CrewCrew
FeedSignalsMy Subscriptions
Get Started
Digital Privacy & Data Rights

Digital Privacy & Data Rights — August 5, 2026

  1. Signals
  2. /
  3. Digital Privacy & Data Rights

Digital Privacy & Data Rights — August 5, 2026

Digital Privacy & Data Rights|August 5, 2026(2h ago)4 min read8.3AI quality score — automatically evaluated based on accuracy, depth, and source quality
0 subscribers

A "no-logs" VPN exposed 58 million connection logs this week, contradicting privacy claims—the latest in a surge of major breaches affecting millions. The FTC took action against Hims & Hers for deceptive privacy practices, signaling aggressive enforcement on health data. These incidents underscore mounting risks to everyday users from both attackers and companies that misrepresent their data safeguards.

Digital Privacy & Data Rights — August 5, 2026


This Week's Top Story


"No-Logs" VPN Exposed 58 Million Connection Records—Contradicting Core Privacy Promise

  • What happened: A breached VPN service that marketed itself as maintaining no activity logs had its entire database leaked, exposing 58 million connection logs along with millions of user, device, and payment records. The breach directly contradicts the service's core privacy marketing claim that no user activity was retained.
  • Who's affected: Millions of VPN users globally who relied on the service's privacy guarantees; the exposure includes connection metadata that could reveal user browsing behavior and location patterns.
  • Why it matters: This incident exemplifies the gap between privacy marketing claims and actual data practices. Users who chose this VPN specifically for its "no-logs" promise now face exposure of the exact data the company claimed it never collected—a critical trust violation that undermines the entire VPN trust model.

Screenshot of VPN security breach report showing exposed connection logs database
Screenshot of VPN security breach report showing exposed connection logs database

securityaffairs.com

securityaffairs.com


Data Breaches & Incidents (at least 3 items)


Paidwork — Exposed 23 Million User Accounts with Financial Data

  • Scope: 23 million user records including bank account numbers, passwords, and personal financial information.
  • Root cause: Data breach confirmed and listed on Have I Been Pwned; specific attack vector not disclosed in available sources.
  • User action: Check your account status on Have I Been Pwned (haveibeenpwned.com) immediately; reset your Paidwork password and monitor bank accounts for unauthorized activity.

Image showing freelance worker at desk with notification of data compromise
Image showing freelance worker at desk with notification of data compromise

foxnews.com

foxnews.com


PNLD — UK Police and Government Contact Data Published on Dark Web

  • Scope: Police, government, and customer contact details exposed, including names and emails from "Ask the Police" user community.
  • Root cause: PNLD confirms data was exfiltrated and published on the dark web; intrusion vector not detailed in public disclosure.
  • User action: UK residents who used "Ask the Police" service should expect potential phishing and social engineering attempts; verify any official communications directly with police forces.

CareCloud — 345,000 Patient Records Exposed in Healthcare Cyberattack

  • Scope: Over 345,000 patient records compromised at cloud-based EHR and practice management provider.
  • Root cause: Cyberattack; CareCloud Inc. (Somerset, NJ) disclosed the theft of patient data.
  • User action: Affected patients should monitor health insurance statements and credit for fraudulent billing; request credit monitoring services offered by CareCloud in response to the breach.

Regulatory & Enforcement Actions (at least 2 items)


FTC vs. Hims & Hers — Deceptive Privacy Practices in Health Data Handling

  • Ruling: FTC and state attorneys general filed enforcement action against telehealth platform Hims & Hers for deceiving consumers about data privacy practices and failing to secure sensitive health information.
  • Penalty: Full details of fines and remediation orders not yet finalized in available sources; enforcement action announced July 29, 2026.
  • Precedent: This action signals aggressive FTC enforcement on health data privacy, particularly targeting companies making false privacy claims to attract telehealth users. Companies marketing privacy-first health services now face heightened scrutiny of actual data handling practices.

Legislation & Policy Moves (at least 2 items)

  • United States — SECURE Data Act: Comprehensive federal privacy bill introduced by House Republicans in April 2026 to establish uniform consumer privacy standards and preempt state privacy law patchwork — status: introduced —

  • United States — State Privacy Law Enforcement Acceleration: Multiple U.S. state privacy laws coming into force as of January 1, 2026, with heightened enforcement activity expected throughout 2026 — status: in effect —


Advocacy & Civil Society

No recent civil society or advocacy reports from EFF, NOYB, or Privacy International were published after July 29, 2026 in available search results.


Industry & Tech Response

No significant new privacy feature announcements or platform policy changes from major tech companies were reported in the past 7 days in available sources.


Reader Action Items

  • Check if you're affected: Visit Have I Been Pwned to search your email across the Paidwork and other breaches disclosed this week. If listed, change your password immediately and enable two-factor authentication on financial accounts.
  • Settings to review: If you use a VPN service, verify its actual data retention policy (not marketing claims) by requesting their transparency report or privacy audit results. Disable VPN auto-connect features that may store connection metadata.
  • Rights you can exercise: If affected by Hims & Hers or CareCloud breaches, you have the right under HIPAA (U.S.) or GDPR (EU) to request a copy of your data held and demand correction of inaccuracies. Submit these requests directly to the company's privacy contact.

What to Watch Next Week

  • Ongoing FTC action against Hims & Hers—watch for settlement details and remediation orders.
  • U.S. state privacy enforcement activity in the second week of August, as multiple state laws now active.
  • Further disclosure of the VPN breach scope—monitor Have I Been Pwned and security research sites for additional affected user counts.

Crew Digital Privacy & Data Rights — curated weekly from FTC, EDPB, IAPP, and security media sources.

This content was collected, curated, and summarized entirely by AI — including how and what to gather. It may contain inaccuracies. Crew does not guarantee the accuracy of any information presented here. Always verify facts on your own before acting on them. Crew assumes no legal liability for any consequences arising from reliance on this content.

Explore related topics
  • QWhich VPN company suffered the data leak?
  • QWill the VPN face regulatory penalties?
  • QHow can users verify true no-logs VPNs?

Powered by

CrewCrew

Sources

Want your own AI intelligence feed?

Create custom signals on any topic. AI curates and delivers 24/7.