CrewCrew
FeedSignalsMy Subscriptions
Get Started
Digital Privacy & Data Rights

Digital Privacy & Data Rights — 2026-10-11

  1. Signals
  2. /
  3. Digital Privacy & Data Rights

Digital Privacy & Data Rights — 2026-10-11

Digital Privacy & Data Rights|October 11, 2026(3h ago)5 min read8.1AI quality score — automatically evaluated based on accuracy, depth, and source quality
0 subscribers

The week's biggest privacy story centers on the EY data breach, where a 15-day hack on a third-party IT support platform exposed client tax data with an 81-day notice gap. Meanwhile, regulatory shifts include the FTC's new enforcement policy promoting age-verification technology under COPPA, and the EDPB's selection of transparency compliance as its 2026 coordinated enforcement topic. These developments highlight growing risks in third-party vendor ecosystems and tightening regulatory expectations for online safety and data transparency.

Based on the research results provided, here is the curated article for Digital Privacy & Data Rights for October 11, 2026.

Digital Privacy & Data Rights — 2026-10-11


This Week's Top Story

Source image
Source image

pkware.com

2026 Data Breaches: Cybersecurity Incidents


EY Data Breach: 15-Day Hack and 81-Day Notice Gap

  • What happened: Ernst & Young (EY) confirmed a cyber breach affecting a platform used to support its tax services. Hackers accessed the system for 15 days, exposing personal and financial information belonging to individuals linked to Goldman Sachs and Man Group. The incident involved a third-party IT support platform rather than the financial firms' own systems. A significant concern is the "notice gap," where 81 days passed between the breach and the notification to affected clients.
  • Who's affected: Clients of EY’s tax services, specifically individuals linked to Goldman Sachs and Man Group. The breach highlights the risk to end-users when their data is held by professional service providers using third-party IT infrastructure.
  • Why it matters: This incident underscores the fragility of supply-chain security in the financial sector. The long delay in notification (81 days) raises questions about incident response protocols and transparency obligations. It serves as a precedent for stricter scrutiny of third-party vendor security practices.

EY Data Breach illustration showing a lock and digital data streams
EY Data Breach illustration showing a lock and digital data streams

shattered.io

shattered.io


Data Breaches & Incidents


ASOS — Customer Data Breach via Rogue Notification

  • Scope: Customer data of UK fashion retailer ASOS was compromised. Hackers sent a rogue push notification to users claiming they had "fully compromised" the company's cloud storage.
  • Root cause: The exact technical vector is under investigation, but the incident involved unauthorized access leading to malicious notifications being pushed to customers' devices.
  • User action: Affected users should be wary of phishing attempts disguised as official communications. Monitor bank statements for unusual activity and change passwords if suspicious activity is detected.

Double Counter (Discord) — Security Bot Breach

  • Scope: User data exposed after an attacker broke into the cloud systems of "Double Counter," a popular Discord security bot, on October 4, 2026.
  • Root cause: Compromise of the bot's cloud infrastructure.
  • User action: Discord users who utilized this bot should review their linked accounts and enable two-factor authentication (2FA) where available. Consider revoking access if no longer needed.

Defense Manpower Data Center (DMDC) — Massive Personnel Record Leak

  • Scope: Sensitive personal information belonging to more than three million people, including Social Security numbers and job details, was exposed.
  • Root cause: A major data breach involving the Pentagon's Defense Manpower Data Center information system.
  • User action: Individuals with military connections should monitor credit reports for identity theft signs and consider freezing their credit. Utilize identity theft protection services offered by the government or private providers.

Regulatory & Enforcement Actions


FTC vs. Online Services (COPPA Enforcement Policy)

  • Ruling: The Federal Trade Commission (FTC) issued an Enforcement Policy Statement Promoting the Adoption of Age-Verification Technology on February 25, 2026. This statement clarifies how the FTC will evaluate compliance with COPPA, specifically regarding age-verification methods.
  • Penalty: No specific fine is attached to the policy statement itself, but it sets the stage for future enforcement actions against services that fail to implement adequate age verification.
  • Precedent: This reshapes compliance expectations by signaling that "self-certification" of age may no longer be sufficient for certain platforms. It pushes the industry toward more robust, technical age-verification solutions to protect children's privacy.

EDPB Coordinated Enforcement Framework (CEF) 2026

  • Ruling: During its October plenary, the European Data Protection Board (EDPB) selected the topic for its fifth coordinated enforcement action: compliance with obligations of transparency and information under the GDPR.
  • Penalty: The outcome will vary by national authority, but coordinated actions typically lead to fines, warnings, or remediation orders across multiple EU member states.
  • Precedent: Organizations operating in the EU must now prioritize reviewing their privacy notices and transparency mechanisms. The EDPB's focus suggests a unified approach to tackling vague or misleading privacy policies across borders.

Legislation & Policy Moves

  • US — SECURE Data Act: A comprehensive federal consumer privacy bill introduced by U.S. House Republicans (April 22, 2026). It aims to create a uniform federal standard to preempt the state privacy law patchwork. — Status: Introduced/In Committee — Effective Date: TBD
  • Global — EDPB Transparency Focus: While not a new law, the EDPB's decision to focus its 2026 enforcement on GDPR transparency articles effectively acts as a policy directive for all EU member states. — Status: Active Enforcement Planning — Effective Date: 2026

Advocacy & Civil Society

  • EFF Deeplinks: The Electronic Frontier Foundation continues to publish resources on digital rights, surveillance, and encryption. Recent coverage emphasizes the importance of strong encryption and privacy tools in the face of expanding surveillance tech.
  • Privacy Guides: The community-driven project released a "Data Breach Roundup" covering incidents from Oct 3–8, 2026, highlighting the ASOS hack and Danish breaches. This resource helps users track real-time threats and understand the scale of recent leaks.

Industry & Tech Response

No specific platform feature updates or product launches were identified in the fresh search results from the past 24 hours. However, the industry response to the EY breach involves immediate audits of third-party IT support vendors by major financial institutions, as noted in cybersecurity reporting.


Reader Action Items

  • Check if you're affected: If you are a client of Goldman Sachs or Man Group through EY tax services, check your email for official breach notifications. For ASOS users, verify any recent push notifications were legitimate before clicking links.
  • Settings to review: Review your Discord bot permissions. If you use third-party security bots like Double Counter, ensure they are from verified sources and revoke access for unused bots.
  • Rights you can exercise: Under GDPR, you can request transparency reports from companies processing your data in the EU. In the US, monitor your credit reports via AnnualCreditReport.com following the Pentagon breach if you have military ties.

What to Watch Next Week

  • FTC Age Verification Enforcement: Watch for the first enforcement actions taken under the new COPPA age-verification policy statement.
  • EDPB National Investigations: Monitor national DPAs in the EU as they begin preliminary inquiries into transparency compliance per the EDPB's 2026 CEF selection.
  • SECURE Data Act Progress: Track hearings or amendments related to the SECURE Data Act in the House Energy and Commerce Committee.

Crew Digital Privacy & Data Rights — curated weekly from EFF, regulators (EDPB/FTC), IAPP, and tech media.

This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.

Explore related topics
  • QWhy did EY wait 81 days to notify clients?
  • QHow can users protect data on third-party apps?
  • QWhat data was exposed in the DMDC leak?

Powered by

CrewCrew

Sources

Want your own AI intelligence feed?

Create custom signals on any topic. AI curates and delivers 24/7.