Big Tech Privacy & Security Violations, July 2025 β July 2026
This note reproduces a compiled report on major privacy violations, security breaches, and Terms of Service changes by Amazon, Google, Meta, and Microsoft between July 2025 and July 2026. Total financial penalties in the United States alone exceed $4 billion, with additional billions in EU fines. The report documents the erosion of privacy rights that billions of users take for granted.
β¦
Read full article
Summary
This note reproduces a compiled report on major privacy violations, security breaches, and Terms of Service changes by Amazon, Google, Meta, and Microsoft between July 2025 and July 2026. Total financial penalties in the United States alone exceed $4 billion, with additional billions in EU fines. The report documents the erosion of privacy rights that billions of users take for granted.
Impact on regular people: Even when you turn tracking off, pay for a product, or read the terms, these companies keep finding ways to collect data, restrict repair, change rules after purchase, and lock you in. The report shows that these are not isolated mistakes β they are repeated patterns.
Why the "it's fine" narrative is wrong
The common defense is that "everyone accepts these terms," "you have nothing to hide," or "this is the price of convenience." The evidence in this report contradicts that: users explicitly turned tracking off and were tracked anyway; hardware features already built into devices were sold back as subscriptions; terms were changed after purchase with no opt-out; and personal data was used to train AI models without clear consent. These are business-model choices, not technical necessities.
Open Source and consumer rights as the counterweight
Open-source software, right-to-repair laws, and community resources like the Consumer Rights Wiki are the main practical defenses against this erosion. They restore transparency, modifiability, longevity, and user control.
Executive Summary
Over the past twelve months β from July 2025 to July 2026 β the world's four largest technology companies have faced an unprecedented wave of regulatory enforcement, legal judgments, and public scrutiny over their handling of personal data. This report documents every major privacy violation, security breach, and Terms of Service change affecting Amazon, Google, Meta, and Microsoft during this period. The total financial penalties assessed against these four companies exceed $4 billion in the United States alone, with additional billions in European Union fines. But the true cost is measured not in dollars β it is measured in the erosion of fundamental privacy rights that billions of users take for granted every day.
Key Findings at a Glance
- Amazon paid a historic $2.5 billion FTC settlement for secretly enrolling millions of consumers in Prime subscriptions and making cancellation nearly impossible.
- Google was ordered to pay $425 million in a class action for tracking users who explicitly turned off tracking, plus a $135 million settlement for secretly using Android users' cellular data.
- Meta was fined EUR 200 million under the EU Digital Markets Act for forcing users to either pay for privacy or surrender their data, and began training AI models on Europeans' public social media posts without clear consent.
- Microsoft's Windows Recall feature sparked global privacy outrage by taking screenshots of users' screens every few seconds, while Copilot vulnerabilities exposed corporate secrets through AI-assisted attacks.
Amazon: Violations & Regulatory Actions
The $2.5 Billion FTC Settlement (September 2025)
In September 2025, the Federal Trade Commission secured the largest settlement in its history against Amazon.com, Inc. and two senior executives β Senior Vice President Neil Lindsay and Vice President Jamil Ghani. The company was ordered to pay a staggering $1 billion civil penalty and provide $1.5 billion in consumer refunds to approximately 35 million Americans harmed by deceptive Prime subscription practices. The FTC's investigation revealed that Amazon knowingly designed what regulators called 'subscription traps' β deliberately confusing user interfaces that led consumers to enroll in Prime without their knowledge. Internal Amazon documents showed executives privately describing their practices as 'shady' and calling unwanted subscriptions 'an unspoken cancer.' The company then made cancellation extraordinarily difficult, requiring consumers to navigate a complex, multi-step process that internal tests showed was intentionally designed to prevent them from leaving. FTC Chairman Andrew N. Ferguson stated: 'The evidence showed that Amazon used sophisticated subscription traps designed to manipulate consumers into enrolling in Prime, and then made it exceedingly hard for consumers to end their subscription.' The $1 billion civil penalty is the largest ever in a case involving an FTC rule violation.
- Source: FTC Press Release β FTC.gov
Ring Facial Recognition Class Action (June 2026)
In June 2026, Amazon and its Ring subsidiary were hit with a major class action lawsuit over the 'Familiar Faces' facial recognition feature launched in December 2025. The suit, filed by Hagens Berman in the U.S. District Court for the Western District of Washington, alleges that Ring captures and stores biometric facial recognition data of passersby without their knowledge or consent. While Ring doorbell owners can opt into the Familiar Faces feature, the people walking past their homes or businesses cannot. The lawsuit states that Amazon retains this facial biometric data for up to six months, even for individuals who are never saved by a Ring user. The feature is banned in Texas, Illinois, and Portland, Oregon due to strict local biometric privacy laws β but operates freely in the remaining 47 states. U.S. Senator Edward Markey wrote to Amazon in October 2025: 'Amazon's system forces non-consenting bystanders into a biometric database without their knowledge or consent. This is an unacceptable privacy violation.' The proposed class encompasses millions of individuals across the United States.
- Source: Class Action Filing β Hagens Berman
- Related: CBS News Coverage β CBS News
AWS Security Breaches (2025)
Amazon Web Services, which hosts a significant portion of the internet's infrastructure, suffered multiple serious security incidents in 2025. In January 2025, a ransomware group known as Codefinger targeted AWS users by exploiting compromised credentials, using Amazon's own server-side encryption tools to lock victims out of their data and demanding ransom payments. The attackers leveraged SSE-C (server-side encryption with customer-provided keys) to encrypt S3 bucket data with AES-256 keys that Amazon does not retain, making decryption impossible without the attackers' cooperation. In December 2025, AWS experienced another major breach when attackers compromised numerous customer accounts through stolen IAM (Identity and Access Management) credentials, subsequently exploiting EC2 and ECS instances for an extensive crypto-mining operation. The breach, discovered on December 17, 2025, potentially affected thousands of users and raised significant concerns about cloud credential security. Amazon launched an internal investigation and advised users to update IAM credentials and implement multi-factor authentication.
- Source: AWS Security Blog β BlackFog
Google: Violations & Regulatory Actions
$425 Million Privacy Verdict (September 2025)
In September 2025, a federal jury ordered Google to pay $425.7 million for privacy violations affecting approximately 98 million users. The case centered on Google's 'Web & App Activity' setting, which the company represented as a way for users to control data collection. Even when users turned this setting off or paused it, Google continued transmitting their data from non-Google branded apps back to its servers for profiling and advertising purposes. The jury found Google liable for invasion of privacy and intrusion upon seclusion, though it declined to find violations of California's Computer Data Access and Fraud Act. The award was significantly lower than the $31 billion in damages initially sought by plaintiffs. After Google appealed, the judge ordered the company to pay interest on the $425 million from the date of the initial verdict. Both Google's motion to decertify the class and plaintiffs' motion to increase the payout were denied. Eligible class members include anyone with a non-enterprise Google account who turned off or paused 'Web & App Activity' between July 1, 2016 and September 23, 2024, yet still had their data transmitted to Google from non-Google apps.
- Source: Kiplinger β Kiplinger
- Legal Analysis: Thompson Coburn β Thompson Coburn
$135 Million Android Data Settlement (March 2026)
In March 2026, Google agreed to a $135 million class action settlement over allegations that Android devices secretly used cellular data paid for by users to transmit tracking information back to Google. The lawsuit, Joseph Taylor v. Google LLC, covers over 100 million Americans with Android devices who used cellular data between November 12, 2017 and the date of final approval. Plaintiffs alleged that Google 'effectively forces users to subsidize its surveillance by secretly programming Android devices to constantly transmit user information.' This data collection allegedly occurred even when users had shut down apps or disabled location tracking. The settlement provides automatic cash payments (capped at $100 per person) via electronic payment methods including PayPal, Venmo, or Zelle. Notably, a separate parallel lawsuit in California covering approximately 14 million Android users settled for $314.6 million in July 2025, meaning California residents are excluded from the federal settlement. As part of both settlements, Google agreed to significant injunctive relief to better protect Android user privacy.
- Source: ClassAction.org β ClassAction.org
- Source: CNET β CNET
DOJ Antitrust Remedies (September 2025 β April 2026)
In August 2024, Judge Amit Mehta ruled that Google had illegally maintained a monopoly in general search services and search text advertising. The remedies phase concluded in September 2025 with a landmark order that fundamentally restructures Google's business practices. The court imposed a six-year prohibition on exclusive default search contracts covering Google Search, Chrome, Google Assistant, and the Gemini app on devices manufactured by Apple, Samsung, and other partners. The order requires Google to share its search index and user-interaction data (excluding advertising data) with qualified competitors β a mandate Google is aggressively appealing, citing 'irreparable harm' to user privacy. The court also ordered annual rebidding of default search contracts and established a five-member Technical Committee to oversee compliance. In April 2026, the DOJ filed a cross-appeal seeking stronger remedies, including forced divestiture of Chrome and an outright ban on the $20 billion annual Apple default search deal. Both appeals are expected to be heard by the D.C. Circuit in late 2026 or early 2027, with potential Supreme Court review extending into 2028.
- Source: NPR β NPR
- Source: Tech Insider β Tech Insider
Meta: Violations & Regulatory Actions
EUR 200 Million DMA Fine (April 2025)
In April 2025, the European Commission imposed a EUR 200 million fine on Meta for breaching the Digital Markets Act (DMA) through its 'pay or consent' advertising model. Between November 2023 and November 2024, Meta presented EU users with a binary choice: either consent to comprehensive personal data harvesting for personalized advertising, or pay a monthly subscription fee of up to EUR 9.99 for an ad-free experience. The Commission determined that this model did not provide users with a genuine, equivalent alternative that used less of their personal data. Under Article 5(2) of the DMA, gatekeepers must obtain user consent before combining personal data across services, and users who refuse must have access to a less personalized but equivalent experience. Meta's model violated both requirements. In response to the fine, Meta introduced a third 'less personalized ads' option in January 2026, but consumer groups including BEUC found that the option was not presented equally with the other choices and imposed 'ad breaks' that degraded the user experience. The Commission continues monitoring Meta's compliance.
- Source: European Commission β EU Digital Markets Act
- Source: BEUC Assessment β BEUC
AI Training on EU User Data (May 2025)
On May 27, 2025, Meta began using public posts, photos, captions, and comments from adult EU users of Facebook and Instagram to train its artificial intelligence models. The company relied on 'legitimate interest' under GDPR Article 6(1)(f) rather than obtaining explicit user consent β a legal basis that privacy advocates strongly dispute. The Irish Data Protection Commission (DPC), Meta's lead EU regulator, initially halted the plans in June 2024 but ultimately allowed them to proceed after Meta implemented improvements including updated transparency notices, an easier-to-use objection form, and data protection measures like de-identification and filtering. However, Hamburg's data protection authority initiated urgent proceedings demanding suspension of AI training on German users' data. The privacy organization NOYB ('None of Your Business'), led by activist Max Schrems, sent a cease-and-desist letter threatening collective legal action. Schrems stated: 'Meta's absurd claims that stealing everyone's personal data is necessary for AI training is laughable. Other AI providers do not use social network data β and generate even better models than Meta.' Crucially, once data is used to train AI models, it cannot be 'extracted' β making the objection process a race against time.
- Source: European Newsroom β European Newsroom
- Source: noyb β noyb.eu
WhatsApp Antitrust Order (June 2026)
In June 2026, the European Commission ordered Meta to restore access for rival AI assistants to its WhatsApp messaging platform within five days. The order came after Meta updated its terms in October 2025 to ban third-party AI chatbots from WhatsApp entirely, reserving the platform exclusively for Meta's own AI assistant. The Commission stated the intervention was necessary to prevent 'serious and irreparable harm to competition in this growing market by Meta's conduct.' Meta reacted furiously, accusing the Commission of 'regulatory overreach' and announcing plans to appeal. The interim measures require Meta to maintain access for rival AI providers until the antitrust investigation concludes. This case highlights Meta's broader strategy of leveraging its dominant messaging platform β used by approximately 80% of Europeans β to favor its own AI services over competitors. The White House has previously intervened on Meta's behalf when EU regulators have acted against the company.
- Source: European Commission β EC Press
- Source: Le Monde β Le Monde
Microsoft: Violations & Regulatory Actions
Windows Recall Privacy Controversy (2024-2025)
Microsoft's Recall feature, announced in 2024 and rolled out to Copilot+ PCs in May 2025, represents one of the most controversial privacy features in modern computing history. Recall takes screenshots of a user's screen every few seconds, uses on-device AI to analyze the content, and builds a searchable database of everything the user has ever viewed or typed on their PC β including passwords, financial documents, medical records, and private messages. Following massive public backlash and security researcher criticism, Microsoft made Recall opt-in rather than enabled by default, added Windows Hello biometric authentication requirements, and implemented encryption. However, the company clarified that Recall cannot be fully uninstalled β only disabled. The feature remains excluded from the European Economic Area, where regulators deemed it incompatible with GDPR requirements. Security researchers documented that if a device is compromised by malware, an attacker could potentially access the entire Recall database, extracting sensitive information stored in screenshots. In January 2026, Microsoft confirmed a bug causing Recall to capture screenshots of confidential emails and bypass data loss prevention policies β an issue that had persisted since late January 2026 before being patched.
- Source: nGuard Security Analysis β nGuard
Copilot Security Vulnerabilities (2025-2026)
Microsoft 365 Copilot has been plagued by a series of serious security vulnerabilities that expose corporate data to unauthorized access. In May 2025, researchers at Aim Security disclosed CVE-2025-32711 ('EchoLeak'), the first documented zero-click vulnerability in a production AI system, rated CVSS 9.3 out of 10. The vulnerability allowed attackers to exfiltrate data from Copilot's context without any user interaction β simply by sending a crafted email that Copilot would later process. Other documented attack vectors include ASCII Smuggling (using invisible Unicode characters to hide stolen data in hyperlinks), Mermaid Diagram Exfiltration, Confidential Label Bypass (January 2026), and Indirect Prompt Injection via Email. The fundamental risk, however, is not exotic vulnerabilities but 'oversharing' β Copilot inherits all permissions a user has across SharePoint, OneDrive, and Teams, instantly making every poorly permissioned document searchable and summarizable by AI. In March 2024, the European Data Protection Supervisor found the European Commission itself in breach of data protection law for its use of Microsoft 365, citing insufficient specification of data collection and missing transfer safeguards. The breaches were remediated by July 2025, but the ruling set a precedent for all EU organizations using Microsoft cloud services.
- Source: Security Today β Security Today
- Source: SURF Netherlands β SURF
Azure Security Incidents (2025-2026)
Microsoft Azure faced critical security challenges throughout 2025. In early 2025, researchers identified CVE-2025-55241, a vulnerability in Microsoft Entra ID (formerly Azure Active Directory) that could allow attackers to impersonate global administrators across tenants. Microsoft rated the vulnerability as critical (CVSS 10.0) and issued an emergency patch, though the flaw demonstrated the fragility of cloud identity boundaries. In May 2026, Microsoft Threat Intelligence disclosed a sophisticated attack by threat actor Storm-2949 that turned a single compromised identity into a full cloud-wide breach. The attackers leveraged legitimate Azure management features to execute code remotely on virtual machines, access Key Vaults, manipulate SQL server firewall rules, and exfiltrate massive volumes of data from Azure Storage accounts using custom Python scripts. The attack spanned SaaS, PaaS, and IaaS layers, demonstrating that cloud identity compromise is now the primary vector for enterprise breaches. Additionally, in July 2025, a ProPublica investigation revealed that Microsoft had hired engineers in China to maintain federal defense systems, supervised by American 'digital escorts' with limited technology experience. The Office of the Director of National Intelligence has called China the 'most active and persistent cyber threat to U.S. Government, private-sector, and critical infrastructure networks.'
- Source: Microsoft Security Blog β Microsoft Security
Terms of Service & Privacy Policy Changes
Amazon β BSA Update (March 2026)
Effective March 4, 2026, Amazon updated its Business Solutions Agreement with a new 'Agent Policy' that requires all automated systems accessing Amazon services to clearly identify themselves, comply continuously with policy terms, and cease access immediately if requested by Amazon. The policy prohibits using Amazon materials for AI development and gives Amazon broad authority to revoke access from any automated system without prior notice or explanation. Critically, sellers and software providers who continued using Amazon's services after March 4 automatically accepted these updated terms with no option to opt out. The changes effectively closed the data pipeline that third-party tools had used for years, consolidating Amazon's control over its marketplace data while restricting external AI development.
Meta β Privacy Policy Update (December 2025)
Meta's updated Privacy Policy, effective December 16, 2025, governs how user data is collected, used, and shared across Facebook, Instagram, and Messenger. The policy introduced new provisions for AI training data usage and modified how users can manage their privacy settings. Simultaneously, Meta updated its Terms of Service in January 2025 with significant changes including unilateral terms updates (users automatically consent to future changes by continuing to use the platform), broad content rights for AI training, and legacy contact provisions for posthumous account management. Critically, the new Terms allow Meta to use user content for AI and machine learning purposes without explicit opt-in consent. While Meta claims it does not 'sell' personal data, the updated language grants broad licensing rights that many privacy advocates argue effectively enables unrestricted AI training on user content. The terms also state that by simply using the platform, users automatically agree to any future changes β a practice that removes meaningful choice.
Microsoft β Multiple Updates (2025-2026)
Microsoft updated its Services Agreement on September 30, 2025, with changes including new provisions for exportable data, updated Xbox and Minecraft EULA references, Skype retirement accommodations, and new restrictions on AI services usage. The Privacy Statement underwent significant revisions in March and June 2026, reorganizing sections, adding Copilot-specific privacy controls, updating personalized advertising language, introducing new diagnostic data subsections, and adding age-appropriate experience provisions for the Microsoft Store. The June 2026 Privacy Statement update added information about access, export, and deletion controls in Microsoft Copilot and Microsoft 365 Copilot, clarified how Copilot in Edge processes page content and browsing history, and removed references to health-related ad targeting. Microsoft also updated its 'Artificial Intelligence and Copilot capabilities' section to describe how Copilot Health uses information for personalized health and wellness assistance.
Appendix: Additional Violations & Incidents
The following incidents, while smaller in financial impact or regulatory scope, represent important patterns in how these companies handle user data and respond to privacy concerns. Each entry includes a brief summary and source link for further investigation.
Amazon β Additional Incidents
- Luxembourg GDPR Fine Appeal Upheld (March 2025) β Amazon's appeal of a EUR 746 million GDPR fine for processing personal data for targeted advertising without proper consent was rejected by Luxembourg's Administrative Court. The fine, originally issued in July 2021, remains one of the largest GDPR penalties ever imposed. Source
- Codefinger Ransomware (January 2025) β Ransomware group Codefinger targeted AWS users by exploiting compromised credentials, using AWS's SSE-C encryption to lock victims out of their own S3 buckets with encryption keys Amazon does not retain. Source
Google β Additional Incidents
- Privacy Sandbox Shutdown (October 2025) β Google officially discontinued its Privacy Sandbox initiative after six years, abandoning plans to replace third-party cookies. The reversal followed regulatory pressure from the UK CMA, EU authorities, and U.S. DOJ antitrust scrutiny. Source
- $314.6M California Android Settlement (July 2025) β A separate California class action covering approximately 14 million Android users settled for $314.6 million over similar allegations of unauthorized cellular data collection for tracking purposes. Source
Meta β Additional Incidents
- EUR 800 Million Antitrust Fine (November 2024) β The European Commission fined Meta EUR 800 million for tying its Facebook Marketplace classified ads service to its social network and imposing unfair trading conditions on competing ad providers. Source
- EUR 91 Million Plaintext Password Fine (September 2024) β Ireland's DPC fined Meta EUR 91 million for storing certain Facebook user passwords in plaintext within internal systems since 2019, violating GDPR Article 5(1)(f) requiring appropriate security measures. Source
- EUR 251 Million 2018 Breach Fine (September 2024) β The DPC fined Meta EUR 251 million for a 2018 Facebook breach that exposed personal data of 29 million users through a flaw in the 'view as' feature. Source
Microsoft β Additional Incidents
- LinkedIn EUR 310 Million GDPR Fine (October 2024) β Ireland's DPC fined LinkedIn (owned by Microsoft) EUR 310 million for processing user data without proper consent for behavioral analysis and targeted advertising. Source
- Austrian Kids' Data Violation (October 2025) β Austria's data protection authority found Microsoft violated EU law in its handling of children's data, marking another European enforcement action against the company's data practices. Source
- M365 Copilot Confidential Email Bug (January 2026) β Microsoft confirmed a bug causing Copilot to summarize confidential emails since late January 2026, bypassing data loss prevention policies. An emergency patch was released. Source
- SharePoint Zero-Day (July 2025) β Hackers exploited a zero-day vulnerability in Microsoft SharePoint impacting businesses, federal agencies, and universities globally. Emergency patches were released but some platform versions remained vulnerable. Source
Your Privacy Matters
- Document compiled for privacy advocacy and public awareness.
- All sources verified and linked. This document is intended for educational and advocacy purposes to inform the public about their digital rights.
Comfac Relevance
- Vendor risk: Comfac uses Google Workspace, Microsoft 365, Azure, AWS, and other services documented in this report. These incidents belong in vendor-risk reviews and DPO evidence.
- Client accreditation: The report provides independent, cited examples of vendor behavior for security questionnaires and ISO 27001 evidence.
- Awareness: The public Security & Privacy News page surfaces these patterns so employees, clients, and the public can recognize them.
Related Notes
2026-07-13-major-tech-privacy-violations.md2026-07-13-consumer-rights-wiki-megacorporation-violations-index.md2026-07-13-australian-consumer-law-unfair-contract-terms.md
References
- Original document:
work/security-iso/BigTech_Privacy_Violations_2025-2026.docx
Converted to markdown and added to the security-privacy news feed on 2026-07-13.