clones Signal but stores copies of chats. Security researchers warned that such archiving undermines the very end-to-end encryption Signal provides.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.nbcnews.com&#x2F;tech&#x2F;security&#x2F;photo-appears-shows-mike-waltz-using-signal-app-can-archive-messages-rcna204434&quot;&gt;www.nbcnews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-us-rule-restricting-bulk-transfers-of-sensitive-personal-data-takes-effect&quot;&gt;18. US rule restricting bulk transfers of sensitive personal data takes effect&lt;&#x2F;h3&gt;
&lt;p&gt;On 8 April the Justice Department&#x27;s rule under Executive Order 14117 came into force, curbing sales of bulk sensitive American data to countries of concern. The named states include China, Russia, Iran and North Korea.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.reedsmith.com&#x2F;articles&#x2F;dojs-final-rule-on-preventing-access-to-us-sensitive-personal-data&#x2F;&quot;&gt;www.reedsmith.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-ofcom-consults-on-widening-its-online-safety-enforcement-codes&quot;&gt;19. Ofcom consults on widening its online safety enforcement codes&lt;&#x2F;h3&gt;
&lt;p&gt;On 24 April the UK regulator opened a consultation on expanding measures such as account blocking and disabling comments. The move came as platforms faced new duties to assess and reduce risks to children.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ofcom.org.uk&#x2F;online-safety&#x2F;illegal-and-harmful-content&#x2F;roadmap-to-regulation&quot;&gt;www.ofcom.org.uk&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-yale-new-haven-health-notifies-5-5-million-patients-of-a-data-breach&quot;&gt;20. Yale New Haven Health notifies 5.5 million patients of a data breach&lt;&#x2F;h3&gt;
&lt;p&gt;The Connecticut system disclosed that an intruder had accessed its network in March and exfiltrated files holding patient information. The records could include names, Social Security numbers, dates of birth and medical record numbers, making it the year&#x27;s largest healthcare breach so far.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;04&#x2F;25&#x2F;data-breach-at-connecticut-yale-new-haven-health-affects-over-5-million&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0224 • March 2025</title>
          <pubDate>Thu, 03 Apr 2025 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0224/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0224/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0224/">&lt;!-- Covered month: March 2025 (2025-03-01 to 2025-03-31) --&gt;
&lt;p&gt;March 2025 was dominated by encryption fights, a wave of breach disclosures and a sharp rise in government and corporate data grabs.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-mozilla-rewrites-firefox-s-terms-of-use-after-a-user-backlash&quot;&gt;1. Mozilla rewrites Firefox&#x27;s terms of use after a user backlash&lt;&#x2F;h3&gt;
&lt;p&gt;Mozilla revised the new Firefox Terms of Use within days of publishing them, after the original wording appeared to grant the company a broad licence over anything users typed or uploaded. It also quietly dropped its longstanding promise never to sell personal data, citing the shifting legal definition of a sale.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;03&#x2F;03&#x2F;mozilla-rewrites-firefoxs-terms-of-use-after-user-backlash&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-apple-takes-the-uk-government-to-a-secret-surveillance-tribunal&quot;&gt;2. Apple takes the UK government to a secret surveillance tribunal&lt;&#x2F;h3&gt;
&lt;p&gt;Apple lodged a complaint with the Investigatory Powers Tribunal over a Technical Capability Notice that orders it to break the encryption protecting iCloud data. The case is the first of its kind brought before the tribunal, and followed Apple withdrawing Advanced Data Protection from British users.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;03&#x2F;05&#x2F;apple_reportedly_ipt_complaint&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-age-verification-bills-spread-from-pornography-to-skin-cream&quot;&gt;3. Age verification bills spread from pornography to skin cream&lt;&#x2F;h3&gt;
&lt;p&gt;The Electronic Frontier Foundation warned that age verification mandates have spread far beyond adult websites to cover skincare products, dating apps and diet pills. It argued that no method of age checking is both accurate and private, and that each one forces everyone to hand over sensitive data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;03&#x2F;first-porn-now-skin-cream-age-verification-bills-are-out-control&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-lawsuit-details-how-doge-pushed-into-social-security-systems&quot;&gt;4. Lawsuit details how DOGE pushed into Social Security systems&lt;&#x2F;h3&gt;
&lt;p&gt;A lawsuit brought by unions and advocacy groups set out how the Department of Government Efficiency pressed Social Security officials to grant sweeping access to sensitive systems. A sworn declaration described staff being told to admit DOGE personnel before background checks were complete, in apparent breach of the Privacy Act.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.nextgov.com&#x2F;people&#x2F;2025&#x2F;03&#x2F;lawsuit-outlines-how-doge-pushed-access-social-security-systems-and-data&#x2F;403630&#x2F;&quot;&gt;www.nextgov.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-x-suffers-a-major-outage-and-disputes-who-was-behind-it&quot;&gt;5. X suffers a major outage and disputes who was behind it&lt;&#x2F;h3&gt;
&lt;p&gt;X was knocked offline by a distributed denial of service attack, with a group calling itself Dark Storm claiming responsibility. Elon Musk blamed addresses linked to Ukraine, but security researchers could not verify the claim and said most traffic came from elsewhere.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;cyberscoop.com&#x2F;x-ddos-attack-researchers-elon-musk-dark-storm&#x2F;&quot;&gt;cyberscoop.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-western-alliance-bank-discloses-breach-linked-to-cleo-hack&quot;&gt;6. Western Alliance Bank discloses breach linked to Cleo hack&lt;&#x2F;h3&gt;
&lt;p&gt;Western Alliance Bank told nearly 22,000 customers that their data had been stolen through a vulnerability in the Cleo file transfer tool. The exposed records included names, Social Security numbers, dates of birth, passport details and financial account numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.securityweek.com&#x2F;western-alliance-bank-discloses-data-breach-linked-to-cleo-hack&#x2F;&quot;&gt;www.securityweek.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-amazon-ends-local-voice-processing-on-echo-devices&quot;&gt;7. Amazon ends local voice processing on Echo devices&lt;&#x2F;h3&gt;
&lt;p&gt;Amazon told Echo owners that its &quot;Do Not Send Voice Recordings&quot; option would stop working, sending all recordings to its cloud for processing. The company said its new generative features required the change, removing the only setting that had kept some voice data off its servers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.malwarebytes.com&#x2F;blog&#x2F;news&#x2F;2025&#x2F;03&#x2F;amazon-disables-option-to-store-echo-voice-recordings-on-your-device&quot;&gt;www.malwarebytes.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-spyx-stalkerware-breach-exposes-nearly-two-million-people&quot;&gt;8. SpyX stalkerware breach exposes nearly two million people&lt;&#x2F;h3&gt;
&lt;p&gt;A breach at the stalkerware operation SpyX exposed records on close to two million people, including thousands of Apple users. Among the leaked data were around 17,000 iCloud usernames and passwords stored in plain text, alongside victims&#x27; device and location details.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;03&#x2F;19&#x2F;data-breach-at-stalkerware-spyx-affects-close-to-2-million-including-thousands-of-apple-users&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-hellcat-hackers-run-a-worldwide-jira-hacking-spree&quot;&gt;9. HellCat hackers run a worldwide Jira hacking spree&lt;&#x2F;h3&gt;
&lt;p&gt;The HellCat group worked through a string of large companies, including Jaguar Land Rover, by abusing Jira credentials harvested by infostealer malware. Stolen development logs, source code and employee data were leaked, with many credentials still valid years after they were taken.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;hellcat-hackers-go-on-a-worldwide-jira-hacking-spree&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-clearview-ai-settles-biometric-case-with-an-equity-stake&quot;&gt;10. Clearview AI settles biometric case with an equity stake&lt;&#x2F;h3&gt;
&lt;p&gt;A judge approved Clearview AI&#x27;s settlement of an Illinois biometric privacy class action, valued at roughly 51 million dollars. Rather than cash, members of the class were granted a stake in the facial recognition company, an arrangement that twenty-two state attorneys general opposed.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;clearview-ai-illinois-class-action-lawsuit-settlement&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-us-treasury-lifts-sanctions-on-tornado-cash&quot;&gt;11. US Treasury lifts sanctions on Tornado Cash&lt;&#x2F;h3&gt;
&lt;p&gt;The Treasury removed the cryptocurrency mixer Tornado Cash from its sanctions list, reversing a designation it had imposed in 2022. The move followed a federal appeals court ruling that immutable smart contracts were not property that the government could sanction.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.coindesk.com&#x2F;policy&#x2F;2025&#x2F;03&#x2F;21&#x2F;u-s-government-removes-tornado-cash-sanctions&quot;&gt;www.coindesk.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-hacker-defaces-nyu-website-and-exposes-admissions-data&quot;&gt;12. Hacker defaces NYU website and exposes admissions data&lt;&#x2F;h3&gt;
&lt;p&gt;A hacker took over New York University&#x27;s website and posted data drawn from decades of admissions records. More than a million people had information exposed, including names, addresses, test scores and grade point averages, and the attacker framed the breach around the university&#x27;s admissions practices.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;hacker-nyu-website-admissions-race&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-23andme-files-for-bankruptcy-and-its-dna-data-hangs-in-the-balance&quot;&gt;13. 23andMe files for bankruptcy and its DNA data hangs in the balance&lt;&#x2F;h3&gt;
&lt;p&gt;The genetic testing firm 23andMe filed for bankruptcy protection and its chief executive resigned, raising alarm about the fate of DNA data held on roughly fifteen million customers. Privacy advocates and state attorneys general warned that the sensitive genetic archive could be sold through the court process.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;03&#x2F;23&#x2F;dna-testing-company-23andme-files-for-bankruptcy-protection-ceo-resigns&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-virginia-governor-vetoes-high-risk-ai-bill&quot;&gt;14. Virginia governor vetoes high-risk AI bill&lt;&#x2F;h3&gt;
&lt;p&gt;Governor Glenn Youngkin vetoed House Bill 2094, which would have regulated high-risk artificial intelligence systems used in decisions about jobs, credit and healthcare. The veto stopped Virginia from becoming the second state, after Colorado, to adopt a broad AI governance law.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;iapp.org&#x2F;news&#x2F;a&#x2F;virginia-governor-vetoes-ai-bill&quot;&gt;iapp.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-security-expert-troy-hunt-is-caught-by-a-mailchimp-phish&quot;&gt;15. Security expert Troy Hunt is caught by a Mailchimp phish&lt;&#x2F;h3&gt;
&lt;p&gt;Troy Hunt, who runs the Have I Been Pwned breach service, fell for a phishing email that captured his Mailchimp credentials. Attackers exported his newsletter list of around 16,000 subscribers, along with the IP addresses and approximate locations Mailchimp had collected.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2025&#x2F;03&#x2F;25&#x2F;troy_hunt_mailchimp_phish&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-the-atlantic-publishes-the-full-signal-war-plans-thread&quot;&gt;16. The Atlantic publishes the full Signal war plans thread&lt;&#x2F;h3&gt;
&lt;p&gt;After officials insisted no classified material had been shared, The Atlantic published the full Signal exchange in which Pentagon leaders discussed strikes on Yemen. The messages, sent to a group that had accidentally included the magazine&#x27;s editor, contained aircraft types, weapons and attack timings.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cnbc.com&#x2F;2025&#x2F;03&#x2F;26&#x2F;atlantic-publishes-signal-thread-with-trump-vp-vance-hegseth-waltz.html&quot;&gt;www.cnbc.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-streamelements-discloses-a-third-party-data-breach&quot;&gt;17. StreamElements discloses a third-party data breach&lt;&#x2F;h3&gt;
&lt;p&gt;The streaming services firm StreamElements confirmed a breach at a former third-party provider after a hacker began leaking customer records. The stolen data covered roughly 210,000 customers and included names, addresses, phone numbers and email addresses.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;streamelements-discloses-third-party-data-breach-after-hacker-leaks-data&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-utah-makes-app-stores-responsible-for-age-verification&quot;&gt;18. Utah makes app stores responsible for age verification&lt;&#x2F;h3&gt;
&lt;p&gt;Utah became the first state to enact an App Store Accountability Act, shifting the duty to verify ages onto Apple and Google rather than individual apps. The law requires parental consent before minors can download apps, drawing fresh privacy concerns about centralised identity checks.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;03&#x2F;27&#x2F;new-utah-law-makes-app-stores-responsible-for-age-verification&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-eff-argues-online-tracking-is-out-of-control&quot;&gt;19. EFF argues online tracking is out of control&lt;&#x2F;h3&gt;
&lt;p&gt;The Electronic Frontier Foundation set out how invisible tracking code on most websites lets companies, including data brokers, collect and sell information about people&#x27;s browsing. It pointed to an updated version of its Privacy Badger tool that strips tracking added to links across Google and Facebook services.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2025&#x2F;03&#x2F;online-tracking-out-control-privacy-badger-can-help-you-fight-back&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-oracle-faces-criticism-over-its-handling-of-two-breaches&quot;&gt;20. Oracle faces criticism over its handling of two breaches&lt;&#x2F;h3&gt;
&lt;p&gt;Oracle came under fire for its response to two separate security incidents, one involving Oracle Health patient records and another involving claims of stolen Oracle Cloud credentials. The company flatly denied any cloud breach even as customers said leaked samples appeared genuine, and researchers accused it of careful wordsmithing.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;03&#x2F;31&#x2F;oracle-under-fire-for-its-handling-of-separate-security-incidents&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0223 • February 2025</title>
          <pubDate>Thu, 06 Mar 2025 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0223/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0223/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0223/">&lt;!-- Covered month: February 2025 (2025-02-01 to 2025-02-28) --&gt;
&lt;p&gt;February 2025 was defined by encryption under siege, with Britain and Sweden pressing for backdoors while breaches, AI chatbots, and a new government data grab kept defenders busy.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-apple-pulls-icloud-end-to-end-encryption-from-the-united-kingdom&quot;&gt;1. Apple pulls iCloud end-to-end encryption from the United Kingdom&lt;&#x2F;h3&gt;
&lt;p&gt;Apple withdrew its Advanced Data Protection feature for British users on 21 February after the government secretly ordered the company to build a way into encrypted iCloud data. New users can no longer enable the protection, and existing users will eventually have to turn it off.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;apple-pulls-icloud-end-to-end-encryption-feature-in-the-uk&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-sweden-weighs-a-law-to-force-backdoors-into-signal-and-whatsapp&quot;&gt;2. Sweden weighs a law to force backdoors into Signal and WhatsApp&lt;&#x2F;h3&gt;
&lt;p&gt;Swedish police and security agencies pushed legislation that would compel encrypted messaging apps to retain messages and hand over suspects&#x27; histories. Signal&#x27;s president said the company would leave the Swedish market rather than break the encryption that underpins its service.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;sweden-seeks-backdoor-access-to-messaging-apps&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-judge-blocks-doge-from-accessing-treasury-payment-systems&quot;&gt;3. Judge blocks DOGE from accessing Treasury payment systems&lt;&#x2F;h3&gt;
&lt;p&gt;A federal judge restricted the Department of Government Efficiency from reaching Treasury databases holding the payment records of millions of Americans. States had sued to stop the access, arguing that affiliates had been handed sensitive personal information they did not need.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.npr.org&#x2F;2025&#x2F;02&#x2F;08&#x2F;g-s1-47350&#x2F;states-sue-to-stop-doge-accessing-personal-data&quot;&gt;www.npr.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-musk-s-doge-seeks-access-to-sensitive-irs-taxpayer-records&quot;&gt;4. Musk&#x27;s DOGE seeks access to sensitive IRS taxpayer records&lt;&#x2F;h3&gt;
&lt;p&gt;DOGE pushed for entry to an IRS system holding Social Security numbers, bank details, and salary data for millions of taxpayers. Lawmakers and privacy advocates warned that giving a political appointee such reach raised grave risks of misuse.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.npr.org&#x2F;2025&#x2F;02&#x2F;18&#x2F;nx-s1-5299959&#x2F;elon-musks-doge-group-seeks-access-to-sensitive-irs-taxpayer-data&quot;&gt;www.npr.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-experts-flag-security-and-privacy-risks-in-the-deepseek-ai-app&quot;&gt;5. Experts flag security and privacy risks in the DeepSeek AI app&lt;&#x2F;h3&gt;
&lt;p&gt;Security researchers warned that the Chinese chatbot collected extensive user data and sent it to servers in China, where authorities could compel its disclosure. The findings prompted bans on government devices across several American states and federal agencies.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;02&#x2F;experts-flag-security-privacy-risks-in-deepseek-ai-app&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-south-korea-suspends-deepseek-downloads-over-privacy-violations&quot;&gt;6. South Korea suspends DeepSeek downloads over privacy violations&lt;&#x2F;h3&gt;
&lt;p&gt;South Korea&#x27;s data protection regulator found that DeepSeek had transferred personal data, including user prompts, to third parties without proper consent. The company removed its app from South Korean stores on 15 February while the issues were addressed.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;thehackernews.com&#x2F;2025&#x2F;02&#x2F;south-korea-suspends-deepseek-ai.html&quot;&gt;thehackernews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-mozilla-rewrites-firefox-terms-after-a-privacy-backlash&quot;&gt;7. Mozilla rewrites Firefox terms after a privacy backlash&lt;&#x2F;h3&gt;
&lt;p&gt;Mozilla introduced new Firefox terms granting itself a broad licence over information entered through the browser, alarming users who feared their data would be sold or fed to AI. Facing the outcry, Mozilla revised the language and insisted it was not using people&#x27;s data to train AI.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;02&#x2F;28&#x2F;mozilla-responds-to-backlash-over-new-terms-saying-its-not-using-peoples-data-for-ai&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-grubhub-confirms-a-breach-affecting-customers-and-drivers&quot;&gt;8. Grubhub confirms a breach affecting customers and drivers&lt;&#x2F;h3&gt;
&lt;p&gt;Grubhub disclosed on 4 February that an intrusion at a third-party contractor exposed customer and driver contact details, including names, email addresses, and phone numbers. Payment information was not taken, but the data later fed an extortion attempt tied to a wider campaign.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;02&#x2F;04&#x2F;grubhub-confirms-data-breach-affecting-customers-and-drivers&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-background-check-firm-disa-reveals-a-breach-affecting-3-3-million-people&quot;&gt;9. Background-check firm DISA reveals a breach affecting 3.3 million people&lt;&#x2F;h3&gt;
&lt;p&gt;Employment screening provider DISA Global Solutions disclosed that hackers had accessed the data of more than 3.3 million people, including Social Security numbers and financial details. The company took roughly ten months after discovering the intrusion to notify those affected.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;02&#x2F;25&#x2F;us-employee-screening-giant-disa-says-hackers-accessed-data-of-more-than-3m-people&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-australian-ivf-provider-genea-confirms-hackers-accessed-patient-data&quot;&gt;10. Australian IVF provider Genea confirms hackers accessed patient data&lt;&#x2F;h3&gt;
&lt;p&gt;The fertility giant Genea told patients on 19 February that attackers had reached its systems during a cyberattack claimed by the Termite ransomware group. The stolen records included names, addresses, Medicare numbers, and sensitive medical histories.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;02&#x2F;19&#x2F;australian-ivf-giant-genea-confirms-hackers-accessed-data-during-cyberattack&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-hacker-leaks-34-million-omnigpt-chat-messages&quot;&gt;11. Hacker leaks 34 million OmniGPT chat messages&lt;&#x2F;h3&gt;
&lt;p&gt;A threat actor claimed to have breached the AI aggregator OmniGPT, exposing the email addresses and phone numbers of 30,000 users along with more than 34 million lines of conversation. The leaked logs reportedly contained credentials, billing details, and API keys.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;hackread.com&#x2F;omnigpt-ai-chatbot-breach-hacker-leak-user-data-messages&#x2F;&quot;&gt;hackread.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-china-s-salt-typhoon-keeps-breaching-telecom-firms-despite-sanctions&quot;&gt;12. China&#x27;s Salt Typhoon keeps breaching telecom firms despite sanctions&lt;&#x2F;h3&gt;
&lt;p&gt;Researchers reported that the Salt Typhoon group continued to compromise telecommunications providers by exploiting old Cisco vulnerabilities. The campaign followed earlier intrusions that reached the lawful intercept systems used for law enforcement wiretaps.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;02&#x2F;13&#x2F;chinas-salt-typhoon-hackers-continue-to-breach-telecom-firms-despite-us-sanctions&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-court-grants-preliminary-approval-to-apple-s-95-million-siri-settlement&quot;&gt;13. Court grants preliminary approval to Apple&#x27;s $95 million Siri settlement&lt;&#x2F;h3&gt;
&lt;p&gt;A federal judge preliminarily approved a $95 million deal settling claims that Siri recorded private conversations after accidental activations and shared them with third parties. Class members can claim up to $20 per device, and Apple agreed to delete older Siri audio recordings.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.courthousenews.com&#x2F;judge-grants-preliminary-approval-of-95-million-settlement-in-apples-siri-eavesdropping-suit&#x2F;&quot;&gt;www.courthousenews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-spain-arrests-a-hacker-accused-of-attacking-nato-and-the-united-states-army&quot;&gt;14. Spain arrests a hacker accused of attacking NATO and the United States Army&lt;&#x2F;h3&gt;
&lt;p&gt;Spanish police arrested a suspect on 5 February over roughly forty cyberattacks that breached systems run by NATO, the United States Army, the United Nations, and Spanish bodies. Investigators said the suspect had leaked and sold stolen data under several aliases.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;legal&#x2F;spain-arrests-suspected-hacker-of-us-and-spanish-military-agencies&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-orange-group-confirms-a-breach-after-a-hacker-leaks-internal-documents&quot;&gt;15. Orange Group confirms a breach after a hacker leaks internal documents&lt;&#x2F;h3&gt;
&lt;p&gt;The French telecoms operator Orange confirmed an intrusion at its Romanian operations after a HellCat-linked actor leaked thousands of files. The haul included around 380,000 email addresses, source code, contracts, and employee and customer records.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;orange-group-confirms-breach-after-hacker-leaks-company-documents&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-mozilla-is-still-promoting-the-data-removal-service-onerep&quot;&gt;16. Mozilla is still promoting the data removal service Onerep&lt;&#x2F;h3&gt;
&lt;p&gt;Krebs on Security reported that Mozilla continued to recommend the data removal service Onerep almost a year after the founder was tied to people-search sites. The arrangement undercut Mozilla&#x27;s privacy messaging, since the same person had profited from exposing the very data Onerep promised to scrub.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;02&#x2F;nearly-a-year-later-mozilla-is-still-promoting-onerep&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-phished-card-data-is-being-turned-into-apple-and-google-wallets&quot;&gt;17. Phished card data is being turned into Apple and Google wallets&lt;&#x2F;h3&gt;
&lt;p&gt;Investigators detailed how Chinese cybercrime groups revived the carding trade by loading stolen card details into mobile wallets. The technique lets criminals spend phished funds online and in shops, bypassing many fraud controls.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;02&#x2F;how-phished-data-turns-into-apple-google-wallets&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-a-notorious-malware-and-spam-host-shifts-onto-kaspersky-networks&quot;&gt;18. A notorious malware and spam host shifts onto Kaspersky networks&lt;&#x2F;h3&gt;
&lt;p&gt;One of the most abuse-friendly bulletproof hosting providers for cybercriminals began routing its traffic through networks operated by the Russian security firm Kaspersky Lab. The move raised fresh questions about who is shielding online criminal infrastructure.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;02&#x2F;notorious-malware-spam-host-prospero-moves-to-kaspersky-lab&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-new-administration-brings-cuts-to-cyber-and-consumer-protections&quot;&gt;19. New administration brings cuts to cyber and consumer protections&lt;&#x2F;h3&gt;
&lt;p&gt;Krebs on Security reported that early moves under the new administration weakened agencies that guard data security and consumer privacy. The cuts threatened oversight of data brokers and the watchdogs that hold breached companies to account.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;02&#x2F;trump-2-0-brings-cuts-to-cyber-consumer-protections&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-united-states-soldier-charged-in-the-at-t-phone-records-hack&quot;&gt;20. United States soldier charged in the AT&amp;amp;T phone records hack&lt;&#x2F;h3&gt;
&lt;p&gt;A serving soldier charged over the theft of AT&amp;amp;T customer call records had searched online whether hacking could be treason. The case shed light on how stolen telecom data, including the records of public figures, was traded among young criminals.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2025&#x2F;02&#x2F;u-s-soldier-charged-in-att-hack-searched-can-hacking-be-treason&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0222 • January 2025</title>
          <pubDate>Thu, 06 Feb 2025 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0222/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0222/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0222/">&lt;!-- Covered month: January 2025 (2025-01-01 to 2025-01-31) --&gt;
&lt;p&gt;January 2025 opened the year with a flood of location data scandals, hard regulatory action against connected cars and data brokers, and a Supreme Court ruling that sealed the fate of TikTok.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-apple-agrees-to-pay-95-million-dollars-to-settle-siri-privacy-lawsuit&quot;&gt;1. Apple agrees to pay 95 million dollars to settle Siri privacy lawsuit&lt;&#x2F;h3&gt;
&lt;p&gt;Apple agreed to a 95 million dollar settlement over claims that Siri recorded private conversations after unintended activations and passed them to third parties. The plaintiffs said mentions of Air Jordan trainers and Olive Garden triggered matching advertisements, and Apple denied any wrongdoing.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.npr.org&#x2F;2025&#x2F;01&#x2F;03&#x2F;g-s1-40940&#x2F;apple-settle-lawsuit-siri-privacy&quot;&gt;www.npr.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-telegram-reports-a-sharp-rise-in-handing-user-data-to-law-enforcement&quot;&gt;2. Telegram reports a sharp rise in handing user data to law enforcement&lt;&#x2F;h3&gt;
&lt;p&gt;Telegram&#x27;s transparency figures showed it gave phone numbers and IP addresses to United States authorities on 900 occasions in 2024, affecting 2,253 users. The surge followed the arrest of chief executive Pavel Durov in France and a quiet rewrite of the platform&#x27;s data sharing policy.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;01&#x2F;07&#x2F;telegram-reports-spike-in-sharing-user-data-with-law-enforcement&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-justice-department-issues-final-rule-curbing-bulk-data-flows-to-countries-of-concern&quot;&gt;3. Justice Department issues final rule curbing bulk data flows to countries of concern&lt;&#x2F;h3&gt;
&lt;p&gt;On 8 January the Justice Department published its final rule restricting transfers of bulk sensitive personal data to China, Russia, Iran, North Korea, Cuba and Venezuela. The measure implements an executive order and covers genomic, biometric, geolocation, financial and health information.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.federalregister.gov&#x2F;documents&#x2F;2025&#x2F;01&#x2F;08&#x2F;2024-31486&#x2F;preventing-access-to-us-sensitive-personal-data-and-government-related-data-by-countries-of-concern&quot;&gt;www.federalregister.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-texas-sues-allstate-and-arity-over-secret-driver-tracking&quot;&gt;4. Texas sues Allstate and Arity over secret driver tracking&lt;&#x2F;h3&gt;
&lt;p&gt;Texas Attorney General Ken Paxton sued Allstate and its subsidiary Arity for collecting and selling the location data of more than 45 million drivers. The state alleged the firms paid app developers to embed a tracking kit in everyday apps, building what they called the world&#x27;s largest driving behaviour database.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.texasattorneygeneral.gov&#x2F;news&#x2F;releases&#x2F;attorney-general-ken-paxton-sues-allstate-and-arity-unlawfully-collecting-using-and-selling-over-45&quot;&gt;www.texasattorneygeneral.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-a-breach-of-gravy-analytics-threatens-the-location-privacy-of-millions&quot;&gt;5. A breach of Gravy Analytics threatens the location privacy of millions&lt;&#x2F;h3&gt;
&lt;p&gt;Data broker Gravy Analytics confirmed that a hacker had taken files from its cloud environment using a misappropriated key, exposing vast quantities of precise smartphone location data. A threat actor posted samples showing tracked devices across the United States, Russia and Europe and threatened to release more.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;01&#x2F;13&#x2F;gravy-analytics-data-broker-breach-trove-of-location-data-threatens-privacy-millions&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-ftc-finalises-order-banning-mobilewalla-from-selling-sensitive-location-data&quot;&gt;6. FTC finalises order banning Mobilewalla from selling sensitive location data&lt;&#x2F;h3&gt;
&lt;p&gt;The Federal Trade Commission finalised an order barring data broker Mobilewalla from selling location data that could reveal visits to clinics and places of worship. The agency said the firm sold the information without taking reasonable steps to confirm that consumers had consented.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2025&#x2F;01&#x2F;ftc-finalizes-order-banning-mobilewalla-selling-sensitive-location-data&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-ftc-takes-action-against-general-motors-over-secret-driver-data-sales&quot;&gt;7. FTC takes action against General Motors over secret driver data sales&lt;&#x2F;h3&gt;
&lt;p&gt;The Federal Trade Commission alleged that General Motors and OnStar collected precise location and driving behaviour data and sold it to third parties without clear consent. The proposed order imposes a five year ban on disclosing such data to consumer reporting agencies that had used it to set insurance rates.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2025&#x2F;01&#x2F;ftc-takes-action-against-general-motors-sharing-drivers-precise-location-driving-behavior-data&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-ftc-finalises-new-children-s-privacy-rule-limiting-data-monetisation&quot;&gt;8. FTC finalises new children&#x27;s privacy rule limiting data monetisation&lt;&#x2F;h3&gt;
&lt;p&gt;On 16 January the Federal Trade Commission finalised its first major overhaul of the Children&#x27;s Online Privacy Protection Rule since 2013. The amendments require parents to opt in to targeted advertising, expand the definition of personal information to include biometric identifiers, and limit how long operators may retain children&#x27;s data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2025&#x2F;01&#x2F;ftc-finalizes-changes-childrens-privacy-rule-limiting-companies-ability-monetize-kids-data&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-biden-issues-an-eleventh-hour-cybersecurity-executive-order&quot;&gt;9. Biden issues an eleventh hour cybersecurity executive order&lt;&#x2F;h3&gt;
&lt;p&gt;President Biden signed Executive Order 14144 to strengthen the security of federal software supply chains and promote privacy preserving digital identity. The order also directs agencies towards quantum resistant cryptography and expands sanctions powers against malicious cyber actors.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.npr.org&#x2F;2025&#x2F;01&#x2F;16&#x2F;nx-s1-5261112&#x2F;biden-cybersecurity-executive-order&quot;&gt;www.npr.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-treasury-sanctions-a-china-based-hacker-over-the-ofac-breach&quot;&gt;10. Treasury sanctions a China based hacker over the OFAC breach&lt;&#x2F;h3&gt;
&lt;p&gt;On 17 January the Treasury sanctioned Yin Kecheng over the compromise of its own network, including the Office of Foreign Assets Control. The attackers reached unclassified but sensitive documents by exploiting a stolen key from the third party software provider BeyondTrust.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;home.treasury.gov&#x2F;news&#x2F;press-releases&#x2F;sb0042&quot;&gt;home.treasury.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-supreme-court-upholds-the-tiktok-sale-or-ban-law&quot;&gt;11. Supreme Court upholds the TikTok sale or ban law&lt;&#x2F;h3&gt;
&lt;p&gt;The Supreme Court unanimously upheld the law requiring ByteDance to divest TikTok or face a nationwide ban, rejecting the company&#x27;s free speech arguments. The government cited the risk of Chinese collection of data from 170 million American users and the potential to manipulate the platform&#x27;s content.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.scotusblog.com&#x2F;2025&#x2F;01&#x2F;supreme-court-upholds-tiktok-ban&#x2F;&quot;&gt;www.scotusblog.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-hewlett-packard-enterprise-probes-a-hacker-s-data-theft-claim&quot;&gt;12. Hewlett Packard Enterprise probes a hacker&#x27;s data theft claim&lt;&#x2F;h3&gt;
&lt;p&gt;Hewlett Packard Enterprise launched an investigation after the threat actor IntelBroker advertised files it said were stolen from the company&#x27;s systems. The listing claimed to include source code, private repositories, digital certificates and some personal information, though the firm said it saw no evidence of operational impact.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;01&#x2F;21&#x2F;hpe-investigating-security-breach-after-hacker-claims-theft-of-sensitive-data&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-trump-fires-three-members-of-the-federal-surveillance-watchdog&quot;&gt;13. Trump fires three members of the federal surveillance watchdog&lt;&#x2F;h3&gt;
&lt;p&gt;President Trump dismissed three Democratic members of the Privacy and Civil Liberties Oversight Board by a one sentence email. The removals left the board without a quorum, stripping it of the ability to begin new oversight of government surveillance programmes.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.lawfaremedia.org&#x2F;article&#x2F;trump-s-sacking-of-pclob-members-threatens-data-privacy&quot;&gt;www.lawfaremedia.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-otelier-breach-exposes-reservations-for-marriott-hilton-and-hyatt-guests&quot;&gt;14. Otelier breach exposes reservations for Marriott, Hilton and Hyatt guests&lt;&#x2F;h3&gt;
&lt;p&gt;Hotel management platform Otelier suffered a breach after attackers reached its cloud storage using stolen employee credentials. The stolen records covered millions of guest reservations and personal details across major hotel brands, with credentials taken by information stealing malware.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;otelier-data-breach-exposes-info-hotel-reservations-of-millions&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-community-health-center-breach-affects-more-than-a-million-patients&quot;&gt;15. Community Health Center breach affects more than a million patients&lt;&#x2F;h3&gt;
&lt;p&gt;The Connecticut nonprofit Community Health Center said it detected unauthorised activity on 2 January and that a hacker had exfiltrated data from its network. The exposed records of more than a million people included diagnoses, test results, insurance details and Social Security numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.hipaajournal.com&#x2F;community-health-center-data-breach&#x2F;&quot;&gt;www.hipaajournal.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-ftc-takes-action-against-godaddy-over-lax-data-security&quot;&gt;16. FTC takes action against GoDaddy over lax data security&lt;&#x2F;h3&gt;
&lt;p&gt;The Federal Trade Commission alleged that GoDaddy failed to use basic protections such as multi factor authentication despite advertising award winning security. The agency said the lapses led to several breaches that let attackers reach customers&#x27; websites and data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2025&#x2F;01&#x2F;ftc-takes-action-against-godaddy-alleged-lax-data-security-its-website-hosting-services&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-powerschool-begins-notifying-students-and-teachers-after-a-mass-breach&quot;&gt;17. PowerSchool begins notifying students and teachers after a mass breach&lt;&#x2F;h3&gt;
&lt;p&gt;Education software vendor PowerSchool began notifying individuals affected by a breach of its support portal that was carried out with a single compromised credential. The exposed records relating to families and educators included names, grades, birth dates and Social Security numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2025&#x2F;01&#x2F;28&#x2F;powerschool-begins-notifying-students-and-teachers-after-massive-data-breach&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-researchers-find-an-exposed-deepseek-database-leaking-chat-logs&quot;&gt;18. Researchers find an exposed DeepSeek database leaking chat logs&lt;&#x2F;h3&gt;
&lt;p&gt;Security firm Wiz reported that the Chinese AI company DeepSeek had left a database open to the internet without authentication. The exposed records included more than a million log lines, user chat histories and secret keys that could have granted control of its systems.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;thehackernews.com&#x2F;2025&#x2F;01&#x2F;deepseek-ai-database-exposed-over-1.html&quot;&gt;thehackernews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-at-t-and-verizon-say-they-evicted-the-salt-typhoon-hackers&quot;&gt;19. AT&amp;amp;T and Verizon say they evicted the Salt Typhoon hackers&lt;&#x2F;h3&gt;
&lt;p&gt;AT&amp;amp;T and Verizon stated in early January that they had removed the China linked Salt Typhoon group from their networks. The intrusions had reached systems used for court ordered wiretaps and exposed the call metadata of large numbers of users.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cybersecuritydive.com&#x2F;news&#x2F;att-verizon-salt-typhoon&#x2F;736680&#x2F;&quot;&gt;www.cybersecuritydive.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-conduent-cyberattack-disrupts-government-services-across-several-states&quot;&gt;20. Conduent cyberattack disrupts government services across several states&lt;&#x2F;h3&gt;
&lt;p&gt;Outsourcing provider Conduent discovered a cyber incident on 13 January after attackers had lurked in its systems since October. The intrusion disrupted benefits and payment services for state agencies in Wisconsin, Oklahoma and elsewhere, and the company later confirmed that personal data had been taken.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;securityaffairs.com&#x2F;184128&#x2F;data-breach&#x2F;conduent-january-2025-breach-impacts-10m-people.html&quot;&gt;securityaffairs.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0221 • December 2024</title>
          <pubDate>Thu, 02 Jan 2025 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0221/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0221/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0221/">&lt;!-- Covered month: December 2024 (2024-12-01 to 2024-12-31) --&gt;
&lt;p&gt;December 2024 closed the year with record European fines, fresh data broker crackdowns, and a stark warning that lawful surveillance backdoors had become a national security liability.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-irish-regulator-fines-meta-eur251-million-over-2018-facebook-breach&quot;&gt;1. Irish regulator fines Meta €251 million over 2018 Facebook breach&lt;&#x2F;h3&gt;
&lt;p&gt;The Irish Data Protection Commission fined Meta €251 million on 17 December for a 2018 flaw that let attackers steal access tokens for around 29 million accounts. The regulator found Meta had failed to document the breach properly and had processed more data than it needed.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;meta-fined-263-million-gdpr-violations-data-breach&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-italy-fines-openai-eur15-million-over-chatgpt-data-collection&quot;&gt;2. Italy fines OpenAI €15 million over ChatGPT data collection&lt;&#x2F;h3&gt;
&lt;p&gt;Italy&#x27;s Garante fined OpenAI €15 million on 20 December, ruling that the company trained ChatGPT on personal data without a proper legal basis and without an adequate age check. The watchdog also ordered OpenAI to run a six month public awareness campaign about how it gathers data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.euronews.com&#x2F;next&#x2F;2024&#x2F;12&#x2F;20&#x2F;italys-privacy-watchdog-fines-openai-15-million-after-probe-into-chatgpt-data-collection&quot;&gt;www.euronews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-ftc-bars-gravy-analytics-and-venntel-from-selling-sensitive-location-data&quot;&gt;3. FTC bars Gravy Analytics and Venntel from selling sensitive location data&lt;&#x2F;h3&gt;
&lt;p&gt;On 3 December the Federal Trade Commission announced a proposed order banning Gravy Analytics and its subsidiary Venntel from selling location data that tracks visits to clinics, churches and other sensitive sites. The companies must build a programme to identify and protect such locations.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2024&#x2F;12&#x2F;ftc-takes-action-against-gravy-analytics-venntel-unlawfully-selling-location-data-tracking-consumers&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-ftc-orders-mobilewalla-to-stop-selling-location-data-without-consent&quot;&gt;4. FTC orders Mobilewalla to stop selling location data without consent&lt;&#x2F;h3&gt;
&lt;p&gt;The same day the FTC moved against Mobilewalla, which had collected more than 500 million advertising identifiers paired with precise location data. For the first time the agency treated harvesting bid data from ad auctions for other purposes as an unfair practice.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2024&#x2F;12&#x2F;ftc-takes-action-against-mobilewalla-collecting-selling-sensitive-location-data&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-cisa-and-fbi-urge-americans-to-use-encrypted-messaging-apps&quot;&gt;5. CISA and FBI urge Americans to use encrypted messaging apps&lt;&#x2F;h3&gt;
&lt;p&gt;After the Salt Typhoon intrusions into US telecoms, officials on 4 December recommended that people move to end to end encrypted apps such as Signal. The advice marked a notable reversal for agencies that had long pressed for lawful access to encrypted communications.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;12&#x2F;04&#x2F;fbi-recommends-encrypted-messaging-apps-combat-chinese-hackers&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-salt-typhoon-shows-the-danger-of-surveillance-backdoors&quot;&gt;6. Salt Typhoon shows the danger of surveillance backdoors&lt;&#x2F;h3&gt;
&lt;p&gt;Reporting on 11 December argued that the Salt Typhoon breach exposed how the wiretap systems mandated by US law had handed foreign spies a way in. Security experts said the episode proved that no backdoor can be reserved for the good actors alone.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;theintercept.com&#x2F;2024&#x2F;12&#x2F;11&#x2F;fbi-phone-encryption-salt-typhoon&#x2F;&quot;&gt;theintercept.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-watchdog-finds-us-border-surveillance-failing-privacy-rules&quot;&gt;7. Watchdog finds US border surveillance failing privacy rules&lt;&#x2F;h3&gt;
&lt;p&gt;A Government Accountability Office assessment published on 20 December found that Customs and Border Protection had met none of six baseline privacy protections for its towers, aerostats and ground sensors. The agency had deployed years of mass surveillance without the required safeguards.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;12&#x2F;customs-border-protection-fails-baseline-privacy-requirements-surveillance&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-volkswagen-leak-exposes-location-data-of-800-000-electric-cars&quot;&gt;8. Volkswagen leak exposes location data of 800,000 electric cars&lt;&#x2F;h3&gt;
&lt;p&gt;A misconfigured cloud store run by Volkswagen&#x27;s software unit Cariad left the precise location data of about 800,000 electric vehicles open for months. For many of the cars the data was accurate enough to map a driver&#x27;s daily routine, and it touched politicians and police officers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;electrek.co&#x2F;2024&#x2F;12&#x2F;30&#x2F;massive-data-leak-at-volkswagen-exposes-800000-ev-drivers&#x2F;&quot;&gt;electrek.co&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-eu-opens-formal-proceedings-against-tiktok-over-election-risks&quot;&gt;9. EU opens formal proceedings against TikTok over election risks&lt;&#x2F;h3&gt;
&lt;p&gt;On 17 December the European Commission opened formal Digital Services Act proceedings against TikTok over its handling of risks to the annulled Romanian presidential election. Investigators will examine its recommender systems, coordinated inauthentic behaviour and political advertising.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.euronews.com&#x2F;my-europe&#x2F;2024&#x2F;12&#x2F;17&#x2F;european-commission-opens-probe-against-tiktok-over-romanian-election&quot;&gt;www.euronews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-commission-orders-tiktok-to-preserve-romanian-election-data&quot;&gt;10. Commission orders TikTok to preserve Romanian election data&lt;&#x2F;h3&gt;
&lt;p&gt;Earlier, on 5 December, the Commission issued a retention order requiring TikTok to freeze and keep data tied to systemic risks around elections in the European Union. The order covered national votes between late November 2024 and the end of March 2025.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.jurist.org&#x2F;news&#x2F;2024&#x2F;12&#x2F;european-commission-issues-retention-order-against-tiktok-in-the-context-of-romania-elections&#x2F;&quot;&gt;www.jurist.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-amnesty-exposes-serbian-spyware-and-cellebrite-phone-hacking&quot;&gt;11. Amnesty exposes Serbian spyware and Cellebrite phone hacking&lt;&#x2F;h3&gt;
&lt;p&gt;Amnesty International reported on 16 December that Serbian police and intelligence used Cellebrite tools and bespoke NoviSpy malware to break into the phones of journalists and activists. Devices were often infected while held during ordinary stops and interviews.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.amnesty.org&#x2F;en&#x2F;latest&#x2F;news&#x2F;2024&#x2F;12&#x2F;serbia-authorities-using-spyware-and-cellebrite-forensic-extraction-tools-to-hack-journalists-and-activists&#x2F;&quot;&gt;www.amnesty.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-krispy-kreme-discloses-cyberattack-disrupting-online-orders&quot;&gt;12. Krispy Kreme discloses cyberattack disrupting online orders&lt;&#x2F;h3&gt;
&lt;p&gt;Krispy Kreme told the Securities and Exchange Commission on 11 December that an intrusion had disrupted online ordering across parts of the United States. The Play ransomware group later claimed the attack, which exposed the personal data of more than 160,000 people.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;12&#x2F;11&#x2F;krispy-kreme-discloses-cyberattack-that-is-disrupting-online-orders&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-france-fines-orange-eur50-million-for-ads-disguised-as-emails&quot;&gt;13. France fines Orange €50 million for ads disguised as emails&lt;&#x2F;h3&gt;
&lt;p&gt;The French regulator CNIL announced on 10 December a €50 million fine against Orange for slipping advertisements into users&#x27; inboxes that looked almost identical to real emails. More than 7.8 million people had seen the disguised messages.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cnil.fr&#x2F;en&#x2F;advertisements-inserted-among-emails-orange-fined-eu50-million&quot;&gt;www.cnil.fr&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-dutch-regulator-fines-netflix-eur4-75-million-over-transparency&quot;&gt;14. Dutch regulator fines Netflix €4.75 million over transparency&lt;&#x2F;h3&gt;
&lt;p&gt;The Dutch Data Protection Authority fined Netflix €4.75 million on 18 December for failing to tell customers clearly what it did with their data between 2018 and 2020. People who asked what information the company held also received insufficient answers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;dutch-fines-millions-regulator-netflix&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-apple-agrees-to-95-million-settlement-over-siri-eavesdropping&quot;&gt;15. Apple agrees to $95 million settlement over Siri eavesdropping&lt;&#x2F;h3&gt;
&lt;p&gt;On 31 December Apple settled a long running class action for $95 million over claims that Siri recorded users without the wake phrase. The plaintiffs said captured snippets were shared with third parties without consent.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cbsnews.com&#x2F;news&#x2F;siri-civil-lawsuit-settlement-apple-iphone-eavesdropping&#x2F;&quot;&gt;www.cbsnews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-ascension-confirms-ransomware-breach-hit-5-6-million-patients&quot;&gt;16. Ascension confirms ransomware breach hit 5.6 million patients&lt;&#x2F;h3&gt;
&lt;p&gt;The health system Ascension disclosed on 19 December that a May ransomware attack had exposed the records of nearly 5.6 million people. The stolen data included Social Security numbers, medical details and payment information.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cybersecuritydive.com&#x2F;news&#x2F;ascension-cyberattack-data-breach&#x2F;736183&#x2F;&quot;&gt;www.cybersecuritydive.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-connectoncall-breach-exposes-data-of-more-than-900-000-patients&quot;&gt;17. ConnectOnCall breach exposes data of more than 900,000 patients&lt;&#x2F;h3&gt;
&lt;p&gt;The telehealth provider ConnectOnCall began notifying patients on 11 December after attackers reached its platform for three months earlier in the year. Names, phone numbers, health conditions and some Social Security numbers were taken.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.hipaajournal.com&#x2F;connectoncall-data-breach&#x2F;&quot;&gt;www.hipaajournal.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-us-soldier-arrested-over-at-t-and-verizon-extortion&quot;&gt;18. US soldier arrested over AT&amp;amp;T and Verizon extortion&lt;&#x2F;h3&gt;
&lt;p&gt;A US Army soldier was arrested on 20 December over the theft and sale of call records from AT&amp;amp;T and Verizon under the alias Kiberphant0m. Investigators linked the case to the wider extortion campaign against Snowflake customers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;12&#x2F;u-s-army-soldier-arrested-in-att-verizon-extortions&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-bitcoin-atm-operator-byte-federal-discloses-58-000-person-breach&quot;&gt;19. Bitcoin ATM operator Byte Federal discloses 58,000 person breach&lt;&#x2F;h3&gt;
&lt;p&gt;Byte Federal, one of the largest Bitcoin ATM operators in the United States, told 58,000 users on 12 December that attackers had reached their data through a flaw in GitLab. The exposed records included Social Security numbers, identity documents and user photos.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;12&#x2F;12&#x2F;bitcoin-atm-giant-byte-federal-says-58000-users-personal-data-compromised-in-breach&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-spain-fines-telefonica-eur1-3-million-over-2022-data-breach&quot;&gt;20. Spain fines Telefónica €1.3 million over 2022 data breach&lt;&#x2F;h3&gt;
&lt;p&gt;Spain&#x27;s data protection authority fined Telefónica €1.3 million, in a decision reported on 3 December, for weak safeguards behind a 2022 breach affecting more than a million Movistar and O2 customers. The regulator faulted both the inadequate security and the slow notification.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.telecompaper.com&#x2F;news&#x2F;telefonica-handed-eur-13-million-fine-for-2022-data-breach--1521465&quot;&gt;www.telecompaper.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0220 • November 2024</title>
          <pubDate>Thu, 05 Dec 2024 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0220/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0220/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0220/">&lt;!-- Covered month: November 2024 (2024-11-01 to 2024-11-30) --&gt;
&lt;p&gt;November 2024 was dominated by the Salt Typhoon telecom espionage revelations, a wave of breach disclosures, and fresh fines and surveillance fights on both sides of the Atlantic.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-fbi-and-cisa-confirm-china-linked-hackers-breached-multiple-us-telecoms&quot;&gt;1. FBI and CISA confirm China-linked hackers breached multiple US telecoms&lt;&#x2F;h3&gt;
&lt;p&gt;The two agencies acknowledged a broad espionage campaign in which Salt Typhoon stole call records and tapped court-ordered wiretap systems at several carriers. They confirmed that the intruders targeted communications belonging to people involved in government and politics.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2024&#x2F;11&#x2F;14&#x2F;salt_typhoon_hacked_multiple_telecom&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-t-mobile-detects-intrusion-attempts-tied-to-the-telecom-spying-campaign&quot;&gt;2. T-Mobile detects intrusion attempts tied to the telecom spying campaign&lt;&#x2F;h3&gt;
&lt;p&gt;T-Mobile said it spotted hackers probing its network through a connected wireline provider and severed the link before customer data was reached. The company reported the activity to the government while declining to name Salt Typhoon as the culprit.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2024&#x2F;11&#x2F;18&#x2F;tmobile_us_attack_salt_typhoon&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-canadian-man-arrested-over-the-snowflake-data-extortions&quot;&gt;3. Canadian man arrested over the Snowflake data extortions&lt;&#x2F;h3&gt;
&lt;p&gt;Alexander Moucka, who used aliases including Judische, was held in Ontario on a US warrant tied to the theft of data from more than 160 Snowflake customers. Victims of the campaign included AT&amp;amp;T, Ticketmaster, and Neiman Marcus.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;11&#x2F;canadian-man-arrested-in-snowflake-data-extortions&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-fintech-giant-finastra-investigates-a-file-transfer-breach&quot;&gt;4. Fintech giant Finastra investigates a file-transfer breach&lt;&#x2F;h3&gt;
&lt;p&gt;Finastra, which serves most of the world&#x27;s largest banks, found that an intruder used stolen credentials to take roughly 400 gigabytes of data from an internal transfer platform. A criminal then advertised the haul for sale on a cybercrime forum.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;11&#x2F;fintech-giant-finastra-investigating-data-breach&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-south-korea-fines-meta-over-sharing-sensitive-facebook-data&quot;&gt;5. South Korea fines Meta over sharing sensitive Facebook data&lt;&#x2F;h3&gt;
&lt;p&gt;The Personal Information Protection Commission penalised Meta about 15.6 million dollars for handing advertisers data on roughly 980,000 users without consent. The shared categories included religion, political views, and whether a person was a North Korean defector.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;facebook-south-korea-privacy-regulator-fine&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-unsealed-documents-reveal-how-much-nso-group-controls-pegasus&quot;&gt;6. Unsealed documents reveal how much NSO Group controls Pegasus&lt;&#x2F;h3&gt;
&lt;p&gt;Court filings in WhatsApp&#x27;s lawsuit showed that NSO, not its government clients, ran the data retrieval process behind its spyware. The papers also revealed that the firm cut off ten customers for abusing the tool.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;11&#x2F;15&#x2F;nso-group-admits-cutting-off-10-customers-because-they-abused-its-pegasus-spyware-say-unsealed-court-documents&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-eff-documents-force-disclosure-of-immigrant-social-media-surveillance&quot;&gt;7. EFF documents force disclosure of immigrant social media surveillance&lt;&#x2F;h3&gt;
&lt;p&gt;A Freedom of Information lawsuit revealed that the government rebranded its extreme vetting effort and kept spending over 100 million dollars to monitor immigrants online. The records show a hunt for vague derogatory information that raises clear free speech concerns.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;11&#x2F;eff-lawsuit-discloses-documents-detailing-governments-social-media-surveillance&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-eff-warns-the-national-security-state-will-make-ai-even-less-accountable&quot;&gt;8. EFF warns the national security state will make AI even less accountable&lt;&#x2F;h3&gt;
&lt;p&gt;A White House directive pushed the security apparatus to lead on artificial intelligence, which EFF argued would deepen secrecy around already opaque systems. The group cautioned that classified AI used for consequential decisions would escape public scrutiny.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;11&#x2F;us-national-security-state-here-make-ai-even-less-transparent-and-accountable&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-criminals-abuse-the-fbi-emergency-data-request-system&quot;&gt;9. Criminals abuse the FBI emergency data request system&lt;&#x2F;h3&gt;
&lt;p&gt;Schneier highlighted how attackers used compromised police accounts to send fake emergency requests and trick companies into handing over user data. Some fraudulent requests cited invented threats such as human trafficking to add urgency.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2024&#x2F;11&#x2F;criminals-exploiting-fbi-emergency-data-requests.html&quot;&gt;www.schneier.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-hot-topic-breach-exposes-the-data-of-57-million-customers&quot;&gt;10. Hot Topic breach exposes the data of 57 million customers&lt;&#x2F;h3&gt;
&lt;p&gt;A breach notification service alerted tens of millions of shoppers that their details had been stolen from the retailer and its sister brands. The exposed records included email addresses, dates of birth, and partial payment card data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;11&#x2F;13&#x2F;hot-topic-data-breach-exposed-personal-data-of-57-million-customers&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-satellite-giant-maxar-confirms-a-breach-of-employee-data&quot;&gt;11. Satellite giant Maxar confirms a breach of employee data&lt;&#x2F;h3&gt;
&lt;p&gt;Maxar said a hacker using a Hong Kong address reached files holding staff names, addresses, and Social Security numbers. More than half of the firm&#x27;s workers hold US security clearances for classified projects.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;11&#x2F;18&#x2F;satellite-giant-maxar-confirms-hacker-accessed-employees-personal-data&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-andrew-tate-s-online-platform-is-breached-and-its-members-exposed&quot;&gt;12. Andrew Tate&#x27;s online platform is breached and its members exposed&lt;&#x2F;h3&gt;
&lt;p&gt;Intruders copied chat servers and lifted hundreds of thousands of usernames and registered email addresses from the subscription site The Real World. They disrupted a live stream and passed the data to a breach notification service.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2024&#x2F;11&#x2F;22&#x2F;andrew_tate_raid&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-selectblinds-discovers-payment-skimming-malware-on-its-website&quot;&gt;13. SelectBlinds discovers payment-skimming malware on its website&lt;&#x2F;h3&gt;
&lt;p&gt;The retailer said malware had sat on its checkout page since early in the year, scraping the details of more than 200,000 customers. The harvested data included names, addresses, and full payment card numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;selectblinds-customers-credit-card-info-data-breach-website-malware&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-amazon-confirms-employee-data-leaked-through-a-contractor&quot;&gt;14. Amazon confirms employee data leaked through a contractor&lt;&#x2F;h3&gt;
&lt;p&gt;Amazon acknowledged that staff records appeared on a crime forum after a breach at a vendor using the MOVEit file transfer tool. The exposed information covered names, work contact details, and office locations across millions of records.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.404media.co&#x2F;amazon-confirms-breach-of-employee-data&#x2F;&quot;&gt;www.404media.co&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-senators-demand-an-audit-of-airport-facial-recognition&quot;&gt;15. Senators demand an audit of airport facial recognition&lt;&#x2F;h3&gt;
&lt;p&gt;A bipartisan group of twelve senators pressed the Department of Homeland Security to evaluate the accuracy and privacy effects of facial scanning before it spreads to hundreds of airports. They warned that mandatory scans could build a federal surveillance database without congressional approval.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;tsa-facial-recognition-tech-senators-call-for-audits&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-british-software-firm-microlise-confirms-staff-data-stolen&quot;&gt;16. British software firm Microlise confirms staff data stolen&lt;&#x2F;h3&gt;
&lt;p&gt;Microlise said a cyberattack with the hallmarks of ransomware took some employee data and disrupted tracking systems used by DHL and Serco. The incident temporarily disabled vehicle tracking and panic alarms on prisoner transport vans.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2024&#x2F;11&#x2F;06&#x2F;microlise_cyberattack&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-ford-investigates-breach-claims-and-blames-a-third-party-supplier&quot;&gt;17. Ford investigates breach claims and blames a third-party supplier&lt;&#x2F;h3&gt;
&lt;p&gt;After criminals advertised a database of customer records, Ford said it found no breach of its own systems. The company traced the small exposed batch to publicly available dealer business addresses held by a supplier.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2024&#x2F;11&#x2F;18&#x2F;ford_actively_investigating_breach&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-nokia-investigates-a-claimed-theft-of-its-source-code&quot;&gt;18. Nokia investigates a claimed theft of its source code&lt;&#x2F;h3&gt;
&lt;p&gt;A pair of criminals said they obtained Nokia source code, keys, and credentials through a contractor that worked with the firm. Nokia investigated the claim, which raised questions about why outside contractors could reach such material.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2024&#x2F;11&#x2F;06&#x2F;nokia_data_theft&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-india-fines-meta-and-bans-whatsapp-data-sharing-for-ads&quot;&gt;19. India fines Meta and bans WhatsApp data sharing for ads&lt;&#x2F;h3&gt;
&lt;p&gt;The Competition Commission of India penalised Meta about 25 million dollars and barred it from using WhatsApp data for advertising for five years. The regulator tied the order to the 2021 privacy policy change that expanded mandatory data sharing.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;11&#x2F;18&#x2F;india-fines-meta-25-4-million-over-whatsapp-privacy-policy&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-secret-service-tracks-phone-locations-without-a-warrant&quot;&gt;20. Secret Service tracks phone locations without a warrant&lt;&#x2F;h3&gt;
&lt;p&gt;Schneier flagged reporting that the Secret Service used the Locate X tool to follow people through location data harvested from ordinary apps. The agency argued that opaque terms of service mean it does not need a warrant for the practice.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2024&#x2F;11&#x2F;secret-service-tracking-peoples-locations-without-warrant.html&quot;&gt;www.schneier.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0219 • October 2024</title>
          <pubDate>Thu, 07 Nov 2024 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0219/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0219/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0219/">&lt;!-- Covered month: October 2024 (2024-10-01 to 2024-10-31) --&gt;
&lt;p&gt;October 2024 brought record fines for Big Tech, a wave of mass breaches, and fresh proof that the state and data brokers keep buying their way around warrants.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-ireland-fines-linkedin-310-million-euros-over-behavioural-advertising&quot;&gt;1. Ireland fines LinkedIn 310 million euros over behavioural advertising&lt;&#x2F;h3&gt;
&lt;p&gt;The Irish Data Protection Commission fined LinkedIn 310 million euros on 24 October for processing members&#x27; data for behavioural analysis and targeted advertising without a valid legal basis. The regulator found the platform breached the fairness, lawfulness and transparency principles of the GDPR and ordered it to bring its advertising into line within three months.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.dataprotection.ie&#x2F;en&#x2F;news-media&#x2F;press-releases&#x2F;irish-data-protection-commission-fines-linkedin-ireland-eu310-million&quot;&gt;www.dataprotection.ie&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-chinese-hackers-breached-the-wiretap-systems-us-law-mandates&quot;&gt;2. Chinese hackers breached the wiretap systems US law mandates&lt;&#x2F;h3&gt;
&lt;p&gt;The Wall Street Journal reported on 5 October that a group known as Salt Typhoon had penetrated the networks of Verizon, AT&amp;amp;T and Lumen and reached the lawful interception systems used to fulfil court ordered wiretaps. The breach exposed exactly the kind of surveillance backdoor that security experts have warned about for decades.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.wsj.com&#x2F;tech&#x2F;cybersecurity&#x2F;u-s-wiretap-systems-targeted-in-china-linked-hack-327fc63b&quot;&gt;www.wsj.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-schneier-says-china-is-hacking-the-lawful-access-backdoor&quot;&gt;3. Schneier says China is hacking the lawful access backdoor&lt;&#x2F;h3&gt;
&lt;p&gt;Bruce Schneier argued on 8 October that the telecom breach proved a long standing point, that a wiretap capability built for the good guys is a capability anyone can abuse. He wrote that the law mandated backdoors under CALEA cannot tell a friendly agency from a hostile one.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.schneier.com&#x2F;blog&#x2F;archives&#x2F;2024&#x2F;10&#x2F;china-possibly-hacking-us-lawful-access-backdoor.html&quot;&gt;www.schneier.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-ftc-orders-marriott-to-overhaul-security-after-three-breaches&quot;&gt;4. FTC orders Marriott to overhaul security after three breaches&lt;&#x2F;h3&gt;
&lt;p&gt;The Federal Trade Commission announced on 9 October that Marriott and its Starwood subsidiary must build a comprehensive security programme to settle charges over breaches that exposed data on more than 344 million guests. Marriott also agreed to pay 52 million dollars to 49 states and to let customers request deletion of their personal information.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2024&#x2F;10&#x2F;ftc-takes-action-against-marriott-starwood-over-multiple-data-breaches&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-internet-archive-breach-exposes-31-million-accounts&quot;&gt;5. Internet Archive breach exposes 31 million accounts&lt;&#x2F;h3&gt;
&lt;p&gt;The Internet Archive disclosed on 9 October that attackers had stolen authentication data for around 31 million registered users, including email addresses, screen names and hashed passwords. Days later the same intruders reached the organisation&#x27;s Zendesk support system and read sensitive support tickets.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;internet-archive-hacked-data-breach-impacts-31-million-users&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-ftc-finalises-its-click-to-cancel-rule-for-subscriptions&quot;&gt;6. FTC finalises its click to cancel rule for subscriptions&lt;&#x2F;h3&gt;
&lt;p&gt;The Federal Trade Commission announced its final negative option rule on 16 October, requiring sellers to make cancelling a subscription as easy as signing up. The rule also forces clear disclosures and express consent before a company can enrol someone in a recurring charge.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2024&#x2F;10&#x2F;federal-trade-commission-announces-final-click-cancel-rule-making-it-easier-consumers-end-recurring&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-cfpb-open-banking-rule-gives-people-control-of-financial-data&quot;&gt;7. CFPB open banking rule gives people control of financial data&lt;&#x2F;h3&gt;
&lt;p&gt;The Consumer Financial Protection Bureau finalised its personal financial data rights rule on 22 October, letting consumers move their banking data to another provider for free. The rule limits how authorised third parties may use and retain that data and bars them from exploiting it for unrelated purposes.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.consumerfinance.gov&#x2F;about-us&#x2F;newsroom&#x2F;cfpb-finalizes-personal-financial-data-rights-rule-to-boost-competition-protect-privacy-and-give-families-more-choice-in-financial-services&#x2F;&quot;&gt;www.consumerfinance.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-eff-tells-massachusetts-court-to-limit-reuse-of-monitoring-data&quot;&gt;8. EFF tells Massachusetts court to limit reuse of monitoring data&lt;&#x2F;h3&gt;
&lt;p&gt;The Electronic Frontier Foundation filed a brief on 22 October urging the state&#x27;s highest court to bar police from mining pretrial electronic monitoring data to investigate unrelated crimes. The group argued that location data gathered for one purpose cannot become a general warrant for fishing expeditions.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;10&#x2F;eff-massachusetts-highest-court-pretrial-electronic-monitoring-should-not&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-cisco-takes-devhub-portal-offline-after-data-leak&quot;&gt;9. Cisco takes DevHub portal offline after data leak&lt;&#x2F;h3&gt;
&lt;p&gt;A threat actor known as IntelBroker claimed on 14 October to have taken source code, certificates, API tokens and customer files from a Cisco environment. Cisco confirmed on 18 October that the data came from a public facing DevHub instance and took the portal offline after the hacker published stolen files.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;cisco-takes-devhub-portal-offline-after-hacker-publishes-stolen-data&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-hot-topic-breach-exposes-millions-of-shopper-records&quot;&gt;10. Hot Topic breach exposes millions of shopper records&lt;&#x2F;h3&gt;
&lt;p&gt;A hacker using the alias Satanic posted on 21 October claiming to have taken vast amounts of personal data from Hot Topic and its sister brands. The stolen records included names, addresses, phone numbers and partial payment card details, traced to malware on a third party vendor.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;cyberinsider.com&#x2F;hot-topic-allegedly-breached-350-million-customers-data-for-sale&#x2F;&quot;&gt;cyberinsider.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-california-regulator-opens-data-broker-registration-probe&quot;&gt;11. California regulator opens data broker registration probe&lt;&#x2F;h3&gt;
&lt;p&gt;The California Privacy Protection Agency announced on 30 October that its enforcement division was reviewing whether data brokers had registered as the Delete Act requires. Brokers that fail to register face penalties of 200 dollars a day ahead of a 2026 platform that will let people delete their data from every broker at once.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;cppa.ca.gov&#x2F;announcements&#x2F;2024&#x2F;20241030.html&quot;&gt;cppa.ca.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-eff-warns-age-verification-laws-will-harm-more-than-they-help&quot;&gt;12. EFF warns age verification laws will harm more than they help&lt;&#x2F;h3&gt;
&lt;p&gt;The Electronic Frontier Foundation filed a brief with the Fifth Circuit on 4 October arguing that Mississippi&#x27;s age verification law violates the First Amendment. The group said the law burdens adults and minors alike, threatens online anonymity and creates fresh privacy risks without protecting children.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;10&#x2F;eff-fifth-circuit-age-verification-laws-will-hurt-more-they-help&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-fidelity-breach-exposes-data-of-77-000-customers&quot;&gt;13. Fidelity breach exposes data of 77,000 customers&lt;&#x2F;h3&gt;
&lt;p&gt;Fidelity Investments told regulators in early October that an intruder using two newly created customer accounts had accessed the data of more than 77,000 people. The exposed records included Social Security numbers and driver&#x27;s licence details, though the firm said no customer accounts were touched.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;10&#x2F;10&#x2F;fidelity-says-data-breach-exposed-personal-data-of-77000-customers&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-indian-court-orders-telegram-to-delete-star-health-leak-bots&quot;&gt;14. Indian court orders Telegram to delete Star Health leak bots&lt;&#x2F;h3&gt;
&lt;p&gt;The Madras High Court ordered on 25 October that Telegram block chatbots used to leak the medical records and policy documents of Star Health customers. The insurer had sued Telegram and Cloudflare after a hacker offered the data of about 31 million policyholders for sale.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.businesstoday.in&#x2F;india&#x2F;story&#x2F;star-health-insurance-data-leak-madras-high-court-orders-telegram-to-delete-chatbots-posts-451532-2024-10-25&quot;&gt;www.businesstoday.in&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-change-healthcare-tells-100-million-people-their-data-was-stolen&quot;&gt;15. Change Healthcare tells 100 million people their data was stolen&lt;&#x2F;h3&gt;
&lt;p&gt;Change Healthcare began notifying roughly 100 million Americans on 30 October that their medical, financial and personal data had been stolen in a February ransomware attack. The breach exposed health records, billing information and Social Security numbers in the largest healthcare data theft yet recorded.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;10&#x2F;change-healthcare-breach-hits-100m-americans&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-mobile-ad-data-fuels-a-global-surveillance-free-for-all&quot;&gt;16. Mobile ad data fuels a global surveillance free for all&lt;&#x2F;h3&gt;
&lt;p&gt;Brian Krebs reported on 23 October that commercial tools such as Babel Street let almost anyone track a person&#x27;s movements using the advertising identifiers leaking from ordinary phone apps. The investigation showed how police officers, abortion seekers and other vulnerable people can be followed with no warrant and little recourse.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;10&#x2F;the-global-surveillance-free-for-all-in-mobile-ad-data&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-eff-warns-a-sale-of-23andme-data-would-endanger-privacy&quot;&gt;17. EFF warns a sale of 23andMe data would endanger privacy&lt;&#x2F;h3&gt;
&lt;p&gt;The Electronic Frontier Foundation cautioned on 9 October that the company&#x27;s signal it might sell itself put the genetic data of around 15 million customers at risk. The group set out steps people can take to delete their samples and pressed any buyer to honour strong privacy commitments.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;10&#x2F;sale-23andmes-data-would-be-bad-privacy-heres-what-customers-can-do&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-eff-tells-new-york-that-age-checks-threaten-everyone-s-privacy&quot;&gt;18. EFF tells New York that age checks threaten everyone&#x27;s privacy&lt;&#x2F;h3&gt;
&lt;p&gt;The Electronic Frontier Foundation submitted comments in October on New York&#x27;s plan to enforce its Stop Addictive Feeds Exploitation Act for minors. The group argued that requiring platforms to verify ages would force every user to surrender identity data and chill protected speech.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;10&#x2F;eff-new-york-age-verification-threatens-everyones-speech-and-privacy&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-casio-confirms-ransomware-attack-leaked-personal-data&quot;&gt;19. Casio confirms ransomware attack leaked personal data&lt;&#x2F;h3&gt;
&lt;p&gt;Casio confirmed on 14 October that a ransomware attack had exposed the personal data of employees, business partners and some customers, alongside sensitive company files. The Underground gang claimed the intrusion and threatened to publish confidential documents after the firm refused to meet its demands.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;10&#x2F;14&#x2F;casio-confirms-customer-data-compromised-in-ransomware-attack&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-brazil-arrests-hacker-linked-to-the-national-public-data-breach&quot;&gt;20. Brazil arrests hacker linked to the National Public Data breach&lt;&#x2F;h3&gt;
&lt;p&gt;Brazilian police announced on 18 October the arrest of a man suspected of being USDoD, the cybercriminal tied to the National Public Data breach that leaked Social Security numbers for much of the United States. The same figure was blamed for breaching the FBI&#x27;s InfraGard programme and leaking the contact details of 80,000 members.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;10&#x2F;brazil-arrests-usdod-hacker-in-fbi-infragard-breach&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0218 • September 2024</title>
          <pubDate>Thu, 03 Oct 2024 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0218/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0218/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0218/">&lt;!-- Covered month: September 2024 (2024-09-01 to 2024-09-30) --&gt;
&lt;p&gt;September 2024 brought record European fines, fresh breach disclosures and a sharp reminder that surveillance reaches from telecom wiretap systems to children&#x27;s social accounts.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-irish-regulator-fines-meta-91-million-euro-over-plaintext-passwords&quot;&gt;1. Irish regulator fines Meta 91 million euro over plaintext passwords&lt;&#x2F;h3&gt;
&lt;p&gt;The Irish Data Protection Commission fined Meta 91 million euro on 27 September for storing some Facebook and Instagram passwords in readable plaintext. The regulator found four breaches of the GDPR, including a failure to notify and document the incident promptly.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.dataprotection.ie&#x2F;en&#x2F;news-media&#x2F;press-releases&#x2F;DPC-announces-91-million-fine-of-Meta&quot;&gt;www.dataprotection.ie&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-dutch-watchdog-fines-clearview-ai-30-5-million-euro-for-illegal-face-database&quot;&gt;2. Dutch watchdog fines Clearview AI 30.5 million euro for illegal face database&lt;&#x2F;h3&gt;
&lt;p&gt;The Dutch Data Protection Authority fined Clearview AI 30.5 million euro on 3 September for building a database of more than thirty billion scraped facial images without consent. The regulator added penalties of up to 5.1 million euro if the company does not stop the violations.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.autoriteitpersoonsgegevens.nl&#x2F;en&#x2F;current&#x2F;dutch-dpa-imposes-a-fine-on-clearview-because-of-illegal-data-collection-for-facial-recognition&quot;&gt;www.autoriteitpersoonsgegevens.nl&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-ftc-report-finds-vast-commercial-surveillance-across-social-media-platforms&quot;&gt;3. FTC report finds vast commercial surveillance across social media platforms&lt;&#x2F;h3&gt;
&lt;p&gt;A Federal Trade Commission staff report published on 19 September found that large social media and streaming firms engaged in mass surveillance of users with weak controls. The report criticised inadequate safeguards for children and teenagers and the indefinite retention of personal data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2024&#x2F;09&#x2F;ftc-staff-report-finds-large-social-media-video-streaming-companies-have-engaged-vast-surveillance&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-telegram-agrees-to-hand-user-ip-addresses-and-phone-numbers-to-police&quot;&gt;4. Telegram agrees to hand user IP addresses and phone numbers to police&lt;&#x2F;h3&gt;
&lt;p&gt;On 23 September, Telegram changed its privacy policy to share IP addresses and phone numbers of suspects with authorities in response to valid legal requests. The shift followed the arrest of founder Pavel Durov in France and widened cooperation far beyond terrorism cases.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;legal&#x2F;telegram-hands-over-data-on-thousands-of-users-to-us-law-enforcement&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-moneygram-says-hackers-stole-customer-personal-and-transaction-data&quot;&gt;5. MoneyGram says hackers stole customer personal and transaction data&lt;&#x2F;h3&gt;
&lt;p&gt;MoneyGram disclosed that attackers accessed customer data between 20 and 22 September, prompting a week of service outages. The stolen records included names, addresses, dates of birth, Social Security numbers, bank account numbers and copies of government identification.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;10&#x2F;07&#x2F;moneygram-says-hackers-stole-customers-personal-information-and-transaction-data&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-mozilla-hit-with-gdpr-complaint-over-firefox-tracking-feature&quot;&gt;6. Mozilla hit with GDPR complaint over Firefox tracking feature&lt;&#x2F;h3&gt;
&lt;p&gt;The privacy group noyb filed a complaint with the Austrian regulator on 25 September over Firefox&#x27;s Privacy Preserving Attribution feature. The group argued that Mozilla enabled the advertising measurement tool by default without informing users or seeking their consent.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;09&#x2F;25&#x2F;mozilla-hit-with-privacy-complaint-in-eu-over-firefox-tracking-tech&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-instagram-makes-teenage-accounts-private-by-default&quot;&gt;7. Instagram makes teenage accounts private by default&lt;&#x2F;h3&gt;
&lt;p&gt;Meta announced Instagram Teen Accounts on 17 September, placing users under sixteen into private profiles with stricter messaging and content settings. Teenagers need a parent&#x27;s permission to loosen the defaults, and the changes began rolling out in the United States, Canada, the United Kingdom and Australia.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;about.fb.com&#x2F;news&#x2F;2024&#x2F;09&#x2F;instagram-teen-accounts&#x2F;&quot;&gt;about.fb.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-at-t-agrees-to-pay-13-million-dollars-to-the-fcc-over-a-vendor-breach&quot;&gt;8. AT&amp;amp;T agrees to pay 13 million dollars to the FCC over a vendor breach&lt;&#x2F;h3&gt;
&lt;p&gt;The Federal Communications Commission announced a 13 million dollar settlement with AT&amp;amp;T on 17 September over a cloud breach at one of its vendors. The vendor retained the billing data of around nine million customers for years after it should have been destroyed, and attackers exfiltrated it in 2023.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;broadbandbreakfast.com&#x2F;fcc-fines-at-t-13-million-for-data-breach-last-year&#x2F;&quot;&gt;broadbandbreakfast.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-china-linked-salt-typhoon-hackers-breach-us-broadband-and-wiretap-systems&quot;&gt;9. China-linked Salt Typhoon hackers breach US broadband and wiretap systems&lt;&#x2F;h3&gt;
&lt;p&gt;On 25 September it emerged that the Salt Typhoon group had compromised major US broadband providers and the systems used for court-authorised wiretaps. The intrusion raised fears that a foreign government had gained access to sensitive law enforcement surveillance data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.semafor.com&#x2F;article&#x2F;09&#x2F;25&#x2F;2024&#x2F;chinas-salt-typhoon-hacking-campaign-targets-us-internet-service-providers&quot;&gt;www.semafor.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-disney-to-drop-slack-after-a-1-1-terabyte-data-leak&quot;&gt;10. Disney to drop Slack after a 1.1 terabyte data leak&lt;&#x2F;h3&gt;
&lt;p&gt;Disney told staff on 20 September that it would stop using Slack following a breach that leaked more than a terabyte of internal messages and files. The leaked trove included unreleased project details, login credentials and crew passport numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;fortune.com&#x2F;2024&#x2F;09&#x2F;20&#x2F;disney-slack-data-breach-nullbulge&#x2F;&quot;&gt;fortune.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-23andme-agrees-to-a-30-million-dollar-settlement-over-genetic-data-breach&quot;&gt;11. 23andMe agrees to a 30 million dollar settlement over genetic data breach&lt;&#x2F;h3&gt;
&lt;p&gt;On 12 September, 23andMe agreed to a 30 million dollar settlement over the 2023 breach that exposed the data of nearly seven million customers. The case alleged the company failed to protect sensitive genetic information and to warn users targeted by ancestry.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.malwarebytes.com&#x2F;blog&#x2F;news&#x2F;2024&#x2F;09&#x2F;23andme-to-pay-30-million-in-settlement-over-2023-data-breach&quot;&gt;www.malwarebytes.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-apple-moves-to-drop-its-lawsuit-against-spyware-maker-nso-group&quot;&gt;12. Apple moves to drop its lawsuit against spyware maker NSO Group&lt;&#x2F;h3&gt;
&lt;p&gt;Apple asked a court on 13 September to dismiss its own case against the Pegasus spyware vendor NSO Group. The company argued that pursuing the suit risked exposing sensitive threat intelligence that could help spyware makers refine their tools.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;apple-seeks-dismissal-of-nso-lawsuit-pegasus-spyware&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-california-signs-laws-extending-privacy-rules-to-artificial-intelligence&quot;&gt;13. California signs laws extending privacy rules to artificial intelligence&lt;&#x2F;h3&gt;
&lt;p&gt;Governor Gavin Newsom signed AB 1008 on 28 September, clarifying that personal information under the state privacy law can exist inside artificial intelligence systems. A companion law, AB 2013, requires generative AI developers to disclose details about their training data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.wsgr.com&#x2F;en&#x2F;insights&#x2F;governor-newsom-signs-and-vetoes-major-california-ai-legislation.html&quot;&gt;www.wsgr.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-uk-regulator-reprimands-sky-betting-and-gaming-over-advertising-cookies&quot;&gt;14. UK regulator reprimands Sky Betting and Gaming over advertising cookies&lt;&#x2F;h3&gt;
&lt;p&gt;The Information Commissioner&#x27;s Office reprimanded Bonne Terre, trading as Sky Betting and Gaming, for setting advertising cookies before users could refuse them. Personal data was shared with advertising technology firms the moment people opened the site, without prior consent.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;ico.org.uk&#x2F;about-the-ico&#x2F;media-centre&#x2F;news-and-blogs&#x2F;2024&#x2F;09&#x2F;action-taken-against-sky-betting-and-gaming-for-using-cookies-without-consent&#x2F;&quot;&gt;ico.org.uk&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-medicare-contractor-breach-affects-more-than-three-million-people&quot;&gt;15. Medicare contractor breach affects more than three million people&lt;&#x2F;h3&gt;
&lt;p&gt;The Centers for Medicare and Medicaid Services began notifying affected individuals on 6 September after a breach at contractor Wisconsin Physicians Service. The incident stemmed from the MOVEit file transfer flaw and exposed names, Social Security numbers and Medicare identifiers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cms.gov&#x2F;newsroom&#x2F;press-releases&#x2F;cms-notifies-individuals-potentially-impacted-data-breach&quot;&gt;www.cms.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-dell-investigates-leak-of-employee-records-on-a-hacking-forum&quot;&gt;16. Dell investigates leak of employee records on a hacking forum&lt;&#x2F;h3&gt;
&lt;p&gt;Dell began investigating a breach after a hacker leaked details of more than ten thousand employees and partners on 19 September. The exposed records included full names, internal identifiers and employment status drawn from the company&#x27;s systems.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;dell-investigates-data-breach-claims-after-hacker-leaks-employee-info&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-eff-warns-the-ftc-report-shows-commercial-surveillance-is-out-of-control&quot;&gt;17. EFF warns the FTC report shows commercial surveillance is out of control&lt;&#x2F;h3&gt;
&lt;p&gt;The Electronic Frontier Foundation argued on 26 September that the new FTC findings confirmed an unchecked surveillance economy. The group called for comprehensive privacy legislation rather than relying on companies to police their own data practices.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;09&#x2F;ftc-report-confirms-commercial-surveillance-out-control&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-slim-cd-breach-exposes-credit-card-data-of-1-7-million-people&quot;&gt;18. Slim CD breach exposes credit card data of 1.7 million people&lt;&#x2F;h3&gt;
&lt;p&gt;The payment gateway Slim CD disclosed on 6 September that attackers had access to its systems for almost ten months. The compromised data included names, addresses and credit card numbers and expiry dates of around 1.7 million individuals.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.securityweek.com&#x2F;slim-cd-data-breach-impacts-1-7-million-individuals&#x2F;&quot;&gt;www.securityweek.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-fortinet-confirms-customer-data-stolen-from-a-third-party-cloud-drive&quot;&gt;19. Fortinet confirms customer data stolen from a third-party cloud drive&lt;&#x2F;h3&gt;
&lt;p&gt;Fortinet confirmed on 13 September that a hacker had stolen customer files from a third-party cloud-based shared drive. The attacker claimed to hold 440 gigabytes of data and published it after the company refused to pay a ransom.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;09&#x2F;13&#x2F;fortinet-confirms-customer-data-breach&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-eso-solutions-ransomware-attack-compromises-data-of-2-7-million-patients&quot;&gt;20. ESO Solutions ransomware attack compromises data of 2.7 million patients&lt;&#x2F;h3&gt;
&lt;p&gt;The healthcare and emergency services software provider ESO Solutions disclosed a ransomware attack that exposed the records of around 2.7 million patients. Attackers exfiltrated data before encrypting company systems, exposing sensitive medical and personal details.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;healthcare-software-provider-data-breach-impacts-27-million&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0217 • August 2024</title>
          <pubDate>Thu, 05 Sep 2024 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0217/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0217/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0217/">&lt;!-- Covered month: August 2024 (2024-08-01 to 2024-08-31) --&gt;
&lt;p&gt;August 2024 brought the arrest of Telegram&#x27;s founder, a record GDPR fine on Uber, the National Public Data mega-breach and a run of court rulings that reshaped surveillance and Big Tech privacy.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-national-public-data-confirms-breach-exposing-social-security-numbers&quot;&gt;1. National Public Data confirms breach exposing Social Security numbers&lt;&#x2F;h3&gt;
&lt;p&gt;The background check broker National Public Data confirmed a breach after a hacker leaked a database said to hold billions of records of names, addresses and Social Security numbers. The firm later filed for bankruptcy as more than a dozen lawsuits piled up.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;national-public-data-confirms-breach-exposing-social-security-numbers&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-telegram-ceo-pavel-durov-indicted-in-france&quot;&gt;2. Telegram CEO Pavel Durov indicted in France&lt;&#x2F;h3&gt;
&lt;p&gt;French police arrested Telegram co-founder Pavel Durov at a Paris airport on 24 August, and prosecutors indicted him days later on charges tied to crime on the platform. One of the charges, providing cryptology services without a licence, alarmed privacy advocates across the messaging industry.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.npr.org&#x2F;2024&#x2F;08&#x2F;28&#x2F;nx-s1-5091295&#x2F;telegram-ceo-pavel-durov-france-indicted&quot;&gt;www.npr.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-federal-court-rules-google-is-an-illegal-monopoly&quot;&gt;3. Federal court rules Google is an illegal monopoly&lt;&#x2F;h3&gt;
&lt;p&gt;Judge Amit Mehta ruled on 5 August that Google had unlawfully maintained its monopoly over search and search advertising. The decision opened the door to remedies that could reshape how the company collects and exploits user data.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.goodwinlaw.com&#x2F;en&#x2F;insights&#x2F;publications&#x2F;2024&#x2F;08&#x2F;alerts-technology-antc-google-is-an-illegal-monopoly-federal-court-rules&quot;&gt;www.goodwinlaw.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-dutch-regulator-fines-uber-290-million-euros-over-us-data-transfers&quot;&gt;4. Dutch regulator fines Uber 290 million euros over US data transfers&lt;&#x2F;h3&gt;
&lt;p&gt;The Dutch Data Protection Authority fined Uber 290 million euros for sending European drivers&#x27; personal data to the United States without proper safeguards. The penalty ranked among the largest ever imposed under the GDPR.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.autoriteitpersoonsgegevens.nl&#x2F;en&#x2F;current&#x2F;dutch-dpa-imposes-a-fine-of-290-million-euro-on-uber-because-of-transfers-of-drivers-data-to-the-us&quot;&gt;www.autoriteitpersoonsgegevens.nl&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-x-agrees-to-suspend-use-of-eu-data-to-train-grok&quot;&gt;5. X agrees to suspend use of EU data to train Grok&lt;&#x2F;h3&gt;
&lt;p&gt;Ireland&#x27;s Data Protection Commission won an undertaking from X to stop processing European users&#x27; public posts to train its Grok artificial intelligence tool. It was the first time the regulator had used its urgent High Court powers in this way.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.dataprotection.ie&#x2F;en&#x2F;news-media&#x2F;press-releases&#x2F;dpc-welcomes-xs-agreement-suspend-its-processing-personal-data-purpose-training-ai-tool-grok&quot;&gt;www.dataprotection.ie&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-brazil-lifts-its-ban-on-meta-training-ai-with-user-data&quot;&gt;6. Brazil lifts its ban on Meta training AI with user data&lt;&#x2F;h3&gt;
&lt;p&gt;Brazil&#x27;s data protection authority lifted the suspension that had stopped Meta from using public posts to train its generative models. The regulator allowed processing to resume after Meta improved transparency, while keeping data of under-eighteens off limits.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;thehackernews.com&#x2F;2024&#x2F;07&#x2F;brazil-halts-metas-ai-data-processing.html&quot;&gt;thehackernews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-city-of-columbus-sues-researcher-who-exposed-its-ransomware-leak&quot;&gt;7. City of Columbus sues researcher who exposed its ransomware leak&lt;&#x2F;h3&gt;
&lt;p&gt;The City of Columbus, Ohio, sued the security researcher who revealed that data stolen in a ransomware attack contained unencrypted personal records of residents. Critics said the lawsuit tried to silence a whistleblower rather than protect the public.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.malwarebytes.com&#x2F;blog&#x2F;news&#x2F;2024&#x2F;09&#x2F;city-of-columbus-tries-to-silence-security-researcher&quot;&gt;www.malwarebytes.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-halliburton-hit-by-ransomhub-ransomware-attack&quot;&gt;8. Halliburton hit by RansomHub ransomware attack&lt;&#x2F;h3&gt;
&lt;p&gt;Oil services giant Halliburton disclosed in an SEC filing that an unauthorised party had accessed its systems and disrupted operations. Researchers later linked the August intrusion to the RansomHub ransomware gang, and the company reported a 35 million dollar loss.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;halliburton-cyberattack-linked-to-ransomhub-ransomware-gang&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-toyota-confirms-third-party-data-breach-impacting-customers&quot;&gt;9. Toyota confirms third-party data breach impacting customers&lt;&#x2F;h3&gt;
&lt;p&gt;Toyota confirmed that customer and employee data had been stolen after a hacker leaked 240GB of files on a forum. The carmaker blamed a third-party entity and said its own systems were not breached.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;toyota-confirms-third-party-data-breach-impacting-customers&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-microchip-technology-discloses-cyberattack-impacting-operations&quot;&gt;10. Microchip Technology discloses cyberattack impacting operations&lt;&#x2F;h3&gt;
&lt;p&gt;Chipmaker Microchip Technology told regulators that an intrusion had disrupted servers and forced factories to run below normal levels. The company later said attackers obtained employee contact details and hashed passwords.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;microchip-technology-discloses-cyberattack-impacting-operations&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-enzo-biochem-fined-4-5-million-dollars-over-2023-ransomware-breach&quot;&gt;11. Enzo Biochem fined 4.5 million dollars over 2023 ransomware breach&lt;&#x2F;h3&gt;
&lt;p&gt;The attorneys general of New York, New Jersey and Connecticut fined biotech firm Enzo Biochem for security failures that exposed health data on 2.4 million people. Investigators found shared logins, no multi-factor authentication and a password left unchanged for a decade.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2024&#x2F;08&#x2F;14&#x2F;enzo_biochem_ransomware_fine&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-adt-confirms-breach-exposing-customer-contact-details&quot;&gt;12. ADT confirms breach exposing customer contact details&lt;&#x2F;h3&gt;
&lt;p&gt;Home security firm ADT disclosed that an attacker had accessed databases holding customer email addresses, phone numbers and postal addresses. The company said it had no reason to believe financial data or home security systems were compromised.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.sec.gov&#x2F;Archives&#x2F;edgar&#x2F;data&#x2F;0001703056&#x2F;000095015724001064&#x2F;form8k.htm&quot;&gt;www.sec.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-microsoft-pushes-recall-to-october-after-privacy-backlash&quot;&gt;13. Microsoft pushes Recall to October after privacy backlash&lt;&#x2F;h3&gt;
&lt;p&gt;Microsoft said its controversial Recall feature, which captures screenshots of user activity, would reach Windows Insiders in October rather than launch broadly. The delay followed sustained criticism from researchers who showed how easily the snapshots could be extracted.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.malwarebytes.com&#x2F;blog&#x2F;news&#x2F;2024&#x2F;06&#x2F;microsoft-recall-delayed-after-privacy-and-security-concerns&quot;&gt;www.malwarebytes.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-google-says-iranian-group-targeted-trump-and-biden-campaign-staff&quot;&gt;14. Google says Iranian group targeted Trump and Biden campaign staff&lt;&#x2F;h3&gt;
&lt;p&gt;Google&#x27;s Threat Analysis Group reported that the Iran-linked group APT42 had run phishing operations against people tied to both presidential campaigns. The disclosure detailed how the attackers compromised the personal accounts of political figures.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;abcnews.go.com&#x2F;Politics&#x2F;iran-hacking-group-targeted-emails-biden-trump-campaign&#x2F;story?id=112844299&quot;&gt;abcnews.go.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-justice-department-sues-tiktok-over-children-s-privacy&quot;&gt;15. Justice Department sues TikTok over children&#x27;s privacy&lt;&#x2F;h3&gt;
&lt;p&gt;The US Department of Justice sued TikTok and ByteDance, alleging they collected data from millions of children without parental consent in breach of federal law. The complaint sought heavy civil penalties and an order to stop the practice.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.npr.org&#x2F;2024&#x2F;08&#x2F;02&#x2F;g-s1-15126&#x2F;doj-tiktok-lawsuit-children-data&quot;&gt;www.npr.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-nist-releases-first-finalised-post-quantum-encryption-standards&quot;&gt;16. NIST releases first finalised post-quantum encryption standards&lt;&#x2F;h3&gt;
&lt;p&gt;The National Institute of Standards and Technology published three finished standards for encryption designed to resist future quantum computers. The release gave organisations a concrete path to protect long-lived data against a coming threat.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.nist.gov&#x2F;news-events&#x2F;news&#x2F;2024&#x2F;08&#x2F;nist-releases-first-3-finalized-post-quantum-encryption-standards&quot;&gt;www.nist.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-appeals-court-rules-geofence-warrants-are-categorically-unconstitutional&quot;&gt;17. Appeals court rules geofence warrants are categorically unconstitutional&lt;&#x2F;h3&gt;
&lt;p&gt;The Fifth Circuit held in United States v. Smith that geofence warrants, which sweep up location data from everyone near a place, violate the Fourth Amendment. Privacy advocates welcomed the ruling as a check on dragnet location surveillance.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;08&#x2F;federal-appeals-court-finds-geofence-warrants-are-categorically-unconstitutional&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-cyberattack-on-mobile-guardian-wipes-thousands-of-student-devices&quot;&gt;18. Cyberattack on Mobile Guardian wipes thousands of student devices&lt;&#x2F;h3&gt;
&lt;p&gt;A breach of the school device management platform Mobile Guardian let an intruder remotely wipe iOS and ChromeOS devices around the world. Singapore reported that roughly 13,000 students across 26 schools lost access to their machines.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;08&#x2F;06&#x2F;cyberattack-knocks-mobile-guardian-mdm-offline-and-wipes-thousands-of-student-devices&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-patelco-credit-union-confirms-member-data-exposed-in-ransomware-attack&quot;&gt;19. Patelco Credit Union confirms member data exposed in ransomware attack&lt;&#x2F;h3&gt;
&lt;p&gt;Patelco Credit Union acknowledged that a ransomware attack had exposed personal data including Social Security numbers and dates of birth. The breach affected more than a million current and former members and employees.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cutimes.com&#x2F;2024&#x2F;08&#x2F;26&#x2F;patelcos-data-breach-affected-726000-people&#x2F;&quot;&gt;www.cutimes.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-eff-warns-that-police-drones-erode-backyard-privacy&quot;&gt;20. EFF warns that police drones erode backyard privacy&lt;&#x2F;h3&gt;
&lt;p&gt;The Electronic Frontier Foundation argued that the spread of police drones threatens privacy in spaces that courts once treated as protected. With old aerial surveillance precedents offering little shield, it urged states to require warrants for drone flights.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;08&#x2F;backyard-privacy-age-drones&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0216 • July 2024</title>
          <pubDate>Thu, 01 Aug 2024 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0216/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0216/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0216/">&lt;!-- Covered month: July 2024 (2024-07-01 to 2024-07-31) --&gt;
&lt;p&gt;July 2024 was dominated by the fallout from the Snowflake breaches, record-breaking fines and bans, and fresh fights over surveillance and online safety law.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-at-t-says-criminals-stole-phone-records-of-nearly-all-customers&quot;&gt;1. AT&amp;amp;T says criminals stole phone records of nearly all customers&lt;&#x2F;h3&gt;
&lt;p&gt;AT&amp;amp;T disclosed on 12 July that attackers had downloaded call and text records covering almost all of its wireless customers from a third-party cloud workspace. The stolen metadata revealed who contacted whom and, for some accounts, cell tower identifiers that could approximate a person&#x27;s location.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;07&#x2F;12&#x2F;att-phone-records-stolen-data-breach&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-twilio-confirms-breach-after-hackers-leak-33-million-authy-phone-numbers&quot;&gt;2. Twilio confirms breach after hackers leak 33 million Authy phone numbers&lt;&#x2F;h3&gt;
&lt;p&gt;Twilio confirmed that attackers had abused an unsecured endpoint to harvest the phone numbers of 33 million users of its Authy two-factor authentication app. The exposed numbers gave criminals a ready list of targets for phishing and SIM-swapping attacks.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.securityweek.com&#x2F;twilio-confirms-data-breach-after-hackers-leak-33m-authy-user-phone-numbers&#x2F;&quot;&gt;www.securityweek.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-evolve-bank-says-ransomware-gang-stole-data-on-millions-of-customers&quot;&gt;3. Evolve Bank says ransomware gang stole data on millions of customers&lt;&#x2F;h3&gt;
&lt;p&gt;Evolve Bank and Trust confirmed that the LockBit ransomware group had stolen the personal information of more than seven million people after the bank refused to pay. The haul included names, Social Security numbers, and bank account details, which the gang then published on its leak site.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;07&#x2F;09&#x2F;evolve-bank-says-ransomware-gang-stole-personal-data-on-millions-of-customers&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-healthequity-says-data-breach-affects-4-3-million-people&quot;&gt;4. HealthEquity says data breach affects 4.3 million people&lt;&#x2F;h3&gt;
&lt;p&gt;The health savings account custodian HealthEquity disclosed that a partner&#x27;s compromised credentials had exposed the protected health information of 4.3 million individuals. The leaked records included names, addresses, Social Security numbers, and employment details.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;healthequity-says-data-breach-impacts-43-million-people&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-texas-wins-1-4-billion-dollar-biometric-settlement-against-meta&quot;&gt;5. Texas wins 1.4 billion dollar biometric settlement against Meta&lt;&#x2F;h3&gt;
&lt;p&gt;Texas secured a record 1.4 billion dollar settlement from Meta over its capture of residents&#x27; facial geometry without consent through Facebook&#x27;s tag suggestions feature. The Electronic Frontier Foundation argued the outcome would have come sooner had individuals been allowed to sue directly.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;07&#x2F;texas-wins-14-billion-biometric-settlement-against-meta-it-would-have-happened&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-us-commerce-department-ban-forces-kaspersky-out-of-the-country&quot;&gt;6. US Commerce Department ban forces Kaspersky out of the country&lt;&#x2F;h3&gt;
&lt;p&gt;Kaspersky said it would wind down its United States operations after the Commerce Department barred new sales of its security products from 20 July. Officials warned that the Russian firm could be compelled to gather and weaponise the data of American users.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;07&#x2F;16&#x2F;kaspersky-to-shut-down-us-operations-lay-off-employees-after-us-government-ban&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-crowdstrike-update-bricks-windows-machines-around-the-world&quot;&gt;7. CrowdStrike update bricks Windows machines around the world&lt;&#x2F;h3&gt;
&lt;p&gt;A faulty Falcon Sensor channel file from CrowdStrike crashed roughly 8.5 million Windows machines on 19 July, grounding flights and disrupting hospitals and banks. The episode showed how deeply a single security vendor&#x27;s code is woven into critical infrastructure.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2024&#x2F;07&#x2F;19&#x2F;crowdstrike_falcon_sensor_bsod_incident&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-the-kosa-internet-censorship-bill-passes-the-senate&quot;&gt;8. The KOSA internet censorship bill passes the Senate&lt;&#x2F;h3&gt;
&lt;p&gt;The Senate passed the Kids Online Safety Act by 91 votes to 3, advancing a measure that would create a duty of care for online platforms. The Electronic Frontier Foundation warned the bill would chill protected speech and push services towards privacy-invasive age verification.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;07&#x2F;kosa-internet-censorship-bill-just-passed-senate-its-our-last-chance-stop-it&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-rockyou2024-leak-compiles-nearly-10-billion-passwords&quot;&gt;9. RockYou2024 leak compiles nearly 10 billion passwords&lt;&#x2F;h3&gt;
&lt;p&gt;A forum user published a file containing close to 10 billion unique plaintext passwords gathered from thousands of past breaches. Researchers warned the trove could fuel credential-stuffing and brute-force attacks against almost any unprotected system.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.malwarebytes.com&#x2F;blog&#x2F;news&#x2F;2024&#x2F;07&#x2F;rockyou2024-nearly-10-billion-passwords-leaked&quot;&gt;www.malwarebytes.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-meta-s-pay-or-consent-model-fails-eu-competition-rules&quot;&gt;10. Meta&#x27;s pay or consent model fails EU competition rules&lt;&#x2F;h3&gt;
&lt;p&gt;The European Commission found that Meta&#x27;s choice between paying a fee or accepting tracking breaches the Digital Markets Act because it denies users an equivalent, less personalised option. The case shows regulators turning to competition law to address data protection concerns that privacy rules alone have struggled to resolve.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;07&#x2F;01&#x2F;metas-pay-or-consent-model-fails-eu-competition-rules-commission-finds&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-un-cybercrime-draft-convention-dangerously-expands-surveillance-powers&quot;&gt;11. UN cybercrime draft convention dangerously expands surveillance powers&lt;&#x2F;h3&gt;
&lt;p&gt;The Electronic Frontier Foundation warned that the draft UN Cybercrime Convention would authorise open-ended evidence gathering with weak privacy safeguards. Civil society groups urged delegates to push back before the final negotiating session opened.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;07&#x2F;un-cybercrime-draft-convention-dangerously-expands-state-surveillance-powers&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-ai-mass-surveillance-at-the-olympics-is-a-privacy-nightmare&quot;&gt;12. AI mass surveillance at the Olympics is a privacy nightmare&lt;&#x2F;h3&gt;
&lt;p&gt;Techdirt examined France&#x27;s deployment of algorithmic video surveillance for the Paris Olympics under a law that civil liberties groups say breaches the GDPR. France became the first EU country to legalise such a sweeping AI-powered monitoring system.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.techdirt.com&#x2F;2024&#x2F;07&#x2F;31&#x2F;ai-mass-surveillance-at-the-olympics-is-a-privacy-nightmare&#x2F;&quot;&gt;www.techdirt.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-google-abandons-its-plan-to-drop-third-party-cookies-in-chrome&quot;&gt;13. Google abandons its plan to drop third-party cookies in Chrome&lt;&#x2F;h3&gt;
&lt;p&gt;Google reversed its long-running pledge to phase out third-party cookies, choosing instead to let users make a browser-wide choice about tracking. Privacy advocates and regulators had spent years scrutinising both the cookies and the Privacy Sandbox meant to replace them.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2024&#x2F;07&#x2F;23&#x2F;google_cookies_third_party_continue&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-ftc-bans-ngl-labs-from-offering-its-anonymous-app-to-minors&quot;&gt;14. FTC bans NGL Labs from offering its anonymous app to minors&lt;&#x2F;h3&gt;
&lt;p&gt;The Federal Trade Commission and the Los Angeles District Attorney barred the anonymous messaging app NGL from serving anyone under 18 and secured a five million dollar payment. Regulators said the firm sent users fake messages to push paid subscriptions and falsely claimed its AI filtered out bullying.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;07&#x2F;09&#x2F;ftc-bans-ngl-from-offering-its-anonymous-social-app-to-minors&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-supreme-court-rules-platforms-have-a-first-amendment-right-to-curate&quot;&gt;15. Supreme Court rules platforms have a First Amendment right to curate&lt;&#x2F;h3&gt;
&lt;p&gt;The Supreme Court held in the NetChoice cases that platforms have a constitutional right to decide what speech they carry, free of state mandates. The Electronic Frontier Foundation welcomed the decision while warning that related laws still threaten privacy through age verification.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;07&#x2F;effs-statement-netchoice-decisions&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-patelco-credit-union-shuts-down-banking-systems-after-ransomware-attack&quot;&gt;16. Patelco Credit Union shuts down banking systems after ransomware attack&lt;&#x2F;h3&gt;
&lt;p&gt;The California credit union took its online banking, mobile app, and call centre offline after a ransomware attack disrupted its systems at the start of July. The shutdown left more than 400,000 members unable to access many services for days.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;patelco-shuts-down-banking-systems-following-ransomware-attack&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-rite-aid-confirms-breach-exposing-data-on-2-2-million-people&quot;&gt;17. Rite Aid confirms breach exposing data on 2.2 million people&lt;&#x2F;h3&gt;
&lt;p&gt;Rite Aid confirmed that the RansomHub gang had stolen the personal details of 2.2 million customers in a June intrusion that it disclosed in July. The exposed records included names, addresses, dates of birth, and government identification numbers tied to past purchases.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;rite-aid-confirms-data-breach-after-june-ransomware-attack&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-weak-squarespace-defaults-let-attackers-hijack-domains&quot;&gt;18. Weak Squarespace defaults let attackers hijack domains&lt;&#x2F;h3&gt;
&lt;p&gt;Krebs on Security reported that weak authentication defaults in Squarespace&#x27;s migration of Google Domains let attackers seize at least a dozen organisations&#x27; domains. The hijackers exploited accounts that legitimate owners had never claimed, redirecting websites and email to themselves.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;07&#x2F;researchers-weak-security-defaults-enabled-squarespace-domains-hijacks&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-email-addresses-of-15-million-trello-users-leaked-online&quot;&gt;19. Email addresses of 15 million Trello users leaked online&lt;&#x2F;h3&gt;
&lt;p&gt;A threat actor published more than 15 million Trello email addresses gathered by abusing an unsecured API that linked addresses to public profiles. The combined data of email addresses and real names handed phishers and stalkers a convenient targeting list.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;email-addresses-of-15-million-trello-users-leaked-on-hacking-forum&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-adt-confirms-breach-after-customer-data-leaked-on-hacking-forum&quot;&gt;20. ADT confirms breach after customer data leaked on hacking forum&lt;&#x2F;h3&gt;
&lt;p&gt;The home security company ADT confirmed that attackers had stolen customer records and posted them on a hacking forum at the end of July. The exposed data included customer emails, addresses, and details of the products they had bought.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;adt-confirms-data-breach-after-customer-info-leaked-on-hacking-forum&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0215 • June 2024</title>
          <pubDate>Thu, 04 Jul 2024 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0215/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0215/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0215/">&lt;!-- Covered month: June 2024 (2024-06-01 to 2024-06-30) --&gt;
&lt;p&gt;June 2024 was dominated by the sprawling Snowflake credential thefts, fresh curbs on Big Tech artificial intelligence and surveillance, and a run of regulators, courts and breach disclosures reshaping data protection.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-snowflake-breach-exposes-165-customer-organisations&quot;&gt;1. Snowflake breach exposes 165 customer organisations&lt;&#x2F;h3&gt;
&lt;p&gt;Mandiant and Snowflake disclosed in June that a financially motivated group it tracks as UNC5537 had used stolen passwords to raid roughly 165 customer accounts. None of the affected tenants had enforced multi-factor authentication, and many credentials had not been changed for years.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;thehackernews.com&#x2F;2024&#x2F;06&#x2F;snowflake-breach-exposes-165-customers.html&quot;&gt;thehackernews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-hacker-accesses-internal-tile-tool-that-hands-location-data-to-police&quot;&gt;2. Hacker accesses internal Tile tool that hands location data to police&lt;&#x2F;h3&gt;
&lt;p&gt;On 12 June a hacker reached an internal tool at the location tracker maker Tile that processes data requests from law enforcement, using the credentials of a former employee. The intruder scraped customer names, physical addresses, email addresses and phone numbers, then attempted to extort the company.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.404media.co&#x2F;hacker-accesses-internal-tile-tool-that-provides-location-data-to-cops&#x2F;&quot;&gt;www.404media.co&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-microsoft-reverses-course-and-makes-windows-recall-opt-in&quot;&gt;3. Microsoft reverses course and makes Windows Recall opt-in&lt;&#x2F;h3&gt;
&lt;p&gt;After security researchers showed that the Recall feature stored unencrypted screenshots of everything a user did, Microsoft announced in June that it would be turned off by default. The company also required Windows Hello and encryption before the tool could be switched on.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;microsoft-reverses-course-recall-opt-in&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-apple-unveils-private-cloud-compute-for-on-device-and-cloud-artificial-intelligence&quot;&gt;4. Apple unveils Private Cloud Compute for on-device and cloud artificial intelligence&lt;&#x2F;h3&gt;
&lt;p&gt;At its developer conference on 10 June, Apple announced Private Cloud Compute, a system meant to extend device-level privacy guarantees into the cloud. The company said personal data sent for processing would not be accessible to anyone, including Apple, and pledged to publish the code for public inspection.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;security.apple.com&#x2F;blog&#x2F;private-cloud-compute&#x2F;&quot;&gt;security.apple.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-meta-pauses-plans-to-train-artificial-intelligence-on-european-user-data&quot;&gt;5. Meta pauses plans to train artificial intelligence on European user data&lt;&#x2F;h3&gt;
&lt;p&gt;On 14 June the Irish Data Protection Commission said Meta had agreed to pause training its models on data from European users. The company had planned to rely on legitimate interests rather than seek explicit consent, prompting regulatory engagement and public criticism.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.dataprotection.ie&#x2F;en&#x2F;news-media&#x2F;latest-news&#x2F;dpc-statement-meta-ai&quot;&gt;www.dataprotection.ie&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-noyb-files-complaints-in-eleven-countries-over-meta-artificial-intelligence-training&quot;&gt;6. noyb files complaints in eleven countries over Meta artificial intelligence training&lt;&#x2F;h3&gt;
&lt;p&gt;On 6 June the privacy group noyb lodged complaints with eleven European data protection authorities, asking them to halt Meta&#x27;s planned data use through an urgency procedure. It argued that using years of public and non-public posts to train artificial intelligence without consent breached the data protection rules.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;noyb.eu&#x2F;en&#x2F;noyb-urges-11-dpas-immediately-stop-metas-abuse-personal-data-ai&quot;&gt;noyb.eu&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-truist-bank-confirms-breach-as-data-appears-for-sale&quot;&gt;7. Truist Bank confirms breach as data appears for sale&lt;&#x2F;h3&gt;
&lt;p&gt;Truist Bank confirmed in June that its systems had been breached after a dark web seller offered stolen records. The post claimed to contain data on tens of thousands of employees along with bank transaction details such as names, account numbers and balances.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.malwarebytes.com&#x2F;blog&#x2F;news&#x2F;2024&#x2F;06&#x2F;truist-bank-confirms-data-breach&quot;&gt;www.malwarebytes.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-united-states-bans-kaspersky-software&quot;&gt;8. United States bans Kaspersky software&lt;&#x2F;h3&gt;
&lt;p&gt;On 20 June the Commerce Department issued a first-of-its-kind determination prohibiting the sale of Kaspersky antivirus and security products to people in the United States. Officials said the Russian firm&#x27;s software could be exploited to gather sensitive data and pass it to the Russian government.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bis.gov&#x2F;press-release&#x2F;commerce-department-prohibits-russian-kaspersky-software-u.s.-customers&quot;&gt;www.bis.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-julian-assange-pleads-guilty-and-walks-free&quot;&gt;9. Julian Assange pleads guilty and walks free&lt;&#x2F;h3&gt;
&lt;p&gt;The WikiLeaks founder pleaded guilty in June to a single count of conspiring to obtain and disclose classified national defence information. He received a sentence of time served and was freed, ending a long legal battle over the publication of secret documents.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.justice.gov&#x2F;archives&#x2F;opa&#x2F;pr&#x2F;wikileaks-founder-pleads-guilty-and-sentenced-conspiring-obtain-and-disclose-classified&quot;&gt;www.justice.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-polyfill-supply-chain-attack-hits-more-than-100-000-websites&quot;&gt;10. Polyfill supply-chain attack hits more than 100,000 websites&lt;&#x2F;h3&gt;
&lt;p&gt;In late June the cdn.polyfill.io domain began injecting malicious code into a widely used JavaScript library, redirecting visitors on more than 100,000 sites to scam pages. Cloudflare responded by automatically rewriting requests to serve a safe mirror of the library instead.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;blog.cloudflare.com&#x2F;automatically-replacing-polyfill-io-links-with-cloudflares-mirror-for-a-safer-internet&#x2F;&quot;&gt;blog.cloudflare.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-eff-opposes-the-american-privacy-rights-act&quot;&gt;11. EFF opposes the American Privacy Rights Act&lt;&#x2F;h3&gt;
&lt;p&gt;On 24 June the Electronic Frontier Foundation told Congress it opposed the American Privacy Rights Act in its current form. The group warned that the bill would freeze protections in place, override stronger state laws and stop states from passing tougher rules.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;06&#x2F;eff-opposes-american-privacy-rights-act&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-ftc-refers-tiktok-children-s-privacy-complaint-to-the-justice-department&quot;&gt;12. FTC refers TikTok children&#x27;s privacy complaint to the Justice Department&lt;&#x2F;h3&gt;
&lt;p&gt;On 18 June the Federal Trade Commission announced it had referred a complaint against TikTok and ByteDance to the Justice Department. The regulator said it had reason to believe the companies were violating the children&#x27;s privacy law after a review of an earlier settlement.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.ftc.gov&#x2F;news-events&#x2F;news&#x2F;press-releases&#x2F;2024&#x2F;06&#x2F;statement-commission-regarding-tiktok-complaint-referral-doj&quot;&gt;www.ftc.gov&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-clearview-ai-settles-biometric-privacy-case-with-an-equity-stake&quot;&gt;13. Clearview AI settles biometric privacy case with an equity stake&lt;&#x2F;h3&gt;
&lt;p&gt;In June Clearview AI reached an unusual settlement of biometric privacy claims, granting the class a 23 percent ownership stake in the company rather than a cash payment. The fund was valued at roughly 51.75 million dollars and addressed the firm&#x27;s scraping of billions of facial images.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.biometricupdate.com&#x2F;202406&#x2F;clearview-settles-bipa-lawsuit-plaintiffs-take-23-of-company&quot;&gt;www.biometricupdate.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-detroit-settles-wrongful-facial-recognition-arrest-case&quot;&gt;14. Detroit settles wrongful facial recognition arrest case&lt;&#x2F;h3&gt;
&lt;p&gt;On 28 June the city of Detroit agreed to pay 300,000 dollars to Robert Williams, who was wrongly arrested after a false facial recognition match. The settlement also imposed strict limits on police use of the technology, barring arrests based on a match alone.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;fortune.com&#x2F;2024&#x2F;06&#x2F;29&#x2F;facial-recognition-technology-mistake-detroit-police-settlement-robert-williams-aclu&#x2F;&quot;&gt;fortune.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-australian-regulator-takes-medibank-to-court-over-2022-breach&quot;&gt;15. Australian regulator takes Medibank to court over 2022 breach&lt;&#x2F;h3&gt;
&lt;p&gt;On 5 June the Australian Information Commissioner began civil penalty proceedings against the insurer Medibank in the Federal Court. The action alleges that the company failed to take reasonable steps to protect the personal information of 9.7 million people exposed in a 2022 attack.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.oaic.gov.au&#x2F;news&#x2F;media-centre&#x2F;oaic-takes-civil-penalty-action-against-medibank&quot;&gt;www.oaic.gov.au&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-synnovis-ransomware-attack-disrupts-london-hospitals-and-exposes-patient-data&quot;&gt;16. Synnovis ransomware attack disrupts London hospitals and exposes patient data&lt;&#x2F;h3&gt;
&lt;p&gt;A ransomware attack on the pathology provider Synnovis on 3 June forced major London hospitals to cancel thousands of operations and appointments. On 20 June the attackers published stolen data, including patient names, NHS numbers and test results.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;qilin-ransomware-gang-linked-to-attack-on-london-hospitals&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-los-angeles-county-health-agency-discloses-phishing-breach-affecting-200-000-people&quot;&gt;17. Los Angeles County health agency discloses phishing breach affecting 200,000 people&lt;&#x2F;h3&gt;
&lt;p&gt;In mid-June the Los Angeles County Department of Public Health disclosed a phishing attack that compromised the credentials of dozens of staff. The intrusion exposed sensitive information on more than 200,000 people, including diagnoses, prescriptions and Social Security numbers.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.infosecurity-magazine.com&#x2F;news&#x2F;los-angeles-health-data-breach&#x2F;&quot;&gt;www.infosecurity-magazine.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-alleged-leader-of-the-scattered-spider-hacking-group-arrested&quot;&gt;18. Alleged leader of the Scattered Spider hacking group arrested&lt;&#x2F;h3&gt;
&lt;p&gt;On 15 June Krebs on Security reported that police in Spain had arrested a 22-year-old British man accused of leading the Scattered Spider extortion group. The group has been tied to data theft and phishing attacks against numerous large companies.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;06&#x2F;alleged-boss-of-scattered-spider-hacking-group-arrested&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-eu-vote-on-message-scanning-chat-control-proposal-is-withdrawn&quot;&gt;19. EU vote on message-scanning Chat Control proposal is withdrawn&lt;&#x2F;h3&gt;
&lt;p&gt;A planned Council vote on the child sexual abuse regulation, known to critics as Chat Control, was pulled in late June amid heavy opposition. Campaigners and technical experts warned that the bulk scanning of private messages would undermine encryption for millions of users.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.patrick-breyer.de&#x2F;en&#x2F;pirates-wednesdays-vote-on-eus-chat-control-bill-could-open-the-floodgates-to-unprecedented-surveillance&#x2F;&quot;&gt;www.patrick-breyer.de&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-pure-storage-confirms-breach-of-its-snowflake-workspace&quot;&gt;20. Pure Storage confirms breach of its Snowflake workspace&lt;&#x2F;h3&gt;
&lt;p&gt;On 11 June the storage company Pure Storage confirmed that attackers had accessed a Snowflake workspace containing telemetry information. The exposed data included company names, usernames and email addresses, though the firm said it did not contain credentials for customer systems.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2024&#x2F;06&#x2F;11&#x2F;pure_storage_snowflake_breach&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
      <item>
          <title>Privacy Roundup #0214 • May 2024</title>
          <pubDate>Thu, 06 Jun 2024 15:00:00 +0000</pubDate>
          <author>hello@peterspath.net (Peter)</author>
          <link>https://peterspath.net/blog/privacy-roundup-0214/</link>
          <guid>https://peterspath.net/blog/privacy-roundup-0214/</guid>
          <description xml:base="https://peterspath.net/blog/privacy-roundup-0214/">&lt;!-- Covered month: May 2024 (2024-05-01 to 2024-05-31) --&gt;
&lt;p&gt;May 2024 was dominated by the Snowflake breach wave and a fierce backlash against artificial intelligence features that quietly harvest personal data.&lt;&#x2F;p&gt;
&lt;h3 id=&quot;1-dell-partner-portal-api-abused-to-steal-49-million-customer-records&quot;&gt;1. Dell partner portal API abused to steal 49 million customer records&lt;&#x2F;h3&gt;
&lt;p&gt;A criminal registered fake partner accounts and hammered an unrated Dell portal API to scrape names, addresses and order details for roughly 49 million people. Dell began emailing affected customers in early May and stressed that no payment data was taken.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;dell-api-abused-to-steal-49-million-customer-records-in-data-breach&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;2-ascension-ransomware-attack-forces-hospitals-onto-pen-and-paper&quot;&gt;2. Ascension ransomware attack forces hospitals onto pen and paper&lt;&#x2F;h3&gt;
&lt;p&gt;A ransomware intrusion detected on 8 May knocked out electronic health records across Ascension&#x27;s 142 hospitals, forcing staff to divert ambulances and track medication by hand. Nurses and doctors warned that the outage put patients at real risk while the network was slowly restored.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;ascension-restoring-network-after-cyberattack&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;3-uk-confirms-ministry-of-defence-payroll-data-exposed-in-breach&quot;&gt;3. UK confirms Ministry of Defence payroll data exposed in breach&lt;&#x2F;h3&gt;
&lt;p&gt;The UK government confirmed that a contractor-run armed forces payment network was compromised, exposing names, bank details and some addresses of about 270,000 serving personnel, reservists and veterans. Ministers pointed to potential failings by the contractor that may have eased the intruder&#x27;s access.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;uk-confirms-ministry-of-defence-payroll-data-exposed-in-data-breach&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;4-slack-under-attack-over-sneaky-ai-training-policy&quot;&gt;4. Slack under attack over sneaky AI training policy&lt;&#x2F;h3&gt;
&lt;p&gt;Users discovered that Slack had opted them into training its machine learning models on messages and files by default, with opt-out buried behind an email request. The disclosure prompted a public outcry and forced Salesforce to rewrite the confusing privacy language.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;techcrunch.com&#x2F;2024&#x2F;05&#x2F;17&#x2F;slack-under-attack-over-sneaky-ai-training-policy&#x2F;&quot;&gt;techcrunch.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;5-microsoft-s-windows-recall-feature-branded-a-privacy-minefield&quot;&gt;5. Microsoft&#x27;s Windows Recall feature branded a privacy minefield&lt;&#x2F;h3&gt;
&lt;p&gt;Microsoft unveiled Recall, a Windows tool that screenshots everything on screen every few seconds into a searchable local database. Security researchers warned it would capture passwords and banking details, and the backlash forced Microsoft to make the feature opt-in.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.theregister.com&#x2F;2024&#x2F;05&#x2F;22&#x2F;windows_recall&#x2F;&quot;&gt;www.theregister.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;6-eu-council-gives-final-green-light-to-the-ai-act&quot;&gt;6. EU Council gives final green light to the AI Act&lt;&#x2F;h3&gt;
&lt;p&gt;On 21 May the Council of the European Union granted final approval to the AI Act, the first comprehensive law of its kind anywhere in the world. It bans uses deemed an unacceptable risk, such as social scoring, and imposes strict rules on higher-risk systems.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.consilium.europa.eu&#x2F;en&#x2F;press&#x2F;press-releases&#x2F;2024&#x2F;05&#x2F;21&#x2F;artificial-intelligence-ai-act-council-gives-final-green-light-to-the-first-worldwide-rules-on-ai&#x2F;&quot;&gt;www.consilium.europa.eu&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;7-operation-endgame-dismantles-malware-dropper-ecosystem&quot;&gt;7. Operation Endgame dismantles malware dropper ecosystem&lt;&#x2F;h3&gt;
&lt;p&gt;Police across Europe and the United States announced the largest ever action against botnets, taking down more than 100 servers and arresting four people. The coordinated effort disrupted dropper malware families including IcedID, Smokeloader, Pikabot and Bumblebee.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;05&#x2F;operation-endgame-hits-malware-delivery-platforms&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;8-hacking-group-claims-breach-of-560-million-ticketmaster-customers&quot;&gt;8. Hacking group claims breach of 560 million Ticketmaster customers&lt;&#x2F;h3&gt;
&lt;p&gt;The ShinyHunters group claimed to have stolen 1.3 terabytes of Ticketmaster data covering roughly 560 million people, offering it for sale online. The records traced back to a third-party cloud database, part of the wider campaign against poorly secured Snowflake accounts.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.cbsnews.com&#x2F;news&#x2F;ticketmaster-breach-shinyhunters-560-million-customers&#x2F;&quot;&gt;www.cbsnews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;9-christie-s-confirms-breach-after-ransomhub-threatens-to-leak-data&quot;&gt;9. Christie&#x27;s confirms breach after RansomHub threatens to leak data&lt;&#x2F;h3&gt;
&lt;p&gt;The auction house Christie&#x27;s confirmed a data breach after the RansomHub gang added it to a dark web extortion site and threatened to publish stolen client information. The criminals claimed to hold identity documents belonging to around 500,000 private clients.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.bleepingcomputer.com&#x2F;news&#x2F;security&#x2F;christies-confirms-breach-after-ransomhub-threatens-to-leak-data&#x2F;&quot;&gt;www.bleepingcomputer.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;10-snowflake-denies-that-the-reported-breach-originated-with-its-products&quot;&gt;10. Snowflake denies that the reported breach originated with its products&lt;&#x2F;h3&gt;
&lt;p&gt;As the campaign against its customers widened, Snowflake denied that any vulnerability in its platform caused the breaches at firms such as Ticketmaster and Santander. The company instead pointed to compromised customer credentials and accounts that lacked multi-factor authentication.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;therecord.media&#x2F;snowflake-response-reported-breach-santander-ticketmaster&quot;&gt;therecord.media&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;11-eff-adds-bluetooth-to-the-long-list-of-border-surveillance-technologies&quot;&gt;11. EFF adds Bluetooth to the long list of border surveillance technologies&lt;&#x2F;h3&gt;
&lt;p&gt;The Electronic Frontier Foundation revealed that Bluetooth trackers and scanners had joined the growing arsenal of surveillance technology deployed along the United States and Mexico border. The findings showed how everyday wireless signals can quietly map the movements of travellers and residents.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2024&#x2F;05&#x2F;add-bluetooth-long-list-border-surveillance-technologies&quot;&gt;www.eff.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;12-why-your-wi-fi-router-doubles-as-an-apple-airtag&quot;&gt;12. Why your Wi-Fi router doubles as an Apple AirTag&lt;&#x2F;h3&gt;
&lt;p&gt;University of Maryland researchers showed that Apple&#x27;s Wi-Fi location service could be queried to map billions of routers worldwide and track devices without consent. They traced sensitive movements including Starlink terminals in Ukraine and Gaza, exposing a global tracking risk.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;05&#x2F;why-your-wi-fi-router-doubles-as-an-apple-airtag&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;13-investigation-exposes-stark-industries-as-a-hub-for-kremlin-cyberattacks&quot;&gt;13. Investigation exposes Stark Industries as a hub for Kremlin cyberattacks&lt;&#x2F;h3&gt;
&lt;p&gt;A detailed investigation traced the ownership of Stark Industries Solutions, a bulletproof hosting provider that appeared just before Russia invaded Ukraine. The firm served as a staging ground for repeated cyberattacks and disinformation operations across Europe.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;05&#x2F;stark-industries-solutions-an-iron-hammer-in-the-cloud&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;14-united-states-charges-russian-man-as-boss-of-lockbit-ransomware-group&quot;&gt;14. United States charges Russian man as boss of LockBit ransomware group&lt;&#x2F;h3&gt;
&lt;p&gt;American prosecutors named and charged a Russian national as the leader of LockBit, one of the most prolific ransomware operations in the world. The indictment followed an international effort to disrupt the gang&#x27;s infrastructure and unmask its operators.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;05&#x2F;u-s-charges-russian-man-as-boss-of-lockbit-ransomware-group&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;15-treasury-sanctions-creators-of-the-911-s5-proxy-botnet&quot;&gt;15. Treasury sanctions creators of the 911 S5 proxy botnet&lt;&#x2F;h3&gt;
&lt;p&gt;The United States Treasury sanctioned three Chinese nationals accused of running 911 S5, a proxy service built on a vast botnet of compromised computers. Authorities said the service let criminals route malicious traffic and commit fraud worth billions.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;05&#x2F;treasury-sanctions-creators-of-911-s5-proxy-botnet&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;16-first-american-discloses-cyberattack-affecting-44-000-people&quot;&gt;16. First American discloses cyberattack affecting 44,000 people&lt;&#x2F;h3&gt;
&lt;p&gt;The mortgage and title insurance giant First American told regulators that a December cyberattack had exposed personal information belonging to roughly 44,000 individuals. The company concluded its investigation and offered affected people credit monitoring.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.securityweek.com&#x2F;personal-information-of-44000-compromised-in-first-american-cyberattack&#x2F;&quot;&gt;www.securityweek.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;17-european-parliament-uncovers-breach-of-its-recruitment-platform&quot;&gt;17. European Parliament uncovers breach of its recruitment platform&lt;&#x2F;h3&gt;
&lt;p&gt;The European Parliament told staff that its PEOPLE recruitment application had been breached, exposing identity documents and sensitive records for more than 8,000 candidates. The flaw went unnoticed for months and surfaced as the institution hardened security before the June elections.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.euronews.com&#x2F;next&#x2F;2024&#x2F;05&#x2F;08&#x2F;european-parliament-election-prep-unearthed-data-breach&quot;&gt;www.euronews.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;18-vermont-legislature-passes-data-privacy-bill-with-a-right-to-sue&quot;&gt;18. Vermont legislature passes data privacy bill with a right to sue&lt;&#x2F;h3&gt;
&lt;p&gt;Vermont lawmakers passed a comprehensive privacy bill that would let residents sue data brokers and large data holders for misusing their personal information. Consumer advocates praised the private right of action as a possible turning point for state privacy law.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.vermontpublic.org&#x2F;local-news&#x2F;2024-05-13&#x2F;vermont-legislature-passes-data-privacy-bill-that-could-shape-national-efforts&quot;&gt;www.vermontpublic.org&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;19-santander-employee-data-exposed-in-snowflake-customer-breach&quot;&gt;19. Santander employee data exposed in Snowflake customer breach&lt;&#x2F;h3&gt;
&lt;p&gt;Banco Santander confirmed that a third-party database had been accessed, exposing data on customers in Spain, Chile and Uruguay along with current and former staff. The intrusion formed part of the wider attack on poorly protected Snowflake accounts.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;www.securityweek.com&#x2F;santander-employee-data-breach-linked-to-snowflake-attack&#x2F;&quot;&gt;www.securityweek.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
&lt;h3 id=&quot;20-is-your-computer-part-of-the-largest-botnet-ever&quot;&gt;20. Is your computer part of the largest botnet ever?&lt;&#x2F;h3&gt;
&lt;p&gt;Following the 911 S5 takedown, investigators detailed how millions of Windows machines had been quietly conscripted into the proxy network through tainted free software. Users were urged to check whether their devices had become part of the sprawling criminal infrastructure.&lt;&#x2F;p&gt;
&lt;p&gt;→ &lt;a rel=&quot;external&quot; href=&quot;https:&#x2F;&#x2F;krebsonsecurity.com&#x2F;2024&#x2F;05&#x2F;is-your-computer-part-of-the-largest-botnet-ever&#x2F;&quot;&gt;krebsonsecurity.com&lt;&#x2F;a&gt;&lt;&#x2F;p&gt;
</description>
      </item>
    </channel>
</rss>
