Visualização de leitura

Suisun City Declares Emergency After Cyberattack Disrupts Systems

Suisun City Emergency

The Suisun City emergency declared by local officials followed a cyberattack that forced the Northern California municipality to shut down its information technology network, disrupting some communications used by public safety agencies. The incident has placed the California city of roughly 30,000 residents among communities confronting the growing threat of cyberattacks against essential local services.  The Suisun City Council declared a state of emergency Saturday after the attack compromised the city's computer systems. Officials said the network shutdown was necessary to contain the threat and preserve potential evidence for a federal investigation into the incident.  Although the Suisun City cyberattack affected communications operations involving both the fire and police departments, city officials said there was no imminent danger to the public. They also emphasized that public safety services continued to operate despite the disruption.  One of the most significant effects involved the handling of emergency communications, including the routing of 911 calls. Suisun City dispatchers began receiving emergency police and fire calls through the Solano County dispatch center as officials worked around the damaged municipal network. 

Suisun City Emergency Response Shifts Dispatch Operations 

The Suisun City emergency response required officials to temporarily move some communications functions outside the city's own computer infrastructure. By Sunday morning, online city services and internal municipal operations remained unavailable while cybersecurity specialists investigated the attack.  Those experts were also working to restore the affected systems. The decision to take the network offline was intended not only to stop the cyberattack from spreading but also to protect evidence that could assist federal investigators in determining how the intrusion occurred and who was responsible.  City officials described the attack as apparently the first incident of its kind to affect Suisun City. The municipality is located about 55 miles north of San Francisco and has a population of approximately 30,000. 

California City Attack Highlights Broader Cyber Threats 

The California city incident also comes amid federal investigations into a separate wave of cyberattacks involving municipal water systems in a dozen states.  Late last month, the FBI, the Environmental Protection Agency and the Cybersecurity and Infrastructure Security Agency warned that cyberattackers had remotely accessed online infrastructure used by water and wastewater systems in at least seven states. Federal agencies said the hackers believed to be affiliated with Iran were targeting internet-connected industrial controllers with the goal of “to cause disruptive effects within the United States.”  The risks became apparent in Minnesota, where 30 water systems were affected by a cyberattack. Officials reported dramatic declines in water levels before backup systems were activated to prevent further disruption.  While the water-system attacks are separate from the Suisun City cyberattack, the incidents illustrate the expanding range of public infrastructure that can be exposed when essential services depend on connected computer networks.

Suisun City Cyberattack Comes Amid Funding Concerns 

The recent attacks have also prompted calls for greater federal support for cybersecurity efforts. Last week, a bipartisan group of lawmakers urged the restoration of federal funding for Department of Homeland Security programs intended to coordinate cybersecurity efforts across multiple states.  The lawmakers' concerns reflect the increasingly interconnected nature of cyber threats. An attack may occur within one municipality or state, but the technology and infrastructure involved can be linked to broader systems and networks that cross jurisdictional boundaries.  Gov. Gavin Newsom's office, in a statement to The Times, said there was no evidence that California water systems were among those targeted in the recent series of attacks. The governor's office nevertheless argued that cybersecurity efforts conducted independently by individual states are less effective than a coordinated federal approach.  “Cyber threats do not stop at state lines, and no state can defend against them alone,” the governor's office said.  The statement also pointed to reductions in the federal cybersecurity workforce and cuts affecting critical programs. According to the governor's office, those changes have weakened partnerships, threat intelligence capabilities and technical assistance intended to protect essential services nationwide.  “Federal cuts to the nation’s cybersecurity workforce and critical programs have weakened the partnerships, threat intelligence and technical support that help protect essential services across the country,” the governor's office said. “Reducing these capabilities while cyber threats continue to grow leaves every state, and the nation, less prepared for the next attack.” 

Californians can tell data brokers to DROP their information

California has launched the Delete Request and Opt‑out Platform (DROP), a state‑run portal that lets residents send deletion and opt‑out requests to all registered data brokers in one place.

DROP was created under California’s Delete Act, which forces data brokers to register with the California Privacy Protection Agency (CPPA) or face fines. Currently over 600 data brokers are in the registry.

Data brokers collect and sell extensive personal information, including financial details, online behaviors, and location data. This data is often gathered without explicit consent, raising concerns about privacy and transparency.

DROP is a state service that sends a standardized deletion/opt‑out request to all data brokers registered with the California Privacy Protection Agency. Starting August 1, 2026, registered data brokers in California are required to access DROP and have 90 days to delete a person’s records after a request.

How to use DROP

You’ll need to provide at least one reachable email address and/or mobile phone to verify your identity and track the request. Be ready to provide basic personal data (name, address, contact details) that brokers are likely to have and that DROP uses to match your records.

  • Go to the DROP portal.
  • Use the “Get Started” button on the homepage.
  • Accept the terms and conditions presented by the platform by using the “I accept” button.
  • You’ll need to verify that you are a California resident: you can either input your personal information manually, or authenticate via Login.gov, which allows identity verification through a federal login. If you receive the message “Unable to verify” your status as a California resident, click the link on screen to “Request a review of your eligibility.”
  • After residency verification, create a deletion request:
    • Provide your email address and/or phone number to verify contact details.
    • Fill in basic information (name, address, etc.) so brokers can locate your records.
  • Submit your request through DROP and you’ll receive a DROP ID that lets you track the status of your request online. Store that number somewhere.

Now, it’s up to the data brokers. They now have 90 days to delete your records and comply with opt‑out obligations. If you run into a problem there is a dedicated help site.

For non-Californians

Some other states—like Oregon, Texas, and Vermont—also require data broker registration, though only California currently offers a centralized platform like DROP. If you live in such a state, check your attorney general’s website or privacy office for a “data broker registry” or opt‑out guidance, and follow their listed processes to submit requests directly to each broker.

Even without DROP, US residents can still reduce data broker collection and sale of their data, but it requires more manual work. Where no centralized government tool exists, you can identify brokers by searching for “data broker opt‑out” and review lists from privacy advocacy groups.

For each broker you’ll have to submit individual requests:

  • Use their web forms, email addresses, or postal addresses to request:
    • Deletion of your data, and
    • Opt‑out from sale or sharing of your data.

You’ll need to provide enough information to match your record (e.g., name, address, email, phone) but avoid oversharing additional sensitive data.

It’s advisable to maintain a spreadsheet with dates, brokers, and confirmations. Most privacy laws specify response deadlines, often 30–45 days, though this varies by state.

Sounds like a lot of work? Malwarebytes Personal Data Remover can help.

How to reduce future data broker collection

This is probably the only field where “security by obscurity” works.

Use multiple email addresses where you reserve one for financial/critical accounts and use aliases or disposable emails for newsletters, shopping, and registrations, making it harder for brokers to build a unified profile.

A VPN encrypts your traffic and hides your IP address, reducing the ability of websites and analytics firms to link activity to a stable, location‑based identifier.

For non‑critical services, avoid providing full legal names, exact home addresses, or phone numbers if they’re not strictly necessary. This is especially true for rewards and loyalty programs.


Your name, address, and phone number may already be for sale.  

Data brokers collect and sell your personal details to anyone willing to pay. Malwarebytes Personal Data Remover finds them and gets your information removed, then keeps watch so it stays that way. 

Apple Faces Lawsuit Over Hide My Email Privacy Vulnerability

Hide My Email

Apple is facing a proposed class-action lawsuit after Anthony Alvarez alleged that the company’s Hide My Email feature failed to protect users’ real email addresses as advertised. The complaint, filed in the U.S. District Court for the Northern District of California, claims Apple promoted Hide My Email as a privacy safeguard while continuing to charge customers for access through its iCloud+ subscription service.  The legal action follows a report from 404 Media that revealed a reported vulnerability in Hide My Email. The report claimed the flaw could allow someone to identify a user’s actual email address from the private relay address generated by the feature. According to the report, Apple had been aware of the issue for more than a year before releasing a fix. 

Hide My Email Vulnerability Becomes the Focus of Apple Lawsuit 

Apple confirmed that it deployed a patch on July 3, 2026, stating that the Hide My Email vulnerability had been fully resolved. However, the lawsuit alleges that Apple continued marketing the feature as secure while the reported weakness remained unresolved.  The complaint states that security researchers first informed Apple about the vulnerability in June 2025. Although Apple acknowledged the report, Anthony Alvarez’s lawsuit claims the company did not resolve the issue for nearly a year. The filing also alleges that Apple incorrectly stated in March 2026 that the problem had been fixed, even though researchers reported that the vulnerability remained exploitable. 

How Apple’s Hide My Email Feature Works 

Hide My Email was introduced with Sign in with Apple in 2019. The feature creates unique relay addresses for supported apps and websites, allowing messages to reach a user’s inbox without revealing the person’s actual email address. Apple later expanded Hide My Email through the paid iCloud+ subscription, launched alongside iOS 15 and macOS Monterey in September 2021. The iCloud+ version allows subscribers to create unlimited private relay addresses for websites, newsletters and email communication. The lawsuit argues that millions of Apple users relied on Hide My Email to reduce spam, limit online tracking, protect personal information from data brokers and avoid exposure during third-party data breaches. Researchers cited in the complaint said that once a real email address is revealed, it may be linked with publicly available people-search databases, potentially exposing identities and other personal information.

Anthony Alvarez Claims Apple Misled Customers Over Privacy 

The complaint argues that Apple built much of its brand identity around privacy, referencing marketing statements such as “Privacy. That’s iPhone,” “What happens on your iPhone, stays on your iPhone,” and descriptions of privacy as a “fundamental human right” and “core value.”  According to the lawsuit, Apple’s privacy messaging influenced consumer decisions and helped justify premium pricing for Apple hardware and services. The plaintiffs claim Hide My Email was promoted as a central part of those privacy commitments.  The filing alleges that Apple asked researchers not to publicly disclose details of the vulnerability instead of warning customers or temporarily disabling the feature. It claims users were never informed that their real email addresses could potentially be exposed while Apple continued presenting Hide My Email as a privacy protection tool. 

Lawsuit Seeks Damages and Changes From Apple 

Anthony Alvarez is seeking reimbursement for iCloud+ subscription fees and other alleged financial losses. The lawsuit requests an injunction requiring Apple to either provide the privacy protection promised through Hide My Email or clearly disclose any limitations.  The complaint includes claims involving California’s Unfair Competition Law, False Advertising Law and Consumers Legal Remedies Act, along with allegations of fraud, negligent misrepresentation, breach of contract, breach of implied warranty and unjust enrichment.  The lawsuit argues customers paid for Apple’s privacy protections in multiple ways, including iCloud+ subscription fees and premium prices associated with Apple devices marketed as offering stronger privacy features. Apple has stated that the July 3, 2026 patch resolved the Hide My Email issue. 

California Hits General Motors With Record $12.75 Million CCPA Privacy Settlement

California Privacy Settlement

California Attorney General Rob Bonta and a coalition of state and local enforcement agencies have announced a $12.75 million settlement with General Motors over allegations that the automaker illegally collected and sold drivers’ personal data without proper consent, in violation of the California Consumer Privacy Act (CCPA). The California privacy settlement marks the largest CCPA penalty in California history so far and represents the state’s first enforcement action focused on data minimization requirements under California privacy law. The case centers on allegations that General Motors shared sensitive driver information, including geolocation data and driving behavior, with data brokers Verisk Analytics and LexisNexis Risk Solutions between 2020 and 2024.

California Privacy Settlement Targets Driver Data Sales

According to the complaint, GM collected data through its OnStar connected vehicle platform, which offers emergency assistance, navigation, and crash response services. Investigators alleged that the company sold names, contact details, precise location information, and driving behavior data of hundreds of thousands of Californians to the two data brokers. Authorities said the data was intended to help create driver-risk scoring products that could be used by insurance companies when setting premiums. The investigation was conducted jointly by the California Department of Justice, the California Privacy Protection Agency (CalPrivacy), and district attorneys from San Francisco, Los Angeles, Napa, and Sonoma counties. Attorney General Rob Bonta said the settlement sends a clear message about consumer control over personal data. “General Motors sold the data of California drivers without their knowledge or consent,” Bonta said in the announcement, adding that the data could reveal sensitive details about consumers’ daily routines and movements.

CCPA Violations and Data Minimization Concerns

A major part of the case focused on alleged violations of the CCPA’s data minimization and purpose limitation requirements, which were added to California law in 2023. Under these provisions, companies are required to collect and retain only the data necessary for a disclosed purpose. Investigators alleged that GM retained driving and location data long after it was needed to operate OnStar services and later sold that retained data to third parties. Authorities also alleged that GM failed to clearly inform consumers about how their information would be used. The complaint stated that GM’s privacy policies suggested driver data would only be used to provide requested OnStar services and even claimed the company did not sell driving or location information. Investigators said the company’s practices contradicted those statements. San Francisco District Attorney Brooke Jenkins described modern vehicles as “rolling data collection machines” and said consumers deserve transparency about what information is collected and how it is shared. Los Angeles County District Attorney Nathan J. Hochman said companies handling consumer data would be held accountable under California privacy laws, regardless of their size.

Connected Vehicle Privacy Under Scrutiny

The settlement follows growing regulatory scrutiny around connected vehicle privacy and automotive data collection practices. In 2023, CalPrivacy launched investigations into connected car manufacturers and their handling of consumer information. Public attention increased further in 2024 after a report by The New York Times highlighted how automakers were sharing driving behavior data with insurance companies. The reporting indicated that some consumers outside California had experienced increased insurance premiums tied to such data-sharing practices. California investigators later determined that California drivers were likely not directly affected through insurance rate increases because state insurance laws prohibit insurers from using driving behavior data to set premiums. However, regulators maintained that the collection, retention, and sale of the data itself violated California privacy requirements.

Settlement Terms for General Motors

Under the proposed California privacy settlement, General Motors must implement several privacy-related measures over the coming years. The company will be required to:
  • Pay $12.75 million in civil penalties.
  • Stop selling driving data to consumer reporting agencies for five years.
  • Delete retained driving data within 180 days unless consumers provide express consent for limited uses.
  • Request the deletion of driver data already shared with LexisNexis and Verisk.
  • Establish and maintain a comprehensive privacy compliance program.
  • Submit privacy assessments and compliance reports to California regulators and prosecutors.
The settlement also reinforces California’s broader push to strengthen consumer control over personal information under the CCPA. CalPrivacy Executive Director Tom Kemp said California privacy laws require businesses to collect only the information they genuinely need and to be transparent about how that data is handled. Alongside the settlement announcement, regulators also highlighted the state’s Delete Request and Opt-out Platform (DROP), which allows Californians to submit requests to delete personal information held by hundreds of registered data brokers.
❌