12 – Breaking News & Latest Updates 2026
Skip to main content

Privacy

As gadgets and services get smarter, they need more data, and face the hard problem of keeping it safe. Data privacy has become a huge problem for Google, Facebook, Amazon, and any company using artificial intelligence to power its services — and a major sticking point for lawmakers looking to regulate. Here’s all the news on data privacy and how it’s changing tech.

Wes Davis
Wes Davis
The biggest known MOVEit hack leaked the personal information of up to 11 million people.

Maximus, a company that administers government programs like Medicaid and Medicare, was swept up in the broad MOVEit hacking campaign in May that affected over 2,000 organizations.

Victims filed a proposed class action lawsuit against the company after the attack, which as TechCrunch noted saw the leak of social security and other sensitive health information for between 8 and 11 million people.

Wes Davis
Wes Davis
Over 50,000 students’ data was stolen in a recent MOVEit breach.

National Student Clearinghouse (NSC), a Virginia-based educational nonprofit, said in a sample data breach notice filed with the California Attorney General that it suffered a MOVEit-related cyber attack on May 30th, reported Bleeping Computer.

The NSC says in the letter that stolen data may include SSNs and other personal and school-related records. Bleeping Computer writes that 890 schools’ were affected. The organization acknowledges the breach and subsequent patch on its website.

Richard Lawler
Richard Lawler
The stans have discovered facial recognition.

This report by 404 Media discusses an unnamed Taylor Swift fan TikTok account with 90,000 followers that finds people in viral videos and releases their information, like name, occupation, and social media profiles. It does this using PimEyes, one of several facial recognition search engines. And at least so far, TikTok has declined to remove it.

One target told me he felt violated after the TikTok account using facial recognition tech targeted him. Another said they initially felt flattered before “that promptly gave way to worry.” All of the victims I spoke to echoed one general point—this behavior showed them just how exposed we all potentially are simply by existing in public.

Jay Peters
Jay Peters
Not a great look for Musk.

A new Justice Department filing says that Elon Musk’s actions at X (formerly Twitter) might have violated a privacy order from the FTC, according to The Washington Post.

Seems like Musk may have made some bad decisions:

Multiple employees testified that Musk gave directives that were at odds with the company’s normal processes and policies, according to the filing.

Richard Lawler
Richard Lawler
TLO is the latest doxing slang for you to worry about.

404 Media, a new outlet formed by members of Vice’s former tech vertical Motherboard, follows up a previous report on criminals using TransUnion’s TLOxp tool to sell info (SSN, previous address, everything) on virtually any target via Telegram.

Now, as they report, while the fraudsters’ access to TLOxp may have ended, its name has become the “Xerox” of doxing, even as criminals use other similar tools to sell detailed reports on people for $15 - $20,

Emma Roth
Emma Roth
A leaked document offers a glimpse at negotiations between TikTok and the US government.

In a draft agreement obtained by Forbes, TikTok reportedly offered the government a number of concessions to avoid a ban in the US.

That included the ability for the DOJ and DOD to examine TikTok’s US servers, prevent changes to its privacy policies, and even “veto the hiring” of anyone on its data security team. It’s not clear if any of these purported agreements are still on the table, however, as Forbes says the document was drafted in the summer of 2022.

Richard Lawler
Richard Lawler
What if your mobile apps weren’t spying on you and exposing your data?

Meet Veilid (pronounced Vay-Lid), an open-source, peer-to-peer application framework launched at Def Con this week.

Described as “conceptually similar to IPFS and Tor,” the team behind it says it will bring the better parts of those with more performance and security for messaging, file-sharing, or social network apps that don’t harvest user data.

As proof of concept, the team has posted source code for VeilidChat, a Signal-like messaging app. There’s more coverage from the Washington Post, Engadget, and The Register.

Richard Lawler
Richard Lawler
The FCC is taking public comments on its plan for a cybersecurity version of the Energy Star sticker.

If you have questions about the proposed US Cyber Trust Mark that’s supposed to help customers answer questions about security and privacy; this 30-day comment period is a good time to speak up.

Details are in the Notice of Proposed Rulemaking (PDF) here. FCC commissioners are taking input on questions like who will run the program, what kinds of devices it applies to, and what security standards should be involved.

Proposed U.S. Cyber Trust Mark logo
Proposed U.S. Cyber Trust Mark logo
Image: FCC
Wes Davis
Wes Davis
Detroit police falsely arrested an eight-month-pregnant Black woman based on a bad facial recognition match.

Porcha Woodruff is suing the city of Detroit and a Detroit detective after she was arrested for a carjacking while she was eight months pregnant. She’d been identified by facial recognition software matching her to a video of the crime. From the complaint:

On February 16, 2023, at 7:50 a.m., Ms. Woodruff was preparing her children for school when she was confronted by six Detroit police officers at her doorstep. They presented her with an arrest warrant for robbery and carjacking, leaving her baffled and assuming it was a joke, given her visibly pregnant state. However, the officers made it clear they were serious and proceeded to arrest her.

Racial bias in facial recognition hasn’t been solved. Woodruff’s false arrest based on facial recognition isn’t a first for Detroit, which has done this twice before.

Wes Davis
Wes Davis
California’s privacy regulator will investigate what car companies do with the data they collect.

The California Privacy Protection Agency (CPPA) is gearing up to make automakers’ data collection its first target since the agency’s inception in 2020.

CPPA executive director Ashkan Soltani said in the regulator’s release that modern, connected vehicles can gather a “wealth of information” about people in or near them, and the agency wants to know what they’re doing with that data:

“Our Enforcement Division is making inquiries into the connected vehicle space to understand how these companies are complying with California law when they collect and use consumers’ data,” Soltani said.

Jon Porter
Jon Porter
Instagram and Facebook’s targeted ads face Norwegian crackdown.

After Meta was fined in the EU over its handling of user data in January, Norway plans to ban the company from showing users in the country personalized ads based on their online activity, Politico reports.

The ban will run for three months from August 4th, and Meta faces a fine of up to 1 million Norwegian Krone (around $99,680) for each day it doesn’t comply.

Wes Davis
Wes Davis
A bill requiring tech platforms to report suspected drug activity to the US Drug Enforcement Agency is moving to the Senate.

The Senate Judiciary Committee moved forward a bill, called the Cooper Davis Act, that would make tech companies report users suspected of criminal drug activity to the DEA. Surveillance litigation director Andrew Crocker of the Electronic Frontier Foundation laid out the group’s concerns (via Gizmodo):

“[The bill’s] vague requirements and criminal penalties would result in companies over-reporting users to the [DEA] for innocent, protected speech. And because the bill encourages companies to undermine encryption out of fear of liability, it could lead to dragnet scanning of private user communications. This bill contains no warrant requirement, no required notice, and limited user protections, and deserves to be defeated on the Senate floor.”

Cody Venzke, senior policy counsel at the American Civil Liberties Union also opposes it:

“The bill will expand law enforcement’s access to user data, undermine the protections of Constitutional statutory warrant requirements, and exacerbate existing racial disparities in criminal drug enforcement. Platforms are not equipped to be deputized as DEA informants, and this bill will likely cause more harm than it heals. We urge the full Senate to reject this approach.”

The Cooper Davis Act

[congress.gov]

Emma Roth
Emma Roth
Threads might run into some moderation issues when it integrates with ActivityPub.

Alex Stamos, Facebook’s former security chief, points out that the integration could make it more difficult for Meta to put a stop to “spammers, troll farms, and economically driven abusers” due to the way the decentralized social networking protocol is set up.

Threads may also face issues when complying with data regulation policies around the globe, many of which grant users the right to delete their data. As explained by Stamos, ActivityPub “has the ability to tell other servers to delete content but no mechanism to enforce.”

Wes Davis
Wes Davis
Over 100 artists and bands are boycotting big venues over facial recognition tech.

Responding to the spread of facial recognition technology at concert venues, over 100 bands and artists like Rage Against the Machine and Boots Riley are participating in a boycott orchestrated by digital rights advocacy group Fight for the Future.

Madison Square Garden has made headlines as lawyers for firms actively litigating against venue owner MSG Entertainment reported being kicked out or denied entry after being flagged by the tech.