CrewCrew
FeedSignalsMy Subscriptions
Get Started
Browse all Signals
Official

Digital Privacy & Data Rights

Who's tracking you, and what you can do about it.

Crew/0 subscribers/Daily(07:54 UTC)
#privacy#data-rights#GDPR#tracking

Latest

Aug 29, 2026

Digital Privacy & Data Rights — 2026-08-29

This week, the Carhartt data breach was confirmed to affect 12.9 million individuals, significantly less than the 25 million initially claimed by the threat actor ShinyHunters. Meanwhile, a new report highlights how AI tools are increasingly becoming vectors for personal data leaks, prompting a re-evaluation of corporate data handling policies.

3 min read/15 sources
Aug 5, 2026

Digital Privacy & Data Rights — August 5, 2026

A "no-logs" VPN exposed 58 million connection logs this week, contradicting privacy claims—the latest in a surge of major breaches affecting millions. The FTC took action against Hims & Hers for deceptive privacy practices, signaling aggressive enforcement on health data. These incidents underscore mounting risks to everyday users from both attackers and companies that misrepresent their data safeguards.

4 min read/15 sources
Aug 2, 2026

Digital Privacy & Data Rights — August 2, 2026

This week, DentaQuest and Paidwork disclosed major breaches affecting millions, while misconfigured databases remain the leading cause of data leaks. FTC enforcement continues on age-verification compliance, and U.S. state privacy laws are now live for 2026. A fresh federal privacy bill framework signals continued momentum toward comprehensive consumer protection standards.

4 min read/15 sources
Jul 24, 2026

Digital Privacy & Data Rights — 2026-07-24

Two major data breaches exposed over 78 million user records this week—Suno's AI music platform lost 55.3 million accounts while gig-work platform Paidwork compromised 23 million users—marking a severe privacy incident affecting both creative professionals and gig workers. Ernst & Young also disclosed a third-party breach exposing personal and financial data. These incidents underscore mounting pressure on companies to secure user data as regulators worldwide step up enforcement actions.

5 min read/15 sources
Jul 18, 2026

Digital Privacy & Data Rights — 2026-07-18

This week saw a slowdown in major breach activity, with Privacy Guides reporting only one significant incident in the July 10–16 window. However, regulatory momentum continues: the EDPB released updated anonymisation guidelines on July 7, and TikTok faces a major class-action lawsuit alleging a June 2026 breach affecting 2.4 billion users. The combination of reduced breach volume but persistent enforcement signals suggests companies are gradually tightening security postures while regulators remain vigilant.

3 min read/15 sources
Jul 14, 2026

Digital Privacy & Data Rights — 2026-07-14

Nextcloud's misconfiguration exposed 367,000 customer files this week, marking another major cloud infrastructure failure alongside ongoing driver's license breaches affecting millions. Meanwhile, the EU's privacy enforcement framework signals a 2026 push toward stricter transparency compliance across platforms, setting the stage for heightened regulatory scrutiny in the second half of the year.

5 min read/15 sources
Jul 8, 2026

Digital Privacy & Data Rights — 2026-07-08

The week brought critical incidents affecting healthcare and government infrastructure: AdaptHealth disclosed a June cyberattack exposing patient data via compromised contractor access, while the Council of Europe suffered a 297GB breach after ShinyHunters leaked employee records through a PeopleSoft vulnerability. These incidents underscore escalating third-party risk and supply-chain vulnerabilities, prompting urgent calls for stricter vendor access controls across sectors.

4 min read/15 sources
Jul 1, 2026

Digital Privacy & Data Rights — 2026-07-01

A massive 14.2 million email login credentials from Japanese ISPs were exposed in a critical breach, while massive data aggregation operations continue to threaten consumer security at scale. Regulators remain focused on enforcement, with the FTC and EDPB targeting dark patterns and data security failures across platforms.

2 min read/15 sources
Jun 24, 2026

Digital Privacy & Data Rights — 2026-06-24

A massive 24 billion credential dump exposes usernames and passwords from infostealers and breaches worldwide, while a supply-chain attack at market research firm Klue compromises data at multiple cybersecurity companies including Huntress and HackerOne. These incidents underscore the urgent need for stronger breach notification practices and supply-chain security standards across the tech industry.

4 min read/15 sources
Jun 17, 2026

Digital Privacy & Data Rights — 2026-06-17

This week saw multiple high-profile data breaches across enterprise platforms, ongoing university credential exposures, and regulatory enforcement activity from the FTC. A record-setting fine from South Korea against Coupang underscore escalating penalties for mishandled personal data, while technical incidents at ServiceNow raise questions about vendor accountability and disclosure timelines.

5 min read/15 sources
Jun 15, 2026

Digital Privacy & Data Rights — June 15, 2026

South Korea issued a record $409 million fine against Coupang for a massive data breach affecting 37.5 million users, marking the week's biggest enforcement action. Meanwhile, the FTC finalized an order against education software firm Illuminate Education for failing to secure student data. Multiple universities and government entities reported breaches in the June 5–11 roundup, signaling a sustained crisis in organizational data protection practices.

4 min read/15 sources
Jun 12, 2026

Digital Privacy & Data Rights — June 12, 2026

South Korea's record $409 million fine against e-commerce giant Coupang for a massive data breach affecting 37.5 million users dominates this week's privacy enforcement landscape. Simultaneously, ServiceNow disclosed a critical security incident allowing unauthorized customer data access, with reports claiming the company delayed notification despite knowing of the vulnerability since April. These incidents underscore the persistent gap between discovery and disclosure in enterprise security. --> <!-- headline --> South Korea Fines Coupang $409M for Breach of 37.5 Million Users—Record Penalty Sets New Enforcement Bar <!-- /headline -->

4 min read/15 sources
Jun 10, 2026

Digital Privacy & Data Rights — June 10, 2026

This week's privacy landscape is dominated by major data breaches at DentaQuest (2.6M records) and a suspicious Discord breach claim affecting 10M users, plus a critical FTC enforcement action against Illuminate for failing to secure student data. These incidents underscore ongoing vulnerabilities in both healthcare and education sectors, where sensitive personal and medical information remains at risk.

4 min read/15 sources
Jun 8, 2026

Digital Privacy & Data Rights — 2026-06-08

Multiple dental and education breaches exposed millions this week, while the FTC moved against ed-tech companies failing to secure student data. The TechCrunch year-end breach report tallied the sector's worst incidents—from critical infrastructure hacks to government data exposure—underlining that 2026 has been a record year for high-impact security failures affecting everyday users.

4 min read/15 sources
Jun 5, 2026

Digital Privacy & Data Rights — 2026-06-05

This week brought alarming breaches of millions of records across hospitality and education sectors, while U.S. regulators continued shaping age-verification policy to protect minors online. A critical IIT student database leak exposed nearly 180,000 exam records, underscoring persistent infrastructure vulnerabilities in emerging markets.

4 min read/15 sources
Jun 3, 2026

Digital Privacy & Data Rights — 2026-06-03

Carnival Cruise Line disclosed a massive breach affecting nearly 6 million travelers this week, marking one of the largest hospitality sector incidents in recent memory. Meanwhile, Charter Communications faced leaked customer records after refusing ransom demands. These incidents underscore persistent vulnerabilities in travel and telecom infrastructure as regulatory pressure on data protection intensifies globally.

4 min read/15 sources
Jun 1, 2026

Digital Privacy & Data Rights — 2026-06-01

A major cruise industry breach exposed nearly 6 million passengers' data this week, while California sued 23andMe over a 2023 genetic data breach affecting 6.9 million customers. Meanwhile, the FTC issued a landmark COPPA policy statement encouraging age verification technologies to protect children online—a significant regulatory shift that could reshape children's privacy enforcement.

4 min read/15 sources
May 29, 2026

Digital Privacy & Data Rights — 2026-05-29

Charter Communications and Carnival Cruise Lines confirmed massive data breaches affecting millions, with ShinyHunters hackers leaking 13M+ and 6M records respectively after the companies refused ransom demands. The FTC continues pushing age-verification technology adoption to protect children online, while Mexico disclosed a government breach exposing 36M citizens' data. These incidents underscore the persistent gap between corporate security practices and escalating extortion threats.

3 min read/15 sources
May 27, 2026

Digital Privacy & Data Rights — 2026-05-27

This week's biggest story comes from the healthcare sector: nine HIPAA-regulated entities disclosed fresh breaches affecting patient medical, financial, and biometric data, compounding ongoing fallout from the NYC Health + Hospitals incident affecting 1.8 million people. On the regulatory front, the FTC began enforcing the new TAKE IT DOWN Act — the first federal law requiring platforms to remove non-consensual intimate imagery within 48 hours, setting a significant precedent for victims' digital rights. Together, these developments underscore that sensitive personal data — from fingerprints to medical records to intimate images — remains dangerously exposed across both private industry and government-adjacent systems.

8 min read/15 sources
May 25, 2026

Digital Privacy & Data Rights — 2026-05-25

ShinyHunters struck again this week, leaking 9.4 GB of 7-Eleven franchise applicant data including Social Security numbers after the company refused to pay ransom — the same threat actor behind several major April breaches. Meanwhile, nine healthcare entities disclosed HIPAA-regulated breaches, and the FTC began enforcing the newly passed TAKE IT DOWN Act against non-consensual intimate imagery. Everyday users face escalating risks as ransomware groups become bolder and biometric data joins financial and medical records as prime targets.

7 min read/15 sources

Want your own AI intelligence feed?

Create custom signals on any topic. AI curates and delivers 24/7.

Create Signal

Powered by

CrewCrew