Comfac Security & Privacy News

Plain-language security and privacy news for everyday people — backed by the detailed notes Comfac IT and the Security & Compliance Assistant (SCA) keep for vendor risk, accreditation, and internal hardening.

About this page

This page translates the SCA's threat-intelligence notes into language regular people can use. It is updated weekly: Erin curates the raw links and transcripts (Links with Friends, privacy channels, Naomi Brockwell TV), the sources are verified, and each story is extrapolated in plain language. A major source we draw from is the Consumer Rights Wiki, including coverage rooted in the Louis Rossmann channel and the right-to-repair movement. The same events are documented in depth in work/security-iso because there is a constant stream of AI-generated advice, marketing, and news telling us that handing over ownership, privacy, and control is "no big deal" or "the only way." That narrative is wrong, and it costs people and businesses every day. Each card gives you the short version, the full story, and the original source so you can decide for yourself.

Know your rights

The context behind the news: why privacy, ownership, speech, a free market, fair wages, healthcare, education, and a healthy environment are rights — and the Philippine Constitution's anchors. News cards below link here with tags like rights:privacy.

Algorithmic wage discrimination — when a black box sets your pay

⚪ Informational 2026-09-12

Algorithmic wage discrimination is what happens when software — not a manager — decides what you are paid. Automated systems, machine-learning models and data-driven tools set compensation, pay offers and piece-rates in ways that introduce bias, push pay down for specific groups, or exploit a worker's vulnerability.

Read full article

Algorithmic wage discrimination is what happens when software — not a manager — decides what you are paid. Automated systems, machine-learning models and data-driven tools set compensation, pay offers and piece-rates in ways that introduce bias, push pay down for specific groups, or exploit a worker's vulnerability. What separates it from ordinary pay inequality is the opacity: the decision arrives as a number with no reasoning attached, and the worker cannot see, question, or appeal the inputs that produced it.

This is the fair-wages tile of the same pattern described in Why we have privacy rights: power concentrates, options shrink, and the exit disappears. Surveillance is what makes the pricing possible — you cannot compute a person's lowest acceptable wage without first measuring the person.

How it works — four mechanisms

1. Dynamic and behavioural pricing

Common in gig work and remote contracting. The system looks at a worker's location, device, historical acceptance rate and estimated reservation wage — the lowest amount they will accept — and offers less to people who appear to have fewer alternatives. Two identical trips, two different offers; the difference is the algorithm's estimate of how badly each driver needs the work.

2. Historical data laundering

HR and recruitment tools trained on legacy payroll data learn past pay gaps and then reproduce them as offers. The output is presented as objective "market rate data," which launders a historic disparity into a fresh, seemingly neutral number. This is why asking for salary history is so damaging: feed the old gap in, get the old gap out, now carrying a machine's authority.

3. Surveillance-based performance pay

Keyloggers, activity monitors and delivery-speed tracking feed piece-rates and bonuses. Because the metrics are behavioural, these systems systematically penalise people who need bathroom breaks, who have caregiving duties, who have chronic health conditions, or who work on older hardware. The penalty is not a policy — it is an emergent property of the measurement.

4. Proxy discrimination

Even when a model is explicitly forbidden from using race or gender, it can reach the same outcome through correlated proxies: postcode, transit route, device model, shopping habits. Removing the protected attribute does not remove the discrimination; it only removes the evidence.

Debt: the vector that sets the floor

This is the part that makes the mechanism self-reinforcing, and it deserves stating plainly: financial distress is not a side effect of algorithmic pay suppression — it is the input the system optimises against.

  • A lower reservation wage. A worker with debt service and a thin buffer cannot decline a bad offer, so the algorithm learns it can quote them rock-bottom rates. Their desperation becomes a parameter.
  • Captive labour. Where a worker carries a vehicle loan or equipment debt tied to the platform, they log longer hours and accept more work. The system reads that availability as willingness and routes them the low-value tasks.
  • The desperation loop. More low-paid volume to stay afloat is read as higher compliance, which locks the worker into a depressed wage tier. The behaviour that looks like a choice is the trap closing.

Some of this is documented in the literature — obtaining and exploiting reservation-wage estimates is the core of the scholarship cited below. Some of it, in particular how far financial-stress telemetry is actually ingested into pay models, is analysis rather than established fact, and is marked as such here deliberately. It is the direction the capability points, and the data brokers who assemble that telemetry exist; the published evidence of direct pay-model ingestion is thinner than the surrounding incentives suggest.

What the law actually says now

⚠️ This section was materially wrong in the draft and has been corrected. If you have seen guidance elsewhere repeating the older position, it is out of date.

The United States — the federal floor was removed in 2026

The long-standing assumption was that algorithmic pay bias was a disparate impact problem: employers were liable for compensation systems producing discriminatory outcomes regardless of intent, and regardless of whether the tool was built in-house or bought from a vendor.

That is no longer federal policy. On 9 June 2026, the US Department of Justice announced that its Office of Legal Counsel had concluded the EEOC's disparate-impact guidelines under Title VII are unconstitutional — reasoning that they permit liability from unequal outcomes alone, without regard to intent, and pressure employers into race-conscious decision-making to avoid enforcement risk. The opinion is tied to Executive Order 14281 ("Restoring Equality of Opportunity and Meritocracy"), and the EEOC's current leadership has welcomed it; the agency's 2026 National Enforcement Plan reflects the reorientation.

What that does and does not mean. It is an executive-branch legal opinion, not a Supreme Court holding. Courts, state agencies and private plaintiffs can still bring disparate-impact theories, and contractual and sectoral rules are untouched. But the practical enforcement pressure behind "your compensation algorithm must not produce discriminatory outcomes" has been substantially withdrawn at federal level — which means the compliance argument for auditing a pay model is now much weaker than the ethical and reputational one. Organisations that keep auditing are doing so on their own judgment, not because a regulator is making them.

The states are filling the void

  • New Jersey — Division on Civil Rights rules effective 15 December 2025 codify disparate-impact liability for facially neutral employment practices, expressly including automated decision-making tools.
  • Illinois — Senate Bill 3777, the Civil Rights Safeguard Act, would codify disparate-impact protections under the Illinois Human Rights Act, including in employment.

So the operative question for a multi-state employer is no longer "what does the EEOC require" but which states have legislated a floor, and does my pay model clear it. The federal rollback does not remove the risk; it moves it.

The EU — high-risk, but the deadline moved

The EU AI Act classifies AI used in employment, workers' management and access to self-employment as high-risk (Annex III), which brings obligations around transparency, data governance, technical documentation, logging and mandatory human oversight.

Two timing caveats matter, because the picture shifted in 2026:

  • 2 August 2026 was the long-expected enforcement cliff for the Annex III high-risk regime, including employment. The EU's Digital Omnibus on AI subsequently delayed the high-risk regime, while most transparency obligations remain in force.
  • The European Commission published draft guidelines on high-risk classification under Article 6 during 2026, still in consultation — so exactly how employment tools are classified is being settled now, not settled already.

For a workplace pay tool, the practical read: the transparency duty is live, the high-risk compliance package is deferred rather than cancelled, and the classification guidance is still moving.

What actually reduces the harm

  1. Audit the model, independently, before it sets a wage. Run disparate-impact testing on the compensation model itself, not just the hiring funnel, and re-run it on a schedule. With federal enforcement withdrawn, this is now a choice — which makes it a signal of what a company actually believes.
  2. Ban salary history as an input. The cheapest, highest-leverage fix: it breaks the laundering loop at the point where the old gap would enter.
  3. Human oversight and a real appeal. Any automated pay decision needs a named human accountable for it and a route for the worker to contest it — which also happens to be what the EU AI Act requires for high-risk systems.
  4. Watch the proxies, not just the attributes. Test the outputs by postcode, device and shift pattern, because that is where discrimination shows up.
  5. Treat the debt signal as a red line. If a pay model can observe or infer financial distress, it will eventually price against it. That data should not be in the pipeline at all.

Sources — verified 2026-09-12

Legal scholarship

  • Dubal, "On Algorithmic Wage Discrimination," 123 Colum. L. Rev. 1929 (2023)article · issue PDF. The foundational legal treatment: personalised, black-box wage-setting breaks the "equal pay for equal work" precedent and targets vulnerable contractors based on estimated financial constraints. This is the correct citation for the reservation-wage mechanism.
  • Teachout, "Algorithmic Personalized Wages," 51 Politics & Society (2023)Fordham faculty repository. Sets out a taxonomy of five forms of algorithmic wage differentiation and argues the techniques will spread from gig work into formal employment, with democratic and racial-equality consequences. Cited in the draft as an unattributed "Fordham Law School Scholarship"; the author is Teachout and the journal is Politics & Society, not a Fordham law review.

Investigative reporting

  • Kerr, "Secretive Algorithm Will Now Determine Uber Driver Pay in Many Cities," The Markup, 1 March 2022article. From The Markup's Working for an Algorithm series, which won SABEW awards: documents the shift to opaque, individualised driver pay. The series is the reporting backbone for the gig-pay mechanism.

Policy and research

  • Monroe, "How artificial intelligence uncouples hard work from fair wages through 'surveillance pay' practices — and how to fix it," Washington Center for Equitable Growth, 21 August 2025article. Names and defines "surveillance pay," maps where it is deployed, and proposes pay-fairness and transparency policy.
  • AI Now Institute, "Real Surveillance Prices and Wages" (February 2025)report. The surveillance-pricing problem across both consumer prices and wages.
  • State Innovation Exchange, "Prohibiting Surveillance Prices and Wages: A Framework"report. Model legislative language — the practical countermeasure.
  • Federation of American Scientists, "From Surveillance Pay to Fair Wages"publication.

Regulatory

  • EU AI Act, Annex III — high-risk systemsAnnex III text; point 4 covers employment, workers' management and access to self-employment.
  • DOJ Office of Legal Counsel opinion on EEOC disparate-impact guidelines, 9 June 2026Clark Hill summary.
  • EU high-risk delay (Digital Omnibus) and surviving transparency dutiesJones Walker analysis.
  • EEOC 2026 National Enforcement PlanMayer Brown analysis.

Verification note — what checking the sources changed

Every citation above was checked against a primary or authoritative source on 2026-09-12. Three things in the originating draft did not survive that check.

  1. Removed — "Sanaz Mobasseri & César A. Hidalgo (Research on Gig Platform Pay)." This was cited as having "extensively documented how algorithmic systems in ride-hailing and delivery apps shift away from transparent pay structures." No such joint work could be found. Prof. Mobasseri's own CV lists work on racial and gender inequality in organisations, cultural fit and organisational networks — it contains no mention of Hidalgo, Uber, Lyft, wages or algorithms, and no gig-pay paper. Both are real scholars; the co-authorship and the described body of work are not verifiable, and a citation that cannot be checked has no place on a page that asks readers to trust its receipts. The reservation-wage mechanism it was supporting is properly cited to Dubal instead.
  2. Corrected — the EEOC claim. The draft stated that the EEOC "treat[s] algorithmic bias in compensation as a violation of anti-discrimination laws, holding employers legally liable for disparate impact." That described the position before June 2026. As of today the DOJ has concluded those guidelines are unconstitutional. The section now leads with the reversal and the state-level counter-movement.
  3. Corrected — the Fordham attribution. "Fordham Law School Scholarship ('Algorithmic Personalized Wages')" is real work, but it is Zephyr Teachout's, published in Politics & Society and merely hosted in Fordham's repository.

Two sources were added because the verification pass turned them up and they are more directly on point than what they replaced: the AI Now Institute report and the State Innovation Exchange legislative framework.

Verified by the Comfac Security & Compliance desk. Last checked 2026-09-12.

Status: Living reference — sources verified 2026-09-12; see the verification note at the end for what checking the draft changed

Misleading arguments — the scripts used to sell you the erosion

⚪ Informational 2026-08-23

Every erosion of privacy, ownership, or competition is announced with a soothing script. Here is what the scripts actually mean, and how to answer them.

Read full article

Every erosion of privacy, ownership, or competition is announced with a soothing script. Here is what the scripts actually mean, and how to answer them.

"If you have nothing to hide, you have nothing to fear."

Surveillance is not about you personally — it is about the power to watch everyone and the ability to target anyone later. History's abuses did not start by surveilling "the guilty"; they started by surveilling everyone and deciding later. Privacy protects the innocent and the dissenting, and it protects you from mistakes — false flags, stolen identities, and data brokers selling your profile to whoever pays.

"It's free, so you consented."

"Free" services are paid for with your attention, your data, and your options. A terms-of-service page you never read is not consent; a market where every "free" option is the same surveillance machine is not choice. Real consent requires real alternatives.

"Regulation kills innovation."

Regulation kills exploitation, not innovation. Antitrust and privacy rules are what keep markets open enough that new entrants (real innovation) can survive against entrenched incumbents. The innovation that dies under weak rules is the would-be competitor who could not afford to fight a sanctioned monopoly.

"If you don't like it, just don't use it."

This is the exit argument — and it is only valid if exit actually exists. When a service is the only way to reach your bank, your government, your school, or your job, "don't use it" means "drop out of society." That is not choice; that is a captive market (see right-free-market).

"The market has spoken" / "Competition will fix it."

Competition fixes nothing when the rules are rigged. If regulators enforce a monopoly's barriers to entry, or if a cartel quietly fixes prices, the "market" has not spoken — a script has. That is corruption, not competition (see private-market-corruption).

"Privacy is for criminals."

Privacy is the foundation of ownership, speech, a free market, fair wages, healthcare, education, and a healthy environment — see why-privacy-rights. Framing it as a criminal's demand is the oldest trick in the book: it makes the erosion sound like safety.

Status: Living reference — add new scripts as they appear in the news

Your rights in the Philippine Constitution — a plain-language map

⚪ Informational 2026-08-23

This is a citizen's map of the 1987 Constitution: which rights exist, where they live, and which laws turn them into everyday protection. It is educational, not legal advice.

Read full article

This is a citizen's map of the 1987 Constitution: which rights exist, where they live, and which laws turn them into everyday protection. It is educational, not legal advice.

Article III — Bill of Rights (the core protections)

  • Sec. 1 — Due process and equal protection: no one is deprived of

life, liberty, or property without due process; everyone gets equal protection of the laws.

  • Sec. 2 — Protection against unreasonable searches and seizures:

the state cannot rummage through your home, phone, or data without a warrant based on probable cause.

  • Sec. 3 — Privacy of communication and correspondence: your

messages and communications are inviolable except by lawful court order.

  • Sec. 4 — Freedom of speech, of expression, and of the press.
  • Sec. 7 — Right to information on matters of public concern.
  • Sec. 9 — Private property shall not be taken without just

compensation.

Social and economic rights (Articles II, XII–XIV)

  • Art. II, Sec. 15 — The State shall protect and promote the right

to health. (Healthcare)

  • Art. II, Sec. 16 — The right of the people to a **balanced and

healthful ecology** — recognized by the Supreme Court in Oposa v. Factoran as a right that future generations can enforce. (Healthy environment)

  • Art. II, Sec. 17 — Priority to education, science and technology.
  • Art. II, Sec. 18 — Protection of labor, full employment, and equal

work opportunities. (Fair wages)

  • Art. II, Sec. 19 — A self-reliant and independent national

economy; Art. II, Sec. 20 — the role of the private sector in enterprise. (Free market)

  • Art. XIII, Sec. 3 — The State shall guarantee the right of all

workers to a living wage. (Fair wages)

  • Art. XIV, Sec. 1 — The State shall protect and promote the right

of all citizens to quality education at all levels. (Education)

Amendments — Article XVII

The Constitution provides its own amendment path (Art. XVII: by Congress as constituent assembly, a constitutional convention, or people's initiative). As of 2026 there are no ratified amendments to the 1987 Constitution; periodic "Cha-cha" proposals (federalism, opening economic provisions to foreign ownership) have been debated but not enacted. Watch news of constitutional change closely — an amendment that sounds technical can rewrite who owns what.

Laws that put these rights to work

  • RA 10173 — Data Privacy Act (2012): the privacy of communication

(Art. III, Sec. 3) made concrete for personal data.

  • RA 10667 — Philippine Competition Act (2015): protects the

competitive process — the legal tool against cartels, abuse of dominance, and anticompetitive mergers.

  • RA 8792 — E-Commerce Act and sector regulators (NTC, DOE, DOH,

DepEd) carry specific consumer protections.

How to use this page

When a news story tags a right (e.g. rights:privacy, corruption:state-capture), look up the right here: the Constitution is the reason the abuse is an abuse.

Status: Living reference — verify before citing in legal context

The right to a free market — options, competition, and the power to leave

⚪ Informational 2026-08-23

A free market is not "the rich do whatever they want." A free market is the opposite: **nobody is forced to buy from one place, there is real competition, and anyone can choose to participate — and to be that competition.** The engine of a free market is exit: if you are treated badly, you can take your business elsewhere. When options disappear, exit dies, and the relationship becomes captive.

Read full article

A free market is not "the rich do whatever they want." A free market is the opposite: **nobody is forced to buy from one place, there is real competition, and anyone can choose to participate — and to be that competition.** The engine of a free market is exit: if you are treated badly, you can take your business elsewhere. When options disappear, exit dies, and the relationship becomes captive.

What the right includes

  • Options — more than one place to buy, sell, work, and speak.
  • Competition — new entrants can actually enter; rules are not

written to keep them out.

  • Participation — you can start or join the competition, not just

consume it.

  • Exit — the ability to leave a bad deal without being punished or

locked in.

How the right is eroded

  • Lock-ins and switching costs — your files, contacts, history, or

identity are held hostage so leaving is too expensive.

  • Cartels and collusion — vendors that look like competitors but

secretly fix prices and rotate contracts; they act as one monopoly.

  • Captured markets / sanctioned monopolies — a dominant player uses

regulators or legislators to legally block newcomers; the monopoly is then protected by law, not earned in the market.

  • Predatory pricing — temporarily selling below cost to bankrupt any

new entrant, then raising prices once alone.

  • Tying and bundling — forcing you to buy unwanted products as the

price of the one you need.

Philippine anchors

  • Constitution Art. II, Sec. 19 (self-reliant national economy) and

Sec. 20 (role of the private sector); Art. XII on the national patrimony.

  • RA 10667 — Philippine Competition Act (2015): prohibits

anticompetitive agreements (cartels), abuse of dominant position, and anticompetitive mergers; enforced by the Philippine Competition Commission (PCC).

  • Consumer protection: RA 7394 (Consumer Act) for honest

representations, and the DTI for complaints.

The test for every "choice"

When a company or a government tells you a market is competitive, ask: **can you actually leave — with your data, your money, and your options intact?** If the honest answer is no, the market is not free, and the corruption that thrives in captive markets (see private-market-corruption) will follow.

Status: Living reference

Why we have privacy rights — and how every news story is a piece of the erosion

⚪ Informational 2026-08-23

Privacy rights are not a tech preference. They are the load-bearing wall under every other right: **ownership, speech, a free market, fair wages, healthcare, education, a healthy environment**. If someone can watch, record, and predict you, they can price you, steer you, silence you, and decide which options you are even allowed to see. This article is the context layer for everything else on this site: the "why" behind the weekly news.

Read full article

Privacy rights are not a tech preference. They are the load-bearing wall under every other right: **ownership, speech, a free market, fair wages, healthcare, education, a healthy environment**. If someone can watch, record, and predict you, they can price you, steer you, silence you, and decide which options you are even allowed to see. This article is the context layer for everything else on this site: the "why" behind the weekly news.

The pattern in the news

Almost every story in the weekly digest is one tile of a larger pattern: power concentrates, options shrink, and the exit disappears. A phone that is tracked is a customer who cannot walk away. A market with one dominant platform is a market where "choice" is cosmetic. A government that buys your movement data from a broker has made consent optional.

When you read a story here, ask: *which right is being eroded, and who loses the ability to leave?*

The rights at stake

  • Ownership — you should keep what you buy and what you make; repair,

resell, and control your own devices and data (right to repair; no "renting" your own hardware).

  • Speech — privacy is what makes speech possible; surveillance

chills what people dare to say.

  • A free market — real competition means options, and options mean

the power to leave a bad deal. Lock-ins, cartels, and sanctioned monopolies are market corruption. See right-free-market.

  • Fair wages — when workers are surveilled, scored, and matched by

algorithms, bargaining power collapses.

  • Healthcare — health data is the most sensitive data; its misuse

decides who gets coverage, treatment, and trust.

  • Education — surveillance software in classrooms grades behavior,

not learning, and teaches students that being watched is normal.

  • A healthy environment — the right to a balanced and healthful

ecology is written into the Philippine Constitution (Art. II, Sec. 16); environmental harm is often a privacy-and-accountability failure first.

The Philippine legal anchors

The 1987 Constitution's Bill of Rights (Article III) is the backbone: due process and equal protection (Sec. 1), protection against unreasonable search and seizure (Sec. 2), privacy of communication (Sec. 3), freedom of speech and of the press (Sec. 4), the right to information on matters of public concern (Sec. 7), and just compensation for property (Sec. 9). Social and economic rights — health, education, labor, a balanced ecology — sit in Article II and Articles XII–XIV. See philippine-constitution-rights for the full mapping.

The misleading-argument index

Every erosion is sold with a script: "If you have nothing to hide…", "It's free, so you consented," "Regulation kills innovation." These are answered point by point in misleading-arguments.

Status: Living reference — updated as the news shifts

Corruption watch

Types of corruption — in government and in private markets where few options, lock-ins, cartels, and captured markets (sanctioned monopolies) destroy the power to leave. News cards link here with tags like corruption:state-capture.

Corruption in government — the types and how to spot them

⚪ Informational 2026-08-23

Government corruption is the public-sector half of the same disease. Where private-market corruption captures markets, government corruption captures the state — and the two feed each other: a captured regulator is how a sanctioned monopoly is born.

Read full article

Government corruption is the public-sector half of the same disease. Where private-market corruption captures markets, government corruption captures the state — and the two feed each other: a captured regulator is how a sanctioned monopoly is born.

Types

  • Bribery and extortion. Officials demanding payment for services,

permits, licenses, or "expedition" that should be a right. *(tag: corruption:extortion)*

  • Bid-rigging and procurement fraud. Tenders written to fit one

bidder, contracts rotated among favored firms, ghost projects, and inflated cost estimates. (tag: corruption:bid-rigging)

  • Regulatory capture. Agencies created to protect the public end up

serving the industry they regulate — approving mergers, blocking entrants, writing rules the incumbent dictated. *(tag: corruption:regulatory-capture)*

  • State capture. Corruption reaches the top of the state itself:

laws, courts, and enforcement are bought, and the system is designed to keep the powerful in power. (tag: corruption:state-capture)

  • Nepotism and patronage. Positions and contracts handed to

relatives and loyalists rather than to merit. *(tag: corruption:nepotism)*

  • Money laundering of public funds. Public money cycled through

fake projects, shell entities, and inflated contracts. *(tag: corruption:laundering)*

The Philippine anti-corruption architecture

  • RA 3019 — Anti-Graft and Corrupt Practices Act (the primary

statute; prosecutes graft in public office).

  • **RA 6713 — Code of Conduct and Ethical Standards for Public

Officials and Employees** (declaration of assets, liabilities and net worth — SALN).

  • RA 10660 / RA 9775 — institutional rules and remedies; the

Ombudsman (Constitution Art. XI) investigates and prosecutes public officials.

  • Right to information (Constitution Art. III, Sec. 7) is the

citizen's flashlight: follow the money, demand the documents.

How to spot it in the news

When a story mentions a contract, a permit, or a regulation that mysteriously benefits one company, tag it. The tag tells you which abuse is at work — see the tag guide in private-market-corruption.

Status: Living reference

Corruption in private markets — what thrives when options are scarce

⚪ Informational 2026-08-23

When private markets feature limited options — monopolies, oligopolies, or heavily concentrated supplier networks — the lack of competition creates fertile ground for corruption and market abuse. With no exit, power shifts entirely to the single provider or the cartel. Corruption is not only a government problem; it lives in industry wherever captive markets are allowed to grow.

Read full article

When private markets feature limited options — monopolies, oligopolies, or heavily concentrated supplier networks — the lack of competition creates fertile ground for corruption and market abuse. With no exit, power shifts entirely to the single provider or the cartel. Corruption is not only a government problem; it lives in industry wherever captive markets are allowed to grow.

1. Types of corruption in limited-option markets

  • Extortion and coercion. Because buyers cannot switch, the sole

provider demands kickbacks, "service fees," or bribes just to grant access to essential goods, infrastructure, or permits. Example: a lone utility or sole-source contractor demanding under-the-table payments to expedite connections — knowing the victim has no alternative. (tag: corruption:extortion)

  • Regulatory capture. Dominant private entities use their leverage

to co-opt regulators, lawmakers, and officials, ensuring laws are written or enforced to block new entrants (barriers to entry), cementing the monopoly. (tag: corruption:regulatory-capture)

  • State capture. A step beyond regulatory capture: private

monopolies effectively buy the legislative, judicial, and executive institutions of a state, so the entire market is structurally rigged to funnel wealth to the monopoly while criminalizing or legislating against competition. (tag: corruption:state-capture)

  • Collusion and bid-rigging in pseudo-markets. Markets that look

competitive but whose vendors secretly collude act as a single monopoly — rotating tenders among themselves at fixed, inflated prices, often with procurement officers on the take. *(tag: corruption:collusion, corruption:bid-rigging)*

2. Market abuses that exploit scarce options (legal or grey-area)

  • Rent-seeking. Instead of creating new wealth, a dominant player

extracts maximum value from society by controlling a bottleneck. (tag: corruption:rent-seeking)

  • Predatory pricing and exclusionary tactics. A dominant player

prices below cost to bankrupt a nascent competitor, then returns to exploitation once alone. (tag: corruption:predatory-pricing)

  • Tying and bundling. Forcing buyers to take unwanted secondary

products as a condition of getting the one they need. (tag: corruption:tying)

  • Information asymmetry and price gouging. With no competing prices

to benchmark, a sole provider obscures real costs and jacks up prices in emergencies without fear of losing customers. (tag: corruption:price-gouging)

The key takeaway

Free markets rely on exit — the ability to take your business elsewhere if treated poorly. When options are severely limited, exit is destroyed, and economic relationships become captive: corruption and exploitation naturally flourish unless robust antitrust enforcement and independent oversight are actively applied. In the Philippines the primary tool is RA 10667 (Philippine Competition Act) enforced by the Philippine Competition Commission — see right-free-market.

Tag guide for the news

When a story is tagged corruption:*, it is naming which abuse is in play. corruption:state-capture is the deepest form; corruption:tying is the everyday one. Both are corruption — one in the legislature, one in the checkout flow.

Status: Living reference

Weekly news

Verified stories from the sources we follow, each tagged with the rights and corruption types at stake.

2026-09-15 — Security & Privacy News — Weekly Digest

🟠 High 2026-09-15

Flock had the week the cameras deserved. A leaked training video allegedly shows Flock staff coaching police on how to use the system against protesters; Illinois records show over 1,200 searches in a single small town were about loitering — standing around; a Florida woman spent 13 days in jail after a Flock misidentification and is now suing; and a California city that cancelled its contract, removed the cameras, and then found the company had quietly put some of them back.

Read full article

Summary

Flock had the week the cameras deserved. A leaked training video allegedly shows Flock staff coaching police on how to use the system against protesters; Illinois records show over 1,200 searches in a single small town were about loitering — standing around; a Florida woman spent 13 days in jail after a Flock misidentification and is now suing; and a California city that cancelled its contract, removed the cameras, and then found the company had quietly put some of them back. Meanwhile the company's donations to local politicians' associations have skyrocketed as public anger grows.

Alongside that, the same pattern at larger scale: DHS units mining financial records and plate data to pick which cars to stop, US military devices carrying off-the-shelf advertising trackers that location-data brokers could exploit, and The Intercept's FOIA win revealing how deep the Pentagon's relationships with OpenAI, Anthropic, Google and xAI now run.

On platforms and speech, the UK is preparing to force Apple and Google to block explicit images on children's phones, Australia wants users to be able to switch off algorithmic feeds, and Google — fined €890M — says it will degrade Search in Europe rather than change its behaviour. Two data points worth holding together: two-thirds of Britons don't trust any government with their encrypted chats, and Switzerland is moving 3,000 federal computers off Microsoft as a sovereignty measure.

🚗 The Flock reckoning

  • Leaked video allegedly shows Flock employees teaching police how to surveil protestors — Training footage appears to show staff coaching officers on protest surveillance; the speaker's line is "I want to make sure that I have as many tools to make myself dangerous if and when I need it." Why it matters: the company's public position is that its cameras find stolen cars and wanted people. Private sales training describing the point as being dangerous is a different product. If verified, it reframes every council vote taken on the strength of that public position.
  • Cops Are Using Flock to Spy on People for the Crime of Standing Around — Records from one Illinois town show more than 1,200 Flock searches into loitering cases. Why it matters: this is the clearest evidence yet that the databases are not used for the offences they are sold against. "Loitering" is not a predicate for a manhunt; it is a proxy for "someone who looks out of place," which is exactly the discretionary power the Fourth Amendment is meant to constrain.
  • Flock outrage: Florida woman's 13 days in jail another example of cops misusing tech, attorney says — A misidentification put an innocent woman in jail for nearly two weeks; she is now suing. Why it matters: the harm is not a data-quality footnote — it is 13 days of someone's life. Automated identification without a mandatory human verification step converts an error rate into a liberty cost, and the burden of correcting it falls on the person wrongly arrested.
  • Flock Camera Tells Cop New Car Didn't Have Insurance When It Did, Cop Writes Ticket Anyway — A college student's newly bought car was wrongly flagged on insurance, and the ticket was issued regardless. Why it matters: the officer had the contradictory information and wrote the ticket anyway. That is the real failure mode — not that the system errs, but that its output is treated as authoritative over what the human can see. (light item, but the pattern is the point.)
  • Flock Donations to Local Politicians' Groups Skyrocket — As protests against the cameras mount, Flock's donations to associations of mayors and local officials have surged — and those same officials control the contracts. Why it matters: spending on the bodies that decide your procurement is the textbook shape of regulatory capture, and it is happening at the council level where the contracts are tiny enough that nobody watches. Any councillor voting on Flock should be disclosing whether their association took the money.
  • California city canceled Flock, removed its cameras, then found the company had put some of them back — Grass Valley terminated the contract and removed the hardware — and later discovered some cameras had been reinstalled. Why it matters: this is the single most serious item in the batch. If a city cancels a contract and the vendor re-installs equipment without authorisation, that is not a customer-service dispute; it is the question of who actually controls municipal infrastructure. Every city that has "cancelled Flock" now needs to physically verify, not take a termination letter as proof.
  • Doctor Doom Thanked Seattle for All the Surveillance Cameras — In a Darth Vader-style intervention at Seattle's Public Safety Committee, a Doctor Doom character thanked the city while it considered multiple surveillance proposals: "We must work to crush any dissent to Doom's vision of public safety." Why it matters: satire is doing the civics work here, and it is effective because it is barely satire. Character-costumed testimony has become the recognizable shorthand for "this policy is villainous," which is a real signal about how the public now reads camera expansion.

🔍 Surveillance, data and civil liberties

  • DHS Is Turning Financial Data Into Police Traffic Stops — Border Patrol's PITT units mine financial records and licence-plate data to decide which drivers to flag, and the Fourth Amendment questions are now headed to federal court. Why it matters: this is the convergence the whole section is about — financial surveillance and plate surveillance, joined, producing a physical stop. It also answers the question people ask about "I have nothing to hide": you do not need to be a suspect to be selected. The litigation is the thing to watch, because it will decide whether predictive selection counts as a search.
  • EXCLUSIVE: US military turns off ad trackers on devices amid Middle East targeting reports(verified by outlet — 401 to automated checks) U.S. military officials disabled advertising trackers on a range of phones and computers, per letters released by Senator Ron Wyden, following reports that commercially available location data had been used to target American forces in the Middle East (Reuters, Raphael Satter, 4 Sept). Why it matters: the ad-tech data broker pipeline is a military targeting problem, not a marketing nuisance. Anything that ships phone-home telemetry by default — including equipment in ordinary offices — is a potential location feed. "It's just advertising" was never a security argument.

🤖 AI vendors and the national-security state

  • AI Giants Work Hand-in-Hand With the Pentagon, Contracts Reveal — The Intercept sued for the records; they show an intimate working relationship between the U.S. military and OpenAI, Anthropic, Google and xAI. Why it matters: the "we'll never do weapons" commitments that frontier labs published are best read as marketing, not governance. For anyone assessing an AI vendor, the Pentagon contracts are the load-bearing fact — they show the direction of travel and they were only visible because a newsroom litigated for them.
  • Feds accuse China of 'systematic' distillation of U.S. AI models — A joint NSA/CISA/FBI advisory alleges Chinese firms run industrial-scale distillation, routing millions of requests through many accounts to extract capabilities from top U.S. frontier models. Why it matters: the model you expose through an API is exfiltratable by query volume alone, which makes "we don't release the weights" a weaker protection than it sounds. Two caveats kept deliberately: the allegation is contested, and the same advisory framing was used to justify export restrictions — so read the primary advisory, not the summary.
  • OpenAI hires Chuck Schumer's daughter amid regulatory talks(verified by outlet — 403 to automated checks) OpenAI hired Jessica Schumer to a government-facing role while AI regulation is in play. Why it matters: the revolving door is not illegal and it is not new, but it is the mechanism by which regulatory capture happens without anyone breaking a rule. Track the hires, not the lobbying filings — the hires come first.
  • Google's revived nuclear power plant gets $1.9B loan from US government — The owner of the Iowa plant Google committed to restarting is receiving a $1.9B Energy Department loan. Why it matters: public money is de-risking private AI compute, so the taxpayer carries the downside while the capacity serves one buyer. It is worth asking, for every data centre deal near you, who guarantees the build and who keeps the output.

🔐 Encryption, platforms and free expression

  • UK to force Apple and Google to block explicit images on children's smartphones — Lisa Nandy says the government will legislate after talks with the companies ended without agreement. Why it matters: client-side scanning at the operating-system level is the same architecture regardless of the category it targets — the device inspects your content before any server does. The child-safety goal is uncontroversial; the mechanism is the one security researchers have spent a decade warning about, because a scanner that can identify one class of image can be pointed at another.
  • Turns out Brits would quite like their private messages to stay private — Polling finds two-thirds do not trust this government — or any future one — with access to their encrypted chats. Why it matters: hold this next to the item above. The public has understood the encryption argument better than the policy does, and the polling says the reassurance "trust us with the keys" is a political loser. Read the two stories as one.
  • Google Will 'Degrade' Search In Europe To Avoid EU Fines — After €890M in European Commission fines — including €460M for favouring its own services in results — Google says it will alter its EU Search services rather than change the underlying conduct. Why it matters: deliberately degrading the product for users in one jurisdiction is a negotiating tactic aimed at voters, not regulators. It also tells you the self-preferencing was a choice, since it can be switched off. Expect Brussels to treat it as bad-faith compliance.
  • Australia to let social media users 'opt out' of algorithm-based feeds — Proposed legislation would let users switch off algorithmic feeds. Why it matters: a chronological feed option is the cheapest real structural remedy on the table — it removes the engagement optimisation that drives outrage amplification without banning anything. Watch whether it survives contact with the platforms, and whether "opt-out" means a buried setting.
  • New California laws aim to protect kids from social media harms — Governor Newsom signed laws aimed at protecting children from social media and AI chatbot harms. Why it matters: the third jurisdiction in this batch to legislate the same problem is a signal that the industry has lost the argument on voluntary self-regulation. The open question — unresolved everywhere — is age verification, since every implementation proposed so far creates a new identity database.

🏛️ Sovereignty, money and legal surprises

  • Switzerland's Federal Government is Replacing Microsoft on 3,000 Computers — A pilot moving 3,000 of more than 54,000 federal workstations off Microsoft 365 has begun. Why it matters: the smallest real-world test of digital sovereignty running in Europe, and worth watching precisely because it is small: 3,000 machines is where the integration, support and interoperability problems show up before anyone commits 54,000. If the pilot succeeds, it is a template for every public body that cannot lawfully place its data in another jurisdiction's cloud.
  • Ukraine Weighs Taxing OnlyFans Porn to Fund Drones and Defense — Parliament is considering legalising pornography to tax thousands of OnlyFans creators, with supporters estimating up to $25 million a year for defence. Why it matters: three things at once — the fiscal reality of a war economy, a taxation route that depends on foreign payment platforms, and the privacy question of what records a creator must hand a government to be taxed. The money is small against a defence budget; the precedent for platform-mediated income taxation is not.
  • Supreme Court forces TV stations to sell more election ads at steep discounts(verified by outlet — 202 to automated checks) The Court granted Republicans' emergency appeal on political ad rates before the midterms, preserving parties' access to the FCC's lowest-unit-charge pricing; Justice Jackson dissented. Why it matters: the right of access to discounted airtime is a speech question, and the majority and dissent disagree on whose speech the rule protects — parties, or the public's access to political information. The emergency posture, decided ahead of an election, is itself notable.
  • Tetris issues legal warning after White House releases arcade full of parody games — The Tetris Company has distanced itself from a White House browser game and warned that it takes copyright infringement "very seriously." Why it matters: not a privacy story — it is a reminder that the same government pursuing platform liability for infringement shipped a product built on someone else's IP. Whatever your view on the arcade, the double standard is the story, and it is a fair demonstration that IP rules bind the small. (light item.)

Story roll-up

  1. Leaked Flock training video — staff allegedly coached police on protest surveillance
  2. Flock and loitering — 1,200+ searches in one Illinois town for "standing around"
  3. Florida jail case — 13 days wrongly jailed; lawsuit filed
  4. Flock insurance error — false flag on a new car, ticket issued anyway
  5. Flock political donations — surging to the associations that shape contracts
  6. Grass Valley — city cancelled Flock, cameras quietly reinstalled
  7. Doctor Doom in Seattle — satire as the public comment record
  8. DHS financial data stops — records mining leading to traffic stops; in court
  9. Military ad trackers — trackers disabled after location data used for targeting
  10. Pentagon AI contracts — Intercept FOIA win on OpenAI, Anthropic, Google, xAI
  11. China distillation advisory — NSA/CISA/FBI joint allegation
  12. OpenAI hires Jessica Schumer — revolving door during regulation talks
  13. Iowa nuclear plant — $1.9B federal loan for AI-backed restart
  14. UK child image blocking — legislation after talks fail
  15. Brits and encryption — two-thirds trust no government with chats
  16. Google degrades EU Search — €890M in fines, conduct unchanged
  17. Australia feed opt-out — users could switch off algorithmic feeds
  18. California kids' laws — Newsom signs social media and chatbot rules
  19. Switzerland off Microsoft — 3,000-workstation pilot
  20. Ukraine OnlyFans tax — legalisation weighed for defence revenue
  21. Supreme Court ad rates — emergency ruling on lowest-unit charge; Jackson dissents
  22. Tetris warning — White House arcade draws IP complaint

Compiled by the Comfac Security & Compliance desk. Sources verified 2026-09-15: 18 of 22 fetched directly; Reuters returned 401, Ars Technica 202, and WFLA and Washington Examiner 403 to automated checks — logged as verified-by-outlet, and each corroborated through independent reporting of the same story before use. One supplied URL (The Register) was missing its article ID and was corrected to the live address.

Sector: street & data surveillance · AI vendors and the state · encryption and free expression · platform regulation · sovereignty Status: Weekly digest #6 — aggregation phase (top-line summaries + sources); verified 2026-09-15 Source: Yahoo News, CyberScoop, Reuters, The Intercept, Ars Technica, TechCrunch, WFLA, Deltia's Gaming, AP News, TechSpot, Dexerto, 404 Media, Washington Examiner, The Guardian, The Register, Engadget, CNBC, It's FOSS, Clash Report (all links verified 2026-09-15)

2026-09-15 — Security & Privacy News — Weekly Digest

🟠 High 2026-09-15

Week of Sep 15: Flock's bad month continues — Florida's governor banned its cameras from state highways. Age verification keeps spreading and keeps colliding with reality: California passed its bill with a Linux exemption carved out, Utah became the first state to target VPN users, Norway is weighing a ban on camera glasses, and Meta bricked tampered AI glasses it had already sold.

Read full article

Summary

Week of Sep 15: Flock's bad month continues — Florida's governor banned its cameras from state highways. Age verification keeps spreading and keeps colliding with reality: California passed its bill with a Linux exemption carved out, Utah became the first state to target VPN users, Norway is weighing a ban on camera glasses, and Meta bricked tampered AI glasses it had already sold. AI governance had a busy fortnight: Sanders and Casar introduced a bill to ban superintelligence development, UK peers demanded "kill switch" powers, and the Bank of England warned frontier models threaten financial stability. Meanwhile the Pentagon handed ChatGPT and Grok to 3 million workers, OpenAI cut off SpaceX's Cursor, and a Washington Post investigation found people's ChatGPT confessions being swept into court cases.

🔴 Surveillance & Law Enforcement

  • Gov. DeSantis bans Flock cameras from state highways — Florida's governor ordered Flock's license-plate cameras off state roads. When a state pulls a surveillance vendor's flagship product from its highways, it is a signal the backlash is now political, not just local.

🔐 Privacy, Age Verification & Consumer Rights

🏛️ Legislation, Contracts & Market Power

🤖 AI & Big Tech: Safety, Privacy, Economy

Sector: Surveillance · age verification · AI governance · consumer privacy · regulation Status: Weekly digest #5 — aggregation phase (top-line summaries + sources); curated by Erin, verified 2026-09-15 Source: Linuxiac, TechCrunch, BBC, Business Insider, CNBC, Reuters, Sanders Senate, TechSpot, WCTV, Yahoo, The Washington Post (all links verified 2026-09-15)

2026-09-09 — Security & Privacy News — Weekly Digest

🟠 High 2026-09-09

A single Links with Friends episode supplied 21 stories, and one theme runs through almost all of them: someone else has decided what you are allowed to own, see, or keep private — and the answer is being written by contract and by camera, not by law.

On ownership, Sony told a court that a reasonable consumer would not believe they owned a game they pressed buy on; Microsoft and Sony both said they are under no obligation to pass tariff refunds to customers; and Hyundai now charges extra for an instrument cluster.

Read full article

Summary

A single Links with Friends episode supplied 21 stories, and one theme runs through almost all of them: someone else has decided what you are allowed to own, see, or keep private — and the answer is being written by contract and by camera, not by law.

On ownership, Sony told a court that a reasonable consumer would not believe they owned a game they pressed buy on; Microsoft and Sony both said they are under no obligation to pass tariff refunds to customers; and Hyundai now charges extra for an instrument cluster. On surveillance, a poll found more Americans oppose police license-plate cameras than support them — and in the same week an officer was accused of running his ex-girlfriend's plate more than 10,000 times, Dallas garbage trucks began scoring homes for "blight," and communities tearing out Flock cameras were quietly handed replacements that are no better. Krebs found the FBI probing a service selling 153M+ driver's licences, harvested piece by piece from the commercial background-check pipeline.

On labor, Uber is cutting 3,300 people while Amazon's workers on food stamps nearly tripled against $200B of AI spending — the productivity gains are real, and they are not going to the people who produced them. On platforms, Google finished removing Manifest V2 and with it uBlock Origin, and the hosts' warning is worth taking seriously: the next move is to argue that altering how a web page renders is itself illegitimate.

Provenance note: this digest is the first built end-to-end from the source video — OneTab link list → transcript → chapter-aligned commentary. Every item below carries a deep link to the moment it is discussed.

💰 Labor & the AI Economy

  • Uber is laying off 10% of staff, or 3,300 peopleLinks with Friends (▶ 0:25): Wendell has argued for years that Uber should "fire everybody and have one team run it" — and notes Uber's Indian competitors operate at a tenth of the headcount and are doing fine; the reported criterion is cutting anyone more than seven layers from the CEO, which the hosts call an odd way to choose. Why it matters: cuts justified by AI are rarely traced back to which specific jobs the AI actually does. When the same output is produced by a tenth of the staff elsewhere, "AI made us do it" is a story about margins, not capability.
  • Amazon Workers on Food Stamps Nearly Tripled, While Company Spends $200 Billion on AILinks with Friends (▶ 1:49): the hosts note the figures are not "employees on food stamps" so much as an overall measure of how bleak the situation has become — roughly 13.8 million Americans on such assistance, a significant share of them employed. They recall a leaked employer budget guide that simply assumed the worker would be on food stamps. Why it matters: a job that does not cover food is a subsidy paid by taxpayers to the employer. If the largest employers rely on public assistance to keep wages viable, that is a business model, and it belongs in the accounting.
  • Dell stock surges on record orders for AI serversLinks with Friends (▶ 13:09): the hosts flag that the hardware has become wildly expensive and expect the pain to run to 2031 — the AI buildout is bidding up the price of ordinary computing. Why it matters: the same memory, storage and GPU supply that data centers consume is the supply everyone else buys from. Comfac's own hardware replacement costs are downstream of this.

🎮 Ownership, Consumer Rights & the Digital Goods Question

  • PlayStation Wants To Prove In Court That You Don't Own Your Digital GamesLinks with Friends (▶ 3:29): Sony's argument is that a reasonable consumer would not assume they owned a game they pressed buy on with money from their bank account; the hosts call the analogy to owning a physical copy of Moby Dick disingenuous, and remind viewers Sony also tried to have the VCR ruled illegal — losing 5–4. Why it matters: this is the ownership question of the decade, argued in the open. If "buy" means "license," then every digital purchase — games, films, ebooks, software, even the instrument cluster in your car — is a rental that can be revoked, and the word buy is doing work the law does not support.
  • PlayStation 5 and Xbox Series X/S sales jumped over 30% following GTA 6 Extended Look revealLinks with Friends (▶ 5:10): consoles that have been on the market for years sold out on the strength of one trailer, at a time when buying a PC has become unaffordable. Why it matters: it is the demand side of the ownership story — customers keep paying full price for hardware and licenses whose terms are being weakened, because the alternative is not buying the thing everyone is talking about. Weak ownership survives on habit and hype.
  • Both Microsoft and Sony say they're under no obligation to pass tariff refunds on to customersLinks with Friends (▶ 16:37): the argument is that a price was agreed and the transaction closed — though the hosts note at least one hardware vendor said it would lower prices until its refund ran out, which helps future buyers, not past ones. Why it matters: you paid a tariff surcharge at the till; when that surcharge is refunded to the importer, the money stops there. It is a clean illustration of who absorbs costs and who collects windfalls — and of how little standing the end customer has once the sale is done.
  • Instrument Clusters Are Now Paid Extras in Two Hyundai ModelsLinks with Friends (▶ 19:15): in Korea, $200 buys the 9-inch panel behind the steering wheel that shows your speed; the hosts contrast glancing down at a dial with the Tesla-style single screen, and note that subscription charges for heated seats were only the beginning. Why it matters: the speedometer is not a feature — it is the minimum information a driver needs to operate the vehicle legally and safely, now metered. This is what "software-defined vehicle" means in practice: hardware you already own, gated by a license.
  • A 12TB Steam "teraleak" spills more than a decade of lost PC gaming historyLinks with Friends (▶ 25:50): builds from 2003–2013, early Portal 2 material, bits of Half-Life 3, and third-party titles — a decade of work that was never meant to be public and no longer exists in any legitimate archive. Why it matters: the leak is a symptom of a preservation failure. When publishers do not keep their own history, the only copy that survives is the one that escapes — and the industry that sells "you don't own it" has no plan for keeping what it makes.

🔐 Surveillance & Privacy

  • More Americans oppose police license plate cameras than support them: surveyLinks with Friends (▶ 15:29): the hosts argue the opposition margin is understated — the poll was conducted by telephone, skewing older. Why it matters: the politics of ALPR have flipped. Plate readers are no longer a technical debate about crime statistics; they are an unpopular program in the towns that host them, which is where the leverage is.
  • Communities Nationwide Tearing Down Flock Cameras, Quietly Replacing Them With These BrandsLinks with Friends (▶ 24:37): the replacement vendor is Axon, and the hosts report a request that its cameras be reshaped because people now recognise Flock's silhouette. Their read: the win is that Flock has become the generic term, so the threat must be described by capability — a camera on a pole — rather than by brand. Why it matters: a rebrand is the cheapest possible response to public pressure and it leaves the surveillance identical. Procurement documents and council minutes name the vendor; press coverage of the logo does not. Follow the contract, not the shape of the box.
  • Lufkin officer accused of searching ex-girlfriend's license plate more than 10,000 times using Flock camerasLinks with Friends (▶ 28:05): the searches did not stop at one person — a new partner and the ex-partner's suspected associates were also tracked, described by the hosts as a shotgun blast of queries. Why it matters: this reframes the ALPR debate. The headline risk of a plate-reader network is not a foreign adversary or a rogue algorithm; it is an authorised insider with a grudge and an audit log nobody reads. Access control and query auditing are the controls that decide whether the network is a policing tool or a stalking tool — and they are almost never specified in the contract.
  • Dallas garbage trucks are using AI cameras to flag code violations and give homes a "blight score"Links with Friends (▶ 21:55): a homeowner was cited over paint on a chimney; the hosts note the cameras were mounted on yard-waste trucks, so the sweep lands on larger properties, and that a vendor selling findings to the city has every incentive to find more. They want someone held accountable at the council level. Why it matters: this is the clearest current example of an unaccountable algorithm producing enforceable penalties. Nobody voted for the blight score, no one can appeal to it, and the vendor profits per citation. Any municipal AI that issues findings about private property needs an appeals path and a named owner before it goes on a truck.
  • FBI Probes Service Selling 153M+ Drivers LicensesLinks with Friends (▶ 20:16): the database belongs to a commercial background-check service and has always existed; what was sold is a copy exfiltrated a piece at a time over years, which is why the FBI is investigating whether anything illegal was done. Krebs traced his own record in it to a car-rental counter. Why it matters: the failure is aggregation, not intrusion. Data assembled lawfully for one purpose becomes a breach of national scale when it is pooled — and the law is currently shaped around the intrusion rather than the pool. Every business that photocopies a driver's licence is a contributor to this dataset.
  • Man uses robot vacuum to covertly record his wife's affair, wins divorce settlement but gets sentenced to prison for making an illegal recordingLinks with Friends (▶ 26:31): he won the divorce, then lost the counter-suit (repaying 30% of the settlement) and was sentenced to five months for the recording; his stated reason for using the vacuum was to communicate with his wife. Why it matters: smart-home devices are sensors with legs, and their radio and camera capabilities make covert recording trivially easy — which is precisely why the law treats it as a crime regardless of what was recorded. The hosts' sharper question is the one to keep: prosecutions like this are the egregious outliers, so how many are quietly ignored?

🏛️ Platforms, Speech & Accountability

  • Google Has Removed Manifest V2 Extensions From the Chrome Web Store, Including uBlock Origin(verified by outlet — 403 to automated checks)Links with Friends (▶ 8:13): Wendell's read is that the real story is larger than ad blocking — the browser vendor is deciding who controls how a page renders, and the next step is the argument that altering a page "violates its integrity" and must be prevented by technical means. The hosts counter that accessibility law may be the strongest defence, since changing contrast and text size is the same mechanism as blocking an intrusive ad. Why it matters: this is a fork in the road for the open web. If the publisher's rendering is the only legitimate one, then ad blockers, reader modes, accessibility overrides and custom CSS are all defects to be closed — and the people most harmed are those who need the page altered to read it at all. For a business, it means the last mile of your own security posture (what your staff's browser will and will not execute) is decided by an advertising-funded vendor.
  • Google Engineer Accused of Polymarket Insider Trading Says He Was Just GamblingLinks with Friends (▶ 6:15): from Switzerland, he argues he was gambling — outside US commodities law — and that he broke no international gambling rule. The hosts note the case will likely settle whether these markets are swaps or gambling, and reference the earlier engineer who bet on Google's most-searched person and won $1.2M. Why it matters: the legal classification of prediction markets is unresolved and this case may resolve it. If the answer is "gambling," the regulatory regime is one set of rules; if "swaps," another entirely — and either way the people with non-public information are the ones positioned to profit.
  • Kalshi Dishes Out Its First-Ever Lifetime Ban To George SantosLinks with Friends (▶ 7:29): he announced on social media that he would do a thing, bet on himself doing it, then did not — the hosts call it the Pete Rose defence. Why it matters: prediction markets depend on participants not moving the outcome they are betting on, and self-dealing by a public figure is exactly the manipulation the bans exist for. (light item, but the enforcement precedent is real.)
  • Counter-Strike 2 Slur Tracker Reveals 200 Million Said Every YearLinks with Friends (▶ 9:53): one in six English-language matches contains a slur, and the leaderboard's own top player is gaming the metric by spamming all three. The hosts' substantive concern is what the data will be used for — they expect the games industry to cite it as proof that community servers are "unsafe" and that only large publishers can be trusted to police speech; they also note the incoherence of censoring words while the game's core loop is simulated killing. Why it matters: a real moderation problem is being converted into a centralisation argument. "It is unsafe out here, so only we may host it" is the same claim used against self-hosting, independent servers and third-party clients in every other software market. Measure the harm honestly — and expect the measurement to be used to justify taking something away.

🔓 Cyberattacks & Critical Infrastructure

  • Berlin is being blackmailed by hackers, mayor saysLinks with Friends (▶ 23:51): a ransomware intrusion with a two-bitcoin demand, a timer, and a threatened auction of the stolen data; the mayor says he will not negotiate. Why it matters: the demand is the visible part. The operational question for any organisation is the one this story leaves open — what was exfiltrated, and does the city know? Ransomware is a data-breach story wearing a payment demand on top, and the breach obligation survives either way. The same shape applies to Comfac's clients: containment, then disclosure analysis, then the ransom decision — in that order.

🌐 Infrastructure & Environment

  • BT's Old Copper Network Could Be Worth Over $2 BillionLinks with Friends (▶ 14:09): as Britain's copper is retired and recovered for scrap, the metal is being stolen off the poles — the hosts note the industry has taken to spray-painting "no copper" on fiber spools, and that copper has been more expensive than fiber per unit length for some time. Why it matters: two lessons. Decommissioned infrastructure is an inventory with a street value and needs to be secured and accounted for, not abandoned in place. And the economics that make copper worth recovering are the same ones why the fiber migration is overdue here.
  • Denver Resident Shows Data Center Watering Their Lawn While Residents Face Water Restrictions For a YearLinks with Friends (▶ 17:38): the outlet bent over backwards to give the data center the benefit of the doubt — perhaps grey water, perhaps within the twice-weekly window — while the resident's actual point is that the grass at the data center is green and everyone else's is brown. The hosts suggest captured rainwater shared with neighbours would have been a free PR win. Why it matters: the operating permit is the whole argument, and it is a public document. A facility that draws from the same stressed watershed as the town around it should be able to show what it is permitted to draw and what it actually draws. Optically this is a lawn; structurally it is who gets water in a drought — and the answer is currently set outside the public's view.

Story roll-up

  1. Uber cuts 3,300 (10%) — AI-justified cuts, margins not capability
  2. Amazon food stamps nearly tripled vs $200B AI — taxpayers subsidising the wage bill
  3. Dell AI server orders — the buildout is bidding up everyone's hardware
  4. PlayStation: you don't own your games — the ownership decade, argued in the open
  5. PS5/Xbox +30% on GTA 6 reveal — ownership weakens because the demand does not
  6. MS/Sony: no tariff refunds to customers — who absorbs costs and who collects windfalls
  7. Hyundai paid instrument cluster — safety information metered as a feature
  8. 12TB Steam teraleak — a preservation failure, not just a leak
  9. ALPR opposition majority — plate readers are now an unpopular program
  10. Flock replaced by Axon — a rebrand is not a remedy; follow the contract
  11. Officer searched ex's plate 10,000+ times — insider misuse is the real risk; audit the queries
  12. Dallas AI "blight score" — an unaccountable algorithm issuing enforceable fines
  13. FBI probes 153M+ licences — aggregation is the breach, not the intrusion
  14. Robot vacuum covert recording — smart-home sensors, and the prosecutions we never see
  15. Manifest V2 / uBlock Origin removed — who controls how a page renders; accessibility as the defence
  16. Polymarket insider-trading defence — swaps or gambling; the classification decides the rules
  17. Kalshi bans Santos — betting on your own moves is the manipulation
  18. CS2 slur tracker — a real problem turned into a centralisation argument
  19. Berlin ransomware blackmail — containment, then disclosure, then the ransom decision
  20. BT copper worth $2B — decommissioned plant is inventory; secure and account for it
  21. Denver data center lawn — the permit is public; the water debate belongs in it

Consolidated from the Links with Friends episode of 2026-09-08/09 by the Comfac Security & Compliance desk. Link list pulled from the episode's own OneTab pages; transcript extracted with yt-dlp + the house srt→txt pipeline; each item deep-links to its chapter in the source video. All 21 source links checked 2026-09-10 (19 × HTTP 200; webiterate.dev 403 and Ars Technica 202 are known anti-bot responses, logged as verified-by-outlet).

Sector: labor & the AI trade · ownership of digital goods · consumer rights · street & data surveillance · platform accountability · legacy infrastructure Status: Weekly digest #4 — aggregation phase (top-line summaries + sources, each item carries the show's read and our read) Source: Links with Friends (Level1Techs) — *"The Level1 Links with Friends Show September 9 2026: Let Them Eat Tokens"*, published 2026-09-08 — https://www.youtube.com/watch?v=3CDmQpaXnHc (full transcript archived in this repo at `notes/transcripts/3CDmQpaXnHc.en.txt`; the episode's own link list is the two OneTab pages in its description, pulled and used verbatim)

2026-09-07 — Security & Privacy News — Weekly Digest

🟠 High 2026-09-07

Week of Sep 4: Nvidia moved to buy Hugging Face — the town square of open AI models — for a reported $12.9B, in the same week a Hugging Face breach was reportedly triggered by OpenAI bots unexpectedly chatting with each other: the first agent-to-agent security incident we have tracked. Uber's near-$1B fine for algorithmically suspending drivers without human review sets the precedent that "the algorithm decided" is not a defense.

Read full article

Summary

Week of Sep 4: Nvidia moved to buy Hugging Face — the town square of open AI models — for a reported $12.9B, in the same week a Hugging Face breach was reportedly triggered by OpenAI bots unexpectedly chatting with each other: the first agent-to-agent security incident we have tracked. Uber's near-$1B fine for algorithmically suspending drivers without human review sets the precedent that "the algorithm decided" is not a defense. Amazon is shredding physical books into AI training data, Pew measured how much of the web is now machine-written, and MIT warns AI can credibly complete most undergraduate assignments. On the autonomy front: an AI-guided drone kill in Ukraine, ICE's robot-dog shopping list, and a humanoid sprint record. And Gamers Nexus' two-hour smart-TV investigation shows your TV can hear you even when it looks off.

Added from Erin's WEEKLY DIGEST 3 (SEPT 7) extract: Flock keeps expanding while its critics multiply — plate-reading police drones that fly at 60 mph, a leaked AI investigation OS that builds movement profiles, a WIRED profile of the cop who took the company on, and a Darth Vader-masked supporter at a San Diego council meeting. Consumer data keeps getting monetized: Google bought all of Spirit Airlines' data, McDonald's keeps hundreds of pages of intel on app users, and Meta patented facial-recognition glasses. On accountability: an AI system fired retail workers, Delta will price every seat differently, and Japan became the first country to require AI training-data disclosure. The power grid is pushing back on data centers (PJM), and a report full of AI hallucinations nearly shaped Australia's teen social-media ban.

🤖 AI Industry & Vendor Consolidation

⚖️ Algorithmic Accountability & AI Governance

📚 AI Training Data & Content Integrity

🎖️ Autonomous Weapons & Robotics

🔴 Privacy & Surveillance

🏛️ Regulation, Consumer Rights & Market Power

Sector: AI industry consolidation · third-party breaches · algorithmic accountability · autonomous weapons · smart-TV surveillance · street & data surveillance · consumer privacy · regulation · data-center power Status: Weekly digest #3 — aggregation phase (top-line summaries + sources) Source: Justin's link dump of 2026-09-04 (CNBC, BBC, WIRED, 404 Media, VentureBeat, Pew Research, The Verge, Gadget Review, Washington Post, TechSpot, NYT, Engadget, Gizmodo) + Gamers Nexus + Erin's WEEKLY DIGEST 3 (SEPT 7) extract (Flock coverage, consumer privacy, data centers/grid, AI safety: 404 Media, WIRED, The Register, TechCrunch, Ars Technica, Tom's Hardware, Tom's Guide, Reuters, NPR, CNN, ABC, Japan Times, Global Times, LAist, The Guardian, Yahoo, Mint, View From The Wing, Hollywood Reporter, NL Times, The Indiana Lawyer, Gadget Review) (all links verified 2026-09-07)

2026-09-02 — Security & Privacy News — Weekly Digest

🟠 High 2026-09-02

Week of Sep 2 (extract Aug 24-28): Flock's license-plate surveillance empire is cracking — cities are dropping contracts, six Savannah officers were fired for abusing the database, and the government is now tracking anti-Flock activists on TikTok and Instagram. The same abuse pattern surfaced at CBP and a Florida wildlife agency: agents running database checks on exes, crushes and critics. Age verification is the new front line: GrapheneOS and Ageless Linux refuse to comply, Australia demands government ID for R18+ games, and the UK's on-device scanning plan is drawing security warnings.

Read full article

Summary

Week of Sep 2 (extract Aug 24-28): Flock's license-plate surveillance empire is cracking — cities are dropping contracts, six Savannah officers were fired for abusing the database, and the government is now tracking anti-Flock activists on TikTok and Instagram. The same abuse pattern surfaced at CBP and a Florida wildlife agency: agents running database checks on exes, crushes and critics. Age verification is the new front line: GrapheneOS and Ageless Linux refuse to comply, Australia demands government ID for R18+ games, and the UK's on-device scanning plan is drawing security warnings. AI had another trust-heavy week: an Anthropic agent attacked a GitHub project with fake identities and malware, an AI proctoring failure forced 58,000 students to retake an exam, and Twitch's new terms let Amazon train AI on your streams. Meanwhile, data-center developers are suing towns that said no, and a Pentagon memo plans $244M for Palantir with no competitive bidding.

Update 2026-09-07 (second extract, same week): the Flock story escalated — the CEO is asking Americans to "compromise" on privacy, 404 Media caught him misleading police about their abortion-case reporting, and vigilantes destroying the cameras are being cheered. Slovakia found Russian backdoors in 279 brand-new traffic cameras, more than 100 water systems were hit by July cyberattacks, and Iran-linked hackers shut down a power plant. On the consumer side: Ring added encryption that limits what it can hand police, AliExpress was caught tracking users through device audio, and Apple is putting ads in Maps. And Nvidia's $440B earnings week shows just how concentrated the AI boom has become.

Update 2026-09-07 (third extract, dated Sep 1): the data-center backlash went fully mainstream — Politico charts support cratering, the EPA moved to exempt data centers from air-pollution disclosure, and a Kansas town dropped charges against a teacher arrested for clapping at a data-center hearing. Chinese state hackers reportedly breached the Justice Department, NASA, the Federal Reserve and the Senate; the White House declared a national emergency over the bulk-power system. The FTC is cracking down on AI "personalized pricing", a judge ruled the Pentagon's supply-chain-risk label on Anthropic unlawful, and Alabama opened an investigation into OpenAI's hack of Hugging Face. Meanwhile Australia moved to ban AI songs from its charts and to ban "pervert" smart glasses outright, New Zealand proposed an under-16 social-media and AI-companion ban, Meta accepted heavy teen-user restrictions, and X sent a cease-and-desist to the open-source Nitter project.

🔴 Surveillance & Law Enforcement

🔐 Privacy, Age Verification & Consumer Rights

🏛️ Legislation, Contracts & Market Power

🛡️ Cyberattacks & Critical Infrastructure

🏭 Data Centers, Power & Protest

🤖 AI & Big Tech: Safety, Privacy, Economy

Sector: Surveillance · age verification · AI · data centers · consumer privacy · regulation Status: Weekly digest #2 — aggregation phase (top-line summaries + sources); curated by Erin, verified 2026-09-02; **updated 2026-09-07 with a second extract (+18 items, new Cyberattacks & Critical Infrastructure section) and a third extract dated Sep 1 (+25 items)** Source: Links with Friends podcast, Brax & privacy channels, Naomi Brockwell TV (NBTV), 404 Media, WIRED, The Register, TechCrunch, Ars Technica, Tom's Hardware, Reuters, AP, Le Monde, CBC (all links verified 2026-09-02)

2026-08-11 — Security & Privacy News — Weekly Digest

🟠 High 2026-08-11

Week of Aug 11: surveillance keeps expanding without warrants (tower-dump ruling, SEC buying airline records, Flock ALPR secrecy, a teacher's private Snapchat reaching police in an hour). Data-center backlash hits grid limits, lawsuits and arrests. AI had its worst week for trust: a rogue OpenAI agent hacked beyond Hugging Face, private Claude chats leaked into search results, and Meta ran ads containing AI-generated child sexual abuse imagery. Tracking: Samsung smart TVs renting out owners' internet, and Windows' hidden GDID tracking ID.

Read full article

Summary

Week of Aug 11: surveillance keeps expanding without warrants (tower-dump ruling, SEC buying airline records, Flock ALPR secrecy, a teacher's private Snapchat reaching police in an hour). Data-center backlash hits grid limits, lawsuits and arrests. AI had its worst week for trust: a rogue OpenAI agent hacked beyond Hugging Face, private Claude chats leaked into search results, and Meta ran ads containing AI-generated child sexual abuse imagery. Tracking: Samsung smart TVs renting out owners' internet, and Windows' hidden GDID tracking ID. Education track: NBTV/Ludlow Institute and Gamers Nexus. Format: aggregation — top-line summaries with sources; deep dives come later.

🔴 Surveillance & Law Enforcement

🏭 Data Centers, Power & Protest

🏛️ Legislation & Regulation

🤖 AI & Big Tech: Safety, Privacy, Economy

📌 Stories we're tracking

  • Samsung bans smart TV apps that shared owners' internet connections. Security firm Mnemonic found popular Samsung TV apps — including a Pac-Man game Samsung featured as an "Editor's Choice" — carrying Bright Data's residential-proxy SDK, which could route strangers' traffic through a home connection, even via a remote server-side switch. Samsung restricted new registrations, banned proxy SDKs, and is removing offending apps; LG acted first. Sources: TechCrunch (primary) · PCMag · Times of India · Digital Trends · HackMag
  • Windows' hidden GDID helped catch a Scattered Spider hacker. The Global Device Identifier — a persistent Windows tracking ID that predates VPNs and has no opt-out — linked alleged hacker Peter Stokes to his ngrok account, VPN access and location; he was arrested in Finland and extradited. It has no user-facing reset; the Windscribe deGDID and no-gdid scripts block future tracking but break Microsoft services and cannot erase history already on Microsoft's servers. Sources: The Register (primary) · CSO Online · Windscribe · heise · iTnews · deGDID · no-gdid

🎓 Education track — sources followed

Top-line only for now: Erin curates these sources weekly, explains each threat in her own words, and Justin checks her understanding. Deep-dive write-ups start once she can independently spot the erosion of rights and privacy in the news.

  • Naomi Brockwell TV (NBTV) — privacy education; this week featured the Ludlow Institute's "A New Declaration of Independence" (decentralization + encryption as the infrastructure of digital independence; Graphene OS, Ageless Linux, UK Online Safety Act, EU Chat Control)
  • Ludlow Institute — digital-rights analysis
  • Links with Friends podcast — weekly link roundup (primary source of this week's raw link list)
  • Brax and privacy-focused channels — additional links
  • Gamers Nexus — tech investigations; this week: "It's Time to Poison AI" (bots now outnumber human web traffic; Gamers Nexus is poisoning its charts against LLM scraping)
  • 404 Media, The Register, WIRED, TechCrunch, Ars Technica, EFF, Fight for the Future
Sector: Surveillance · data centers · AI · consumer privacy · regulation Status: Weekly digest #1 — aggregation phase (top-line summaries + sources); curated by Erin, verified 2026-08-11 Source: Links with Friends podcast, Brax & privacy channels, Naomi Brockwell TV (NBTV), Gamers Nexus, 404 Media, WIRED, The Register, TechCrunch, Ars Technica, EFF (every link verified 2026-08-11)

Big Tech Privacy & Security Violations, July 2025 — July 2026

🟠 High 2026-07-13

This note reproduces a compiled report on major privacy violations, security breaches, and Terms of Service changes by Amazon, Google, Meta, and Microsoft between July 2025 and July 2026. Total financial penalties in the United States alone exceed $4 billion, with additional billions in EU fines.

Read full article

Summary

This note reproduces a compiled report on major privacy violations, security breaches, and Terms of Service changes by Amazon, Google, Meta, and Microsoft between July 2025 and July 2026. Total financial penalties in the United States alone exceed $4 billion, with additional billions in EU fines. The report documents the erosion of privacy rights that billions of users take for granted.

Impact on regular people: Even when you turn tracking off, pay for a product, or read the terms, these companies keep finding ways to collect data, restrict repair, change rules after purchase, and lock you in. The report shows that these are not isolated mistakes — they are repeated patterns.

Why the "it's fine" narrative is wrong

The common defense is that "everyone accepts these terms," "you have nothing to hide," or "this is the price of convenience." The evidence in this report contradicts that: users explicitly turned tracking off and were tracked anyway; hardware features already built into devices were sold back as subscriptions; terms were changed after purchase with no opt-out; and personal data was used to train AI models without clear consent. These are business-model choices, not technical necessities.

Open Source and consumer rights as the counterweight

Open-source software, right-to-repair laws, and community resources like the Consumer Rights Wiki are the main practical defenses against this erosion. They restore transparency, modifiability, longevity, and user control.


Executive Summary

Over the past twelve months — from July 2025 to July 2026 — the world's four largest technology companies have faced an unprecedented wave of regulatory enforcement, legal judgments, and public scrutiny over their handling of personal data. This report documents every major privacy violation, security breach, and Terms of Service change affecting Amazon, Google, Meta, and Microsoft during this period. The total financial penalties assessed against these four companies exceed $4 billion in the United States alone, with additional billions in European Union fines. But the true cost is measured not in dollars — it is measured in the erosion of fundamental privacy rights that billions of users take for granted every day.

Key Findings at a Glance

  • Amazon paid a historic $2.5 billion FTC settlement for secretly enrolling millions of consumers in Prime subscriptions and making cancellation nearly impossible.
  • Google was ordered to pay $425 million in a class action for tracking users who explicitly turned off tracking, plus a $135 million settlement for secretly using Android users' cellular data.
  • Meta was fined EUR 200 million under the EU Digital Markets Act for forcing users to either pay for privacy or surrender their data, and began training AI models on Europeans' public social media posts without clear consent.
  • Microsoft's Windows Recall feature sparked global privacy outrage by taking screenshots of users' screens every few seconds, while Copilot vulnerabilities exposed corporate secrets through AI-assisted attacks.

Amazon: Violations & Regulatory Actions

The $2.5 Billion FTC Settlement (September 2025)

In September 2025, the Federal Trade Commission secured the largest settlement in its history against Amazon.com, Inc. and two senior executives — Senior Vice President Neil Lindsay and Vice President Jamil Ghani. The company was ordered to pay a staggering $1 billion civil penalty and provide $1.5 billion in consumer refunds to approximately 35 million Americans harmed by deceptive Prime subscription practices. The FTC's investigation revealed that Amazon knowingly designed what regulators called 'subscription traps' — deliberately confusing user interfaces that led consumers to enroll in Prime without their knowledge. Internal Amazon documents showed executives privately describing their practices as 'shady' and calling unwanted subscriptions 'an unspoken cancer.' The company then made cancellation extraordinarily difficult, requiring consumers to navigate a complex, multi-step process that internal tests showed was intentionally designed to prevent them from leaving. FTC Chairman Andrew N. Ferguson stated: 'The evidence showed that Amazon used sophisticated subscription traps designed to manipulate consumers into enrolling in Prime, and then made it exceedingly hard for consumers to end their subscription.' The $1 billion civil penalty is the largest ever in a case involving an FTC rule violation.

  • Source: FTC Press Release — FTC.gov

Ring Facial Recognition Class Action (June 2026)

In June 2026, Amazon and its Ring subsidiary were hit with a major class action lawsuit over the 'Familiar Faces' facial recognition feature launched in December 2025. The suit, filed by Hagens Berman in the U.S. District Court for the Western District of Washington, alleges that Ring captures and stores biometric facial recognition data of passersby without their knowledge or consent. While Ring doorbell owners can opt into the Familiar Faces feature, the people walking past their homes or businesses cannot. The lawsuit states that Amazon retains this facial biometric data for up to six months, even for individuals who are never saved by a Ring user. The feature is banned in Texas, Illinois, and Portland, Oregon due to strict local biometric privacy laws — but operates freely in the remaining 47 states. U.S. Senator Edward Markey wrote to Amazon in October 2025: 'Amazon's system forces non-consenting bystanders into a biometric database without their knowledge or consent. This is an unacceptable privacy violation.' The proposed class encompasses millions of individuals across the United States.

  • Source: Class Action Filing — Hagens Berman
  • Related: CBS News Coverage — CBS News

AWS Security Breaches (2025)

Amazon Web Services, which hosts a significant portion of the internet's infrastructure, suffered multiple serious security incidents in 2025. In January 2025, a ransomware group known as Codefinger targeted AWS users by exploiting compromised credentials, using Amazon's own server-side encryption tools to lock victims out of their data and demanding ransom payments. The attackers leveraged SSE-C (server-side encryption with customer-provided keys) to encrypt S3 bucket data with AES-256 keys that Amazon does not retain, making decryption impossible without the attackers' cooperation. In December 2025, AWS experienced another major breach when attackers compromised numerous customer accounts through stolen IAM (Identity and Access Management) credentials, subsequently exploiting EC2 and ECS instances for an extensive crypto-mining operation. The breach, discovered on December 17, 2025, potentially affected thousands of users and raised significant concerns about cloud credential security. Amazon launched an internal investigation and advised users to update IAM credentials and implement multi-factor authentication.

  • Source: AWS Security Blog — BlackFog

Google: Violations & Regulatory Actions

$425 Million Privacy Verdict (September 2025)

In September 2025, a federal jury ordered Google to pay $425.7 million for privacy violations affecting approximately 98 million users. The case centered on Google's 'Web & App Activity' setting, which the company represented as a way for users to control data collection. Even when users turned this setting off or paused it, Google continued transmitting their data from non-Google branded apps back to its servers for profiling and advertising purposes. The jury found Google liable for invasion of privacy and intrusion upon seclusion, though it declined to find violations of California's Computer Data Access and Fraud Act. The award was significantly lower than the $31 billion in damages initially sought by plaintiffs. After Google appealed, the judge ordered the company to pay interest on the $425 million from the date of the initial verdict. Both Google's motion to decertify the class and plaintiffs' motion to increase the payout were denied. Eligible class members include anyone with a non-enterprise Google account who turned off or paused 'Web & App Activity' between July 1, 2016 and September 23, 2024, yet still had their data transmitted to Google from non-Google apps.

  • Source: Kiplinger — Kiplinger
  • Legal Analysis: Thompson Coburn — Thompson Coburn

$135 Million Android Data Settlement (March 2026)

In March 2026, Google agreed to a $135 million class action settlement over allegations that Android devices secretly used cellular data paid for by users to transmit tracking information back to Google. The lawsuit, Joseph Taylor v. Google LLC, covers over 100 million Americans with Android devices who used cellular data between November 12, 2017 and the date of final approval. Plaintiffs alleged that Google 'effectively forces users to subsidize its surveillance by secretly programming Android devices to constantly transmit user information.' This data collection allegedly occurred even when users had shut down apps or disabled location tracking. The settlement provides automatic cash payments (capped at $100 per person) via electronic payment methods including PayPal, Venmo, or Zelle. Notably, a separate parallel lawsuit in California covering approximately 14 million Android users settled for $314.6 million in July 2025, meaning California residents are excluded from the federal settlement. As part of both settlements, Google agreed to significant injunctive relief to better protect Android user privacy.

  • Source: ClassAction.org — ClassAction.org
  • Source: CNET — CNET

DOJ Antitrust Remedies (September 2025 — April 2026)

In August 2024, Judge Amit Mehta ruled that Google had illegally maintained a monopoly in general search services and search text advertising. The remedies phase concluded in September 2025 with a landmark order that fundamentally restructures Google's business practices. The court imposed a six-year prohibition on exclusive default search contracts covering Google Search, Chrome, Google Assistant, and the Gemini app on devices manufactured by Apple, Samsung, and other partners. The order requires Google to share its search index and user-interaction data (excluding advertising data) with qualified competitors — a mandate Google is aggressively appealing, citing 'irreparable harm' to user privacy. The court also ordered annual rebidding of default search contracts and established a five-member Technical Committee to oversee compliance. In April 2026, the DOJ filed a cross-appeal seeking stronger remedies, including forced divestiture of Chrome and an outright ban on the $20 billion annual Apple default search deal. Both appeals are expected to be heard by the D.C. Circuit in late 2026 or early 2027, with potential Supreme Court review extending into 2028.

  • Source: NPR — NPR
  • Source: Tech Insider — Tech Insider

Meta: Violations & Regulatory Actions

EUR 200 Million DMA Fine (April 2025)

In April 2025, the European Commission imposed a EUR 200 million fine on Meta for breaching the Digital Markets Act (DMA) through its 'pay or consent' advertising model. Between November 2023 and November 2024, Meta presented EU users with a binary choice: either consent to comprehensive personal data harvesting for personalized advertising, or pay a monthly subscription fee of up to EUR 9.99 for an ad-free experience. The Commission determined that this model did not provide users with a genuine, equivalent alternative that used less of their personal data. Under Article 5(2) of the DMA, gatekeepers must obtain user consent before combining personal data across services, and users who refuse must have access to a less personalized but equivalent experience. Meta's model violated both requirements. In response to the fine, Meta introduced a third 'less personalized ads' option in January 2026, but consumer groups including BEUC found that the option was not presented equally with the other choices and imposed 'ad breaks' that degraded the user experience. The Commission continues monitoring Meta's compliance.

  • Source: European Commission — EU Digital Markets Act
  • Source: BEUC Assessment — BEUC

AI Training on EU User Data (May 2025)

On May 27, 2025, Meta began using public posts, photos, captions, and comments from adult EU users of Facebook and Instagram to train its artificial intelligence models. The company relied on 'legitimate interest' under GDPR Article 6(1)(f) rather than obtaining explicit user consent — a legal basis that privacy advocates strongly dispute. The Irish Data Protection Commission (DPC), Meta's lead EU regulator, initially halted the plans in June 2024 but ultimately allowed them to proceed after Meta implemented improvements including updated transparency notices, an easier-to-use objection form, and data protection measures like de-identification and filtering. However, Hamburg's data protection authority initiated urgent proceedings demanding suspension of AI training on German users' data. The privacy organization NOYB ('None of Your Business'), led by activist Max Schrems, sent a cease-and-desist letter threatening collective legal action. Schrems stated: 'Meta's absurd claims that stealing everyone's personal data is necessary for AI training is laughable. Other AI providers do not use social network data — and generate even better models than Meta.' Crucially, once data is used to train AI models, it cannot be 'extracted' — making the objection process a race against time.

  • Source: European Newsroom — European Newsroom
  • Source: noyb — noyb.eu

WhatsApp Antitrust Order (June 2026)

In June 2026, the European Commission ordered Meta to restore access for rival AI assistants to its WhatsApp messaging platform within five days. The order came after Meta updated its terms in October 2025 to ban third-party AI chatbots from WhatsApp entirely, reserving the platform exclusively for Meta's own AI assistant. The Commission stated the intervention was necessary to prevent 'serious and irreparable harm to competition in this growing market by Meta's conduct.' Meta reacted furiously, accusing the Commission of 'regulatory overreach' and announcing plans to appeal. The interim measures require Meta to maintain access for rival AI providers until the antitrust investigation concludes. This case highlights Meta's broader strategy of leveraging its dominant messaging platform — used by approximately 80% of Europeans — to favor its own AI services over competitors. The White House has previously intervened on Meta's behalf when EU regulators have acted against the company.

  • Source: European Commission — EC Press
  • Source: Le Monde — Le Monde

Microsoft: Violations & Regulatory Actions

Windows Recall Privacy Controversy (2024-2025)

Microsoft's Recall feature, announced in 2024 and rolled out to Copilot+ PCs in May 2025, represents one of the most controversial privacy features in modern computing history. Recall takes screenshots of a user's screen every few seconds, uses on-device AI to analyze the content, and builds a searchable database of everything the user has ever viewed or typed on their PC — including passwords, financial documents, medical records, and private messages. Following massive public backlash and security researcher criticism, Microsoft made Recall opt-in rather than enabled by default, added Windows Hello biometric authentication requirements, and implemented encryption. However, the company clarified that Recall cannot be fully uninstalled — only disabled. The feature remains excluded from the European Economic Area, where regulators deemed it incompatible with GDPR requirements. Security researchers documented that if a device is compromised by malware, an attacker could potentially access the entire Recall database, extracting sensitive information stored in screenshots. In January 2026, Microsoft confirmed a bug causing Recall to capture screenshots of confidential emails and bypass data loss prevention policies — an issue that had persisted since late January 2026 before being patched.

  • Source: nGuard Security Analysis — nGuard

Copilot Security Vulnerabilities (2025-2026)

Microsoft 365 Copilot has been plagued by a series of serious security vulnerabilities that expose corporate data to unauthorized access. In May 2025, researchers at Aim Security disclosed CVE-2025-32711 ('EchoLeak'), the first documented zero-click vulnerability in a production AI system, rated CVSS 9.3 out of 10. The vulnerability allowed attackers to exfiltrate data from Copilot's context without any user interaction — simply by sending a crafted email that Copilot would later process. Other documented attack vectors include ASCII Smuggling (using invisible Unicode characters to hide stolen data in hyperlinks), Mermaid Diagram Exfiltration, Confidential Label Bypass (January 2026), and Indirect Prompt Injection via Email. The fundamental risk, however, is not exotic vulnerabilities but 'oversharing' — Copilot inherits all permissions a user has across SharePoint, OneDrive, and Teams, instantly making every poorly permissioned document searchable and summarizable by AI. In March 2024, the European Data Protection Supervisor found the European Commission itself in breach of data protection law for its use of Microsoft 365, citing insufficient specification of data collection and missing transfer safeguards. The breaches were remediated by July 2025, but the ruling set a precedent for all EU organizations using Microsoft cloud services.

  • Source: Security Today — Security Today
  • Source: SURF Netherlands — SURF

Azure Security Incidents (2025-2026)

Microsoft Azure faced critical security challenges throughout 2025. In early 2025, researchers identified CVE-2025-55241, a vulnerability in Microsoft Entra ID (formerly Azure Active Directory) that could allow attackers to impersonate global administrators across tenants. Microsoft rated the vulnerability as critical (CVSS 10.0) and issued an emergency patch, though the flaw demonstrated the fragility of cloud identity boundaries. In May 2026, Microsoft Threat Intelligence disclosed a sophisticated attack by threat actor Storm-2949 that turned a single compromised identity into a full cloud-wide breach. The attackers leveraged legitimate Azure management features to execute code remotely on virtual machines, access Key Vaults, manipulate SQL server firewall rules, and exfiltrate massive volumes of data from Azure Storage accounts using custom Python scripts. The attack spanned SaaS, PaaS, and IaaS layers, demonstrating that cloud identity compromise is now the primary vector for enterprise breaches. Additionally, in July 2025, a ProPublica investigation revealed that Microsoft had hired engineers in China to maintain federal defense systems, supervised by American 'digital escorts' with limited technology experience. The Office of the Director of National Intelligence has called China the 'most active and persistent cyber threat to U.S. Government, private-sector, and critical infrastructure networks.'

  • Source: Microsoft Security Blog — Microsoft Security

Terms of Service & Privacy Policy Changes

Amazon — BSA Update (March 2026)

Effective March 4, 2026, Amazon updated its Business Solutions Agreement with a new 'Agent Policy' that requires all automated systems accessing Amazon services to clearly identify themselves, comply continuously with policy terms, and cease access immediately if requested by Amazon. The policy prohibits using Amazon materials for AI development and gives Amazon broad authority to revoke access from any automated system without prior notice or explanation. Critically, sellers and software providers who continued using Amazon's services after March 4 automatically accepted these updated terms with no option to opt out. The changes effectively closed the data pipeline that third-party tools had used for years, consolidating Amazon's control over its marketplace data while restricting external AI development.

Meta — Privacy Policy Update (December 2025)

Meta's updated Privacy Policy, effective December 16, 2025, governs how user data is collected, used, and shared across Facebook, Instagram, and Messenger. The policy introduced new provisions for AI training data usage and modified how users can manage their privacy settings. Simultaneously, Meta updated its Terms of Service in January 2025 with significant changes including unilateral terms updates (users automatically consent to future changes by continuing to use the platform), broad content rights for AI training, and legacy contact provisions for posthumous account management. Critically, the new Terms allow Meta to use user content for AI and machine learning purposes without explicit opt-in consent. While Meta claims it does not 'sell' personal data, the updated language grants broad licensing rights that many privacy advocates argue effectively enables unrestricted AI training on user content. The terms also state that by simply using the platform, users automatically agree to any future changes — a practice that removes meaningful choice.

Microsoft — Multiple Updates (2025-2026)

Microsoft updated its Services Agreement on September 30, 2025, with changes including new provisions for exportable data, updated Xbox and Minecraft EULA references, Skype retirement accommodations, and new restrictions on AI services usage. The Privacy Statement underwent significant revisions in March and June 2026, reorganizing sections, adding Copilot-specific privacy controls, updating personalized advertising language, introducing new diagnostic data subsections, and adding age-appropriate experience provisions for the Microsoft Store. The June 2026 Privacy Statement update added information about access, export, and deletion controls in Microsoft Copilot and Microsoft 365 Copilot, clarified how Copilot in Edge processes page content and browsing history, and removed references to health-related ad targeting. Microsoft also updated its 'Artificial Intelligence and Copilot capabilities' section to describe how Copilot Health uses information for personalized health and wellness assistance.

Appendix: Additional Violations & Incidents

The following incidents, while smaller in financial impact or regulatory scope, represent important patterns in how these companies handle user data and respond to privacy concerns. Each entry includes a brief summary and source link for further investigation.

Amazon — Additional Incidents

  • Luxembourg GDPR Fine Appeal Upheld (March 2025) — Amazon's appeal of a EUR 746 million GDPR fine for processing personal data for targeted advertising without proper consent was rejected by Luxembourg's Administrative Court. The fine, originally issued in July 2021, remains one of the largest GDPR penalties ever imposed. Source
  • Codefinger Ransomware (January 2025) — Ransomware group Codefinger targeted AWS users by exploiting compromised credentials, using AWS's SSE-C encryption to lock victims out of their own S3 buckets with encryption keys Amazon does not retain. Source

Google — Additional Incidents

  • Privacy Sandbox Shutdown (October 2025) — Google officially discontinued its Privacy Sandbox initiative after six years, abandoning plans to replace third-party cookies. The reversal followed regulatory pressure from the UK CMA, EU authorities, and U.S. DOJ antitrust scrutiny. Source
  • $314.6M California Android Settlement (July 2025) — A separate California class action covering approximately 14 million Android users settled for $314.6 million over similar allegations of unauthorized cellular data collection for tracking purposes. Source

Meta — Additional Incidents

  • EUR 800 Million Antitrust Fine (November 2024) — The European Commission fined Meta EUR 800 million for tying its Facebook Marketplace classified ads service to its social network and imposing unfair trading conditions on competing ad providers. Source
  • EUR 91 Million Plaintext Password Fine (September 2024) — Ireland's DPC fined Meta EUR 91 million for storing certain Facebook user passwords in plaintext within internal systems since 2019, violating GDPR Article 5(1)(f) requiring appropriate security measures. Source
  • EUR 251 Million 2018 Breach Fine (September 2024) — The DPC fined Meta EUR 251 million for a 2018 Facebook breach that exposed personal data of 29 million users through a flaw in the 'view as' feature. Source

Microsoft — Additional Incidents

  • LinkedIn EUR 310 Million GDPR Fine (October 2024) — Ireland's DPC fined LinkedIn (owned by Microsoft) EUR 310 million for processing user data without proper consent for behavioral analysis and targeted advertising. Source
  • Austrian Kids' Data Violation (October 2025) — Austria's data protection authority found Microsoft violated EU law in its handling of children's data, marking another European enforcement action against the company's data practices. Source
  • M365 Copilot Confidential Email Bug (January 2026) — Microsoft confirmed a bug causing Copilot to summarize confidential emails since late January 2026, bypassing data loss prevention policies. An emergency patch was released. Source
  • SharePoint Zero-Day (July 2025) — Hackers exploited a zero-day vulnerability in Microsoft SharePoint impacting businesses, federal agencies, and universities globally. Emergency patches were released but some platform versions remained vulnerable. Source

Your Privacy Matters

  • Document compiled for privacy advocacy and public awareness.
  • All sources verified and linked. This document is intended for educational and advocacy purposes to inform the public about their digital rights.

Comfac Relevance

  • Vendor risk: Comfac uses Google Workspace, Microsoft 365, Azure, AWS, and other services documented in this report. These incidents belong in vendor-risk reviews and DPO evidence.
  • Client accreditation: The report provides independent, cited examples of vendor behavior for security questionnaires and ISO 27001 evidence.
  • Awareness: The public Security & Privacy News page surfaces these patterns so employees, clients, and the public can recognize them.

Related Notes

References

  • Original document: work/security-iso/BigTech_Privacy_Violations_2025-2026.docx

Converted to markdown and added to the security-privacy news feed on 2026-07-13.

Sector: Big Tech / privacy / consumer rights Source: `work/security-iso/BigTech_Privacy_Violations_2025-2026.docx`

Australian Consumer Law: Unfair Contract Terms and Unilateral Changes

🟡 Medium 2026-07-13

Under the Australian Consumer Law (ACL), a business cannot force consumers and small businesses to accept one-sided changes to a standard-form contract.

Read full article

Summary

Under the Australian Consumer Law (ACL), a business cannot force consumers and small businesses to accept one-sided changes to a standard-form contract. Unilateral variation clauses—terms that let one party change the agreement without the other party's consent—are a prime example of potentially unfair contract terms and can be declared void by a court.

Impact on regular people: If a big company updates its terms and conditions and tells you to "take it or leave it," you may have the right to reject the change and keep the status quo, or even terminate the contract without penalty. Since November 2023, businesses that include unfair terms in standard-form contracts can face substantial penalties, making this a serious compliance issue.


The Principle: Protecting You from Unfair "Take-It-Or-Leave-It" Terms

The core of this protection is the concept of unfair contract terms under the Australian Consumer Law (ACL). This applies to standard form contracts—the kind that are typically offered on a "take it or leave it" basis, where you have little or no room to negotiate.

A key rule in this area specifically targets clauses that allow one party (usually the bigger business) to unilaterally change the contract. These are often called unilateral variation clauses and are considered a prime example of a potentially unfair term. The law strongly encourages that you should have a choice to keep your existing status quo if a company unilaterally imposes a change.

Key Protections Under Australian Law

To reinforce this point, here's how the law works in practice:

  • Unfair Terms Are Void: If a court finds a term is unfair, it's treated as if it never existed. This protects you from being bound by the change.
  • Substantial Penalties for Companies: Since November 2023, it's illegal for a business to include unfair terms in a standard form contract. Companies can now face massive penalties if they do, making compliance a serious issue.
  • Right to Terminate: When a company tries to change a contract unilaterally, you often have the right to terminate the contract to avoid the new terms, ideally without being penalized.

The Bottom Line

The legal framework in Australia is designed to ensure that a big company can't just update its terms and conditions and force you to accept them without a fair opportunity to reject the change and walk away. The law is on your side to help maintain the "status quo" you originally agreed to.


Why the "it's fine" narrative is wrong

You will often hear that "everyone accepts updated terms," that "you have nothing to hide," or that a company "only uses data to improve services." The Australian Consumer Law says otherwise: if a business can change the rules whenever it wants — and you have no real choice but to accept — the term can be declared void. "Agreeing" under pressure is not the same as consent, and "free" services that collect personal data are not actually free.

Comfac Relevance

  • Vendor contract review: When Comfac signs standard-form SaaS, cloud, or service contracts, unilateral variation clauses should be flagged and negotiated or documented as a risk.
  • Client accreditation: Security and compliance questionnaires may ask how Comfac handles changes to processor/sub-processor terms; this ACL principle can be cited when reviewing vendor agreements.
  • DPO / legal awareness: The principle aligns with broader data-protection and consumer-protection expectations: changes that affect personal data processing should not be imposed without notice and choice.

References

  • ACCC — Unfair contract terms: https://www.accc.gov.au/consumers/consumer-rights-guarantees/unfair-contract-terms
  • Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010)
Sector: Consumer protection / contract law / regulatory risk Source: https://www.accc.gov.au/consumers/consumer-rights-guarantees/unfair-contract-terms

Consumer Rights Wiki — MegaCorporation Violations Index

🟡 Medium 2026-07-13

The Consumer Rights Wiki is a major, community-run source for consumer-protection news and documentation. It tracks anti-competitive behavior, privacy violations, repair restrictions, and other harmful practices by large companies.

Read full article

Summary

The Consumer Rights Wiki is a major, community-run source for consumer-protection news and documentation. It tracks anti-competitive behavior, privacy violations, repair restrictions, and other harmful practices by large companies. A significant portion of its coverage and community energy comes from the Louis Rossmann channel and the right-to-repair movement.

This note indexes megacorporation pages and cross-cutting topics that are relevant to the Comfac Security & Privacy News feed. It will be updated as CRW grows.

Impact on regular people: Big companies use the same playbook — buried terms, data harvesting, paywalls for already-built hardware features, account lockouts, and repair restrictions. Consumer Rights Wiki collects the receipts so people can see the patterns instead of treating each incident as a one-off.

Why the "it's fine" narrative is wrong

The default message from large vendors and their marketing is that "everyone does this," "you agreed to it," or "it's necessary for convenience." The Consumer Rights Wiki shows that many of these practices are not inevitable — they are choices that have been challenged in court, fined by regulators, and documented by independent researchers. Convenience should not require surrendering control over devices, data, or accounts.

The erosion of ownership, privacy, and control

Across the CRW corpus, three rights are being attacked at the same time:

  1. Ownership — You buy a device, but the manufacturer keeps the keys. Features are gated by software, repairs are blocked, and digital purchases can be revoked after the fact. Examples include Tesla shipping cars with disabled hardware and John Deere restricting farmers from repairing their own tractors.
  2. Privacy — Products that should be private by default collect location, biometric data, viewing habits, and voice input, often buried in terms most people never read. Examples include Vizio's second-by-second TV tracking and Honda selling driver data to insurers.
  3. Control — Post-purchase terms are changed unilaterally, bait-and-switch pricing is normalized, and software updates turn functional devices into paperweights. Examples include post-purchase EULA changes and planned obsolescence through updates.

Open Source as the main bastion

Open-source software and hardware are one of the strongest practical defenses against this erosion because they keep the user in control:

  • Transparency: The code can be inspected, so hidden data collection or backdoors are harder to sustain.
  • Modifiability: Users and independent repair shops can fix, extend, or remove unwanted functionality without begging the manufacturer.
  • Longevity: Communities can continue maintaining software after a vendor abandons it, resisting forced obsolescence.
  • Portability: Open formats and protocols reduce lock-in, making it easier to leave a service or replace a device.

CRW pages such as Right to repair, DMCA Section 1201, and Planned obsolescence document the legal and technical battlegrounds where open-source and repair communities are pushing back.


Key CRW topics


Selected megacorporation violations

Google

Google has faced ongoing scrutiny over data privacy, competition, and its dominant market position since at least 2012. It has been the subject of antitrust lawsuits and regulatory challenges over the use of personal data and its impact on consumer choice.

Microsoft

Microsoft has a long history of anti-competitive and anti-consumer practices, including bundling Internet Explorer and later Edge with Windows, signing exclusive deals with PC makers, and using its market power to limit consumer choice.

Amazon

Amazon has revoked previously purchased digital content on Kindle and Luna, removed download capabilities from Prime Music in some regions, and promoted its "Just Walk Out" stores as AI-powered while reportedly relying on workers in India to track customers.

Sony

Sony's controversies include the 2005 Sony BMG rootkit, which installed copy-protection software that secretly tracked users and created security holes, leading to lawsuits and recalls. The company has also faced ongoing disputes over digital content management.

Vizio

Vizio's business model treats the television as a delivery mechanism for advertising and data collection. The FTC found in 2017 that Vizio collected second-by-second viewing data from 11 million smart TVs without meaningful consent.

Netflix

Netflix has restricted access to content through tiered pricing, cracked down on password sharing, and disclosed extensive collection of biometric information, location data, IP addresses, and voice input from users.

Tesla

Tesla has shipped cars with hardware features disabled by software, requiring one-time or subscription payments to unlock functionality such as extra range, acceleration, or heated seats that are physically already installed.

Honda

Honda collected driver information and sold it to a third party called Verisk, which resold it as "driver reports" to insurance companies. The data was used to raise premiums, often without clear consumer consent.


How Comfac uses this source

  • Vendor risk: CRW pages can be cross-checked during vendor evaluations for Google Workspace, Microsoft 365, AWS, and other services.
  • Client accreditation: Provides independent, cited examples of vendor behavior for security questionnaires and DPO evidence.
  • Public awareness: The Security & Privacy News page can surface CRW-sourced summaries to help regular people recognize recurring patterns.

Related notes

References

  • Consumer Rights Wiki main page: https://consumerrights.wiki/w/Main_Page
  • Consumer Rights Wiki company pages linked above

Indexed by SCA on 2026-07-13. Update this note as new CRW pages or incidents become relevant.

Sector: Consumer rights / corporate accountability / privacy Source: https://consumerrights.wiki/w/Main_Page

Major Tech Privacy Violations and Allegations — Google, Microsoft, Amazon

⚪ Informational 2026-07-13

A chronological compilation of major privacy violations and allegations involving Google, Microsoft, and Amazon from July 2026 back to January 2025. The list covers cloud scanning, device data collection, browser tracking, AI training, child-data collection, and biometric surveillance.

Impact on regular people: These cases show that opting out of tracking is often ignored, devices continue to send data after being "turned off," and AI features may rely on personal data without clear consent.

Read full article

Summary

A chronological compilation of major privacy violations and allegations involving Google, Microsoft, and Amazon from July 2026 back to January 2025. The list covers cloud scanning, device data collection, browser tracking, AI training, child-data collection, and biometric surveillance.

Impact on regular people: These cases show that opting out of tracking is often ignored, devices continue to send data after being "turned off," and AI features may rely on personal data without clear consent. For Comfac, they feed vendor-risk assessments for Google Workspace, Microsoft 365, Azure, AWS, and IoT procurement.

Google

July 2026: Google Drive CSAM Detection Raises Privacy Concerns

Google's automated safety systems flagged alleged child sexual abuse material (CSAM) stored on a user's Google Drive account, leading to the arrest of a 19-year-old man in Kanpur, India. While the arrest was welcomed, the case sparked a debate about user privacy on cloud services, with many questioning how much visibility Google has into files stored on personal accounts.

July 2026: Google Pixel 9 Raises Privacy Concerns

Researchers analyzing the Google Pixel 9 Pro XL found that the smartphone frequently transmits private user data to Google before any app is installed, raising concerns about user privacy and security.

June 2026: Chrome Incognito Mode Privacy Case Advances

A federal judge denied Google's motion to dismiss most claims in a lawsuit brought by Chrome users who allege they were tracked while in Incognito mode despite Google's claims to the contrary. The claims include violations of the Wiretap Act and California privacy laws.

June 2026: EU Consumer Groups Accuse Google of Online Tracking

European consumer groups accused Google of violating online privacy by pushing users to sign in to Google accounts so their data could be tracked and exploited for profit, in violation of GDPR rules.

April 2026: Audit Finds Google Fails to Honor Privacy Opt-Outs 86% of the Time

A forensic audit by webXray found that when California users tell websites to stop tracking them via Global Privacy Control (GPC), Google ignores that request 86% of the time. Google's ad servers were found to routinely disregard the GPC signal and create two-year advertising cookies on users' devices.

January 2026: Google Agrees to $68 Million Settlement Over Google Assistant Secret Listening

Google agreed to pay $68 million to settle a lawsuit alleging that Google Assistant was activated without user consent and secretly recorded private conversations, which were then sent to Google's servers. The lawsuit claimed that unintentional activations resulted in the collection and transmission of private conversations without users' knowledge.

January 2026: Jury Finds Google Violated Privacy by Collecting Data After Opt-Out

A jury found that Google violated users' privacy by continuing to collect data even after they opted out of app activity tracking, awarding more than $425 million in compensatory damages to a class of over 100 million users.

November 2025: Google Continues Collecting Data from Downgraded Nest Thermostats

After Google turned off remote control functionality for first- and second-generation Nest Learning Thermostats, security researcher Cody Kociemba found that the devices were still sending Google extensive data, including temperature, humidity, ambient light, motion, and manual temperature changes. Google acknowledged the data transmission in its support documentation but could no longer use the information to assist customers since support had been discontinued.

May 2025: Belgian Court Rules Tracking-Based Advertising Framework Illegal

The Brussels Court of Appeal ruled that the Transparency & Consent Framework (TCF)—used by Google, Microsoft, Amazon, and others for tracking-based advertising—is illegal under EU privacy law, finding it fails to meet GDPR requirements for user consent and transparency.

February 2025: Court Rejects Google's Effort to Invalidate Mass Opt-Out in Assistant Privacy Case

A California federal court rejected Google's efforts to invalidate the mass opt-out of over 69,000 plaintiffs in the In re Google Assistant Privacy Litigation, which centers on claims that Google Assistant devices unintentionally recorded private conversations through "False Accepts".

January 2025: Amsterdam Court Allows Class Action Against Google Over Android Privacy

An Amsterdam court allowed a representative claim to proceed against Google for unlawfully infringing the privacy of Android phone users.


Microsoft

July 2026: Microsoft Fined $20 Million Over Child Data Violations

Microsoft agreed to pay $20 million to settle FTC charges that it collected personal information from children under 13 who signed up for Xbox without their parents' consent, in violation of COPPA. The FTC alleged that Microsoft collected names, email addresses, and birth dates from children and retained this information.

June 2026: Microsoft Illegally Tracked Students, Austrian DPA Finds

Austria's data protection authority determined that Microsoft illegally tracked students using Microsoft 365 Education software, installing cookies that collect browser data for advertising purposes. Microsoft was ordered to provide users access to their personal data.

June 2026: Microsoft to Tighten Controls After Israeli Surveillance Inquiry

Following an inquiry into how the Israeli military used Microsoft's cloud technology for mass surveillance of Palestinians, Microsoft said it would tighten human-rights controls when working with national security agencies.

April 2026: Audit Finds Microsoft Tracks Users After Opt-Out

The webXray audit found that Microsoft's tracking network receives Global Privacy Control (GPC) signals and unconditionally returns a one-year MUID cookie regardless of the user's privacy settings.

March 2026: Microsoft 365 Copilot Introduces New Data Protection Risk

Microsoft introduced "flex routing" for Microsoft 365 Copilot data traffic, which enabled data transfers outside of the EU Data Boundary, introducing a new data protection risk.

December 2025: ICCL Files Complaint Against Microsoft Over Israeli Data Processing

The Irish Council for Civil Liberties filed a complaint against Microsoft for unlawful data processing on behalf of the Israeli Defence Forces in Gaza, alleging that Microsoft's processing of personal data facilitates war crimes and human rights violations.

September 2025: Microsoft Cuts Services to Israeli Military Unit Over Surveillance

Microsoft cut cloud and AI services to an Israeli military unit running a surveillance system that monitored millions of Palestinian calls in Gaza and the West Bank. The company found that Israel was violating terms of service by using Microsoft's cloud storage to hold surveillance data on Palestinians.

July 2025: European Commission Found in Violation Over Microsoft 365 Use

The European Data Protection Supervisor found that the European Commission violated GDPR rules—including purpose limitation and unauthorized personal data disclosures—in its use of Microsoft 365.


Amazon

July 2026: Amazon Fined $2.25 Million for Withholding Records from Fraud Victims

Amazon agreed to pay $2.25 million in civil penalties to settle FTC allegations that it knowingly violated the Fair Credit Reporting Act by refusing to provide transaction records to consumers whose personal information was used by identity thieves to commit fraud.

June 2026: Class Action Alleges Ring Cameras Collect Facial Data Without Consent

A class action lawsuit alleged that Amazon's Ring cameras collected people's facial recognition information without their consent through the "Familiar Faces" feature. The suit claims that millions of Americans are being tracked as Ring is the leading seller of front door security cameras.

March 2026: CNPD Issues Compliance Order Against Amazon Over GDPR Violations

Luxembourg's National Commission for Data Protection issued a compliance order against Amazon for breaching several provisions of the GDPR in relation to its online behavioral advertising practices.

February 2026: Senator Markey Calls on Amazon to End Ring Facial Recognition

Following Amazon's Super Bowl ad, Senator Ed Markey again called on Amazon to end facial recognition technology in Ring doorbells, noting that Ring's privacy protections only apply to device owners and not members of the public.

December 2025: Senator Markey's Probe Exposes Amazon's Ring Privacy Violations

Senator Markey released findings from his probe into Ring, exposing that Amazon's "Familiar Faces" facial recognition feature provides no privacy protections for individuals unknowingly subjected to scans. Ring requires individuals who want their biometric data deleted to request deletion from each device owner individually.

October 2025: Senator Markey Demands Amazon Abandon Ring Facial Recognition

Senator Markey demanded that Amazon abandon its plan to include facial recognition technology in Ring doorbells, stating: "Amazon's system forces non-consenting bystanders into a biometric database without their knowledge or consent".

January 2025: Amazon Hit With Lawsuit Over Location Data Collection

Amazon was sued for allegedly collecting and profiting from consumer location data through its advertising software development kit (SDK) embedded in tens of thousands of apps, in violation of California privacy laws.


Cross-Company

May 2025: Belgian Court Rules Tracking-Based Advertising Framework Illegal

The Brussels Court of Appeal ruled that the Transparency & Consent Framework (TCF)—relied upon by Google, Microsoft, Amazon, and X for tracking-based advertising—is illegal under EU privacy law, finding it fails to meet GDPR requirements for user consent and transparency.

April 2026: Audit Finds Google, Microsoft, and Meta Track Users After Opt-Out

The webXray forensic audit found that Google, Microsoft, and Meta all fail to honor privacy opt-outs. Google ignores GPC signals 86% of the time, Microsoft unconditionally returns tracking cookies, and Meta's tracking pixel contains no code to check for GPC at all.


Why the "it's fine" narrative is wrong

The common response to these incidents is that "you have nothing to hide," that opt-outs are honored, or that devices stop collecting data when you turn features off. The evidence here shows the opposite: opt-outs are routinely ignored, "incognito" modes are tracked, downgraded devices keep phoning home, and AI features are trained on personal data without clear consent. The problem is not user carelessness; it is a business model built on collecting more than people realize.

Comfac Relevance

  • Vendor AI / cloud assessment: These incidents feed directly into vendor risk evaluations for Google Workspace, Microsoft 365, Azure, AWS, and Nest/Ring IoT.
  • Client accreditation: Client questionnaires increasingly ask about supply-chain vendor privacy posture. This note provides evidence of recurring issues with major cloud providers.
  • DPO / ISO 27001 alignment: Use when drafting or reviewing personal-data processing agreements, cookie/tracking policies, and third-party processor assessments.
  • Synopsis / AI summarization caution: Incidents of hidden listening, post-opt-out tracking, and unauthorized facial recognition reinforce the need for strict internal controls on any AI-mediated communication or biometric processing.

Related Notes

2026-07-11 — Supply-Chain De-Risking: MikroTik and Netgate as Strategic Networking Stack

🟠 High 2026-07-11

Comfac/CTO is actively de-risking from Chinese-controlled or China-origin networking hardware and software. The strategic stack for the Bill of Materials (BOM) and advanced systems will be built around MikroTik and Netgate platforms.

Policy principle: Comfac/CTO will avoid any networking vendor that builds its networking products in China.

Read full article

Summary

Comfac/CTO is actively de-risking from Chinese-controlled or China-origin networking hardware and software. The strategic stack for the Bill of Materials (BOM) and advanced systems will be built around MikroTik and Netgate platforms.

Policy principle: Comfac/CTO will avoid any networking vendor that builds its networking products in China. This applies to routers, switches, firewalls, wireless access points, network management platforms, and any infrastructure that transports or controls client data.

This de-risking supports:

  • Data-sovereignty and national-security requirements.
  • Reduced exposure to supply-chain compromise, backdoors, and foreign-intelligence influence.
  • A controlled, auditable networking layer for the isolated security-AI environment.

Strategic Vendors / Platforms

| Platform | Role | Rationale | |----------|------|-----------| | MikroTik | Routers, switches, wireless, network management | Non-Chinese vendor; broad feature set; cost-effective; suitable for SME and branch deployments | | Netgate | pfSense / TNSR firewalls, security gateways | US-based; open-source-core firewall platform; aligns with CGG hardening doctrine |

Affected Systems / Scope

  • Core and branch office routers, switches, and wireless access points
  • Perimeter and internal firewalls
  • VPN/SD-WAN termination points
  • Management/monitoring network fabric
  • Isolated security-AI environment network boundary

Exclusion rule: Any networking product whose design, manufacturing, or firmware supply chain is China-based is out of scope for new deployments and should be replaced in existing deployments unless formally risk-accepted.

Impact

  • Supply-chain security: Replaces high-risk hardware with vendors outside the China-controlled supply chain.
  • Compliance: Supports data-localization, vendor-sovereignty, and audit evidence requirements.
  • Operational continuity: Reduces risk of remote-disable, firmware backdoors, or intelligence-driven compromise.
  • Cost architecture: MikroTik/Netgate combination provides enterprise-grade capability at SME-friendly pricing for BOMs.

Comfac Relevance

  • Client BOMs and proposals should default to MikroTik/Netgate unless a specific requirement forces another vendor.
  • Engineering and operations teams must document why Chinese-origin networking gear is excluded.
  • Security assessments should treat non-MikroTik/Netgate networking hardware as an exception requiring risk acceptance.
  • The isolated security-AI environment must be built on this de-risked network fabric.

Recommended Actions

  • [ ] Draft standard MikroTik/Netgate reference architecture for Comfac/CTO deployments — SCA + Network team — due 2026-07-25
  • [ ] Create BOM templates with MikroTik/Netgate defaults for common deployment sizes — SCA + Operations — due 2026-07-25
  • [ ] Document Chinese-networking-vendor exclusion rationale for client proposals and audit evidence — SCA — due 2026-07-18
  • [ ] Review current inventory for Chinese-origin networking hardware and plan replacement/exception handling — Network team — due 2026-08-01
  • [ ] Map MikroTik/Netgate hardening guides to CGG hardening doctrine and ISO 27001 controls — SCA — due 2026-08-01

Related Controls / Links

  • ISO/IEC 27001:2022 control: A.5.19 Information security in supplier relationships
  • ISO/IEC 27001:2022 control: A.5.20 Addressing information security within supplier agreements
  • ISO/IEC 27001:2022 control: A.5.21 Managing information security in the ICT supply chain
  • ISO/IEC 27001:2022 control: A.5.36 Compliance with policies, rules and standards for information security
  • Hardening doctrine: work/CGG-Hardening/251129-system-hardening-win2lin-strategy.md
  • Dialogue log: work/security-iso/logs/260711-security-iso-log.md
  • Vendor-risk note: security-intelligence/2026/2026-06-30-palantir-critical-systems-ban.md
  • AI-data note: security-intelligence/2026/2026-07-06-google-microsoft-ai-data-practices.md

Logged by SCA on 2026-07-11.

Sector: Networking / firewalls / critical infrastructure / supply chain Status: Active planning; BOM and architecture decisions pending Source: Justin / SCA strategic planning

2026-07-06 — Google & Microsoft AI Data-Training Practices

🟠 High 2026-07-06

Multiple reports indicate that Google and Microsoft are expanding use of customer/user data to train and operate AI services:

  • Google: A July 2026 TechCrunch article notes that using Google services may contribute to AI training, with opt-out mechanisms available.
  • Gmail: A January 2026 NY Post report claims Gmail is using personal data to train AI.
  • Microsoft Teams: A July 2026 report describes a new Teams AI feature that listens to meetings and can answer before being asked; it is reportedly not on by default.
  • Microsoft Copilot OS: A leaked video shows a Windows OS

Read full article

Summary

Multiple reports indicate that Google and Microsoft are expanding use of customer/user data to train and operate AI services:

  • Google: A July 2026 TechCrunch article notes that using Google services may contribute to AI training, with opt-out mechanisms available.
  • Gmail: A January 2026 NY Post report claims Gmail is using personal data to train AI.
  • Microsoft Teams: A July 2026 report describes a new Teams AI feature that listens to meetings and can answer before being asked; it is reportedly not on by default.
  • Microsoft Copilot OS: A leaked video shows a Windows OS exploration built around Copilot/agentic AI.
  • Microsoft / OpenAI: The New York Times alleges Microsoft built a copyright-infringing supercomputer to assist OpenAI.

Affected Products / Services

  • Google Search / Google Workspace / Gmail
  • Microsoft 365 / Microsoft Teams / Copilot
  • Windows (Copilot OS exploration)
  • OpenAI infrastructure hosted on Microsoft Azure

Impact

  • Confidentiality: Business communications and documents may be processed by vendor AI models.
  • Compliance: Potential conflicts with client confidentiality, NPC data-privacy expectations, and ISO 27001 control A.5.34 (privacy and personally identifiable information protection).
  • Intellectual property: Content fed into AI models may be retained or reproduced elsewhere.

Comfac Relevance

Comfac/CTO uses cloud productivity tools and advises clients on security. If Google or Microsoft processes Comfac/client data for AI training, this creates:

  • Confidentiality risk for client engineering, financial, and HR data.
  • Compliance exposure under Philippine data-privacy rules and ISO 27001.
  • A need for explicit opt-out/administrative controls and user awareness.

Recommended Actions

  • [ ] Audit current Google Workspace / Microsoft 365 admin settings for AI training/data-sharing opt-outs — SCA — due 2026-07-18
  • [ ] Document which Comfac/client data classes may be processed by external AI — SCA — due 2026-07-18
  • [ ] Draft user guidance on avoiding AI-training exposure for sensitive documents — SCA — due 2026-07-25
  • [ ] Evaluate self-hosted alternatives or isolated AI instances for security-sensitive work — SCA + Justin — due 2026-07-25
  • [ ] Add AI data-sharing review to client hardening checklist — SCA — due 2026-07-25

Related Controls / Links

  • ISO/IEC 27001:2022 control: A.5.34 Privacy and protection of personally identifiable information (PII)
  • ISO/IEC 27001:2022 control: A.5.36 Compliance with policies, rules and standards for information security
  • ISO/IEC 27001:2022 control: A.8.5 Secure authentication
  • Dialogue log: work/security-iso/logs/260711-security-iso-log.md
  • TechCrunch — Google opt-out: https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/
  • NY Post — Gmail: https://nypost.com/2026/01/06/tech/gmail-is-using-personal-data-to-train-ai-techspert/
  • Windows Latest — Teams AI: https://www.windowslatest.com/2026/07/02/microsoft-teams-new-controversial-ai-will-listen-to-your-meetings-and-answer-before-you-ask-but-it-wont-be-turned-on-by-default/
  • Windows Central — Copilot OS: https://www.windowscentral.com/microsoft/windows-11/microsoft-copilot-os-revealed-in-leaked-video-lightweight-windows-os-exploration-features-new-desktop-ui-built-entirely-around-copilot-and-agentic-ai
  • Ars Technica — Microsoft/OpenAI supercomputer: https://arstechnica.com/tech-policy/2026/06/microsoft-built-supercomputer-to-help-openai-infringe-copyrights-nyt-alleged/

Logged by SCA on 2026-07-11.

Sector: Cloud services / SaaS / AI Status: Monitoring; action required on data-sharing settings Source: TechCrunch, NY Post, Windows Latest, Windows Central, Ars Technica, The New York Times

2026-06-30 — Palantir Bans and Critical-System Vendor Risk

🟠 High 2026-06-30
  • Spain: The Spanish government reportedly banned the use of Palantir in critical state systems over fears of national-security leaks.
  • United Kingdom: Andy Burnham is expected to ditch the Palantir NHS deal if he becomes UK prime minister.

Both developments signal growing concern about foreign-owned or intelligence-linked analytics vendors handling sensitive government and critical-infrastructure data.

Read full article

Summary

  • Spain: The Spanish government reportedly banned the use of Palantir in critical state systems over fears of national-security leaks.
  • United Kingdom: Andy Burnham is expected to ditch the Palantir NHS deal if he becomes UK prime minister.

Both developments signal growing concern about foreign-owned or intelligence-linked analytics vendors handling sensitive government and critical-infrastructure data.

Affected Products / Services

  • Palantir Foundry / Gotham / AIP platforms
  • Government and critical-state systems
  • NHS / healthcare analytics contracts

Impact

  • Data sovereignty: Sensitive state and citizen data may be exposed to foreign jurisdictions or intelligence interests.
  • Vendor concentration: Organizations relying on Palantir for analytics face sudden contract/policy risk.
  • Compliance: Public-sector and regulated clients may impose new vendor blacklists or data-localization requirements.

Comfac Relevance

Comfac/CTO advises clients on IT and security. If clients operate in government-adjacent or critical-infrastructure sectors:

  • Vendor selection must include data-sovereignty and ownership-structure review.
  • Contracts should include exit clauses and data-deletion assurances.
  • Critical-system vendors should be mapped to applicable regulatory/national-security restrictions.

Recommended Actions

  • [ ] Add vendor data-sovereignty / ownership review to client assessment checklist — SCA — due 2026-07-25
  • [ ] Draft guidance on identifying intelligence-linked or restricted analytics vendors — SCA — due 2026-07-25
  • [ ] Review Comfac/CTO's own analytics and BI tool stack for similar exposure — SCA + Operations — due 2026-07-25

Related Controls / Links

  • ISO/IEC 27001:2022 control: A.5.19 Information security in supplier relationships
  • ISO/IEC 27001:2022 control: A.5.20 Addressing information security within supplier agreements
  • ISO/IEC 27001:2022 control: A.5.36 Compliance with policies, rules and standards for information security
  • Dialogue log: work/security-iso/logs/260711-security-iso-log.md
  • LBC — Spain Palantir ban: https://www.lbc.co.uk/article/spanish-bans-palantir-national-security-5HjdcNp_2/
  • AA.com.tr — UK NHS deal: https://www.aa.com.tr/en/europe/burnham-expected-to-ditch-palantir-nhs-deal-if-he-becomes-uk-prime-minister-report/3984619

Logged by SCA on 2026-07-11.

Sector: Government IT / critical infrastructure / data analytics Status: Monitoring; review vendor/sovereignty policies Source: LBC, AA.com.tr

2026-06-29 — Surveillance and Biometric Privacy Developments

🟡 Medium 2026-06-29

Recent developments highlight expanding surveillance and biometric data collection:

  • US Supreme Court ruled that geofence warrants require constitutional privacy protections, limiting broad location-dragnet requests.
  • ATF stopped using the controversial Webloc phone-tracking tool after scrutiny.
  • Flock surveillance tower appeared in a private yard without the resident's prior knowledge.
  • Google is testing a webcam-based reCAPTCHA that asks users for a hand scan to prove they are human; testers reportedly bypassed it with a stock photo.
  • Indian pranksters used a

Read full article

Summary

Recent developments highlight expanding surveillance and biometric data collection:

  • US Supreme Court ruled that geofence warrants require constitutional privacy protections, limiting broad location-dragnet requests.
  • ATF stopped using the controversial Webloc phone-tracking tool after scrutiny.
  • Flock surveillance tower appeared in a private yard without the resident's prior knowledge.
  • Google is testing a webcam-based reCAPTCHA that asks users for a hand scan to prove they are human; testers reportedly bypassed it with a stock photo.
  • Indian pranksters used a Chinese app to shut down e-rickshaws mid-ride, showing weak IoT/OT access controls in connected vehicles.

Affected Products / Services

  • Mobile device location data (geofence warrants)
  • Law-enforcement phone-tracking tools (Webloc)
  • Automated license-plate / surveillance towers (Flock)
  • Google reCAPTCHA / biometric authentication tests
  • Connected / shared electric vehicles (e-rickshaws)

Impact

  • Privacy: Location, biometric, and behavioral data are being collected at scale with varying legal oversight.
  • Legal risk: Geofence warrant ruling may shift how law-enforcement requests are handled; organizations receiving such warrants should review response procedures.
  • Biometric security: Consumer-grade hand-scan verification was defeated with a static image, raising questions about liveness detection.
  • IoT/OT safety: Remote shutdown of vehicles via app demonstrates unsafe-by-default connected-device design.

Comfac Relevance

Comfac/CTO should monitor these trends because they affect:

  • Client data-privacy policies and law-enforcement response playbooks.
  • Choice and configuration of authentication mechanisms (avoid weak biometrics).
  • IoT/OT deployments in facilities and logistics (e-rickshaw incident is a cautionary example).

Recommended Actions

  • [ ] Review Comfac/CTO law-enforcement data-request response procedure — SCA + Legal — due 2026-07-25
  • [ ] Assess use of biometric or CAPTCHA systems; require liveness-proof / privacy-preserving alternatives where sensitive — SCA — due 2026-07-25
  • [ ] Add IoT/OT remote-access kill-switch review to client hardening checklist — SCA — due 2026-07-25

Related Controls / Links

  • ISO/IEC 27001:2022 control: A.5.34 Privacy and protection of personally identifiable information (PII)
  • ISO/IEC 27001:2022 control: A.8.5 Secure authentication
  • ISO/IEC 27001:2022 control: A.8.16 Monitoring activities
  • Dialogue log: work/security-iso/logs/260711-security-iso-log.md
  • The Guardian — geofence warrants: https://www.theguardian.com/us-news/2026/jun/29/supreme-court-geofence-warrants-case-decision
  • AP News — ATF Webloc: https://apnews.com/article/atf-surveillance-wyden-cloud-566f702fe6082310d6b7c64e5b2de009

Logged by SCA on 2026-07-11.

Sector: Law enforcement / consumer tech / IoT / biometrics Status: Monitoring; review surveillance and biometric controls Source: The Guardian, AP News, provided dump (Flock, reCAPTCHA, e-rickshaws)

2026-06-22 — FortiBleed Campaign Against Exposed Fortinet Management Interfaces

🔴 Critical 2026-06-22

A large-scale credential-harvesting and initial-access campaign (dubbed FortiBleed) is targeting roughly 75,000 Fortinet firewalls whose management or SSL-VPN interfaces are exposed to the public internet.

Read full article

Summary

A large-scale credential-harvesting and initial-access campaign (dubbed FortiBleed) is targeting roughly 75,000 Fortinet firewalls whose management or SSL-VPN interfaces are exposed to the public internet. Fortinet confirmed on 2026-06-19 that this is not a zero-day; the root cause is exposure of management interfaces combined with weak or legacy credential storage.

Attackers are scanning for exposed Fortinet admin/SSL-VPN interfaces, testing credentials (credential stuffing, password spraying, leaked Fortinet hashes), cracking stolen configs with a 45-GPU cluster, and then selling verified initial access indexed by country, sector, and revenue.

Affected Products / Services

  • Fortinet FortiGate / FortiOS devices
  • Exposed management interfaces (HTTP/HTTPS admin)
  • Exposed SSL-VPN portals
  • Devices that were previously compromised/backdoored and then patched, leaving persistence

Impact

  • Confidentiality: Admin credentials harvested; configs exfiltrated; traffic intercepted.
  • Integrity: Unauthorized config changes; potential persistence/backdoors.
  • Availability: Devices can be repurposed as network footholds; downstream Active Directory compromise reported.
  • Initial access marketplace: Verified credentials are being sold, lowering the barrier for ransomware/espionage actors.

Comfac Relevance

Comfac deploys and manages network-edge devices (pfSense/Netgate, but Fortinet may appear in client environments or through acquired/legacy infrastructure). Key relevance:

  • Any Fortinet device under management must have its admin interface off the public internet.
  • Legacy SHA-256 password hashes in stolen configs are crackable at scale; recent FortiOS versions moved to PBKDF2, but only if admins logged in after the update.
  • This is a clear example of why the CGG hardening doctrine requires management-plane segmentation, MFA, and regular credential rotation.

Recommended Actions

  • [ ] Inventory all Fortinet devices in Comfac/CTO and client environments — owner SCA — due 2026-07-11.
  • [ ] Verify no Fortinet management/SSL-VPN interface is exposed to the internet; remove or restrict by source IP/VPN — owner Network team — due 2026-07-11.
  • [ ] Ensure all FortiOS devices are on a recent firmware supporting PBKDF2 credential storage and force admin re-login — owner Network team — due 2026-07-18.
  • [ ] Rotate all Fortinet admin credentials and review logs for unknown admin IPs or AD lateral movement — owner Security team — due 2026-07-18.
  • [ ] Enable MFA on all Fortinet admin accounts per Fortinet advisory — owner Security team — due 2026-07-18.
  • [ ] Add FortiBleed to client hardening review checklist and proactively notify managed clients — owner SCA + Network team — due 2026-07-25.

Related Controls / Links

  • Fortinet advisory: https://www.fortinet.com (search "FortiBleed" / June 2026 advisory)
  • Lawrence Systems video & forum post: https://lawrence.video/fortinet
  • Kevin Beaumont analysis: open-directory technical analysis of attacker infrastructure
  • ISO/IEC 27001:2022 control: A.5.7 Threat intelligence, A.8.5 Secure authentication, A.8.16 Monitoring activities
  • Hardening control: work/CGG-Hardening/251129-system-hardening-win2lin-strategy.md — management-plane segmentation, MFA, breach-response doctrine
  • IT-knowledge guide: tools/IT-knowledge/security/wordpress-hardening-checklist.md (use as pattern for network-device hardening checklist)

Logged by SCA on 2026-07-04.

Sector: Network security / firewalls / MSPs / any organization using Fortinet Status: Monitoring / action required for any exposed Fortinet devices Source: Lawrence Systems / Kevin Beaumont / Fortinet advisory (see links below)