HeadFlash

Privacy

Privacy Headlines: Texas App Law, Scattered Spider, Europol, Google AI Data

Supreme Court lets Texas enforce app age verification; Europol faces complaint over shadow IT; Google expands Search data for AI; Scattered Spider hacker arrested.

Listen

Supreme Court Allows Texas Age-Verification Law for App Downloads

The U.S. Supreme Court on Monday declined to block Texas from enforcing the Texas App Store Accountability Act, rejecting petitions from plaintiffs who argued the law violates First Amendment free speech rights. Justice Samuel Alito issued two one-sentence orders denying the petitions. The decision follows a three-judge panel of the 5th U.S. Circuit Court of Appeals that ruled the law can take effect, suspending a district court’s December 2024 ruling that found the law unconstitutional. Plaintiffs include the Computer & Communications Industry Association and Students Engaged in Advancing Texas, with Texas Attorney General Ken Paxton as defendant. Plaintiffs argued the law impermissibly restricts access to First Amendment-protected content such as news and educational material. Attorneys for Students Engaged in Advancing Texas stated that protecting First Amendment rights and parents’ rights to supervise their children should not be dictated by government. Paxton’s office countered that the law protects children from “dangerous modern products,” noting that children can download apps that invade privacy, sell data, or expose them to content without parental consent. The ruling sets a precedent for state-level age verification requirements for app stores.

Supreme Court declines to block Texas age-verification law for app downloads | AP News →

FBI Arrests 19-Year-Old Scattered Spider Hacker Using Windows ID Code

The Department of Justice, with assistance from the FBI and Finland’s National Bureau of Investigation, arrested 19-year-old Peter Stokes, a dual U.S.-Estonian citizen, as he attempted to board a flight to Japan from Helsinki. Stokes is allegedly a member of Scattered Spider, a cybercrime syndicate responsible for over $100 million in ransom payments. The group, also known as Octo Tempest, UNC3944, and Oktapus, targeted a luxury jewelry dealer in May 2025, using a social engineering attack to reset credentials via the company’s IT helpdesk and demanding an $8 million ransom. Microsoft played a crucial role in the investigation by providing Global Device Identifier (GDID) data to the FBI. GDID is a unique identifier assigned to every Windows installation, allowing investigators to link Stokes’s physical hardware to specific internet activity and locations. Court documents show Microsoft provided logged data including web activity, videogame history, IP addresses, tool usage, Azure status, and timestamps. Stokes was carrying two hard drives containing incriminating evidence at arrest. He was extradited to the U.S. and appeared in federal court in Chicago on June 30, 2026, where he remains in custody.

Windows 11 identifier code used to track Scattered Spider perp after Microsoft shared info with FBI — 19-year-old US-Estonian hacker arrested over alleged ties to infamous extortion group | Tom’s Hardware →

Front-Lex Complaints to EDPS Over Europol’s ‘Shadow IT’ Data Processing

Human rights organization Front-Lex has filed a complaint with the European Data Protection Supervisor (EDPS) calling for a ban on Europol’s data processing operations on “shadow IT” environments that allegedly violate European law. The complaint was filed on behalf of three named human rights defenders: Dutch activist Frank van der Linde, Austrian human rights defender Natalie Gruber, and David Yambio, president of the Italian campaign group Refugees in Libya. Front-Lex will take the case to the Court of Justice of the European Union (CJEU) within three months if the EDPS does not respond. The complaint builds on a 2024 investigation revealing that Europol unlawfully stored large volumes of sensitive personal data on parallel IT systems lacking normal data protection controls. A former senior Europol official confirmed that van der Linde’s data was processed through a system known internally as the “pressure cooker.” Front-Lex alleges Europol deliberately concealed these systems from the EDPS, and that the parallel networks allowed secret processing of data on individuals not suspected of any crime. The complaint also criticizes the EDPS for failing to uncover the parallel systems during a prior consultation. The case comes as the European Commission plans to double Europol’s budget and expand its data collection powers.

Complaint urges ban on ‘unlawful’ Europol processing of personal data | Computer Weekly →

Google Expands Search Data Collection for AI Training; Opt-Out Available

Google is expanding the data it collects through its Search services to include images, files, audio recordings, and video recordings, which can also be used to train its artificial intelligence models. The change, introduced as an update to privacy settings, will be rolled out gradually over the next few months for Search, Maps, Shopping, Flights, Hotels, Translate, and News. Google Photos is explicitly excluded from this expansion. The platform can now save users’ search history, information from sites visited through its services, generative AI responses, and uploaded media. Users can opt out by disabling “Search Services History” or “Save Media” separately in settings. The Save Media setting covers files and media uploaded through Google Search services. Users can also choose how often saved data is automatically deleted, with options to remove it after three, 18, or 36 months. Google’s help documentation states that history is used to provide, develop, and improve services such as training generative AI models, and to protect users and the public with the help of human reviewers.

Is Google using your searches to train its AI? Here’s how to opt out →