Comfac Security & Privacy News

Plain-language security and privacy news for everyday people β€” backed by the detailed notes Comfac IT and the Security & Compliance Assistant (SCA) keep for vendor risk, accreditation, and internal hardening.

About this page

This page translates the SCA's threat-intelligence notes into language regular people can use. A major source we draw from is the Consumer Rights Wiki, including coverage rooted in the Louis Rossmann channel and the right-to-repair movement. The same events are documented in depth in work/security-iso because there is a constant stream of AI-generated advice, marketing, and news telling us that handing over ownership, privacy, and control is "no big deal" or "the only way." That narrative is wrong, and it costs people and businesses every day. Each card gives you the short version, the full story, and the original source so you can decide for yourself.

Big Tech Privacy & Security Violations, July 2025 β€” July 2026

🟠 High 2026-07-13

This note reproduces a compiled report on major privacy violations, security breaches, and Terms of Service changes by Amazon, Google, Meta, and Microsoft between July 2025 and July 2026. Total financial penalties in the United States alone exceed $4 billion, with additional billions in EU fines. The report documents the erosion of privacy rights that billions of users take for granted.

…

Read full article

Summary

This note reproduces a compiled report on major privacy violations, security breaches, and Terms of Service changes by Amazon, Google, Meta, and Microsoft between July 2025 and July 2026. Total financial penalties in the United States alone exceed $4 billion, with additional billions in EU fines. The report documents the erosion of privacy rights that billions of users take for granted.

Impact on regular people: Even when you turn tracking off, pay for a product, or read the terms, these companies keep finding ways to collect data, restrict repair, change rules after purchase, and lock you in. The report shows that these are not isolated mistakes β€” they are repeated patterns.

Why the "it's fine" narrative is wrong

The common defense is that "everyone accepts these terms," "you have nothing to hide," or "this is the price of convenience." The evidence in this report contradicts that: users explicitly turned tracking off and were tracked anyway; hardware features already built into devices were sold back as subscriptions; terms were changed after purchase with no opt-out; and personal data was used to train AI models without clear consent. These are business-model choices, not technical necessities.

Open Source and consumer rights as the counterweight

Open-source software, right-to-repair laws, and community resources like the Consumer Rights Wiki are the main practical defenses against this erosion. They restore transparency, modifiability, longevity, and user control.


Executive Summary

Over the past twelve months β€” from July 2025 to July 2026 β€” the world's four largest technology companies have faced an unprecedented wave of regulatory enforcement, legal judgments, and public scrutiny over their handling of personal data. This report documents every major privacy violation, security breach, and Terms of Service change affecting Amazon, Google, Meta, and Microsoft during this period. The total financial penalties assessed against these four companies exceed $4 billion in the United States alone, with additional billions in European Union fines. But the true cost is measured not in dollars β€” it is measured in the erosion of fundamental privacy rights that billions of users take for granted every day.

Key Findings at a Glance

  • Amazon paid a historic $2.5 billion FTC settlement for secretly enrolling millions of consumers in Prime subscriptions and making cancellation nearly impossible.
  • Google was ordered to pay $425 million in a class action for tracking users who explicitly turned off tracking, plus a $135 million settlement for secretly using Android users' cellular data.
  • Meta was fined EUR 200 million under the EU Digital Markets Act for forcing users to either pay for privacy or surrender their data, and began training AI models on Europeans' public social media posts without clear consent.
  • Microsoft's Windows Recall feature sparked global privacy outrage by taking screenshots of users' screens every few seconds, while Copilot vulnerabilities exposed corporate secrets through AI-assisted attacks.

Amazon: Violations & Regulatory Actions

The $2.5 Billion FTC Settlement (September 2025)

In September 2025, the Federal Trade Commission secured the largest settlement in its history against Amazon.com, Inc. and two senior executives β€” Senior Vice President Neil Lindsay and Vice President Jamil Ghani. The company was ordered to pay a staggering $1 billion civil penalty and provide $1.5 billion in consumer refunds to approximately 35 million Americans harmed by deceptive Prime subscription practices. The FTC's investigation revealed that Amazon knowingly designed what regulators called 'subscription traps' β€” deliberately confusing user interfaces that led consumers to enroll in Prime without their knowledge. Internal Amazon documents showed executives privately describing their practices as 'shady' and calling unwanted subscriptions 'an unspoken cancer.' The company then made cancellation extraordinarily difficult, requiring consumers to navigate a complex, multi-step process that internal tests showed was intentionally designed to prevent them from leaving. FTC Chairman Andrew N. Ferguson stated: 'The evidence showed that Amazon used sophisticated subscription traps designed to manipulate consumers into enrolling in Prime, and then made it exceedingly hard for consumers to end their subscription.' The $1 billion civil penalty is the largest ever in a case involving an FTC rule violation.

  • Source: FTC Press Release β€” FTC.gov

Ring Facial Recognition Class Action (June 2026)

In June 2026, Amazon and its Ring subsidiary were hit with a major class action lawsuit over the 'Familiar Faces' facial recognition feature launched in December 2025. The suit, filed by Hagens Berman in the U.S. District Court for the Western District of Washington, alleges that Ring captures and stores biometric facial recognition data of passersby without their knowledge or consent. While Ring doorbell owners can opt into the Familiar Faces feature, the people walking past their homes or businesses cannot. The lawsuit states that Amazon retains this facial biometric data for up to six months, even for individuals who are never saved by a Ring user. The feature is banned in Texas, Illinois, and Portland, Oregon due to strict local biometric privacy laws β€” but operates freely in the remaining 47 states. U.S. Senator Edward Markey wrote to Amazon in October 2025: 'Amazon's system forces non-consenting bystanders into a biometric database without their knowledge or consent. This is an unacceptable privacy violation.' The proposed class encompasses millions of individuals across the United States.

  • Source: Class Action Filing β€” Hagens Berman
  • Related: CBS News Coverage β€” CBS News

AWS Security Breaches (2025)

Amazon Web Services, which hosts a significant portion of the internet's infrastructure, suffered multiple serious security incidents in 2025. In January 2025, a ransomware group known as Codefinger targeted AWS users by exploiting compromised credentials, using Amazon's own server-side encryption tools to lock victims out of their data and demanding ransom payments. The attackers leveraged SSE-C (server-side encryption with customer-provided keys) to encrypt S3 bucket data with AES-256 keys that Amazon does not retain, making decryption impossible without the attackers' cooperation. In December 2025, AWS experienced another major breach when attackers compromised numerous customer accounts through stolen IAM (Identity and Access Management) credentials, subsequently exploiting EC2 and ECS instances for an extensive crypto-mining operation. The breach, discovered on December 17, 2025, potentially affected thousands of users and raised significant concerns about cloud credential security. Amazon launched an internal investigation and advised users to update IAM credentials and implement multi-factor authentication.

  • Source: AWS Security Blog β€” BlackFog

Google: Violations & Regulatory Actions

$425 Million Privacy Verdict (September 2025)

In September 2025, a federal jury ordered Google to pay $425.7 million for privacy violations affecting approximately 98 million users. The case centered on Google's 'Web & App Activity' setting, which the company represented as a way for users to control data collection. Even when users turned this setting off or paused it, Google continued transmitting their data from non-Google branded apps back to its servers for profiling and advertising purposes. The jury found Google liable for invasion of privacy and intrusion upon seclusion, though it declined to find violations of California's Computer Data Access and Fraud Act. The award was significantly lower than the $31 billion in damages initially sought by plaintiffs. After Google appealed, the judge ordered the company to pay interest on the $425 million from the date of the initial verdict. Both Google's motion to decertify the class and plaintiffs' motion to increase the payout were denied. Eligible class members include anyone with a non-enterprise Google account who turned off or paused 'Web & App Activity' between July 1, 2016 and September 23, 2024, yet still had their data transmitted to Google from non-Google apps.

  • Source: Kiplinger β€” Kiplinger
  • Legal Analysis: Thompson Coburn β€” Thompson Coburn

$135 Million Android Data Settlement (March 2026)

In March 2026, Google agreed to a $135 million class action settlement over allegations that Android devices secretly used cellular data paid for by users to transmit tracking information back to Google. The lawsuit, Joseph Taylor v. Google LLC, covers over 100 million Americans with Android devices who used cellular data between November 12, 2017 and the date of final approval. Plaintiffs alleged that Google 'effectively forces users to subsidize its surveillance by secretly programming Android devices to constantly transmit user information.' This data collection allegedly occurred even when users had shut down apps or disabled location tracking. The settlement provides automatic cash payments (capped at $100 per person) via electronic payment methods including PayPal, Venmo, or Zelle. Notably, a separate parallel lawsuit in California covering approximately 14 million Android users settled for $314.6 million in July 2025, meaning California residents are excluded from the federal settlement. As part of both settlements, Google agreed to significant injunctive relief to better protect Android user privacy.

  • Source: ClassAction.org β€” ClassAction.org
  • Source: CNET β€” CNET

DOJ Antitrust Remedies (September 2025 β€” April 2026)

In August 2024, Judge Amit Mehta ruled that Google had illegally maintained a monopoly in general search services and search text advertising. The remedies phase concluded in September 2025 with a landmark order that fundamentally restructures Google's business practices. The court imposed a six-year prohibition on exclusive default search contracts covering Google Search, Chrome, Google Assistant, and the Gemini app on devices manufactured by Apple, Samsung, and other partners. The order requires Google to share its search index and user-interaction data (excluding advertising data) with qualified competitors β€” a mandate Google is aggressively appealing, citing 'irreparable harm' to user privacy. The court also ordered annual rebidding of default search contracts and established a five-member Technical Committee to oversee compliance. In April 2026, the DOJ filed a cross-appeal seeking stronger remedies, including forced divestiture of Chrome and an outright ban on the $20 billion annual Apple default search deal. Both appeals are expected to be heard by the D.C. Circuit in late 2026 or early 2027, with potential Supreme Court review extending into 2028.

  • Source: NPR β€” NPR
  • Source: Tech Insider β€” Tech Insider

Meta: Violations & Regulatory Actions

EUR 200 Million DMA Fine (April 2025)

In April 2025, the European Commission imposed a EUR 200 million fine on Meta for breaching the Digital Markets Act (DMA) through its 'pay or consent' advertising model. Between November 2023 and November 2024, Meta presented EU users with a binary choice: either consent to comprehensive personal data harvesting for personalized advertising, or pay a monthly subscription fee of up to EUR 9.99 for an ad-free experience. The Commission determined that this model did not provide users with a genuine, equivalent alternative that used less of their personal data. Under Article 5(2) of the DMA, gatekeepers must obtain user consent before combining personal data across services, and users who refuse must have access to a less personalized but equivalent experience. Meta's model violated both requirements. In response to the fine, Meta introduced a third 'less personalized ads' option in January 2026, but consumer groups including BEUC found that the option was not presented equally with the other choices and imposed 'ad breaks' that degraded the user experience. The Commission continues monitoring Meta's compliance.

  • Source: European Commission β€” EU Digital Markets Act
  • Source: BEUC Assessment β€” BEUC

AI Training on EU User Data (May 2025)

On May 27, 2025, Meta began using public posts, photos, captions, and comments from adult EU users of Facebook and Instagram to train its artificial intelligence models. The company relied on 'legitimate interest' under GDPR Article 6(1)(f) rather than obtaining explicit user consent β€” a legal basis that privacy advocates strongly dispute. The Irish Data Protection Commission (DPC), Meta's lead EU regulator, initially halted the plans in June 2024 but ultimately allowed them to proceed after Meta implemented improvements including updated transparency notices, an easier-to-use objection form, and data protection measures like de-identification and filtering. However, Hamburg's data protection authority initiated urgent proceedings demanding suspension of AI training on German users' data. The privacy organization NOYB ('None of Your Business'), led by activist Max Schrems, sent a cease-and-desist letter threatening collective legal action. Schrems stated: 'Meta's absurd claims that stealing everyone's personal data is necessary for AI training is laughable. Other AI providers do not use social network data β€” and generate even better models than Meta.' Crucially, once data is used to train AI models, it cannot be 'extracted' β€” making the objection process a race against time.

  • Source: European Newsroom β€” European Newsroom
  • Source: noyb β€” noyb.eu

WhatsApp Antitrust Order (June 2026)

In June 2026, the European Commission ordered Meta to restore access for rival AI assistants to its WhatsApp messaging platform within five days. The order came after Meta updated its terms in October 2025 to ban third-party AI chatbots from WhatsApp entirely, reserving the platform exclusively for Meta's own AI assistant. The Commission stated the intervention was necessary to prevent 'serious and irreparable harm to competition in this growing market by Meta's conduct.' Meta reacted furiously, accusing the Commission of 'regulatory overreach' and announcing plans to appeal. The interim measures require Meta to maintain access for rival AI providers until the antitrust investigation concludes. This case highlights Meta's broader strategy of leveraging its dominant messaging platform β€” used by approximately 80% of Europeans β€” to favor its own AI services over competitors. The White House has previously intervened on Meta's behalf when EU regulators have acted against the company.

  • Source: European Commission β€” EC Press
  • Source: Le Monde β€” Le Monde

Microsoft: Violations & Regulatory Actions

Windows Recall Privacy Controversy (2024-2025)

Microsoft's Recall feature, announced in 2024 and rolled out to Copilot+ PCs in May 2025, represents one of the most controversial privacy features in modern computing history. Recall takes screenshots of a user's screen every few seconds, uses on-device AI to analyze the content, and builds a searchable database of everything the user has ever viewed or typed on their PC β€” including passwords, financial documents, medical records, and private messages. Following massive public backlash and security researcher criticism, Microsoft made Recall opt-in rather than enabled by default, added Windows Hello biometric authentication requirements, and implemented encryption. However, the company clarified that Recall cannot be fully uninstalled β€” only disabled. The feature remains excluded from the European Economic Area, where regulators deemed it incompatible with GDPR requirements. Security researchers documented that if a device is compromised by malware, an attacker could potentially access the entire Recall database, extracting sensitive information stored in screenshots. In January 2026, Microsoft confirmed a bug causing Recall to capture screenshots of confidential emails and bypass data loss prevention policies β€” an issue that had persisted since late January 2026 before being patched.

  • Source: nGuard Security Analysis β€” nGuard

Copilot Security Vulnerabilities (2025-2026)

Microsoft 365 Copilot has been plagued by a series of serious security vulnerabilities that expose corporate data to unauthorized access. In May 2025, researchers at Aim Security disclosed CVE-2025-32711 ('EchoLeak'), the first documented zero-click vulnerability in a production AI system, rated CVSS 9.3 out of 10. The vulnerability allowed attackers to exfiltrate data from Copilot's context without any user interaction β€” simply by sending a crafted email that Copilot would later process. Other documented attack vectors include ASCII Smuggling (using invisible Unicode characters to hide stolen data in hyperlinks), Mermaid Diagram Exfiltration, Confidential Label Bypass (January 2026), and Indirect Prompt Injection via Email. The fundamental risk, however, is not exotic vulnerabilities but 'oversharing' β€” Copilot inherits all permissions a user has across SharePoint, OneDrive, and Teams, instantly making every poorly permissioned document searchable and summarizable by AI. In March 2024, the European Data Protection Supervisor found the European Commission itself in breach of data protection law for its use of Microsoft 365, citing insufficient specification of data collection and missing transfer safeguards. The breaches were remediated by July 2025, but the ruling set a precedent for all EU organizations using Microsoft cloud services.

  • Source: Security Today β€” Security Today
  • Source: SURF Netherlands β€” SURF

Azure Security Incidents (2025-2026)

Microsoft Azure faced critical security challenges throughout 2025. In early 2025, researchers identified CVE-2025-55241, a vulnerability in Microsoft Entra ID (formerly Azure Active Directory) that could allow attackers to impersonate global administrators across tenants. Microsoft rated the vulnerability as critical (CVSS 10.0) and issued an emergency patch, though the flaw demonstrated the fragility of cloud identity boundaries. In May 2026, Microsoft Threat Intelligence disclosed a sophisticated attack by threat actor Storm-2949 that turned a single compromised identity into a full cloud-wide breach. The attackers leveraged legitimate Azure management features to execute code remotely on virtual machines, access Key Vaults, manipulate SQL server firewall rules, and exfiltrate massive volumes of data from Azure Storage accounts using custom Python scripts. The attack spanned SaaS, PaaS, and IaaS layers, demonstrating that cloud identity compromise is now the primary vector for enterprise breaches. Additionally, in July 2025, a ProPublica investigation revealed that Microsoft had hired engineers in China to maintain federal defense systems, supervised by American 'digital escorts' with limited technology experience. The Office of the Director of National Intelligence has called China the 'most active and persistent cyber threat to U.S. Government, private-sector, and critical infrastructure networks.'

  • Source: Microsoft Security Blog β€” Microsoft Security

Terms of Service & Privacy Policy Changes

Amazon β€” BSA Update (March 2026)

Effective March 4, 2026, Amazon updated its Business Solutions Agreement with a new 'Agent Policy' that requires all automated systems accessing Amazon services to clearly identify themselves, comply continuously with policy terms, and cease access immediately if requested by Amazon. The policy prohibits using Amazon materials for AI development and gives Amazon broad authority to revoke access from any automated system without prior notice or explanation. Critically, sellers and software providers who continued using Amazon's services after March 4 automatically accepted these updated terms with no option to opt out. The changes effectively closed the data pipeline that third-party tools had used for years, consolidating Amazon's control over its marketplace data while restricting external AI development.

Meta β€” Privacy Policy Update (December 2025)

Meta's updated Privacy Policy, effective December 16, 2025, governs how user data is collected, used, and shared across Facebook, Instagram, and Messenger. The policy introduced new provisions for AI training data usage and modified how users can manage their privacy settings. Simultaneously, Meta updated its Terms of Service in January 2025 with significant changes including unilateral terms updates (users automatically consent to future changes by continuing to use the platform), broad content rights for AI training, and legacy contact provisions for posthumous account management. Critically, the new Terms allow Meta to use user content for AI and machine learning purposes without explicit opt-in consent. While Meta claims it does not 'sell' personal data, the updated language grants broad licensing rights that many privacy advocates argue effectively enables unrestricted AI training on user content. The terms also state that by simply using the platform, users automatically agree to any future changes β€” a practice that removes meaningful choice.

Microsoft β€” Multiple Updates (2025-2026)

Microsoft updated its Services Agreement on September 30, 2025, with changes including new provisions for exportable data, updated Xbox and Minecraft EULA references, Skype retirement accommodations, and new restrictions on AI services usage. The Privacy Statement underwent significant revisions in March and June 2026, reorganizing sections, adding Copilot-specific privacy controls, updating personalized advertising language, introducing new diagnostic data subsections, and adding age-appropriate experience provisions for the Microsoft Store. The June 2026 Privacy Statement update added information about access, export, and deletion controls in Microsoft Copilot and Microsoft 365 Copilot, clarified how Copilot in Edge processes page content and browsing history, and removed references to health-related ad targeting. Microsoft also updated its 'Artificial Intelligence and Copilot capabilities' section to describe how Copilot Health uses information for personalized health and wellness assistance.

Appendix: Additional Violations & Incidents

The following incidents, while smaller in financial impact or regulatory scope, represent important patterns in how these companies handle user data and respond to privacy concerns. Each entry includes a brief summary and source link for further investigation.

Amazon β€” Additional Incidents

  • Luxembourg GDPR Fine Appeal Upheld (March 2025) β€” Amazon's appeal of a EUR 746 million GDPR fine for processing personal data for targeted advertising without proper consent was rejected by Luxembourg's Administrative Court. The fine, originally issued in July 2021, remains one of the largest GDPR penalties ever imposed. Source
  • Codefinger Ransomware (January 2025) β€” Ransomware group Codefinger targeted AWS users by exploiting compromised credentials, using AWS's SSE-C encryption to lock victims out of their own S3 buckets with encryption keys Amazon does not retain. Source

Google β€” Additional Incidents

  • Privacy Sandbox Shutdown (October 2025) β€” Google officially discontinued its Privacy Sandbox initiative after six years, abandoning plans to replace third-party cookies. The reversal followed regulatory pressure from the UK CMA, EU authorities, and U.S. DOJ antitrust scrutiny. Source
  • $314.6M California Android Settlement (July 2025) β€” A separate California class action covering approximately 14 million Android users settled for $314.6 million over similar allegations of unauthorized cellular data collection for tracking purposes. Source

Meta β€” Additional Incidents

  • EUR 800 Million Antitrust Fine (November 2024) β€” The European Commission fined Meta EUR 800 million for tying its Facebook Marketplace classified ads service to its social network and imposing unfair trading conditions on competing ad providers. Source
  • EUR 91 Million Plaintext Password Fine (September 2024) β€” Ireland's DPC fined Meta EUR 91 million for storing certain Facebook user passwords in plaintext within internal systems since 2019, violating GDPR Article 5(1)(f) requiring appropriate security measures. Source
  • EUR 251 Million 2018 Breach Fine (September 2024) β€” The DPC fined Meta EUR 251 million for a 2018 Facebook breach that exposed personal data of 29 million users through a flaw in the 'view as' feature. Source

Microsoft β€” Additional Incidents

  • LinkedIn EUR 310 Million GDPR Fine (October 2024) β€” Ireland's DPC fined LinkedIn (owned by Microsoft) EUR 310 million for processing user data without proper consent for behavioral analysis and targeted advertising. Source
  • Austrian Kids' Data Violation (October 2025) β€” Austria's data protection authority found Microsoft violated EU law in its handling of children's data, marking another European enforcement action against the company's data practices. Source
  • M365 Copilot Confidential Email Bug (January 2026) β€” Microsoft confirmed a bug causing Copilot to summarize confidential emails since late January 2026, bypassing data loss prevention policies. An emergency patch was released. Source
  • SharePoint Zero-Day (July 2025) β€” Hackers exploited a zero-day vulnerability in Microsoft SharePoint impacting businesses, federal agencies, and universities globally. Emergency patches were released but some platform versions remained vulnerable. Source

Your Privacy Matters

  • Document compiled for privacy advocacy and public awareness.
  • All sources verified and linked. This document is intended for educational and advocacy purposes to inform the public about their digital rights.

Comfac Relevance

  • Vendor risk: Comfac uses Google Workspace, Microsoft 365, Azure, AWS, and other services documented in this report. These incidents belong in vendor-risk reviews and DPO evidence.
  • Client accreditation: The report provides independent, cited examples of vendor behavior for security questionnaires and ISO 27001 evidence.
  • Awareness: The public Security & Privacy News page surfaces these patterns so employees, clients, and the public can recognize them.

Related Notes

References

  • Original document: work/security-iso/BigTech_Privacy_Violations_2025-2026.docx

Converted to markdown and added to the security-privacy news feed on 2026-07-13.

Sector: Big Tech / privacy / consumer rights Source: `work/security-iso/BigTech_Privacy_Violations_2025-2026.docx`

Australian Consumer Law: Unfair Contract Terms and Unilateral Changes

🟑 Medium 2026-07-13

Under the Australian Consumer Law (ACL), a business cannot force consumers and small businesses to accept one-sided changes to a standard-form contract. Unilateral variation clausesβ€”terms that let one party change the agreement without the other party's consentβ€”are a prime example of potentially unfair contract terms and can be declared void by a court.

…

Read full article

Summary

Under the Australian Consumer Law (ACL), a business cannot force consumers and small businesses to accept one-sided changes to a standard-form contract. Unilateral variation clausesβ€”terms that let one party change the agreement without the other party's consentβ€”are a prime example of potentially unfair contract terms and can be declared void by a court.

Impact on regular people: If a big company updates its terms and conditions and tells you to "take it or leave it," you may have the right to reject the change and keep the status quo, or even terminate the contract without penalty. Since November 2023, businesses that include unfair terms in standard-form contracts can face substantial penalties, making this a serious compliance issue.


The Principle: Protecting You from Unfair "Take-It-Or-Leave-It" Terms

The core of this protection is the concept of unfair contract terms under the Australian Consumer Law (ACL). This applies to standard form contractsβ€”the kind that are typically offered on a "take it or leave it" basis, where you have little or no room to negotiate.

A key rule in this area specifically targets clauses that allow one party (usually the bigger business) to unilaterally change the contract. These are often called unilateral variation clauses and are considered a prime example of a potentially unfair term. The law strongly encourages that you should have a choice to keep your existing status quo if a company unilaterally imposes a change.

Key Protections Under Australian Law

To reinforce this point, here's how the law works in practice:

  • Unfair Terms Are Void: If a court finds a term is unfair, it's treated as if it never existed. This protects you from being bound by the change.
  • Substantial Penalties for Companies: Since November 2023, it's illegal for a business to include unfair terms in a standard form contract. Companies can now face massive penalties if they do, making compliance a serious issue.
  • Right to Terminate: When a company tries to change a contract unilaterally, you often have the right to terminate the contract to avoid the new terms, ideally without being penalized.

The Bottom Line

The legal framework in Australia is designed to ensure that a big company can't just update its terms and conditions and force you to accept them without a fair opportunity to reject the change and walk away. The law is on your side to help maintain the "status quo" you originally agreed to.


Why the "it's fine" narrative is wrong

You will often hear that "everyone accepts updated terms," that "you have nothing to hide," or that a company "only uses data to improve services." The Australian Consumer Law says otherwise: if a business can change the rules whenever it wants β€” and you have no real choice but to accept β€” the term can be declared void. "Agreeing" under pressure is not the same as consent, and "free" services that collect personal data are not actually free.

Comfac Relevance

  • Vendor contract review: When Comfac signs standard-form SaaS, cloud, or service contracts, unilateral variation clauses should be flagged and negotiated or documented as a risk.
  • Client accreditation: Security and compliance questionnaires may ask how Comfac handles changes to processor/sub-processor terms; this ACL principle can be cited when reviewing vendor agreements.
  • DPO / legal awareness: The principle aligns with broader data-protection and consumer-protection expectations: changes that affect personal data processing should not be imposed without notice and choice.

References

  • ACCC β€” Unfair contract terms: https://www.accc.gov.au/consumers/consumer-rights-guarantees/unfair-contract-terms
  • Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010)
Sector: Consumer protection / contract law / regulatory risk Source: https://www.accc.gov.au/consumers/consumer-rights-guarantees/unfair-contract-terms

Consumer Rights Wiki β€” MegaCorporation Violations Index

🟑 Medium 2026-07-13

The Consumer Rights Wiki is a major, community-run source for consumer-protection news and documentation. It tracks anti-competitive behavior, privacy violations, repair restrictions, and other harmful practices by large companies. A significant portion of its coverage and community energy comes from the Louis Rossmann channel and the right-to-repair movement.

…

Read full article

Summary

The Consumer Rights Wiki is a major, community-run source for consumer-protection news and documentation. It tracks anti-competitive behavior, privacy violations, repair restrictions, and other harmful practices by large companies. A significant portion of its coverage and community energy comes from the Louis Rossmann channel and the right-to-repair movement.

This note indexes megacorporation pages and cross-cutting topics that are relevant to the Comfac Security & Privacy News feed. It will be updated as CRW grows.

Impact on regular people: Big companies use the same playbook β€” buried terms, data harvesting, paywalls for already-built hardware features, account lockouts, and repair restrictions. Consumer Rights Wiki collects the receipts so people can see the patterns instead of treating each incident as a one-off.

Why the "it's fine" narrative is wrong

The default message from large vendors and their marketing is that "everyone does this," "you agreed to it," or "it's necessary for convenience." The Consumer Rights Wiki shows that many of these practices are not inevitable β€” they are choices that have been challenged in court, fined by regulators, and documented by independent researchers. Convenience should not require surrendering control over devices, data, or accounts.

The erosion of ownership, privacy, and control

Across the CRW corpus, three rights are being attacked at the same time:

  1. Ownership β€” You buy a device, but the manufacturer keeps the keys. Features are gated by software, repairs are blocked, and digital purchases can be revoked after the fact. Examples include Tesla shipping cars with disabled hardware and John Deere restricting farmers from repairing their own tractors.
  2. Privacy β€” Products that should be private by default collect location, biometric data, viewing habits, and voice input, often buried in terms most people never read. Examples include Vizio's second-by-second TV tracking and Honda selling driver data to insurers.
  3. Control β€” Post-purchase terms are changed unilaterally, bait-and-switch pricing is normalized, and software updates turn functional devices into paperweights. Examples include post-purchase EULA changes and planned obsolescence through updates.

Open Source as the main bastion

Open-source software and hardware are one of the strongest practical defenses against this erosion because they keep the user in control:

  • Transparency: The code can be inspected, so hidden data collection or backdoors are harder to sustain.
  • Modifiability: Users and independent repair shops can fix, extend, or remove unwanted functionality without begging the manufacturer.
  • Longevity: Communities can continue maintaining software after a vendor abandons it, resisting forced obsolescence.
  • Portability: Open formats and protocols reduce lock-in, making it easier to leave a service or replace a device.

CRW pages such as Right to repair, DMCA Section 1201, and Planned obsolescence document the legal and technical battlegrounds where open-source and repair communities are pushing back.


Key CRW topics


Selected megacorporation violations

Google

Google has faced ongoing scrutiny over data privacy, competition, and its dominant market position since at least 2012. It has been the subject of antitrust lawsuits and regulatory challenges over the use of personal data and its impact on consumer choice.

Microsoft

Microsoft has a long history of anti-competitive and anti-consumer practices, including bundling Internet Explorer and later Edge with Windows, signing exclusive deals with PC makers, and using its market power to limit consumer choice.

Amazon

Amazon has revoked previously purchased digital content on Kindle and Luna, removed download capabilities from Prime Music in some regions, and promoted its "Just Walk Out" stores as AI-powered while reportedly relying on workers in India to track customers.

Sony

Sony's controversies include the 2005 Sony BMG rootkit, which installed copy-protection software that secretly tracked users and created security holes, leading to lawsuits and recalls. The company has also faced ongoing disputes over digital content management.

Vizio

Vizio's business model treats the television as a delivery mechanism for advertising and data collection. The FTC found in 2017 that Vizio collected second-by-second viewing data from 11 million smart TVs without meaningful consent.

Netflix

Netflix has restricted access to content through tiered pricing, cracked down on password sharing, and disclosed extensive collection of biometric information, location data, IP addresses, and voice input from users.

Tesla

Tesla has shipped cars with hardware features disabled by software, requiring one-time or subscription payments to unlock functionality such as extra range, acceleration, or heated seats that are physically already installed.

Honda

Honda collected driver information and sold it to a third party called Verisk, which resold it as "driver reports" to insurance companies. The data was used to raise premiums, often without clear consumer consent.


How Comfac uses this source

  • Vendor risk: CRW pages can be cross-checked during vendor evaluations for Google Workspace, Microsoft 365, AWS, and other services.
  • Client accreditation: Provides independent, cited examples of vendor behavior for security questionnaires and DPO evidence.
  • Public awareness: The Security & Privacy News page can surface CRW-sourced summaries to help regular people recognize recurring patterns.

Related notes

References

  • Consumer Rights Wiki main page: https://consumerrights.wiki/w/Main_Page
  • Consumer Rights Wiki company pages linked above

Indexed by SCA on 2026-07-13. Update this note as new CRW pages or incidents become relevant.

Sector: Consumer rights / corporate accountability / privacy Source: https://consumerrights.wiki/w/Main_Page

Major Tech Privacy Violations and Allegations β€” Google, Microsoft, Amazon

βšͺ Informational 2026-07-13

A chronological compilation of major privacy violations and allegations involving Google, Microsoft, and Amazon from July 2026 back to January 2025. The list covers cloud scanning, device data collection, browser tracking, AI training, child-data collection, and biometric surveillance.

…

Read full article

Summary

A chronological compilation of major privacy violations and allegations involving Google, Microsoft, and Amazon from July 2026 back to January 2025. The list covers cloud scanning, device data collection, browser tracking, AI training, child-data collection, and biometric surveillance.

Impact on regular people: These cases show that opting out of tracking is often ignored, devices continue to send data after being "turned off," and AI features may rely on personal data without clear consent. For Comfac, they feed vendor-risk assessments for Google Workspace, Microsoft 365, Azure, AWS, and IoT procurement.

Google

July 2026: Google Drive CSAM Detection Raises Privacy Concerns

Google's automated safety systems flagged alleged child sexual abuse material (CSAM) stored on a user's Google Drive account, leading to the arrest of a 19-year-old man in Kanpur, India. While the arrest was welcomed, the case sparked a debate about user privacy on cloud services, with many questioning how much visibility Google has into files stored on personal accounts.

July 2026: Google Pixel 9 Raises Privacy Concerns

Researchers analyzing the Google Pixel 9 Pro XL found that the smartphone frequently transmits private user data to Google before any app is installed, raising concerns about user privacy and security.

June 2026: Chrome Incognito Mode Privacy Case Advances

A federal judge denied Google's motion to dismiss most claims in a lawsuit brought by Chrome users who allege they were tracked while in Incognito mode despite Google's claims to the contrary. The claims include violations of the Wiretap Act and California privacy laws.

June 2026: EU Consumer Groups Accuse Google of Online Tracking

European consumer groups accused Google of violating online privacy by pushing users to sign in to Google accounts so their data could be tracked and exploited for profit, in violation of GDPR rules.

April 2026: Audit Finds Google Fails to Honor Privacy Opt-Outs 86% of the Time

A forensic audit by webXray found that when California users tell websites to stop tracking them via Global Privacy Control (GPC), Google ignores that request 86% of the time. Google's ad servers were found to routinely disregard the GPC signal and create two-year advertising cookies on users' devices.

January 2026: Google Agrees to $68 Million Settlement Over Google Assistant Secret Listening

Google agreed to pay $68 million to settle a lawsuit alleging that Google Assistant was activated without user consent and secretly recorded private conversations, which were then sent to Google's servers. The lawsuit claimed that unintentional activations resulted in the collection and transmission of private conversations without users' knowledge.

January 2026: Jury Finds Google Violated Privacy by Collecting Data After Opt-Out

A jury found that Google violated users' privacy by continuing to collect data even after they opted out of app activity tracking, awarding more than $425 million in compensatory damages to a class of over 100 million users.

November 2025: Google Continues Collecting Data from Downgraded Nest Thermostats

After Google turned off remote control functionality for first- and second-generation Nest Learning Thermostats, security researcher Cody Kociemba found that the devices were still sending Google extensive data, including temperature, humidity, ambient light, motion, and manual temperature changes. Google acknowledged the data transmission in its support documentation but could no longer use the information to assist customers since support had been discontinued.

May 2025: Belgian Court Rules Tracking-Based Advertising Framework Illegal

The Brussels Court of Appeal ruled that the Transparency & Consent Framework (TCF)β€”used by Google, Microsoft, Amazon, and others for tracking-based advertisingβ€”is illegal under EU privacy law, finding it fails to meet GDPR requirements for user consent and transparency.

February 2025: Court Rejects Google's Effort to Invalidate Mass Opt-Out in Assistant Privacy Case

A California federal court rejected Google's efforts to invalidate the mass opt-out of over 69,000 plaintiffs in the In re Google Assistant Privacy Litigation, which centers on claims that Google Assistant devices unintentionally recorded private conversations through "False Accepts".

January 2025: Amsterdam Court Allows Class Action Against Google Over Android Privacy

An Amsterdam court allowed a representative claim to proceed against Google for unlawfully infringing the privacy of Android phone users.


Microsoft

July 2026: Microsoft Fined $20 Million Over Child Data Violations

Microsoft agreed to pay $20 million to settle FTC charges that it collected personal information from children under 13 who signed up for Xbox without their parents' consent, in violation of COPPA. The FTC alleged that Microsoft collected names, email addresses, and birth dates from children and retained this information.

June 2026: Microsoft Illegally Tracked Students, Austrian DPA Finds

Austria's data protection authority determined that Microsoft illegally tracked students using Microsoft 365 Education software, installing cookies that collect browser data for advertising purposes. Microsoft was ordered to provide users access to their personal data.

June 2026: Microsoft to Tighten Controls After Israeli Surveillance Inquiry

Following an inquiry into how the Israeli military used Microsoft's cloud technology for mass surveillance of Palestinians, Microsoft said it would tighten human-rights controls when working with national security agencies.

April 2026: Audit Finds Microsoft Tracks Users After Opt-Out

The webXray audit found that Microsoft's tracking network receives Global Privacy Control (GPC) signals and unconditionally returns a one-year MUID cookie regardless of the user's privacy settings.

March 2026: Microsoft 365 Copilot Introduces New Data Protection Risk

Microsoft introduced "flex routing" for Microsoft 365 Copilot data traffic, which enabled data transfers outside of the EU Data Boundary, introducing a new data protection risk.

December 2025: ICCL Files Complaint Against Microsoft Over Israeli Data Processing

The Irish Council for Civil Liberties filed a complaint against Microsoft for unlawful data processing on behalf of the Israeli Defence Forces in Gaza, alleging that Microsoft's processing of personal data facilitates war crimes and human rights violations.

September 2025: Microsoft Cuts Services to Israeli Military Unit Over Surveillance

Microsoft cut cloud and AI services to an Israeli military unit running a surveillance system that monitored millions of Palestinian calls in Gaza and the West Bank. The company found that Israel was violating terms of service by using Microsoft's cloud storage to hold surveillance data on Palestinians.

July 2025: European Commission Found in Violation Over Microsoft 365 Use

The European Data Protection Supervisor found that the European Commission violated GDPR rulesβ€”including purpose limitation and unauthorized personal data disclosuresβ€”in its use of Microsoft 365.


Amazon

July 2026: Amazon Fined $2.25 Million for Withholding Records from Fraud Victims

Amazon agreed to pay $2.25 million in civil penalties to settle FTC allegations that it knowingly violated the Fair Credit Reporting Act by refusing to provide transaction records to consumers whose personal information was used by identity thieves to commit fraud.

June 2026: Class Action Alleges Ring Cameras Collect Facial Data Without Consent

A class action lawsuit alleged that Amazon's Ring cameras collected people's facial recognition information without their consent through the "Familiar Faces" feature. The suit claims that millions of Americans are being tracked as Ring is the leading seller of front door security cameras.

March 2026: CNPD Issues Compliance Order Against Amazon Over GDPR Violations

Luxembourg's National Commission for Data Protection issued a compliance order against Amazon for breaching several provisions of the GDPR in relation to its online behavioral advertising practices.

February 2026: Senator Markey Calls on Amazon to End Ring Facial Recognition

Following Amazon's Super Bowl ad, Senator Ed Markey again called on Amazon to end facial recognition technology in Ring doorbells, noting that Ring's privacy protections only apply to device owners and not members of the public.

December 2025: Senator Markey's Probe Exposes Amazon's Ring Privacy Violations

Senator Markey released findings from his probe into Ring, exposing that Amazon's "Familiar Faces" facial recognition feature provides no privacy protections for individuals unknowingly subjected to scans. Ring requires individuals who want their biometric data deleted to request deletion from each device owner individually.

October 2025: Senator Markey Demands Amazon Abandon Ring Facial Recognition

Senator Markey demanded that Amazon abandon its plan to include facial recognition technology in Ring doorbells, stating: "Amazon's system forces non-consenting bystanders into a biometric database without their knowledge or consent".

January 2025: Amazon Hit With Lawsuit Over Location Data Collection

Amazon was sued for allegedly collecting and profiting from consumer location data through its advertising software development kit (SDK) embedded in tens of thousands of apps, in violation of California privacy laws.


Cross-Company

May 2025: Belgian Court Rules Tracking-Based Advertising Framework Illegal

The Brussels Court of Appeal ruled that the Transparency & Consent Framework (TCF)β€”relied upon by Google, Microsoft, Amazon, and X for tracking-based advertisingβ€”is illegal under EU privacy law, finding it fails to meet GDPR requirements for user consent and transparency.

April 2026: Audit Finds Google, Microsoft, and Meta Track Users After Opt-Out

The webXray forensic audit found that Google, Microsoft, and Meta all fail to honor privacy opt-outs. Google ignores GPC signals 86% of the time, Microsoft unconditionally returns tracking cookies, and Meta's tracking pixel contains no code to check for GPC at all.


Why the "it's fine" narrative is wrong

The common response to these incidents is that "you have nothing to hide," that opt-outs are honored, or that devices stop collecting data when you turn features off. The evidence here shows the opposite: opt-outs are routinely ignored, "incognito" modes are tracked, downgraded devices keep phoning home, and AI features are trained on personal data without clear consent. The problem is not user carelessness; it is a business model built on collecting more than people realize.

Comfac Relevance

  • Vendor AI / cloud assessment: These incidents feed directly into vendor risk evaluations for Google Workspace, Microsoft 365, Azure, AWS, and Nest/Ring IoT.
  • Client accreditation: Client questionnaires increasingly ask about supply-chain vendor privacy posture. This note provides evidence of recurring issues with major cloud providers.
  • DPO / ISO 27001 alignment: Use when drafting or reviewing personal-data processing agreements, cookie/tracking policies, and third-party processor assessments.
  • Synopsis / AI summarization caution: Incidents of hidden listening, post-opt-out tracking, and unauthorized facial recognition reinforce the need for strict internal controls on any AI-mediated communication or biometric processing.

Related Notes

2026-07-11 β€” Supply-Chain De-Risking: MikroTik and Netgate as Strategic Networking Stack

🟠 High 2026-07-11

Comfac/CTO is actively de-risking from Chinese-controlled or China-origin networking hardware and software. The strategic stack for the Bill of Materials (BOM) and advanced systems will be built around MikroTik and Netgate platforms.

Policy principle: Comfac/CTO will avoid any networking vendor that builds its networking products in China. This applies to routers, switches, firewalls, wireless access points, network management platforms, and any infrastructure that transports or controls client data.

This de-risking supports:

…

Read full article

Summary

Comfac/CTO is actively de-risking from Chinese-controlled or China-origin networking hardware and software. The strategic stack for the Bill of Materials (BOM) and advanced systems will be built around MikroTik and Netgate platforms.

Policy principle: Comfac/CTO will avoid any networking vendor that builds its networking products in China. This applies to routers, switches, firewalls, wireless access points, network management platforms, and any infrastructure that transports or controls client data.

This de-risking supports:

  • Data-sovereignty and national-security requirements.
  • Reduced exposure to supply-chain compromise, backdoors, and foreign-intelligence influence.
  • A controlled, auditable networking layer for the isolated security-AI environment.

Strategic Vendors / Platforms

| Platform | Role | Rationale | |----------|------|-----------| | MikroTik | Routers, switches, wireless, network management | Non-Chinese vendor; broad feature set; cost-effective; suitable for SME and branch deployments | | Netgate | pfSense / TNSR firewalls, security gateways | US-based; open-source-core firewall platform; aligns with CGG hardening doctrine |

Affected Systems / Scope

  • Core and branch office routers, switches, and wireless access points
  • Perimeter and internal firewalls
  • VPN/SD-WAN termination points
  • Management/monitoring network fabric
  • Isolated security-AI environment network boundary

Exclusion rule: Any networking product whose design, manufacturing, or firmware supply chain is China-based is out of scope for new deployments and should be replaced in existing deployments unless formally risk-accepted.

Impact

  • Supply-chain security: Replaces high-risk hardware with vendors outside the China-controlled supply chain.
  • Compliance: Supports data-localization, vendor-sovereignty, and audit evidence requirements.
  • Operational continuity: Reduces risk of remote-disable, firmware backdoors, or intelligence-driven compromise.
  • Cost architecture: MikroTik/Netgate combination provides enterprise-grade capability at SME-friendly pricing for BOMs.

Comfac Relevance

  • Client BOMs and proposals should default to MikroTik/Netgate unless a specific requirement forces another vendor.
  • Engineering and operations teams must document why Chinese-origin networking gear is excluded.
  • Security assessments should treat non-MikroTik/Netgate networking hardware as an exception requiring risk acceptance.
  • The isolated security-AI environment must be built on this de-risked network fabric.

Recommended Actions

  • [ ] Draft standard MikroTik/Netgate reference architecture for Comfac/CTO deployments β€” SCA + Network team β€” due 2026-07-25
  • [ ] Create BOM templates with MikroTik/Netgate defaults for common deployment sizes β€” SCA + Operations β€” due 2026-07-25
  • [ ] Document Chinese-networking-vendor exclusion rationale for client proposals and audit evidence β€” SCA β€” due 2026-07-18
  • [ ] Review current inventory for Chinese-origin networking hardware and plan replacement/exception handling β€” Network team β€” due 2026-08-01
  • [ ] Map MikroTik/Netgate hardening guides to CGG hardening doctrine and ISO 27001 controls β€” SCA β€” due 2026-08-01

Related Controls / Links

  • ISO/IEC 27001:2022 control: A.5.19 Information security in supplier relationships
  • ISO/IEC 27001:2022 control: A.5.20 Addressing information security within supplier agreements
  • ISO/IEC 27001:2022 control: A.5.21 Managing information security in the ICT supply chain
  • ISO/IEC 27001:2022 control: A.5.36 Compliance with policies, rules and standards for information security
  • Hardening doctrine: work/CGG-Hardening/251129-system-hardening-win2lin-strategy.md
  • Dialogue log: work/security-iso/logs/260711-security-iso-log.md
  • Vendor-risk note: security-intelligence/2026/2026-06-30-palantir-critical-systems-ban.md
  • AI-data note: security-intelligence/2026/2026-07-06-google-microsoft-ai-data-practices.md

Logged by SCA on 2026-07-11.

Sector: Networking / firewalls / critical infrastructure / supply chain Status: Active planning; BOM and architecture decisions pending Source: Justin / SCA strategic planning

2026-07-06 β€” Google & Microsoft AI Data-Training Practices

🟠 High 2026-07-06

Multiple reports indicate that Google and Microsoft are expanding use of customer/user data to train and operate AI services:

  • Google: A July 2026 TechCrunch article notes that using Google services may contribute to AI training, with opt-out mechanisms available.
  • Gmail: A January 2026 NY Post report claims Gmail is using personal data to train AI.
  • Microsoft Teams: A July 2026 report describes a new Teams AI feature that listens to meetings and can answer before being asked; it is reportedly not on by default.

…

Read full article

Summary

Multiple reports indicate that Google and Microsoft are expanding use of customer/user data to train and operate AI services:

  • Google: A July 2026 TechCrunch article notes that using Google services may contribute to AI training, with opt-out mechanisms available.
  • Gmail: A January 2026 NY Post report claims Gmail is using personal data to train AI.
  • Microsoft Teams: A July 2026 report describes a new Teams AI feature that listens to meetings and can answer before being asked; it is reportedly not on by default.
  • Microsoft Copilot OS: A leaked video shows a Windows OS exploration built around Copilot/agentic AI.
  • Microsoft / OpenAI: The New York Times alleges Microsoft built a copyright-infringing supercomputer to assist OpenAI.

Affected Products / Services

  • Google Search / Google Workspace / Gmail
  • Microsoft 365 / Microsoft Teams / Copilot
  • Windows (Copilot OS exploration)
  • OpenAI infrastructure hosted on Microsoft Azure

Impact

  • Confidentiality: Business communications and documents may be processed by vendor AI models.
  • Compliance: Potential conflicts with client confidentiality, NPC data-privacy expectations, and ISO 27001 control A.5.34 (privacy and personally identifiable information protection).
  • Intellectual property: Content fed into AI models may be retained or reproduced elsewhere.

Comfac Relevance

Comfac/CTO uses cloud productivity tools and advises clients on security. If Google or Microsoft processes Comfac/client data for AI training, this creates:

  • Confidentiality risk for client engineering, financial, and HR data.
  • Compliance exposure under Philippine data-privacy rules and ISO 27001.
  • A need for explicit opt-out/administrative controls and user awareness.

Recommended Actions

  • [ ] Audit current Google Workspace / Microsoft 365 admin settings for AI training/data-sharing opt-outs β€” SCA β€” due 2026-07-18
  • [ ] Document which Comfac/client data classes may be processed by external AI β€” SCA β€” due 2026-07-18
  • [ ] Draft user guidance on avoiding AI-training exposure for sensitive documents β€” SCA β€” due 2026-07-25
  • [ ] Evaluate self-hosted alternatives or isolated AI instances for security-sensitive work β€” SCA + Justin β€” due 2026-07-25
  • [ ] Add AI data-sharing review to client hardening checklist β€” SCA β€” due 2026-07-25

Related Controls / Links

  • ISO/IEC 27001:2022 control: A.5.34 Privacy and protection of personally identifiable information (PII)
  • ISO/IEC 27001:2022 control: A.5.36 Compliance with policies, rules and standards for information security
  • ISO/IEC 27001:2022 control: A.8.5 Secure authentication
  • Dialogue log: work/security-iso/logs/260711-security-iso-log.md
  • TechCrunch β€” Google opt-out: https://techcrunch.com/2026/07/06/if-you-use-google-youre-training-its-ai-heres-how-to-opt-out/
  • NY Post β€” Gmail: https://nypost.com/2026/01/06/tech/gmail-is-using-personal-data-to-train-ai-techspert/
  • Windows Latest β€” Teams AI: https://www.windowslatest.com/2026/07/02/microsoft-teams-new-controversial-ai-will-listen-to-your-meetings-and-answer-before-you-ask-but-it-wont-be-turned-on-by-default/
  • Windows Central β€” Copilot OS: https://www.windowscentral.com/microsoft/windows-11/microsoft-copilot-os-revealed-in-leaked-video-lightweight-windows-os-exploration-features-new-desktop-ui-built-entirely-around-copilot-and-agentic-ai
  • Ars Technica β€” Microsoft/OpenAI supercomputer: https://arstechnica.com/tech-policy/2026/06/microsoft-built-supercomputer-to-help-openai-infringe-copyrights-nyt-alleged/

Logged by SCA on 2026-07-11.

Sector: Cloud services / SaaS / AI Status: Monitoring; action required on data-sharing settings Source: TechCrunch, NY Post, Windows Latest, Windows Central, Ars Technica, The New York Times

2026-06-30 β€” Palantir Bans and Critical-System Vendor Risk

🟠 High 2026-06-30
  • Spain: The Spanish government reportedly banned the use of Palantir in critical state systems over fears of national-security leaks.
  • United Kingdom: Andy Burnham is expected to ditch the Palantir NHS deal if he becomes UK prime minister.

Both developments signal growing concern about foreign-owned or intelligence-linked analytics vendors handling sensitive government and critical-infrastructure data.

Read full article

Summary

  • Spain: The Spanish government reportedly banned the use of Palantir in critical state systems over fears of national-security leaks.
  • United Kingdom: Andy Burnham is expected to ditch the Palantir NHS deal if he becomes UK prime minister.

Both developments signal growing concern about foreign-owned or intelligence-linked analytics vendors handling sensitive government and critical-infrastructure data.

Affected Products / Services

  • Palantir Foundry / Gotham / AIP platforms
  • Government and critical-state systems
  • NHS / healthcare analytics contracts

Impact

  • Data sovereignty: Sensitive state and citizen data may be exposed to foreign jurisdictions or intelligence interests.
  • Vendor concentration: Organizations relying on Palantir for analytics face sudden contract/policy risk.
  • Compliance: Public-sector and regulated clients may impose new vendor blacklists or data-localization requirements.

Comfac Relevance

Comfac/CTO advises clients on IT and security. If clients operate in government-adjacent or critical-infrastructure sectors:

  • Vendor selection must include data-sovereignty and ownership-structure review.
  • Contracts should include exit clauses and data-deletion assurances.
  • Critical-system vendors should be mapped to applicable regulatory/national-security restrictions.

Recommended Actions

  • [ ] Add vendor data-sovereignty / ownership review to client assessment checklist β€” SCA β€” due 2026-07-25
  • [ ] Draft guidance on identifying intelligence-linked or restricted analytics vendors β€” SCA β€” due 2026-07-25
  • [ ] Review Comfac/CTO's own analytics and BI tool stack for similar exposure β€” SCA + Operations β€” due 2026-07-25

Related Controls / Links

  • ISO/IEC 27001:2022 control: A.5.19 Information security in supplier relationships
  • ISO/IEC 27001:2022 control: A.5.20 Addressing information security within supplier agreements
  • ISO/IEC 27001:2022 control: A.5.36 Compliance with policies, rules and standards for information security
  • Dialogue log: work/security-iso/logs/260711-security-iso-log.md
  • LBC β€” Spain Palantir ban: https://www.lbc.co.uk/article/spanish-bans-palantir-national-security-5HjdcNp_2/
  • AA.com.tr β€” UK NHS deal: https://www.aa.com.tr/en/europe/burnham-expected-to-ditch-palantir-nhs-deal-if-he-becomes-uk-prime-minister-report/3984619

Logged by SCA on 2026-07-11.

Sector: Government IT / critical infrastructure / data analytics Status: Monitoring; review vendor/sovereignty policies Source: LBC, AA.com.tr

2026-06-29 β€” Surveillance and Biometric Privacy Developments

🟑 Medium 2026-06-29

Recent developments highlight expanding surveillance and biometric data collection:

  • US Supreme Court ruled that geofence warrants require constitutional privacy protections, limiting broad location-dragnet requests.
  • ATF stopped using the controversial Webloc phone-tracking tool after scrutiny.
  • Flock surveillance tower appeared in a private yard without the resident's prior knowledge.
  • Google is testing a webcam-based reCAPTCHA that asks users for a hand scan to prove they are human; testers reportedly bypassed it with a stock photo.

…

Read full article

Summary

Recent developments highlight expanding surveillance and biometric data collection:

  • US Supreme Court ruled that geofence warrants require constitutional privacy protections, limiting broad location-dragnet requests.
  • ATF stopped using the controversial Webloc phone-tracking tool after scrutiny.
  • Flock surveillance tower appeared in a private yard without the resident's prior knowledge.
  • Google is testing a webcam-based reCAPTCHA that asks users for a hand scan to prove they are human; testers reportedly bypassed it with a stock photo.
  • Indian pranksters used a Chinese app to shut down e-rickshaws mid-ride, showing weak IoT/OT access controls in connected vehicles.

Affected Products / Services

  • Mobile device location data (geofence warrants)
  • Law-enforcement phone-tracking tools (Webloc)
  • Automated license-plate / surveillance towers (Flock)
  • Google reCAPTCHA / biometric authentication tests
  • Connected / shared electric vehicles (e-rickshaws)

Impact

  • Privacy: Location, biometric, and behavioral data are being collected at scale with varying legal oversight.
  • Legal risk: Geofence warrant ruling may shift how law-enforcement requests are handled; organizations receiving such warrants should review response procedures.
  • Biometric security: Consumer-grade hand-scan verification was defeated with a static image, raising questions about liveness detection.
  • IoT/OT safety: Remote shutdown of vehicles via app demonstrates unsafe-by-default connected-device design.

Comfac Relevance

Comfac/CTO should monitor these trends because they affect:

  • Client data-privacy policies and law-enforcement response playbooks.
  • Choice and configuration of authentication mechanisms (avoid weak biometrics).
  • IoT/OT deployments in facilities and logistics (e-rickshaw incident is a cautionary example).

Recommended Actions

  • [ ] Review Comfac/CTO law-enforcement data-request response procedure β€” SCA + Legal β€” due 2026-07-25
  • [ ] Assess use of biometric or CAPTCHA systems; require liveness-proof / privacy-preserving alternatives where sensitive β€” SCA β€” due 2026-07-25
  • [ ] Add IoT/OT remote-access kill-switch review to client hardening checklist β€” SCA β€” due 2026-07-25

Related Controls / Links

  • ISO/IEC 27001:2022 control: A.5.34 Privacy and protection of personally identifiable information (PII)
  • ISO/IEC 27001:2022 control: A.8.5 Secure authentication
  • ISO/IEC 27001:2022 control: A.8.16 Monitoring activities
  • Dialogue log: work/security-iso/logs/260711-security-iso-log.md
  • The Guardian β€” geofence warrants: https://www.theguardian.com/us-news/2026/jun/29/supreme-court-geofence-warrants-case-decision
  • AP News β€” ATF Webloc: https://apnews.com/article/atf-surveillance-wyden-cloud-566f702fe6082310d6b7c64e5b2de009

Logged by SCA on 2026-07-11.

Sector: Law enforcement / consumer tech / IoT / biometrics Status: Monitoring; review surveillance and biometric controls Source: The Guardian, AP News, provided dump (Flock, reCAPTCHA, e-rickshaws)

2026-06-22 β€” FortiBleed Campaign Against Exposed Fortinet Management Interfaces

πŸ”΄ Critical 2026-06-22

A large-scale credential-harvesting and initial-access campaign (dubbed FortiBleed) is targeting roughly 75,000 Fortinet firewalls whose management or SSL-VPN interfaces are exposed to the public internet. Fortinet confirmed on 2026-06-19 that this is not a zero-day; the root cause is exposure of management interfaces combined with weak or legacy credential storage.

…

Read full article

Summary

A large-scale credential-harvesting and initial-access campaign (dubbed FortiBleed) is targeting roughly 75,000 Fortinet firewalls whose management or SSL-VPN interfaces are exposed to the public internet. Fortinet confirmed on 2026-06-19 that this is not a zero-day; the root cause is exposure of management interfaces combined with weak or legacy credential storage.

Attackers are scanning for exposed Fortinet admin/SSL-VPN interfaces, testing credentials (credential stuffing, password spraying, leaked Fortinet hashes), cracking stolen configs with a 45-GPU cluster, and then selling verified initial access indexed by country, sector, and revenue.

Affected Products / Services

  • Fortinet FortiGate / FortiOS devices
  • Exposed management interfaces (HTTP/HTTPS admin)
  • Exposed SSL-VPN portals
  • Devices that were previously compromised/backdoored and then patched, leaving persistence

Impact

  • Confidentiality: Admin credentials harvested; configs exfiltrated; traffic intercepted.
  • Integrity: Unauthorized config changes; potential persistence/backdoors.
  • Availability: Devices can be repurposed as network footholds; downstream Active Directory compromise reported.
  • Initial access marketplace: Verified credentials are being sold, lowering the barrier for ransomware/espionage actors.

Comfac Relevance

Comfac deploys and manages network-edge devices (pfSense/Netgate, but Fortinet may appear in client environments or through acquired/legacy infrastructure). Key relevance:

  • Any Fortinet device under management must have its admin interface off the public internet.
  • Legacy SHA-256 password hashes in stolen configs are crackable at scale; recent FortiOS versions moved to PBKDF2, but only if admins logged in after the update.
  • This is a clear example of why the CGG hardening doctrine requires management-plane segmentation, MFA, and regular credential rotation.

Recommended Actions

  • [ ] Inventory all Fortinet devices in Comfac/CTO and client environments β€” owner SCA β€” due 2026-07-11.
  • [ ] Verify no Fortinet management/SSL-VPN interface is exposed to the internet; remove or restrict by source IP/VPN β€” owner Network team β€” due 2026-07-11.
  • [ ] Ensure all FortiOS devices are on a recent firmware supporting PBKDF2 credential storage and force admin re-login β€” owner Network team β€” due 2026-07-18.
  • [ ] Rotate all Fortinet admin credentials and review logs for unknown admin IPs or AD lateral movement β€” owner Security team β€” due 2026-07-18.
  • [ ] Enable MFA on all Fortinet admin accounts per Fortinet advisory β€” owner Security team β€” due 2026-07-18.
  • [ ] Add FortiBleed to client hardening review checklist and proactively notify managed clients β€” owner SCA + Network team β€” due 2026-07-25.

Related Controls / Links

  • Fortinet advisory: https://www.fortinet.com (search "FortiBleed" / June 2026 advisory)
  • Lawrence Systems video & forum post: https://lawrence.video/fortinet
  • Kevin Beaumont analysis: open-directory technical analysis of attacker infrastructure
  • ISO/IEC 27001:2022 control: A.5.7 Threat intelligence, A.8.5 Secure authentication, A.8.16 Monitoring activities
  • Hardening control: work/CGG-Hardening/251129-system-hardening-win2lin-strategy.md β€” management-plane segmentation, MFA, breach-response doctrine
  • IT-knowledge guide: tools/IT-knowledge/security/wordpress-hardening-checklist.md (use as pattern for network-device hardening checklist)

Logged by SCA on 2026-07-04.

Sector: Network security / firewalls / MSPs / any organization using Fortinet Status: Monitoring / action required for any exposed Fortinet devices Source: Lawrence Systems / Kevin Beaumont / Fortinet advisory (see links below)