Visualização de leitura

Grindr settles HIV status data-sharing lawsuit for $35 million

Grindr has reportedly agreed to pay £26 million (around $35 million) to settle a UK privacy lawsuit alleging that it shared sensitive user data, including some users’ HIV status, with advertisers.

The claim was brought by London law firm Austen Hays on behalf of roughly 12,000 UK Grindr users. It alleges that the dating app breached privacy and data-protection laws during a period ending in early 2020.

The claimants allege that Grindr shared personal and highly sensitive information with advertising companies without consent. According to Austen Hays, the shared data may have included ethnicity, HIV status, the date of a user’s last HIV test, and whether they used pre-exposure prophylaxis (PrEP).

At the time of the alleged data sharing practices, Grindr was owned and controlled by the Chinese gaming company Beijing Kunlun Tech. Grindr was sold to US owners in 2020.

According to a US regulatory filing, Grindr will make two payments of £13 million: one by December 31, 2026, and the second by March 31, 2027.

In its SEC filing, Grindr said that the settlement is not an admission of liability and, while it disputes the allegations, it:

recognizes and acknowledges the distress and loss of trust expressed by some of its UK users regarding that pre-2020 period.

The UK settlement follows a separate enforcement case in Norway. The country’s Data Protection Authority found that Grindr had shared users’ personal data with advertising partners for behavioral advertising without a valid legal basis.

These cases illustrate a crucial privacy point: information does not need to be explicitly labeled as medical information or information about sexual orientation to expose intimate details about someone. Advertising identifiers, IP addresses, locations, device information, and confirmation that a person uses a particular app can be combined to identify them or draw sensitive conclusions about their life.

Many free apps rely on advertising SDKs, analytics providers, and other third parties to make money. These integrations can receive identifiers and event data that help target or measure advertising, but they can also create extensive trails of user behavior.

How to protect your privacy on dating apps

Grindr says it has overhauled its privacy program since 2020 and remains committed to user control and responsible data practices. Even so, dating apps can hold unusually personal information about their users.

To limit what you reveal:

  • Review the app’s privacy settings and turn off optional personalized advertising where available.
  • Limit your profile to details you’re comfortable sharing with potential matches.
  • Avoid linking a dating profile to public social-media accounts unless you want identities to be easily connected.
  • Revoke location permissions when you’re not actively using the app, or choose “while using the app” rather than continuous access where your operating system offers it.
  • Keep the app, your operating system, and your security software updated.
  • Watch for romance scams and extortion attempts, particularly requests to move the conversation off the app, send money, share intimate photos, or reveal identifying information.

If you’re unsure whether a message may be part of a scam, you can check it with Malwarebytes Scam Guard, which can help you assess the conversation and decide what to do next.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

LG TV flaws could let attackers listen in, even in standby mode

Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices.

In the past, we reported on Samsung settling a lawsuit with the Texas Attorney General over how its smart TVs collect and monetize viewing data using Automated Content Recognition (ACR)

ACR technology samples what appears on or is heard through a TV, creates a digital fingerprint, and compares that fingerprint against a reference database. It can be used to identify programs, ads, and viewing habits.

Now, a new investigation by Gamers Nexus, carried out with Level1Techs and independent security researchers, has examined several LG TV models. The team says its found extensive device and network discovery, ACR tracking, and security weaknesses that could increase the consequences if a television were compromised.

Some findings concern LG’s intended product behavior, while others rely on vulnerabilities that researchers say are still being disclosed responsibly. But the broader lesson is clear: A smart TV deserves the same privacy and security consideration as any other internet-connected computer.

According to Gamers Nexus, packet captures and firmware analysis showed the tested LG TVs identifying devices on the local network, such as phones, PCs, printers, switches, and smart-home hardware. The investigation also says the TVs collected nearby Wi-Fi network names, signal information, and device-related identifiers.

This network information could help build a picture of the other devices in a household. Combined with ACR data, advertising IDs, and other information, it could support detailed profiles of what people watch and the devices they use.

The researchers also demonstrated how a compromised TV could capture audio through its microphone, including when the TV appeared to be off. They even showed how the TV stored audio when it was unplugged from the internet and retrieved it after the connection was restored.

The researchers also reported remote-code-execution vulnerabilities to LG. They have not disclosed full details while the responsible disclosure process is ongoing.

A compromised television could be more than a privacy issue. It might provide an attacker with a foothold on a home or business network, access to audio, or a route to probe other devices.

How to stay safe

The concerns are not limited to one brand. Smart TVs sit at the intersection of entertainment, advertising, and the home network. Treating them as security-sensitive devices—and demanding clear, meaningful privacy choices—is increasingly part of staying safe at home.

There is no need to panic, but owners can take a few practical steps to limit what their TV collects and what it can access:

  • Install firmware updates promptly, especially security updates. Check your model’s support page and the TV’s software-update settings.
  • Review the privacy controls under Settings, Privacy & Terms, or User Agreements. Turn off ACR, viewing-information collection, personalized ads, voice recognition, and other features you don’t need.
  • Don’t accept every agreement by default. Read each consent screen and decline optional advertising and voice-data features where possible.
  • Use a separate IoT or guest network for televisions, cameras, speakers, and other smart-home devices. This limits what a compromised device can reach on your main network.
  • Disable UPnP on your router unless it is genuinely needed and avoid exposing TV services directly to the internet.

Our earlier guide to disabling ACR includes instructions for several popular TV brands.


Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Your phone or computer may soon ask how old you are

First, the good news: If you use a Linux-based operating system, you may not be asked your age in a few months. The bad news is that Windows, macOS, iOS, and Android users in California will be.

California has passed a law that requires a range of operating systems to start collecting your age when you first set them up. Under the state’s Digital Age Assurance Act (DAAA), signed into law in October 2025, Windows, macOS, iOS, and Android will all have to do this from January 1, 2027.  Operating systems set up before that date in California will need to do the same by July 1, 2027.

Operating systems will categorize people into four age brackets: under 13, 13–15, 16–17, and 18+. They will then be able to send a non-identifying age signal to app developers. Developers must request that signal from the operating system provider or app store when someone downloads and launches an app. This makes them legally aware of the person’s age bracket.

California wants to stop children from doing things that could hurt them. Kids shouldn’t be able to download apps containing mature content meant only for adults, for example. Age assurance also goes hand in hand with social media restrictions, and Meta recently agreed to put time limits on kids’ social network use as part of a massive court settlement. Another California bill, AB1709, would restrict addictive social media features for children under 16. Measures like these need some form of age assurance to function.

This makes digital rights activists unhappy. The Electronic Frontier Foundation (EFF) isn’t a fan of age verification. It accused California of “outsourcing censorship to developers” through the DAAA rather than focusing on privacy.

The EFF was also uncomfortable with the effect of all this on open-source systems. Age verification requires time and effort from operating system developers. That’s fine if you’re Microsoft, Apple, or Google with a massive development budget. But it’s more problematic for operating systems developed by volunteers, such as Linux distributions. Those that don’t have the resources to comply, or don’t like the privacy implications, might prefer to avoid the Golden State altogether.

GrapheneOS, a privacy-focused mobile operating system that strips Android of its surveillance functions, took that option. In March, it said that it wouldn’t implement age verification, and would happily forego sales of devices running its software in certain regions, if necessary.

Assembly member Buffy Wicks, who introduced the original DAAA, has been listening. She tweaked the legislation with Bill AB1856, which would amend the law to exempt certain open-source operating system providers. California lawmakers passed the bill in late August, and it is now awaiting the governor’s decision.

AB1856 would exempt software that follows open-source rules, allowing it to be reused and built upon by others. This includes software distributed under common licenses such as GPL, MIT, BSD, and Apache. Not one single lawmaker voted against it.

California isn’t alone in mandating the collection of age brackets. Colorado’s SB26-051, now law, does something similar. Legislators there also added parallel open-source exemptions after lobbying by Linux hardware maker System76.  Illinois has also passed age assurance legislation, and New York has a bill in the works.

Exempting open-source operating systems from California and Colorado will please privacy-conscious users, but it’s worth noting that some Linux distributions are going ahead with age assurance anyway. Many have drawn a line in the sand, others, like Fedora, are reportedly planning to do it anyway.

In any case, those using more mainstream operating systems can expect a “How old are you?” or “What’s your birthdate?” question sometime soon. If you’d rather avoid that, consider an open-source operating system instead. Just check with your distribution’s maintainers to see what their plans are.


From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

153M+ driver’s licenses for sale on new dark web platform

A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards.

The collection included more than 153 million driver’s licenses, 10 million ID cards, 3 million travel documents, and 579,000 medical cards, including marijuana dispensary cards, according to reports.

The trove of driver’s license scans reported by KrebsOnSecurity is a sharp reminder that identity verification is not a harmless box-ticking exercise.

The FBI’s New Orleans field office has opened an investigation into an apparent breach involving identity verification provider IDScan.net. The company said it was investigating.

IDScan.net advertises as follows:

“We provide simple, secure solutions to help dispensaries reduce liability and protect their licenses by validating IDs, including a customer’s age, in a matter of seconds.”

The allegedly exposed records were especially concerning because some included more than a basic photo of an ID. KrebsOnSecurity found records containing front-and-back images, as well as infrared and ultraviolet scans, with timestamps that appeared to align with the holders’ travel or car-rental activity.

That matters because a driver’s license is far more useful to an identity thief than a password. You can reset a password. You cannot easily replace your face, date of birth, address, or license number, particularly when they’re accompanied by high-resolution images of your government-issued ID.

The age-verification problem

Age verification has become a common justification for asking people to upload an ID, take a selfie, or submit both to a third-party identity verification provider.

We have previously warned about the privacy and security trade-offs in age-verification systems, particularly those that require people to submit copies of government-issued ID. Such systems can turn a request to access a website into a decision to share an enduring identity document with a company the user may never have heard of.

In our opinion, that is a disproportionate risk. Once someone uploads an ID, the service or its vendor can potentially link the visit to their identity. If the provider is breached, the consequences can extend well beyond unwanted marketing or an exposed email address.

The reported Nexus dataset illustrates a broader concern: Identity documents are collected in many places that people may not connect with one another. Each individual collection may be presented as routine, but together they create an ever-expanding ecosystem of organizations, contractors, software platforms, cloud services, and privacy policies.

Facial images and ID copies can be reused. Criminals may use them to make scams more convincing, pass weak identity checks, or assemble detailed victim profiles from records obtained from separate breaches. An attacker who knows your name, address, date of birth, email address, and license details has a useful foundation for fraud.

This is why “we only need to verify your age” should not automatically mean “please upload your driver’s license” or another form of ID.

How to stay safe

When an ID check is required to use an online service, ask a basic question: Why does this company need a copy of my identity document, and what happens to it afterward? The scale of the data reportedly offered through Nexus shows why the answer matters.

Consumers cannot always refuse an ID check, particularly where it is legally required or necessary for a regulated service. But you can reduce unnecessary exposure:

  • Ask whether an ID image is stored and, if so, for how long.
  • Check whether the company uses a third-party identity verification provider.
  • Prefer services that offer a privacy-preserving age check rather than requiring a full ID upload.
  • Avoid submitting identity documents to sites you do not trust or did not intend to use.
  • Do not email copies of IDs unless there is no safer alternative and you have independently verified the recipient.
  • Be alert for phishing, account-recovery scams, and fraudulent credit applications if you believe your ID may have been exposed.
  • Consider a credit freeze where available.

Let’s face it, an incognito window can only do so much. 
 
Breaches, dark web trading, credit fraud. Malwarebytes Identity Theft Protection monitors for all of it, alerts you fast, and comes with identity theft insurance. 

Flock wants privacy to meet surveillance halfway

Flock Safety CEO Garrett Langley says the United States needs a “compromise” between privacy and public safety.

It’s a neat phrase, except I don’t like to see “compromise” and “privacy” that close together.

“When people talk about just one of these, privacy or safety, they’re prioritizing the wrong thing, and what we have to prioritize as a country is compromise.”

Langley call for compromise comes as the company faces intensifying resistance to its automated license plate reader (ALPR) network. The opposition has begun to affect Flock commercially and operationally, with agencies disabling cameras or canceling contracts.

The problem is that the public has already been doing the compromising: People’s movements have been routinely captured, stored, searched, and, in some cases, shared far beyond the communities that installed the cameras.

Flock’s ALPRs collect detailed records of where vehicles travel, then make that data available to law enforcement for investigations. Langley now says the company wants more regulation and accountability. Flock says it’s reducing its recommended default retention period to seven days and will require case codes for law enforcement and an audit tool designed to flag suspicious access by the end of the year.

Those are welcome concessions, but they do not resolve the underlying concern: A rapidly expanding, privately operated surveillance network can turn ordinary travel into searchable historical data.

The opposition has not faded; it has intensified. NPR reports that cameras have been vandalized in at least 36 states. Vandalism is neither a productive nor lawful answer, but its spread offers a useful measure of how profoundly many people feel excluded from decisions about surveillance in their communities.

A genuine compromise would not start with the assumption that widespread collection is inevitable and then negotiate the retention period. It would begin with democratic consent, strict limits on how the data can be used, independently enforceable access controls, public reporting, meaningful opt-outs where possible, and a clear requirement that surveillance be necessary and proportionate.

Calls to meet halfway are also harder to take seriously when the CEO has been accused by 404 Media of misleading police about the outlet’s reporting on an abortion-related case. According to 404 Media, his account is contradicted by court records and police reports. That accusation makes his public calls for compromise much harder to accept.

Flock is right about one thing: There needs to be accountability. But calling for “compromise” after the cameras are already up sharply limits the choices left to communities. Privacy is not a bargaining chip to be surrendered whenever surveillance vendors promise safety.


Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Popular school apps may be sharing student data with advertisers

A two-year investigation into educational technology (EdTech) apps used by Utah schools found that many were collecting and sharing student data in ways that appeared inconsistent with their privacy commitments.

EdTech is a massive commercial industry and some argue that it functions much like traditional big tech by prioritizing profits, scalable software, and user data collection over proven learning outcomes.

The project, published by the Utah State Board of Education in partnership with Brigham Young University and Internet Safety Labs, examined network traffic from 100 EdTech apps between 2023 and 2025. Rather than relying only on privacy policies or vendor assurances, researchers looked at what the apps actually transmitted while in use.

What they found was concerning. Of the 85 tested apps with relevant data privacy agreements, 52% reportedly collected at least one student-data element that was not permitted under the agreement. Across all the apps tested, researchers found that 61% shared data with third parties, while 36% transmitted data to advertisers.

A school district may have a signed data privacy agreement with an EdTech provider specifying what information the company can collect, why it can use it, and who it may share it with. But contractual promises are not always reflected in how an app behaves. An app can include third-party analytics software, advertising-related services, or other embedded components that send information elsewhere without the school or district having a clear view of those transfers.

This shows how technical testing, including examination of live network traffic, can reveal behavior that paper-based assessments miss. The report concluded that such investigations could expose potential non-compliance not be found through traditional review processes.

The state’s response extended beyond publishing the findings. Vendors with potential issues were asked to explain or remedy them. Companies that addressed concerns could have their identities redacted in the public report, an approach designed to encourage corrective action while holding vendors that failed to respond to account.

Following the investigation, Utah passed H.B. 55, Privacy Compliance for Education Technology Vendors (2026), which took effect on July 1. It amends Utah Code § 53E-9-309. Among other changes, the law requires education entities to include specified student-data protections in vendor contracts, notify vendors of unauthorized use of student data, and terminate contracts when a vendor does not remedy a confirmed privacy violation after being notified.

Since we don’t all live in Utah, the more important question for every school system is: How are your apps behaving?

Protecting student data requires more than trusting a privacy policy. Schools need accurate inventories of the tools in use, clear contractual limits, and access to the technical expertise needed to test whether those limits are being observed.


By the way, did you know about the Malwarebytes Student Protection program?

GTA 6 leak hunt could expose data belonging to thousands of Discord users

Someone leaked footage of the upcoming game Grand Theft Auto (GTA) 6 this month, and the game’s publisher badly wants to know who. It’s after a range of data about members of three Discord servers going back to June 1 this year in a bid to nail the perpetrator.

Take-Two Interactive, the publisher behind the GTA series, hit Microsoft and Discord with a subpoena on August 20. It’s demanding IP addresses, phone numbers, linked Google and Xbox accounts, and OneDrive contents of certain server members. It’s also after their MachineGuid values and Microsoft account device IDs, which identify individual Windows installations and devices that access Microsoft services, respectively.

An account calling itself CyberLeek started publishing game footage on August 17 and also revealed some of the game’s map. It claims ideological motives, publishing a manifesto with three commandments. In brief, it wants publishers to stop publishing digital-only versions of games, stop making players pay extra to unlock single-player content shipped with the base game, and guarantee to preserve single-player modes forever.

CyberLeek warned game publishers:

“Behave, or be the next target.”

Around the same time, CyberLeek also launched a cryptocurrency token called $CYBERLEEK on the Solana network, which it promoted as a way for users to vote on what game footage would be leaked next.

Online commentators accused CyberLeek of using the GTA 6 leaks to pump the value of its cryptocurrency token. However, rather than selling its large holding, the person or people behind CyberLeek “burned” it on Sunday, effectively erasing the tokens. However, they can still collect trading fees from the toke , which reportedly reached up to $60,000 last week.

Who the sweep catches

Take-Two’s Discord subpoena covers servers including one belonging to Australian GTA 5 streamer Matthew Judge, better known as DarkViperAU. He posted on X that he had nothing to do with the event and didn’t know anything about it.

Microsoft and Discord have until September 4 to hand over the data. If they comply, potentially hundreds or thousands of people with no known connection to the leaks could have identifying information handed over to Take-Two as part of its investigation.

Other attacks on Take-Two

This isn’t the first hacking incident that Take-Two and its game studio subsidiary Rockstar have faced. In April, the ShinyHunters cybercrime crew stole 78.6 million Rockstar records without directly compromising any of the company’s internal systems.

Rather than compromising Rockstar, ShinyHunters targeted Anodot, a cloud analytics vendor that held persistent authentication tokens for its customers’ Snowflake cloud database environments.

Persistent authentication tokens are what some software gives you after you’ve proven your credentials once so that you don’t have to go through the login process again. They’re convenient, but the danger is that if someone gets hold of one, they can impersonate you without needing your password.

Gaining access to victims’ data by compromising third-party service providers holding that data is the ShinyHunters gang’s modus operandi.

Neither is this the first time that GTA material has been leaked. In September 2022, a hacker posted video footage of GTA 6 online.

What does all this mean to you? If you’re a gamer, then it means being diligent. GTA’s popularity tends to spawn scams online. The game’s popularity has attracted scammers fraudulently touting free in-game money, malware-filled mods, and more recently, offers of free early access designed to part you with the contents of your crypto wallet.

Real leaked footage can make scams more convincing to gamers who want to see more. Yesterday, Malwarebytes researchers found fake GTA 6 Extended Look and demo sites that lead visitors to password-stealing malware.

Don’t believe offers of early access or downloadable GTA 6 demos. The only safe bet is a direct pre-order from Rockstar. Otherwise, keep your powder dry (and your money safe) until the actual game lands on consoles in November. PC players will have to wait a little longer.


Stop threats before they can do any harm.

Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →

AliExpress caught using silent audio to fingerprint visitors’ browsers

AliExpress, the online marketplace owned by Alibaba Group, has come under scrutiny after researchers and browser maker Brave reported finding silent Web Audio processing on the site that could help fingerprint visitors’ devices.

The audio processing did not record people through their microphones. Instead, it generated and processed an inaudible signal, then measured small, repeatable differences in the way a browser and device handled it.

Browser fingerprinting is a way for websites to identify devices and recognize returning visitors without relying on conventional cookies. It works by using information about a device and browser to create a unique signature.

The AliExpress website was found processing a fixed audio waveform and examining the resulting numerical values. Tiny differences can arise from the browser, operating system, CPU behavior, audio hardware, and drivers. When combined with other signals, they become another input that can contribute to a browser or device identifier.

Investigation of the page’s code reportedly found audio-processing graphs that were set to zero volume but remained connected to the system audio output. That explains why a user could hear nothing, and why muting a browser tab would not necessarily prevent the processing. All the relevant work was occurring within the Web Audio graph rather than through a conventional media player.

And audio measurements were only one part of the reported data collection. The scripts also gathered information tied to canvas rendering, WebGL, display settings, hardware configuration, WebRTC behavior and user interactions. Together, those signals can create a more detailed profile of a device than any one signal would provide on its own.

Fingerprinting can be used for legitimate purposes such as fraud prevention, bot detection, and risk assessment. It can help companies spot suspicious transactions or automated activity even when cookies have been deleted or accounts have changed. But it also raises privacy concerns because users may not know the tracking is happening and have limited control over it.


Safer. Cleaner. Ad-free browsing.


Earlier studies have shown that visitors’ choices about allowing cookies were ignored in more than half the cases studied. Fingerprinting adds another privacy concern because it can allow websites to recognize visitors without relying on cookies at all.

How to protect yourself

The alleged AliExpress implementation is a useful example of how modern tracking can be both silent and technically legitimate at the API level while still raising privacy concerns.

Brave says its browser blocks the AliExpress scripts responsible for the audio-based tracking. Other steps you can take include:

  • Use content blockers and anti-tracking extensions to limit the information websites can collect about your browser and device.
  • Keep your browser up to date since browser vendors continually change privacy defenses as fingerprinting methods evolve.
  • Use a separate browser or browser profile for shopping, ideally without signing in to other services in the same profile.

Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Twitch wants your content for Amazon AI training. Here’s how to opt out

The Dutch Autoriteit Persoonsgegevens (AP) has advised Twitch users to opt out of sharing data with Amazon AI.

Twitch launched as a live-video platform and is currently owned by Amazon. Its core product is live broadcasting with a built-in chat culture: streamers broadcast gameplay, commentary, performances or other live content while viewers interact in real time.

Twitch is one of the world’s largest livestreaming platforms, with millions of people broadcasting and watching content every month.

Last week we learned that Twitch allows Amazon to use content from its platform to train generative AI models, with the setting enabled by default. Chief Product Officer Mike Minton said during an interview:

“If it’s opt-in, nobody would opt in. That’s the honest answer. So, it’s going to be on by default.”

So, to get this straight: they know users don’t want it, yet users are opted in by default and they make it difficult to opt out.

The AP argues that:

“Live streams on Twitch show the gamer’s face, voice and name, and often include images of a private space, such as a bedroom. This constitutes personal data. In the case of facial images, this even involves sensitive personal data. Once these data are stored in Amazon’s AI systems, they cannot simply be removed. As a result, users lose control over their data. Users’ chats and text messages also serve as training material for Amazon.”

Obviously, Twitch users were outraged when they learned about the assumed consent. The setting is in the Streamer Dashboard under Settings > Security and Privacy, near the bottom of the page. That is the basis for reporting that it was difficult to find.

Wait, it gets worse. Ars Technica says the AI training itself isn’t new. What’s new is the option to opt out. That setting arrived more than two years after a company executive confirmed that Amazon was using Twitch content for AI training.

In April 2024, Minton said Amazon was using Twitch content to prototype AI models, although not yet at “production scale.”

How to turn it off

The setting is enabled by default. To turn it off, go to: Settings > Security and Privacy > scroll down to Training for Generative AI, and turn the setting off.

Training for Generative AI setting on Twitch

“Allow your channel content to train generative AI content models of Amazon. Turning this off does not opt you out of Twitch and Amazon using your channel content for other purposes described in the Twitch Privacy Notice, including using AI-supported Twitch features that benefit the community by facilitating streamer growth and monetization (such as real-time sponsorship campaign assistance), viewer discovery (such as recommendations), and community safety (such as AutoMod).”

Note that if you post in another streamer’s chat, whether that chat can be used for AI training depends on that streamer’s setting, not yours. So turning off the option on your own channel does not necessarily stop everything you write on Twitch from becoming training material.

There’s an old saying that “if you’re not a paying customer, you’re the product,” but that shouldn’t be an excuse to disregard users’ privacy or assume consent. We agree with the AP: If you have a Twitch channel and don’t want your content used to train Amazon’s generative AI models, turn the setting off.


Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

9 million images of people’s faces exposed by reverse lookup service

Researcher Jeremiah Fowler found a cloud database containing more than 9 million image files accessible without authentication, WIRED reports.

The leaky bucket, containing some 450 GB of images, was traced back to a US-registered company called ClarityCheck.

In their own words, ClarityCheck says:

“Use reverse image search to identify anyone in a photo. Find names, social profiles, and online presence in seconds.”

While ClarityCheck says it does not use facial recognition, it does describe its image function as a way to identify people and find their names and social profiles.

Granted, there’s a difference.

  • An image search looks for identical or visually similar images, often using image embeddings, metadata, or indexed pages.
  • Facial recognition detects a face, derives face-specific features, and compares them to a structured, face-indexed collection of digital images.

But does that difference matter when your face gets uploaded and stored in an unsecured cloud environment?

It is important to remember here that faces are persistent identifiers. A leaked password can be reset, whereas a person cannot easily replace their face. When an image of someone is linked with names, social profiles, addresses, emails, or phone numbers, that information could potentially be misused for impersonation, targeted phishing, doxxing, or catfishing.

ClarityCheck disputed that the data was publicly exposed because accessing it required an unindexed URL. However, the images didn’t require authentication, and Fowler was able to discover the URLs through the site’s code.

It is unknown how long the bucket was exposed before Fowler found it. Despite earlier alerts from Fowler, ClarityCheck did not restrict access to the database until WIRED contacted the service in July.

People finder tools

People finder tools are online services that aggregate public records, contact data, and social footprints to help locate individuals using names, phone numbers, emails, or addresses.

If you want to check whether someone on social media is using a fake or stolen profile picture because you’re worried they might be a scammer, a conventional reverse image search can help you see where else that picture appears online. You don’t need a people finder tool.

ClarityCheck, along with many others like it, requires users to confirm that they own the image, appear in it, or otherwise have the necessary rights and permission to upload it. Of course, a checkbox cannot prevent someone from lying.

There are a few pointers we want to give people who use ClarityCheck or similar tools:

  • Do not upload a photo of someone else unless you have their permission or another clear legal right to do so.
  • Think twice before uploading your own photo if you’re not sure how it’s going to be used, how long it will be stored, and how secure that storage is.
  • Before using any service, check its policies on image retention, deletion, AI model-training use, storage, third-party sharing, and removing images.
  • If you find yourself in a search result, save the URL and screenshots, request delisting from the search service, and seek removal from the original site or platform hosting the image.

Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Be careful what you put in “anyone with the link” Google Docs

The next time you type something sensitive into a Google Doc—or any other online tool with a sharing feature—be careful about the permissions you grant.

Speaking with The Register, the founder of QR generation service Pageloot said that he learned that the hard way. Siim Kostabi recalled how a contractor working for the company accidentally exposed login details for its staging environment—credentials that were never meant to leave an internal testing setup.

The hapless developer had access to a staging environment (used to test new software code before it goes live). They stored the login details in a Google Doc and then set it to “anyone with the link can view.”

It turns out Google Search can index Google Docs with that setting if the link becomes discoverable on the public web. “Anyone with the link” files aren’t automatically indexed, so we don’t know exactly how Google discovered this particular document. What we do know is that it did: The credentials file ended up in Google Search.

A Pageloot developer typed the company’s domain into Google while debugging, and Google’s autocomplete feature surfaced a staging hostname followed by what looked like a credential string. Sure enough, the document was accessible online. Google Search was surfacing information from a document that had been shared too widely.

To its credit, Pageloot moved quickly. It cut the contractor’s access and changed every affected credential. It also banned password storage in Google Docs, Slack, Notion, and any other shared workspace.

The problem is that none of those fixes existed before autocomplete surfaced the password. If nobody had spotted it, the credentials could have remained exposed.

People share private data in online tools all the time

If there was ever an example of why you should use a password manager, this is it. Instead, the contractor typed their login details into a Google Doc, presumably to keep them handy.

Pageloot isn’t alone in dealing with this problem. Ateam, a Japanese Android game developer, left a Google Drive instance set to “Anyone on the internet with the link can view” from March 2017 until November 2023. That single misconfiguration exposed 1,369 files and personal data for 935,779 people. Ateam said it had seen no evidence anything was taken, though seven years of open access is hardly reassuring.

Scale AI, the data-labeling company central to Meta’s AI ambitions, also left 85 Google Docs with training material for Meta, Google, and xAI editable to anyone with a link. Contractors called the setup “incredibly janky”. Scale later disabled users’ ability to share managed documents publicly.

This is a trend. Three years ago, AI security company Metomic scanned approximately 6.5 million Google Drive files and found that 40.2% contained sensitive information. Just over a third were shared externally, while 0.5% were fully public.

That 0.5% might not sound like a lot, but across 6.5 million files, it still represents thousands of publicly accessible files.

This isn’t just a Google problem, though. People accidentally share sensitive information through other tools too, like the Trello project management system. Making a Trello board public makes it viewable to everyone, which was unfortunate for government users when they exposed passwords and security plans that way in 2018.

The problem is that as tools become increasingly collaborative, people can’t keep up. They make mistakes. Verizon’s 2025 Data Breach Investigations Report attributes around 60% of breaches to human factors including misconfiguration and misuse of valid credentials.

What the checkbox cost

Pageloot encountered another access-control failure involving a customer. A disgruntled former employee whose access had never been revoked used it to redirect the customer’s QR codes to a competitor’s site. It was the same root cause: nobody was watching who had access to what.

Kostabi learned his lesson, which is to keep an eye on who has access to what.

Consumers can take a few simple precautions too. Don’t store passwords or other highly sensitive information in ordinary shared documents. Use a password manager for passwords, and before hitting Share in any online service, check exactly who will be able to access what you’re sharing.


CNET Editors' Choice Award 2026

“One of the best cybersecurity suites on the planet.” 

According to CNET. Read their review


Parents take on Meta, TikTok, Google, and Snap in 3,000 youth safety lawsuits

A group of big tech firms is fighting to stop roughly 3,000 youth safety lawsuits from moving forward, and they just lost a critical procedural battle in court.

The lawsuits, brought by attorneys general and families, allege that Meta, Google, ByteDance’s TikTok, and Snap knew their products were addictive to children and teens and harmful to their mental health, but continued marketing them to young users for profit.

The tech companies tried to appeal against a federal court ruling that allowed those involved to file their lawsuits in court. They argued in the 9th US Circuit Court of Appeals that a linchpin US law meant they couldn’t be sued.

That law is Section 230 of the Communications Decency Act, created 30 years ago. It says that platforms cannot be held responsible for things that their users post online. For years, social media companies treated it like a bulletproof vest. When users posted something bad, the company running it could claim it was the messenger, not the author.

That defense doesn’t seem to be working here. On August 10, the court ruled that Section 230 “provides a defense to liability, not immunity from lawsuits, so the appeal was premature.” This case revolves not so much around what people posted online as how the tech companies allegedly engineered their platforms to present that content to users.

The Nebraska Law Review explains several of the techniques the lawsuits say make these platforms more engaging, and potentially more addictive.

The article explains how certain interactions on these platforms can trigger dopamine release. Those interactions could be as simple as someone responding to your message or liking one of your photos. Dopamine plays an important role in the brain’s reward system.

The NLR article describes techniques such as making those rewards unpredictable, which encourages people to keep checking their accounts habitually. Interface features like the infinite scroll are also designed to keep you on the dopamine train. The paper cites the inventor of that particular idea, who describes it as:

“taking [behavioral] cocaine and just sprinkling it all over your interface.”

Anyone who’s spent too long in bed doomscrolling can relate.

The 9th Circuit’s denial of the appeal is procedurally narrow but strategically enormous. Section 230 is a defense you argue at trial, not a wall that keeps plaintiffs off the courthouse steps. The Third Circuit has gone further, ruling that Section 230 “does not provide immunity to platforms if they face tort lawsuits over injury caused by the algorithms they design.”

The algorithm, in other words, is the product. The product can be defective.

Behind those cases sits a growing pile of discovery material that plaintiffs argue sheds light on how the platforms approached user engagement, and a New Mexico judgment against Meta earlier this month in a case exploring similar complaints. That judgment now totals $942 million because the judge added $567 million onto the original amount, finding Meta had:

“created a public nuisance through its platform design.”

What discovery keeps dragging out

Discovery in these cases has already been unkind to Meta. A 2016 email attributed to Mark Zuckerberg said that alerting parents to teens’ live videos would “probably ruin the product from the start”. A recent court filing alleged that staff at social media giants have compared their own platforms to drugs, with one Meta employee writing that:

“we’re basically pushers.”

Snap looks no better. By late 2022, Snap employees were fielding roughly 10,000 sextortion reports per month, according to a filing in the New Mexico case. An internal investigation concluded that 70% of victims never reported abuse because “they knew no action would be taken by Snap; indeed, of the 30% that did report, none were addressed.”

That number surfaced through New Mexico’s unredacted complaint, not through any Snap disclosure.

Safety features that don’t work

If executives knew, the fixes should have followed. Mostly they didn’t. Researchers at NYU and Northeastern University tested 86 youth safety features and found 51 failed their tests. Snapchat’s failure rate was 73%, Instagram’s 66%, YouTube’s 55% and TikTok’s 50%. Nine features couldn’t even be triggered when the researchers tried. The researchers reported that every cyberbullying safeguard they tested failed.

The bypasses were quick to find. Type “eating disorder” into Instagram search and autocomplete politely offers the deliberate misspellings that pro-eating-disorder communities use to duck the platform’s own blocklist. Safety, in that instance, was doing the opposite of safety.

What parents can do now

Don’t assume in-app safety features work exactly as advertised. If your child uses social media, test the settings yourself and confirm they’re doing what you expect.

Set up a test account and check that each setting blocks what it claims to block. And think about the amount of social media time you want to grant your children, or whether you want to let them use it at all. Either way, it begins with an honest family conversation.

If your child is being harassed by people they know online, encourage them to tell you immediately. Save evidence, block and report the accounts where appropriate, and don’t hesitate to involve the school or law enforcement if the harassment includes threats, blackmail, or sexual exploitation.

You can also report sextortion to the National Center for Missing and Exploited Children’s CyberTipline directly, rather than trusting a platform’s own reporting queue.

Check back here for more details on the federal case. The next several months will decide whether the biggest platforms in history get rewritten by juries, or whether they settle their way out one confidential check at a time.


From reporting threats to removing them.

Cybersecurity risks should never spread beyond a headline. Keep threats off your devices by downloading Malwarebytes today.

Meta ordered to pay $942 million over harm to children

A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms.

Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual exploitation, while making misleading claims about the safety of its products.

Meta said it disagreed with the ruling and planned to appeal.

“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”

But the ruling is more than just a fine. It also imposes product-level obligations in New Mexico. Meta must continue improving its age-assurance tools, including:

  • Develop an under-13 prediction model within two years.
  • Seek proof of age from users it estimates are under 13.
  • Treat uncertain accounts as belonging to minors until their age is verified.
  • Delete personal data collected from under-13 users.

The company must also create a channel through which schools or a child-safety organization can report suspected underage accounts and submit compliance updates twice a year.

This is a significant step. A company can remove individual accounts or posts after the fact, but the New Mexico case focuses on whether the surrounding product design, age checks, disclosure practices, and reporting systems adequately protect children in the first place.

From Meta’s side, this is hardly a one-off incident. The Wall Street Journal reports that Meta is fighting thousands of lawsuits by individuals, school districts, and more than 40 state attorneys general which are pending in state and federal courts. 


Safer. Cleaner. Ad-free browsing.


How to keep your children safe

In February, we published research on how safe kids are when using social media. As the company behind Facebook, Instagram, and WhatsApp, Meta plays a major role in this field. But unfortunately, it seems Meta isn’t even capable of blocking ads that contain AI generated Child Sexual Abuse Material (CSAM).

Some tips for parents:

  • Keep communication open. Keep conversations about online activity open and ongoing, not one-off warnings. Talk to your child about who they interact with online and what kinds of conversations are appropriate. Warn them about strangers in comments, group and gaming chats, and direct messages. Encourage them to leave spaces that make them uncomfortable, even if they didn’t do anything wrong.
  • Set up accounts together. Use child or teen accounts where available and avoid defaulting to adult accounts. Keep friends and followers lists set to private. Avoid using real names, birthdays, or other identifying details unless they are strictly required. Avoid facial recognition features for children’s accounts. For teens, be aware of “spam” or secondary accounts they’ve set up that may have looser settings.
  • Treat age limits seriously. While we don’t like many of the ways they are implemented, the age restrictions are there for good reasons. Do not help children bypass a platform’s minimum age requirement. Age restrictions can reduce exposure to adult spaces, unwanted contact, and features not designed for children.
  • Discuss images and AI explicitly. Teach children never to send intimate images, even to someone they know, and to be wary of “nudify,” face-swap, or AI image-editing apps. Explain that AI-generated sexual images can be used to harass, blackmail, or humiliate someone, even when no original explicit photo exists.
  • Have a simple escalation plan. If someone becomes sexual, coercive, threatening, or asks to move a conversation to another app: stop replying, preserve relevant evidence, block the account, and report it to the platform and appropriate child-protection or law-enforcement services.
  • Teach a “pause before you click” habit. Children should know that ads, giveaways, direct messages, and links can be scams or gateways to harmful material. Encourage them to ask an adult before installing unfamiliar apps, entering personal information, or sharing photos.

The most effective and probably hardest of them all is to find a balance between relying on device and platform controls and helicopter parenting. Device and platform controls can limit screen time, sensitive content, and unknown contacts. And they work best alongside trust, shared rules, and periodic check-ins rather than covert surveillance.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Valve warns Steam hardware buyers: Expect fake delivery scams

Most of us are wise to phishing emails that don’t contain much personal information. Generic “your account is suspended” messages usually get binned on sight. But what about the phishing emails that use your real name and address, and reference the specific product you bought last month? Even for the most suspicious of people, that can be convincing.

It’s also the situation European Steam hardware buyers walked into this week. On August 10, Valve, the company behind the Steam gaming platform and Steam hardware, warned customers that a cyberattack had exposed names, home addresses, phone numbers, Steam email addresses, and details of their hardware orders.

It wasn’t Valve itself that got hacked. Rather, it was its shipping partner CEVA Logistics, which handles delivery of hardware from the gaming store. Passwords and payment information were not touched.

What got stolen

The attack window ran from July 29 to August 1, 2026. Valve learned about it on August 7 and started notifying customers three days later. CEVA stores delivery data for roughly 90 days after shipment, meaning anyone who received a Steam Deck, Steam Controller, or Steam Machine in Europe over the past three months could be affected.

The exposed information may include:

  • Name
  • Street address, postal code, and city
  • Country
  • Phone number
  • Email address linked to the customer’s Steam account
  • The type and price of the ordered hardware

Exact numbers are still unconfirmed. Neither Valve nor CEVA has said how many customer records were involved. Dutch retailers Bol and De Bijenkorf were reportedly told about the same CEVA incident on August 1 and warned their own customers.

Why shipping data is valuable to scammers

A scammer can send an email, text, or even make a phone call that references your genuine order and delivery address before asking you to pay a small customs or redelivery fee, confirm your delivery, or sign in to “verify” your order.


Scam or legit? Scam Guard knows.


Data like this is already widely traded online. Malwarebytes researchers found more than 7,500 compromised datasets containing over 8.4 billion records on the dark web during the first six months of 2026.

Not Valve’s first security incident

Although Valve’s own systems weren’t compromised, that doesn’t mean the consequences can’t be severe.

In May 2025, a threat actor called Machine1337 tried to sell what looked like a dataset of 89 million Steam user records for $5,000. The data turned out to be older SMS messages carrying expired two-factor codes, routed through a third-party intermediary Valve says it never partnered with.

Valve has suffered a direct breach in the past though. November 2011 saw one that exposed records from 35 million users, including usernames, emails, and encrypted credit card details.

What affected buyers should do

In an email to customers, Valve advises them to assume that any message referencing their recent Steam hardware order is fake. That covers email, SMS, and phone calls, even the ones that quote your address correctly.

Steam Support never contacts users through email, Steam Chat, or Discord, and only handles account problems through its help page.

So you don’t need to rush to reset your password, although it never hurts to use a strong, unique password and enable Steam Guard’s two-factor authentication. Instead, be skeptical of any unsolicited emails, texts, or calls about a recent Steam hardware delivery, even if they include details only a real customer would know.


Something feel off? Check it before you click.  

Malwarebytes Scam Guard helps you analyze suspicious links, texts, and screenshots instantly.  

Available with Malwarebytes Premium Security for all your devices, and in the Malwarebytes app for iOS and Android.  

Try it free → 

Sexual predators targeting online accounts for intimate images, FBI warns

The FBI has issued a Public Service Announcement (PSA) warning that criminals are breaking into social media and personal accounts to steal and distribute intimate images and videos without consent. The FBI refers to this type of content as non-consensual intimate images (NCII).

The stolen material may be posted or sold on criminal marketplaces alongside victims’ names, phone numbers, email addresses, and social media handles, creating opportunities for harassment, stalking, and sextortion.

According to the FBI, criminals use a mix of account takeover and social engineering tactics:

  • Password and PIN guessing: Criminals make high-volume login attempts using data from breaches, public social media profiles, leak sites, and other publicly available sources. Known victims may be targeted using name variations, birth dates, and other predictable personal details.
  • Fake customer service texts: Victims receive a message claiming their social media account will be locked or disabled. The criminal triggers a legitimate password reset request, then persuades the victim to hand over the resulting verification code.
  • Phishing emails: Lookalike support domains and email addresses warn of a “new login” and direct victims to a fake password change page designed to steal credentials.

This is different from the familiar “I recorded you” sextortion email, which typically relies on intimidation rather than a real account compromise. Still, if such an email includes a password you still use, change it immediately wherever it remains in use.

How to stay safe

There are several ways to reduce the risk of becoming a victim:

  • Avoid storing sensitive images on social media platforms or other internet-connected services when possible. Breaches and leaks happen, and those images can end up in the wrong hands.
  • Use a password manager to create a unique, long password for every account. Don’t base passwords or PINs on names, birthdays, or other public information.
  • Turn on multi-factor authentication (MFA), preferably with passkeys or hardware security keys where available. MFA is valuable, but criminals can still phish one-time codes and session cookies, so never approve an unexpected prompt or share a verification code.
  • Treat unexpected “account warning” links in texts and emails as suspicious. Open the service’s official app or type the known web address yourself instead. Don’t trust sponsored search results to take you to the correct website.

If you discover that intimate content has been stolen or shared, preserve any relevant links and evidence, secure the affected accounts, and report it through the FBI’s NCII reporting portal at ncii.ic3.gov.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Meta ordered to pay $942 million over harm to children

A New Mexico court has ordered Meta to pay a total of $942 million after finding that Facebook and Instagram harmed young users and that the company misled consumers about the safety of its platforms.

Reportedly, the decision combines a $375 million civil-penalty verdict from March with a newly ordered $567 million abatement fund intended to address the damage. The court accepted the state’s argument that Meta had concealed what it knew about risks to children’s mental health and child sexual exploitation, while making misleading claims about the safety of its products.

Meta said it disagreed with the ruling and planned to appeal.

“We remain confident in our record of protecting teens online and will continue to defend ourselves against claims that misrepresent the facts.”

But the ruling is more than just a fine. It also imposes product-level obligations in New Mexico. Meta must continue improving its age-assurance tools, including:

  • Develop an under-13 prediction model within two years.
  • Seek proof of age from users it estimates are under 13.
  • Treat uncertain accounts as belonging to minors until their age is verified.
  • Delete personal data collected from under-13 users.

The company must also create a channel through which schools or a child-safety organization can report suspected underage accounts and submit compliance updates twice a year.

This is a significant step. A company can remove individual accounts or posts after the fact, but the New Mexico case focuses on whether the surrounding product design, age checks, disclosure practices, and reporting systems adequately protect children in the first place.

From Meta’s side, this is hardly a one-off incident. The Wall Street Journal reports that Meta is fighting thousands of lawsuits by individuals, school districts, and more than 40 state attorneys general which are pending in state and federal courts. 


Safer. Cleaner. Ad-free browsing.


How to keep your children safe

In February, we published research on how safe kids are when using social media. As the company behind Facebook, Instagram, and WhatsApp, Meta plays a major role in this field. But unfortunately, it seems Meta isn’t even capable of blocking ads that contain AI generated Child Sexual Abuse Material (CSAM).

Some tips for parents:

  • Keep communication open. Keep conversations about online activity open and ongoing, not one-off warnings. Talk to your child about who they interact with online and what kinds of conversations are appropriate. Warn them about strangers in comments, group and gaming chats, and direct messages. Encourage them to leave spaces that make them uncomfortable, even if they didn’t do anything wrong.
  • Set up accounts together. Use child or teen accounts where available and avoid defaulting to adult accounts. Keep friends and followers lists set to private. Avoid using real names, birthdays, or other identifying details unless they are strictly required. Avoid facial recognition features for children’s accounts. For teens, be aware of “spam” or secondary accounts they’ve set up that may have looser settings.
  • Treat age limits seriously. While we don’t like many of the ways they are implemented, the age restrictions are there for good reasons. Do not help children bypass a platform’s minimum age requirement. Age restrictions can reduce exposure to adult spaces, unwanted contact, and features not designed for children.
  • Discuss images and AI explicitly. Teach children never to send intimate images, even to someone they know, and to be wary of “nudify,” face-swap, or AI image-editing apps. Explain that AI-generated sexual images can be used to harass, blackmail, or humiliate someone, even when no original explicit photo exists.
  • Have a simple escalation plan. If someone becomes sexual, coercive, threatening, or asks to move a conversation to another app: stop replying, preserve relevant evidence, block the account, and report it to the platform and appropriate child-protection or law-enforcement services.
  • Teach a “pause before you click” habit. Children should know that ads, giveaways, direct messages, and links can be scams or gateways to harmful material. Encourage them to ask an adult before installing unfamiliar apps, entering personal information, or sharing photos.

The most effective and probably hardest of them all is to find a balance between relying on device and platform controls and helicopter parenting. Device and platform controls can limit screen time, sensitive content, and unknown contacts. And they work best alongside trust, shared rules, and periodic check-ins rather than covert surveillance.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Apple WebKit vulnerabilities reveal your IP address, despite Private Relay

Three WebKit mechanisms have been discovered to bypass Apple’s iCloud Private Relay. In fact, the mechanisms can bypass any browser‑level proxy configuration, including Psylo’s proxy, Tor-on-iOS proxy setups, and so on.

Private Relay is a VPN-like system for Safari on iOS which is meant to prevent websites from viewing the visitor’s IP address and location.

But because all three methods described by the researchers occur outside WebKit’s normal page loading path, Apple’s iCloud Private Relay never sees them and, as a result, means you can’t hide your IP address or Domain Name System (DNS) path in these cases.

The three features are:

  • DNS prefetching
    Modern browsers try to be faster by looking up the IP addresses of links on a page before you click them, a feature known as DNS prefetching. In WebKit, these DNS lookups can bypass the configured proxy/relay and go straight through the system’s normal DNS stack, exposing which DNS servers you are using and, indirectly, where you really are. Even if the actual page load goes through Private Relay, the prefetch DNS queries can still leak metadata about your network.
  • WebAuthn and passkeys
    WebAuthn (the standard behind passkeys) sometimes needs to fetch a small file from the website’s domain to verify that the credential is being used on the right site. The researchers found that, on Apple platforms, this fetch is performed outside the usual WebKit page‑loading path, which means it is not sent through the Safari proxy or Private Relay. The result is that a site using passkeys can cause your device to contact it directly, revealing your true IP address even if the rest of your browsing is supposedly hidden behind a relay.
  • WebTransport and related technologies
    WebTransport is a newer API that gives websites a way to open low‑latency, bidirectional connections to a server. In the scenarios the researchers tested, these WebTransport connections were also initiated outside the proxied WebKit code path, creating another route for sites to receive traffic straight from the device. That traffic again carries the device’s real IP, not the relay or proxy IP the user expects.

From a user‑experience point of view, the problem is that all three mechanisms look like normal browser behavior and require no special tricks from a malicious site.

What’s affected

Affected are Safari on iOS and macOS when Private Relay is used, because Private Relay is implemented as a WebKit‑level proxy that only applies to Safari traffic. Additionally, any iOS/macOS browser or app that relies on WebKit’s proxy configuration to hide the IP (e.g., Psylo, Onion Browser/Tor on iOS, and other proxy browsers), since they all hit the same WebKit behavior.

And that’s not necessarily all. For most of iOS’s history, any app that browsed the web had to use Apple’s WebKit framework and JavaScript engine. This meant that Chrome, Firefox, Edge, Brave, and other browsers on iPhone were effectively different shells around the same WebKit engine Safari uses. Under pressure from the EU’s Digital Markets Act (DMA), Japan’s Smartphone Act, and similar regulatory pushes, Apple introduced a mechanism for non‑WebKit engines, but only in constrained ways.

Malwarebytes’ Senior manager for iOS software Roman Dvoinev commented:

“Basically the API has been “open” for a while, but no browser vendor has actually shipped a non-WebKit browser yet. Major players are still in prototype phase, as Apple’s bar for shipping a browser to iOS is very high.”

Malwarebytes VPN is not affected, since it tunnels the device’s entire network traffic at the system level.

The researchers have reported the problems to Apple and are expecting patches by fall.


Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Apple battles it out again with the UK over encrypted iCloud access

The UK Home Office has once again demanded Apple allows it access to encrypted iCloud data.

The Guardian reports that the Home Office issued a Technical Capability Notice to Apple, this time targeting only British users. A Technical Capability Notice is a formal government order that compels tech and telecommunications companies to build or maintain specific technical functions—such as intercepting data or removing encryption protections—so law enforcement can access communications.

In the last round of this ongoing battle, the UK secretly ordered Apple to provide blanket access to protected iCloud backups around the world. Advanced Data Protection (ADP) is Apple’s opt‑in end‑to‑end encryption for iCloud backups, which even Apple itself cannot read. Apple argued that weakening or removing ADP would expose users to data breaches and other threats, and instead chose in January 2025 to withdraw ADP for UK customers rather than build a backdoor, while leaving it available elsewhere.

So, instead of working to keep citizens safe and secure, the Home Office just ended up removing an option for them.

Apple has responded by lodging a complaint with the Investigatory Powers Tribunal (IPT), seeking to challenge the scope and lawfulness of the government’s powers to issue such notices under the Investigatory Powers Act. The Tribunal is an independent court that has the power to investigate claims that the UK intelligence services have acted unlawfully.

Privacy International and Liberty have parallel complaints at the IPT challenging Technical Capability Notices more broadly, including their secrecy and necessity, and have asked for Apple’s claim to be heard in public given its wide public-interest implications.

I feel the fear of leaving an intentional backdoor is justified. If it exists, there is a chance that (AI-assisted) criminals will find and exploit it.

Weighing the importance of the right to privacy and the ability to investigate cases including terrorism and child sexual abuse is not easy. Apple’s ADP is used by many and as soon as criminals would know it’s no longer safe for them to use, they’d move to other platforms. Platforms where no legislative power will be able to gain access.

Reddit r/privacy users have been discussing alternatives for a year.

But, given the danger of a backdoor becoming available for criminals, we think in this case privacy should prevail. Let us know how you feel in the comments.


Browse like no one’s watching. 

Malwarebytes Privacy VPN encrypts your connection and never logs what you do, so the next story you read doesn’t have to feel personal. Try it free → 

Californians can tell data brokers to DROP their information

California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers in one place.

DROP was created under California’s Delete Act, which forces data brokers to register with the California Privacy Protection Agency (CPPA) or face fines. Currently over 600 data brokers are in the registry.

Data brokers collect and sell extensive personal information, including financial details, online behaviors, and location data. This data is often gathered without explicit consent, raising concerns about privacy and transparency.

DROP is a state service that sends a standardized deletion/opt‑out request to all data brokers registered with the California Privacy Protection Agency. Starting August 1, 2026, registered data brokers in California are required to access DROP and have 90 days to delete a person’s records after a request.

How to use DROP

You’ll need to provide at least one reachable email address and/or mobile phone to verify your identity and track the request. Be ready to provide basic personal data (name, address, contact details) that brokers are likely to have and that DROP uses to match your records.

  • Go to the DROP portal.
  • Use the “Get Started” button on the homepage.
  • Accept the terms and conditions presented by the platform by using the “I accept” button.
  • You’ll need to verify that you are a California resident: you can either input your personal information manually, or authenticate via Login.gov, which allows identity verification through a federal login. If you receive the message “Unable to verify” your status as a California resident, click the link on screen to “Request a review of your eligibility.”
  • After residency verification, create a deletion request:
    • Provide your email address and/or phone number to verify contact details.
    • Fill in basic information (name, address, etc.) so brokers can locate your records.
  • Submit your request through DROP and you’ll receive a DROP ID that lets you track the status of your request online. Store that number somewhere.

Now, it’s up to the data brokers. They now have 90 days to delete your records and comply with opt‑out obligations. If you run into a problem there is a dedicated help site.

For non-Californians

Some other states—like Oregon, Texas, and Vermont—also require data broker registration, though only California currently offers a centralized platform like DROP. If you live in such a state, check your attorney general’s website or privacy office for a “data broker registry” or opt‑out guidance, and follow their listed processes to submit requests directly to each broker.

Even without DROP, US residents can still reduce data broker collection and sale of their data, but it requires more manual work. Where no centralized government tool exists, you can identify brokers by searching for “data broker opt‑out” and review lists from privacy advocacy groups.

For each broker you’ll have to submit individual requests:

  • Use their web forms, email addresses, or postal addresses to request:
    • Deletion of your data, and
    • Opt‑out from sale or sharing of your data.

You’ll need to provide enough information to match your record (e.g., name, address, email, phone) but avoid oversharing additional sensitive data.

It’s advisable to maintain a spreadsheet with dates, brokers, and confirmations. Most privacy laws specify response deadlines, often 30–45 days, though this varies by state.

Sounds like a lot of work? Malwarebytes Personal Data Remover can help.

How to reduce future data broker collection

This is probably the only field where “security by obscurity” works.

Use multiple email addresses where you reserve one for financial/critical accounts and use aliases or disposable emails for newsletters, shopping, and registrations, making it harder for brokers to build a unified profile.

A VPN encrypts your traffic and hides your IP address, reducing the ability of websites and analytics firms to link activity to a stable, location‑based identifier.

For non‑critical services, avoid providing full legal names, exact home addresses, or phone numbers if they’re not strictly necessary. This is especially true for rewards and loyalty programs.


Your name, address, and phone number may already be for sale.  

Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way. 

Hims & Hers sued over alleged health data privacy failures

The US Federal Trade Commission (FTC), together with Utah and California, has filed a lawsuit against telehealth provider Hims & Hers.

The FTC alleges that the company shared consumers’ sensitive health information with third‑party advertising platforms despite promising strong privacy protections.

Hims & Hers is a telehealth and digital health platform that connects users with licensed medical providers for online consultations, prescription medications, and personal care products.

The complaint also accuses Hims & Hers of deceptive billing and subscription practices that made it hard for users to avoid charges or cancel subscriptions.

According to the FTC’s complaint, filed in federal court in California, Hims & Hers:

  • Shared sensitive health data, including details about medical conditions, with ad platforms such as Meta and Snap despite privacy promises.
  • Charged before consultations. The company promised users they could consult a medical provider before being charged, but the FTC says many consumers were enrolled in recurring prescription subscriptions shortly after they submitted an intake form, often without first having a consultation.
  • Made cancellation difficult. Before 2023, cancellation reportedly required contacting customer service by phone, email, or chat. Even after an online cancellation option appeared, the FTC alleges the button was hidden behind multiple steps and confusing options.

From a cybersecurity and privacy research perspective, this isn’t just about a single telehealth brand. It highlights three broader trends we see repeatedly in consumer programs:

Privacy policies versus reality. A company can market itself as privacy‑focused while still integrating third‑party advertising and analytics software development kits (SDKs) that leak sensitive information. This becomes especially concerning when health‑related events are linked to user accounts or tracking cookies.

Friction as a feature. Hard‑to‑find cancellation flows and unclear billing practices are examples of “dark patterns” that nudge users into paying for services they might not have chosen given all relevant information.

Regulatory pressure is growing. Health‑related services are under increasing scrutiny, especially when they handle sensitive data and combine it with advertising platforms.

The court will ultimately decide whether Hims & Hers violated the law, but the FTC’s action sends a clear signal: regulators are paying close attention to how health‑related services collect, use, and share sensitive data.

For anyone who values online privacy, the Hims & Hers case is a reminder that “health tech” does not automatically mean “privacy first.”

How to stay safe

More often than not, the privacy loopholes are hidden in the privacy policy somewhere.

Pro tip: one thing AI is good at is reading between the lines. Ask an AI chatbot to summarize a privacy policy and identify when your information may be shared with third parties. AI makes it much easier to understand lengthy privacy policies without reading every word yourself. If companies fail to follow their own privacy policies, regulators and consumers can hold them accountable.

Other than that:

  • Don’t share sensitive information unless it’s genuinely needed to provide the service.
  • Use strong, unique passwords and multifactor authentication (MFA). Even if a company is compliant, breaches happen. Unique passwords and two‑factor authentication limit the damage if your account details are exposed.
  • Check your browser and app permissions. Disable unnecessary tracking features where possible, and consider privacy‑focused browser settings or extensions that limit third‑party cookies and trackers.

Your name, address, and phone number may already be for sale.  

Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way. 

❌