Digital Privacy & Data Rights — October 9, 2026
This week's privacy landscape is dominated by massive data breaches affecting major financial institutions and digital platforms, with over 30 million records exposed across EY, Discord, and the Pentagon. Regulatory bodies are tightening enforcement, highlighted by the FTC's recent action against Amazon and the EDPB's selection of transparency as its 2026 coordinated enforcement topic. For everyday users, this means a heightened risk of identity theft and a clearer expectation for companies to prove they are handling personal data transparently.
Digital Privacy & Data Rights — October 9, 2026
This Week's Top Story
EY Data Breach Widens to Include Goldman Sachs and Man Group
- What happened: Ernst & Young (EY) confirmed a significant data breach after hackers accessed a third-party IT support platform for 15 days. The incident, which occurred earlier in 2026, exposed client tax data and has now been linked to major financial entities including Goldman Sachs and Man Group. The attackers, identified as ShinyHunters, claimed credit for the breach, which featured an 81-day gap between the intrusion and notification.
- Who's affected: Clients of EY, specifically high-net-worth individuals and corporate entities associated with Goldman Sachs and Man Group. The breach exposed six distinct data types, prompting a class-action probe.
- Why it matters: This incident highlights the critical risk of supply-chain attacks in the financial sector. The long delay in notification underscores the need for stricter regulations on breach disclosure timelines to protect users from prolonged exposure.

Data Breaches & Incidents
Discord — Double Counter Security Bot Breach
- Scope: Approximately 28 million user accounts were affected. Exposed data included user IDs, IP addresses, and email addresses.
- Root cause: An attacker broke into the cloud systems of "Double Counter," a popular security bot used on Discord, on October 4, 2026.
- User action: Users should immediately change their Discord passwords and enable two-factor authentication if not already active. Monitor for phishing attempts using your exposed email address.

Asos — Snowflake Data Threat
- Scope: The online fashion retailer Asos reported a potential compromise of its Snowflake data environment. While the exact number of records is still being verified, the incident caused a 13% drop in share prices.
- Root cause: Hackers threatened to leak data following an app notification claiming compromise. The specific attack vector is under investigation, but it involves the cloud data platform Snowflake.
- User action: Asos users should monitor their bank statements for unauthorized transactions and be wary of suspicious emails claiming to be from Asos support.
Trump Mobile — User Data Exposure
- Scope: 3,615 users had their names, contact information, addresses, and order history exposed.
- Root cause: Researchers identified a leak in Trump Mobile's systems, exposing sensitive customer details.
- User action: Affected users should monitor for identity theft attempts given the exposure of physical addresses and order histories.
Regulatory & Enforcement Actions
U.S. Federal Trade Commission (FTC) vs. Amazon.com, Inc.
- Ruling: The FTC filed a lawsuit against Amazon, alleging violations related to consumer privacy and data security practices. The action focuses on how Amazon handles consumer data and its compliance with consent orders.
- Penalty: While specific fines are often part of settlements or later rulings, the legal action itself serves as a major penalty through litigation costs and mandated operational changes.
- Precedent: This reinforces the FTC's stance that large tech companies must strictly adhere to privacy promises and secure consumer data, setting a higher bar for compliance in e-commerce and cloud services.
European Data Protection Board (EDPB) — 2026 Coordinated Enforcement Framework
- Ruling: The EDPB selected "compliance with the obligations of transparency and information" under the GDPR as the topic for its fifth coordinated enforcement action in 2026.
- Penalty: This framework will lead to simultaneous investigations across EU member states, potentially resulting in multiple GDPR fines for companies failing to meet transparency standards.
- Precedent: This signals a unified EU approach to cracking down on opaque data practices, requiring companies to clearly inform users about how their data is collected and used.
Legislation & Policy Moves
- United States — SECURE Data Act: A draft federal privacy bill introduced by House Republicans aiming to establish a uniform national standard for data privacy, preempting the current patchwork of state laws. — Introduced —
- United States — State Privacy Laws: Multiple new state privacy requirements came into force on January 1, 2026, expanding rights for consumers regarding data access, deletion, and opt-outs. — Effective —
Advocacy & Civil Society
- EFF: Continues to monitor surveillance technologies and encryption rights, providing resources for users to protect their digital footprint.
- EDPB: Publishes registers of final one-stop-shop decisions to ensure transparency in cross-border data protection cases.
Industry & Tech Response
- Cloud Security: The Asos and EY incidents have intensified scrutiny on third-party cloud providers like Snowflake and IT support platforms, pushing companies to audit their supply chain security more rigorously.
- Discord Security: In response to the Double Counter breach, platform administrators are urged to review third-party bot permissions and encourage users to limit data sharing with non-essential bots.
Reader Action Items
- Check if you're affected: Verify if your organization uses EY or if you are a client of Goldman Sachs/Man Group. Check Discord's official channels for specific username notifications regarding the Double Counter breach.
- Settings to review: Enable Two-Factor Authentication (2FA) on all social media and financial accounts. Review app permissions on your smartphone, specifically revoking access to location and contacts for apps that do not need them.
- Rights you can exercise: Under new state laws and GDPR, file a "Right to Know" request with companies like Asos or Amazon to see what data they hold about you.
What to Watch Next Week
- Class-Action Lawsuits: Expect formal filings from affected EY clients against the firm and its partners.
- FTC Investigation Updates: Monitor for further details on the Amazon lawsuit and potential settlement talks.
- EDPB Guidance: Look for specific guidelines from national DPAs on what constitutes compliant "transparency" ahead of the coordinated enforcement actions.
Crew Digital Privacy & Data Rights — curated weekly from EFF, regulators (EDPB/FTC/ICO), IAPP, and tech media.
This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.