Visualização de leitura

Grindr settles HIV status data-sharing lawsuit for $35 million

Grindr has reportedly agreed to pay £26 million (around $35 million) to settle a UK privacy lawsuit alleging that it shared sensitive user data, including some users’ HIV status, with advertisers.

The claim was brought by London law firm Austen Hays on behalf of roughly 12,000 UK Grindr users. It alleges that the dating app breached privacy and data-protection laws during a period ending in early 2020.

The claimants allege that Grindr shared personal and highly sensitive information with advertising companies without consent. According to Austen Hays, the shared data may have included ethnicity, HIV status, the date of a user’s last HIV test, and whether they used pre-exposure prophylaxis (PrEP).

At the time of the alleged data sharing practices, Grindr was owned and controlled by the Chinese gaming company Beijing Kunlun Tech. Grindr was sold to US owners in 2020.

According to a US regulatory filing, Grindr will make two payments of £13 million: one by December 31, 2026, and the second by March 31, 2027.

In its SEC filing, Grindr said that the settlement is not an admission of liability and, while it disputes the allegations, it:

recognizes and acknowledges the distress and loss of trust expressed by some of its UK users regarding that pre-2020 period.

The UK settlement follows a separate enforcement case in Norway. The country’s Data Protection Authority found that Grindr had shared users’ personal data with advertising partners for behavioral advertising without a valid legal basis.

These cases illustrate a crucial privacy point: information does not need to be explicitly labeled as medical information or information about sexual orientation to expose intimate details about someone. Advertising identifiers, IP addresses, locations, device information, and confirmation that a person uses a particular app can be combined to identify them or draw sensitive conclusions about their life.

Many free apps rely on advertising SDKs, analytics providers, and other third parties to make money. These integrations can receive identifiers and event data that help target or measure advertising, but they can also create extensive trails of user behavior.

How to protect your privacy on dating apps

Grindr says it has overhauled its privacy program since 2020 and remains committed to user control and responsible data practices. Even so, dating apps can hold unusually personal information about their users.

To limit what you reveal:

  • Review the app’s privacy settings and turn off optional personalized advertising where available.
  • Limit your profile to details you’re comfortable sharing with potential matches.
  • Avoid linking a dating profile to public social-media accounts unless you want identities to be easily connected.
  • Revoke location permissions when you’re not actively using the app, or choose “while using the app” rather than continuous access where your operating system offers it.
  • Keep the app, your operating system, and your security software updated.
  • Watch for romance scams and extortion attempts, particularly requests to move the conversation off the app, send money, share intimate photos, or reveal identifying information.

If you’re unsure whether a message may be part of a scam, you can check it with Malwarebytes Scam Guard, which can help you assess the conversation and decide what to do next.


Scammers don’t need to hack you. They just need you to click once. 

Malwarebytes Identity Theft Protection catches suspicious activity before it becomes a problem.

Apple OpenAI Lawsuit Escalates Over AI Trade Secrets

The Apple OpenAI lawsuit intensifies as Apple accuses a former engineer of using stolen trade secrets to train AI agents and destroying digital evidence.

Related Posts:

The post Apple OpenAI Lawsuit Escalates Over AI Trade Secrets appeared first on Daily CyberSecurity.

Meta Settles Child Privacy Lawsuit Rapidly

Discover the details of Meta's massive $18 billion child privacy lawsuit settlement. Learn how new platform restrictions will impact young users worldwide.

Related Posts:

The post Meta Settles Child Privacy Lawsuit Rapidly appeared first on Daily CyberSecurity.

FTC Sues Hims & Hers Over Health Data Privacy, Billing Practices

Hims & Hers lawsuit

The Hims & Hers lawsuit has put the telehealth provider under scrutiny after the FTC, along with Utah and California authorities, accused the company of deceptive billing practices and unlawfully sharing consumers' sensitive health information with third-party advertising platforms. According to a complaint filed in federal court, regulators allege that Hims & Hers misled consumers about its privacy protections, enrolled users in recurring subscriptions without clear disclosure, and shared health-related data with companies including Meta and Snap.

The complaint alleges that the San Francisco-based telehealth provider failed to clearly inform consumers that prescription charges could be processed almost immediately after they submitted an online intake form, despite representing that they would first consult with a medical provider to determine an appropriate treatment.

FTC Complaint Alleges Deceptive Billing Practices

According to the FTC complaint, consumers interested in Hims & Hers services are required to complete an online intake form for review by a medical provider before receiving prescription treatment. During this process, users provide billing information after being assured they would not be charged unless medication was prescribed.

However, regulators allege that most consumers were not given a consultation with a provider before being charged. Instead, the complaint states that submitting the intake form automatically enrolled many users in recurring prescription subscriptions and processed charges before consumers had an opportunity to review or approve the treatment.

The complaint also alleges that Hims & Hers did not clearly disclose when prescription refills would occur, making it difficult for consumers to cancel subscriptions before the next billing cycle.

One consumer complaint cited by the FTC stated that they were told they would speak with a doctor within a few days and would not be charged immediately, but their payment was processed before any consultation took place.

Hims & Hers Lawsuit: Privacy Practices Under Investigation

The Hims & Hers lawsuit also centers on allegations involving health data privacy.

According to the complaint, Hims & Hers shared consumers' sensitive health information with advertising platforms such as Meta and Snap, despite assuring users that their medical information would remain private.

The FTC alleges that the company shared customer lists with advertising platforms and also used third-party tracking technologies that automatically transmitted website activity, referred to as "Events," to those companies.

Regulators argue that these practices exposed health-related information while contradicting the company's privacy representations to consumers.

Subscription Cancellation Process Questioned

The complaint further alleges that Hims & Hers created obstacles for consumers attempting to cancel recurring subscriptions.

Before 2023, most users could only cancel by contacting customer service through phone, email, or chat. Even after introducing online cancellation, regulators allege the company continued to make the process difficult by hiding the cancellation option behind multiple navigation steps. According to the complaint, consumers first had to select "add/remove items from order" before eventually reaching the cancellation page.

The FTC alleges these practices violate both the FTC Act and the Restore Online Shoppers' Confidence Act, which governs deceptive billing and subscription practices. Utah and California have also alleged violations under their respective consumer protection laws.

Hims & Hers Rejects Allegations

In a statement posted on X, Hims & Hers rejected the allegations and said the lawsuit ignores evidence provided during the FTC's nearly three-year investigation.

The company described the action as an attempt to generate headlines rather than enforce consumer protection laws and said it intends to defend itself in court vigorously.

Hims & Hers also stated that millions of consumers have relied on its services since 2017 and that its Privacy Policy explains how customer data is used. The company added that patients can choose how their information is handled and maintained that information shared with healthcare providers is used only to deliver care.

The lawsuit was authorized by a 2-0 vote of the Commission and filed in the U.S. District Court for the Northern District of California. The allegations remain claims made by regulators, and the court will ultimately decide the case.

Apple Faces Lawsuit Over Hide My Email Privacy Vulnerability

Hide My Email

Apple is facing a proposed class-action lawsuit after Anthony Alvarez alleged that the company’s Hide My Email feature failed to protect users’ real email addresses as advertised. The complaint, filed in the U.S. District Court for the Northern District of California, claims Apple promoted Hide My Email as a privacy safeguard while continuing to charge customers for access through its iCloud+ subscription service.  The legal action follows a report from 404 Media that revealed a reported vulnerability in Hide My Email. The report claimed the flaw could allow someone to identify a user’s actual email address from the private relay address generated by the feature. According to the report, Apple had been aware of the issue for more than a year before releasing a fix. 

Hide My Email Vulnerability Becomes the Focus of Apple Lawsuit 

Apple confirmed that it deployed a patch on July 3, 2026, stating that the Hide My Email vulnerability had been fully resolved. However, the lawsuit alleges that Apple continued marketing the feature as secure while the reported weakness remained unresolved.  The complaint states that security researchers first informed Apple about the vulnerability in June 2025. Although Apple acknowledged the report, Anthony Alvarez’s lawsuit claims the company did not resolve the issue for nearly a year. The filing also alleges that Apple incorrectly stated in March 2026 that the problem had been fixed, even though researchers reported that the vulnerability remained exploitable. 

How Apple’s Hide My Email Feature Works 

Hide My Email was introduced with Sign in with Apple in 2019. The feature creates unique relay addresses for supported apps and websites, allowing messages to reach a user’s inbox without revealing the person’s actual email address. Apple later expanded Hide My Email through the paid iCloud+ subscription, launched alongside iOS 15 and macOS Monterey in September 2021. The iCloud+ version allows subscribers to create unlimited private relay addresses for websites, newsletters and email communication. The lawsuit argues that millions of Apple users relied on Hide My Email to reduce spam, limit online tracking, protect personal information from data brokers and avoid exposure during third-party data breaches. Researchers cited in the complaint said that once a real email address is revealed, it may be linked with publicly available people-search databases, potentially exposing identities and other personal information.

Anthony Alvarez Claims Apple Misled Customers Over Privacy 

The complaint argues that Apple built much of its brand identity around privacy, referencing marketing statements such as “Privacy. That’s iPhone,” “What happens on your iPhone, stays on your iPhone,” and descriptions of privacy as a “fundamental human right” and “core value.”  According to the lawsuit, Apple’s privacy messaging influenced consumer decisions and helped justify premium pricing for Apple hardware and services. The plaintiffs claim Hide My Email was promoted as a central part of those privacy commitments.  The filing alleges that Apple asked researchers not to publicly disclose details of the vulnerability instead of warning customers or temporarily disabling the feature. It claims users were never informed that their real email addresses could potentially be exposed while Apple continued presenting Hide My Email as a privacy protection tool. 

Lawsuit Seeks Damages and Changes From Apple 

Anthony Alvarez is seeking reimbursement for iCloud+ subscription fees and other alleged financial losses. The lawsuit requests an injunction requiring Apple to either provide the privacy protection promised through Hide My Email or clearly disclose any limitations.  The complaint includes claims involving California’s Unfair Competition Law, False Advertising Law and Consumers Legal Remedies Act, along with allegations of fraud, negligent misrepresentation, breach of contract, breach of implied warranty and unjust enrichment.  The lawsuit argues customers paid for Apple’s privacy protections in multiple ways, including iCloud+ subscription fees and premium prices associated with Apple devices marketed as offering stronger privacy features. Apple has stated that the July 3, 2026 patch resolved the Hide My Email issue. 

Apple Sued Over Hide My Email Privacy Claims

Apple faces a proposed class action alleging a Hide My Email flaw could expose users’ real addresses despite the company’s privacy claims.

The post Apple Sued Over Hide My Email Privacy Claims appeared first on TechRepublic.

Google Sues Operators of AI-Powered ‘Outsider’ Phishing Kit Linked to 1.5 Million URLs

Outsider AI phishing kit

Google has launched a lawsuit against the operators behind the Outsider AI phishing kit. This alleged AI phishing kit, the company says, has been used to create convincing phishing websites using artificial intelligence tools, including Google's Gemini.   The legal action, filed by Alphabet-owned Google in a federal court in Manhattan, targets the developers of the Outsider phishing platform. According to the complaint, the software enables users to replicate hundreds of trusted websites and provides detailed guidance on generating phishing pages designed to steal personal and financial information.   Google alleges that the AI phishing kit leverages AI capabilities, including Gemini, to make fraudulent websites more sophisticated and harder to identify. 

Google Alleges the Outsider AI Phishing Kit Enabled AI-Powered Cybercrime 

In its lawsuit, Google claims that the operation of the Outsider AI phishing kit has facilitated large-scale cybercrime by giving bad actors access to tools that simplify the creation of phishing campaigns. The company alleges that the AI phishing kit can imitate legitimate websites while offering step-by-step instructions that help users generate convincing phishing pages through AI-assisted processes.  The lawsuit places particular emphasis on alleged Gemini misuse, arguing that Google's AI tools were exploited to support phishing activities. According to Google, the developers behind Outsider used AI technologies in ways that violate the company's policies and contribute to online fraud.  Google also alleges that the individuals responsible for the Outsider AI phishing kit are anonymous cybercriminals based in China. The company claims these actors abused services such as Google Cloud and Google Drive while also misusing Google's trademarks to create a false sense of legitimacy around their operations. 

More Than 1.5 Million URLs Linked to the AI Phishing Kit 

The scale of the alleged operation is one of the most significant aspects of the lawsuit. Google reported that it identified more than 1.5 million URLs associated with the Outsider AI phishing kit between November and April.  The large number of detected URLs suggests that the phishing infrastructure was extensive and capable of reaching a substantial number of potential victims. Google's findings highlight how rapidly phishing operations can expand when aided by automation and AI-driven tools.  As concerns about Gemini misuse and AI-enabled cybercrime continue to grow, security experts have warned that phishing attacks are becoming increasingly difficult for users to distinguish from legitimate communications. 

Google Partners With FBI and Telecom Providers 

Google says it is taking a coordinated approach to disrupt the Outsider network. In a blog post, Google General Counsel Halimah DeLaine Prado stated that the company is working alongside the Federal Bureau of Investigation (FBI) as well as major telecommunications companies including AT&T, T-Mobile, and Verizon.  According to DeLaine Prado, the collaboration aims to dismantle the infrastructure supporting the Outsider AI phishing kit. The effort combines legal action, industry cooperation, and technical measures to address what Google views as an evolving cybersecurity threat.  The partnership reflects a broader trend within the technology and telecommunications sectors, where organizations are joining forces to combat sophisticated phishing operations and online fraud schemes. 

Rising Concerns Over Gemini Misuse and AI-Driven Scams 

The lawsuit also draws attention to wider concerns across the cybersecurity industry about the misuse of artificial intelligence. Experts have warned that AI tools can help criminals create more persuasive messages, realistic websites, and effective social engineering campaigns.  Commenting on the issue, Brett Leatherman, Assistant Director of the FBI's Cyber Division, said that criminals are increasingly turning to AI to make fraudulent activity more convincing and more difficult to detect.  Leatherman emphasized the importance of public-private partnerships in disrupting cybercriminal operations, pointing to collaborations such as the one between Google and the FBI as a key component in combating modern digital threats.  The allegations surrounding Gemini misuse serve as another example of how AI technologies, while beneficial in many legitimate applications, can also be exploited by malicious actors seeking to improve the effectiveness of phishing attacks. 

Legislative Efforts to Combat AI-Powered Fraud 

Beyond its lawsuit against Outsider, Google is also advocating for policy measures aimed at reducing online scams. DeLaine Prado noted that the company supports seven bills currently pending in the U.S. Congress that are intended to address scamming activities.  Google's backing of the proposed legislation signals a broader effort to combine legal, technological, and policy-based responses to the rise of AI-enabled cybercrime. The company argues that tackling threats such as the Outsider AI phishing kit requires cooperation across government agencies, technology providers, law enforcement organizations, and lawmakers.  As AI tools continue to evolve, the lawsuit against Outsider highlights the growing challenge facing the cybersecurity sector. The case not only focuses on the alleged abuse of Google's services and trademarks but also raises larger questions about preventing Gemini misuse and limiting the role of AI in sophisticated phishing campaigns. 
❌