Visualização de leitura

Grindr settles HIV status data-sharing lawsuit for $35 million

Grindr has reportedly agreed to pay £26 million (around $35 million) to settle a UK privacy lawsuit alleging that it shared sensitive user data, including some users’ HIV status, with advertisers.

The claim was brought by London law firm Austen Hays on behalf of roughly 12,000 UK Grindr users. It alleges that the dating app breached privacy and data-protection laws during a period ending in early 2020.

The claimants allege that Grindr shared personal and highly sensitive information with advertising companies without consent. According to Austen Hays, the shared data may have included ethnicity, HIV status, the date of a user’s last HIV test, and whether they used pre-exposure prophylaxis (PrEP).

At the time of the alleged data sharing practices, Grindr was owned and controlled by the Chinese gaming company Beijing Kunlun Tech. Grindr was sold to US owners in 2020.

According to a US regulatory filing, Grindr will make two payments of £13 million: one by December 31, 2026, and the second by March 31, 2027.

In its SEC filing, Grindr said that the settlement is not an admission of liability and, while it disputes the allegations, it:

recognizes and acknowledges the distress and loss of trust expressed by some of its UK users regarding that pre-2020 period.

The UK settlement follows a separate enforcement case in Norway. The country’s Data Protection Authority found that Grindr had shared users’ personal data with advertising partners for behavioral advertising without a valid legal basis.

These cases illustrate a crucial privacy point: information does not need to be explicitly labeled as medical information or information about sexual orientation to expose intimate details about someone. Advertising identifiers, IP addresses, locations, device information, and confirmation that a person uses a particular app can be combined to identify them or draw sensitive conclusions about their life.

Many free apps rely on advertising SDKs, analytics providers, and other third parties to make money. These integrations can receive identifiers and event data that help target or measure advertising, but they can also create extensive trails of user behavior.

How to protect your privacy on dating apps

Grindr says it has overhauled its privacy program since 2020 and remains committed to user control and responsible data practices. Even so, dating apps can hold unusually personal information about their users.

To limit what you reveal:

  • Review the app’s privacy settings and turn off optional personalized advertising where available.
  • Limit your profile to details you’re comfortable sharing with potential matches.
  • Avoid linking a dating profile to public social-media accounts unless you want identities to be easily connected.
  • Revoke location permissions when you’re not actively using the app, or choose “while using the app” rather than continuous access where your operating system offers it.
  • Keep the app, your operating system, and your security software updated.
  • Watch for romance scams and extortion attempts, particularly requests to move the conversation off the app, send money, share intimate photos, or reveal identifying information.

If you’re unsure whether a message may be part of a scam, you can check it with Malwarebytes Scam Guard, which can help you assess the conversation and decide what to do next.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

LG TV flaws could let attackers listen in, even in standby mode

Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices.

In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR)

ACR technology samples what appears on or is heard through a TV, creates a digital fingerprint, and compares that fingerprint against a reference database. It can be used to identify programs, ads, and viewing habits.

Now, a new investigation by Gamers Nexus, carried out with Level1Techs and independent security researchers, has examined several LG TV models. The team says its found extensive device and network discovery, ACR tracking, and security weaknesses that could increase the consequences if a television were compromised.

Some findings concern LG’s intended product behavior, while others rely on vulnerabilities that researchers say are still being disclosed responsibly. But the broader lesson is clear: A smart TV deserves the same privacy and security consideration as any other internet-connected computer.

According to Gamers Nexus, packet captures and firmware analysis showed the tested LG TVs identifying devices on the local network, such as phones, PCs, printers, switches, and smart-home hardware. The investigation also says the TVs collected nearby Wi-Fi network names, signal information, and device-related identifiers.

This network information could help build a picture of the other devices in a household. Combined with ACR data, advertising IDs, and other information, it could support detailed profiles of what people watch and the devices they use.

The researchers also demonstrated how a compromised TV could capture audio through its microphone, including when the TV appeared to be off. They even showed how the TV stored audio when it was unplugged from the internet and retrieved it after the connection was restored.

The researchers also reported remote-code-execution vulnerabilities to LG. They have not disclosed full details while the responsible disclosure process is ongoing.

A compromised television could be more than a privacy issue. It might provide an attacker with a foothold on a home or business network, access to audio, or a route to probe other devices.

How to stay safe

The concerns are not limited to one brand. Smart TVs sit at the intersection of entertainment, advertising, and the home network. Treating them as security-sensitive devices—and demanding clear, meaningful privacy choices—is increasingly part of staying safe at home.

There is no need to panic, but owners can take a few practical steps to limit what their TV collects and what it can access:

  • Install firmware updates promptly, especially security updates. Check your model’s support page and the TV’s software-update settings.
  • Review the privacy controls under Settings, Privacy & Terms, or User Agreements. Turn off ACR, viewing-information collection, personalized ads, voice recognition, and other features you don’t need.
  • Don’t accept every agreement by default. Read each consent screen and decline optional advertising and voice-data features where possible.
  • Use a separate IoT or guest network for televisions, cameras, speakers, and other smart-home devices. This limits what a compromised device can reach on your main network.
  • Disable UPnP on your router unless it is genuinely needed and avoid exposing TV services directly to the internet.

Our earlier guide to disabling ACR includes instructions for several popular TV brands.


Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Your phone or computer may soon ask how old you are

First, the good news: If you use a Linux-based operating system, you may not be asked your age in a few months. The bad news is that Windows, macOS, iOS, and Android users in California will be.

California has passed a law that requires a range of operating systems to start collecting your age when you first set them up. Under the state’s Digital Age Assurance Act (DAAA), signed into law in October 2025, Windows, macOS, iOS, and Android will all have to do this from January 1, 2027.  Operating systems set up before that date in California will need to do the same by July 1, 2027.

Operating systems will categorize people into four age brackets: under 13, 13–15, 16–17, and 18+. They will then be able to send a non-identifying age signal to app developers. Developers must request that signal from the operating system provider or app store when someone downloads and launches an app. This makes them legally aware of the person’s age bracket.

California wants to stop children from doing things that could hurt them. Kids shouldn’t be able to download apps containing mature content meant only for adults, for example. Age assurance also goes hand in hand with social media restrictions, and Meta recently agreed to put time limits on kids’ social network use as part of a massive court settlement. Another California bill, AB1709, would restrict addictive social media features for children under 16. Measures like these need some form of age assurance to function.

This makes digital rights activists unhappy. The Electronic Frontier Foundation (EFF) isn’t a fan of age verification. It accused California of “outsourcing censorship to developers” through the DAAA rather than focusing on privacy.

The EFF was also uncomfortable with the effect of all this on open-source systems. Age verification requires time and effort from operating system developers. That’s fine if you’re Microsoft, Apple, or Google with a massive development budget. But it’s more problematic for operating systems developed by volunteers, such as Linux distributions. Those that don’t have the resources to comply, or don’t like the privacy implications, might prefer to avoid the Golden State altogether.

GrapheneOS, a privacy-focused mobile operating system that strips Android of its surveillance functions, took that option. In March, it said that it wouldn’t implement age verification, and would happily forego sales of devices running its software in certain regions, if necessary.

Assembly member Buffy Wicks, who introduced the original DAAA, has been listening. She tweaked the legislation with Bill AB1856, which would amend the law to exempt certain open-source operating system providers. California lawmakers passed the bill in late August, and it is now awaiting the governor’s decision.

AB1856 would exempt software that follows open-source rules, allowing it to be reused and built upon by others. This includes software distributed under common licenses such as GPL, MIT, BSD, and Apache. Not one single lawmaker voted against it.

California isn’t alone in mandating the collection of age brackets. Colorado’s SB26-051, now law, does something similar. Legislators there also added parallel open-source exemptions after lobbying by Linux hardware maker System76.  Illinois has also passed age assurance legislation, and New York has a bill in the works.

Exempting open-source operating systems from California and Colorado will please privacy-conscious users, but it’s worth noting that some Linux distributions are going ahead with age assurance anyway. Many have drawn a line in the sand, others, like Fedora, are reportedly planning to do it anyway.

In any case, those using more mainstream operating systems can expect a “How old are you?” or “What’s your birthdate?” question sometime soon. If you’d rather avoid that, consider an open-source operating system instead. Just check with your distribution’s maintainers to see what their plans are.


From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

153M+ driver’s licenses for sale on new dark web platform

A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards.

The collection included more than 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards, according to reports.

The trove of driver’s license scans reported by KrebsOnSecurity is a sharp reminder that identity verification is not a harmless box-ticking exercise.

The FBI’s New Orleans field office has opened an investigation into an apparent breach involving identity verification provider IDScan.net. The company said it was investigating.

IDScan.net advertises as follows:

“We provide simple, secure solutions to help dispensaries reduce liability and protect their licenses by validating IDs, including a customer’s age, in a matter of seconds.”

The allegedly exposed records were especially concerning because some included more than a basic photo of an ID. KrebsOnSecurity found records containing front-and-back images, as well as infrared and ultraviolet scans, with timestamps that appeared to align with the holders’ travel or car-rental activity.

That matters because a driver’s license is far more useful to an identity thief than a password. You can reset a password. You cannot easily replace your face, date of birth, address, or license number, particularly when they’re accompanied by high-resolution images of your government-issued ID.

The age-verification problem

Age verification has become a common justification for asking people to upload an ID, take a selfie, or submit both to a third-party identity verification provider.

We have previously warned about the privacy and security trade-offs in age-verification systems, particularly those that require people to submit copies of government-issued ID. Such systems can turn a request to access a website into a decision to share an enduring identity document with a company the user may never have heard of.

In our opinion, that is a disproportionate risk. Once someone uploads an ID, the service or its vendor can potentially link the visit to their identity. If the provider is breached, the consequences can extend well beyond unwanted marketing or an exposed email address.

The reported Nexus dataset illustrates a broader concern: Identity documents are collected in many places that people may not connect with one another. Each individual collection may be presented as routine, but together they create an ever-expanding ecosystem of organizations, contractors, software platforms, cloud services, and privacy policies.

Facial images and ID copies can be reused. Criminals may use them to make scams more convincing, pass weak identity checks, or assemble detailed victim profiles from records obtained from separate breaches. An attacker who knows your name, address, date of birth, email address, and license details has a useful foundation for fraud.

This is why “we only need to verify your age” should not automatically mean “please upload your driver’s license” or another form of ID.

How to stay safe

When an ID check is required to use an online service, ask a basic question: Why does this company need a copy of my identity document, and what happens to it afterward? The scale of the data reportedly offered through Nexus shows why the answer matters.

Consumers cannot always refuse an ID check, particularly where it is legally required or necessary for a regulated service. But you can reduce unnecessary exposure:

  • Ask whether an ID image is stored and, if so, for how long.
  • Check whether the company uses a third-party identity verification provider.
  • Prefer services that offer a privacy-preserving age check rather than requiring a full ID upload.
  • Avoid submitting identity documents to sites you do not trust or did not intend to use.
  • Do not email copies of IDs unless there is no safer alternative and you have independently verified the recipient.
  • Be alert for phishing, account-recovery scams, and fraudulent credit applications if you believe your ID may have been exposed.
  • Consider a credit freeze where available.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

Flock wants privacy to meet surveillance halfway

Flock Safety CEO Garrett Langley says the United States needs a “compromise” between privacy and public safety.

It’s a neat phrase, except I don’t like to see “compromise” and “privacy” that close together.

“When people talk about just one of these, privacy or safety, they’re prioritizing the wrong thing, and what we have to prioritize as a country is compromise.”

Langley call for compromise comes as the company faces intensifying resistance to its automated license plate reader (ALPR) network. The opposition has begun to affect Flock commercially and operationally, with agencies disabling cameras or canceling contracts.

The problem is that the public has already been doing the compromising: People’s movements have been routinely captured, stored, searched, and, in some cases, shared far beyond the communities that installed the cameras.

Flock’s ALPRs collect detailed records of where vehicles travel, then make that data available to law enforcement for investigations. Langley now says the company wants more regulation and accountability. Flock says it’s reducing its recommended default retention period to seven days and will require case codes for law enforcement and an audit tool designed to flag suspicious access by the end of the year.

Those are welcome concessions, but they do not resolve the underlying concern: A rapidly expanding, privately operated surveillance network can turn ordinary travel into searchable historical data.

The opposition has not faded; it has intensified. NPR reports that cameras have been vandalized in at least 36 states. Vandalism is neither a productive nor lawful answer, but its spread offers a useful measure of how profoundly many people feel excluded from decisions about surveillance in their communities.

A genuine compromise would not start with the assumption that widespread collection is inevitable and then negotiate the retention period. It would begin with democratic consent, strict limits on how the data can be used, independently enforceable access controls, public reporting, meaningful opt-outs where possible, and a clear requirement that surveillance be necessary and proportionate.

Calls to meet halfway are also harder to take seriously when the CEO has been accused by 404 Media of misleading police about the outlet’s reporting on an abortion-related case. According to 404 Media, his account is contradicted by court records and police reports. That accusation makes his public calls for compromise much harder to accept.

Flock is right about one thing: There needs to be accountability. But calling for “compromise” after the cameras are already up sharply limits the choices left to communities. Privacy is not a bargaining chip to be surrendered whenever surveillance vendors promise safety.


Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Popular school apps may be sharing student data with advertisers

A two-year investigation into educational technology (EdTech) apps used by Utah schools found that many were collecting and sharing student data in ways that appeared inconsistent with their privacy commitments.

EdTech is a massive commercial industry and some argue that it functions much like traditional big tech by prioritizing profits, scalable software, and user data collection over proven learning outcomes.

The project, published by the Utah State Board of Education in partnership with Brigham Young University and Internet Safety Labs, examined network traffic from 100 EdTech apps between 2023 and 2025. Rather than relying only on privacy policies or vendor assurances, researchers looked at what the apps actually transmitted while in use.

What they found was concerning. Of the 85 tested apps with relevant data privacy agreements, 52% reportedly collected at least one student-data element that was not permitted under the agreement. Across all the apps tested, researchers found that 61% shared data with third parties, while 36% transmitted data to advertisers.

A school district may have a signed data privacy agreement with an EdTech provider specifying what information the company can collect, why it can use it, and who it may share it with. But contractual promises are not always reflected in how an app behaves. An app can include third-party analytics software, advertising-related services, or other embedded components that send information elsewhere without the school or district having a clear view of those transfers.

This shows how technical testing, including examination of live network traffic, can reveal behavior that paper-based assessments miss. The report concluded that such investigations could expose potential non-compliance not be found through traditional review processes.

The state’s response extended beyond publishing the findings. Vendors with potential issues were asked to explain or remedy them. Companies that addressed concerns could have their identities redacted in the public report, an approach designed to encourage corrective action while holding vendors that failed to respond to account.

Following the investigation, Utah passed H.B. 55, Privacy Compliance for Education Technology Vendors (2026), which took effect on July 1. It amends Utah Code § 53E-9-309. Among other changes, the law requires education entities to include specified student-data protections in vendor contracts, notify vendors of unauthorized use of student data, and terminate contracts when a vendor does not remedy a confirmed privacy violation after being notified.

Since we don’t all live in Utah, the more important question for every school system is: How are your apps behaving?

Protecting student data requires more than trusting a privacy policy. Schools need accurate inventories of the tools in use, clear contractual limits, and access to the technical expertise needed to test whether those limits are being observed.


By the way, did you know about the Malwarebytes Student Protection program?

GTA 6 leak hunt could expose data belonging to thousands of Discord users

Someone leaked footage of the upcoming game Grand Theft Auto (GTA) 6 this month, and the game’s publisher badly wants to know who. It’s after a range of data about members of three Discord servers going back to June 1 this year in a bid to nail the perpetrator.

Take-Two Interactive, the publisher behind the GTA series, hit Microsoft and Discord with a subpoena on August 20. It’s demanding IP addresses, phone numbers, linked Google and Xbox accounts, and OneDrive contents of certain server members. It’s also after their MachineGuid values and Microsoft account device IDs, which identify individual Windows installations and devices that access Microsoft services, respectively.

An account calling itself CyberLeek started publishing game footage on August 17 and also revealed some of the game’s map. It claims ideological motives, publishing a manifesto with three commandments. In brief, it wants publishers to stop publishing digital-only versions of games, stop making players pay extra to unlock single-player content shipped with the base game, and guarantee to preserve single-player modes forever.

CyberLeek warned game publishers:

“Behave, or be the next target.”

Around the same time, CyberLeek also launched a cryptocurrency token called $CYBERLEEK on the Solana network, which it promoted as a way for users to vote on what game footage would be leaked next.

Online commentators accused CyberLeek of using the GTA 6 leaks to pump the value of its cryptocurrency token. However, rather than selling its large holding, the person or people behind CyberLeek “burned” it on Sunday, effectively erasing the tokens. However, they can still collect trading fees from the toke , which reportedly reached up to $60,000 last week.

Who the sweep catches

Take-Two’s Discord subpoena covers servers including one belonging to Australian GTA 5 streamer Matthew Judge, better known as DarkViperAU. He posted on X that he had nothing to do with the event and didn’t know anything about it.

Microsoft and Discord have until September 4 to hand over the data. If they comply, potentially hundreds or thousands of people with no known connection to the leaks could have identifying information handed over to Take-Two as part of its investigation.

Other attacks on Take-Two

This isn’t the first hacking incident that Take-Two and its game studio subsidiary Rockstar have faced. In April, the ShinyHunters cybercrime crew stole 78.6 million Rockstar records without directly compromising any of the company’s internal systems.

Rather than compromising Rockstar, ShinyHunters targeted Anodot, a cloud analytics vendor that held persistent authentication tokens for its customers’ Snowflake cloud database environments.

Persistent authentication tokens are what some software gives you after you’ve proven your credentials once so that you don’t have to go through the login process again. They’re convenient, but the danger is that if someone gets hold of one, they can impersonate you without needing your password.

Gaining access to victims’ data by compromising third-party service providers holding that data is the ShinyHunters gang’s modus operandi.

Neither is this the first time that GTA material has been leaked. In September 2022, a hacker posted video footage of GTA 6 online.

What does all this mean to you? If you’re a gamer, then it means being diligent. GTA’s popularity tends to spawn scams online. The game’s popularity has attracted scammers fraudulently touting free in-game money, malware-filled mods, and more recently, offers of free early access designed to part you with the contents of your crypto wallet.

Real leaked footage can make scams more convincing to gamers who want to see more. Yesterday, Malwarebytes researchers found fake GTA 6 Extended Look and demo sites that lead visitors to password-stealing malware.

Don’t believe offers of early access or downloadable GTA 6 demos. The only safe bet is a direct pre-order from Rockstar. Otherwise, keep your powder dry (and your money safe) until the actual game lands on consoles in November. PC players will have to wait a little longer.


Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

AliExpress caught using silent audio to fingerprint visitors’ browsers

AliExpress, the online marketplace owned by Alibaba Group, has come under scrutiny after researchers and browser maker Brave reported finding silent Web Audio processing on the site that could help fingerprint visitors’ devices.

The audio processing did not record people through their microphones. Instead, it generated and processed an inaudible signal, then measured small, repeatable differences in the way a browser and device handled it.

Browser fingerprinting is a way for websites to identify devices and recognize returning visitors without relying on conventional cookies. It works by using information about a device and browser to create a unique signature.

The AliExpress website was found processing a fixed audio waveform and examining the resulting numerical values. Tiny differences can arise from the browser, operating system, CPU behavior, audio hardware, and drivers. When combined with other signals, they become another input that can contribute to a browser or device identifier.

Investigation of the page’s code reportedly found audio-processing graphs that were set to zero volume but remained connected to the system audio output. That explains why a user could hear nothing, and why muting a browser tab would not necessarily prevent the processing. All the relevant work was occurring within the Web Audio graph rather than through a conventional media player.

And audio measurements were only one part of the reported data collection. The scripts also gathered information tied to canvas rendering, WebGL, display settings, hardware configuration, WebRTC behavior and user interactions. Together, those signals can create a more detailed profile of a device than any one signal would provide on its own.

Fingerprinting can be used for legitimate purposes such as fraud prevention, bot detection, and risk assessment. It can help companies spot suspicious transactions or automated activity even when cookies have been deleted or accounts have changed. But it also raises privacy concerns because users may not know the tracking is happening and have limited control over it.


Safer. Cleaner. Ad-free browsing.


Earlier studies have shown that visitors’ choices about allowing cookies were ignored in more than half the cases studied. Fingerprinting adds another privacy concern because it can allow websites to recognize visitors without relying on cookies at all.

How to protect yourself

The alleged AliExpress implementation is a useful example of how modern tracking can be both silent and technically legitimate at the API level while still raising privacy concerns.

Brave says its browser blocks the AliExpress scripts responsible for the audio-based tracking. Other steps you can take include:

  • Use content blockers and anti-tracking extensions to limit the information websites can collect about your browser and device.
  • Keep your browser up to date since browser vendors continually change privacy defenses as fingerprinting methods evolve.
  • Use a separate browser or browser profile for shopping, ideally without signing in to other services in the same profile.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Twitch wants your content for Amazon AI training. Here’s how to opt out

The Dutch Autoriteit Persoonsgegevens (AP) has advised Twitch users to opt out of sharing data with Amazon AI.

Twitch launched as a live-video platform and is currently owned by Amazon. Its core product is live broadcasting with a built-in chat culture: streamers broadcast gameplay, commentary, performances or other live content while viewers interact in real time.

Twitch is one of the world’s largest livestreaming platforms, with millions of people broadcasting and watching content every month.

Last week we learned that Twitch allows Amazon to use content from its platform to train generative AI models, with the setting enabled by default. Chief Product Officer Mike Minton said during an interview:

“If it’s opt-in, nobody would opt in. That’s the honest answer. So, it’s going to be on by default.”

So, to get this straight: they know users don’t want it, yet users are opted in by default and they make it difficult to opt out.

The AP argues that:

“Live streams on Twitch show the gamer’s face, voice and name, and often include images of a private space, such as a bedroom. This constitutes personal data. In the case of facial images, this even involves sensitive personal data. Once these data are stored in Amazon’s AI systems, they cannot simply be removed. As a result, users lose control over their data. Users’ chats and text messages also serve as training material for Amazon.”

Obviously, Twitch users were outraged when they learned about the assumed consent. The setting is in the Streamer Dashboard under Settings > Security and Privacy, near the bottom of the page. That is the basis for reporting that it was difficult to find.

Wait, it gets worse. Ars Technica says the AI training itself isn’t new. What’s new is the option to opt out. That setting arrived more than two years after a company executive confirmed that Amazon was using Twitch content for AI training.

In April 2024, Minton said Amazon was using Twitch content to prototype AI models, although not yet at “production scale.”

How to turn it off

The setting is enabled by default. To turn it off, go to: Settings > Security and Privacy > scroll down to Training for Generative AI, and turn the setting off.

Training for Generative AI setting on Twitch

“Allow your channel content to train generative AI content models of Amazon. Turning this off does not opt you out of Twitch and Amazon using your channel content for other purposes described in the Twitch Privacy Notice, including using AI-supported Twitch features that benefit the community by facilitating streamer growth and monetization (such as real-time sponsorship campaign assistance), viewer discovery (such as recommendations), and community safety (such as AutoMod).”

Note that if you post in another streamer’s chat, whether that chat can be used for AI training depends on that streamer’s setting, not yours. So turning off the option on your own channel does not necessarily stop everything you write on Twitch from becoming training material.

There’s an old saying that “if you’re not a paying customer, you’re the product,” but that shouldn’t be an excuse to disregard users’ privacy or assume consent. We agree with the AP: If you have a Twitch channel and don’t want your content used to train Amazon’s generative AI models, turn the setting off.


Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

9 million images of people’s faces exposed by reverse lookup service

Researcher Jeremiah Fowler found a cloud database containing more than 9 million image files accessible without authentication, WIRED reports.

The leaky bucket, containing some 450 GB of images, was traced back to a US-registered company called ClarityCheck.

In their own words, ClarityCheck says:

“Use reverse image search to identify anyone in a photo. Find names, social profiles, and online presence in seconds.”

While ClarityCheck says it does not use facial recognition, it does describe its image function as a way to identify people and find their names and social profiles.

Granted, there’s a difference.

  • An image search looks for identical or visually similar images, often using image embeddings, metadata, or indexed pages.
  • Facial recognition detects a face, derives face-specific features, and compares them to a structured, face-indexed collection of digital images.

But does that difference matter when your face gets uploaded and stored in an unsecured cloud environment?

It is important to remember here that faces are persistent identifiers. A leaked password can be reset, whereas a person cannot easily replace their face. When an image of someone is linked with names, social profiles, addresses, emails, or phone numbers, that information could potentially be misused for impersonation, targeted phishing, doxxing, or catfishing.

ClarityCheck disputed that the data was publicly exposed because accessing it required an unindexed URL. However, the images didn’t require authentication, and Fowler was able to discover the URLs through the site’s code.

It is unknown how long the bucket was exposed before Fowler found it. Despite earlier alerts from Fowler, ClarityCheck did not restrict access to the database until WIRED contacted the service in July.

People finder tools

People finder tools are online services that aggregate public records, contact data, and social footprints to help locate individuals using names, phone numbers, emails, or addresses.

If you want to check whether someone on social media is using a fake or stolen profile picture because you’re worried they might be a scammer, a conventional reverse image search can help you see where else that picture appears online. You don’t need a people finder tool.

ClarityCheck, along with many others like it, requires users to confirm that they own the image, appear in it, or otherwise have the necessary rights and permission to upload it. Of course, a checkbox cannot prevent someone from lying.

There are a few pointers we want to give people who use ClarityCheck or similar tools:

  • Do not upload a photo of someone else unless you have their permission or another clear legal right to do so.
  • Think twice before uploading your own photo if you’re not sure how it’s going to be used, how long it will be stored, and how secure that storage is.
  • Before using any service, check its policies on image retention, deletion, AI model-training use, storage, third-party sharing, and removing images.
  • If you find yourself in a search result, save the URL and screenshots, request delisting from the search service, and seek removal from the original site or platform hosting the image.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

❌