Privacy
Privacy Alert: Data Heists, Spy Tactics, and App Risks
Trump exposes massive voter data theft, Iran targets troops via ad tracking, Apple sued, period apps scrutinized, and Qantas gets a pass.
Trump: China Stole Data of 220 Million US Voters
In a primetime speech from the East Room on Thursday, President Trump stated that China stole the voter registration data of 220 million Americans, calling it ‘the largest compromise of election data in history.’ The theft began during the 2020 election cycle and includes names, addresses, phone numbers, political party preferences, and other sensitive registration information. Trump claimed intelligence showed China assigned a data-exploitation unit specifically to this operation. He said some government officials knew about the theft as early as 2020 but did not inform him before that year’s election. Trump accused ‘members of the deep state’ within intelligence agencies of suppressing and downplaying information about Chinese election meddling. He referenced a 2022 declassified intelligence report that found Chinese officials had analyzed multiple U.S. states’ voter registration data, but noted the number of affected Americans—220 million—had never before been reported. Trump also highlighted raw intelligence obtained by the FBI in 2020 detailing an alleged Chinese attempt to manufacture illegal ballots for Joe Biden. He quoted an email from intelligence analysts who admitted they had ‘deliberately massaged the presidential daily briefing to withhold information regarding Chinese activities related to the election,’ and an FBI official who wrote she was running ‘a shadow government’ to keep the intelligence hidden. Trump announced he is directing the Office of the Director of National Intelligence, the Department of Justice, the FBI, and the CIA to investigate how the information was hidden, to fire those involved, and to file criminal charges if appropriate.
Trump reveals China stole voter registration data from 220M Americans →
Apple Faces Class Action Over Hide My Email Vulnerability
Apple was sued this week over a reported flaw in its ‘Hide My Email’ feature that could expose a user’s real email address. A proposed class action lawsuit alleges that Apple violated California’s false advertising law and other consumer protection statutes by knowingly offering a feature that does not work as advertised. A security researcher disclosed the apparent vulnerability to Apple in June 2025. No known instances of exploitation exist, and the steps involved have not been shared with the public as a precaution.
Apple Sued Over Reported ‘Hide My Email’ Flaw - MacRumors →
Iran Used Ad Tracking Data to Target US Troops in Hotels
A Financial Times report revealed that during the Iran war, Iran used ad tracking data to figure out which hotels were housing U.S. troops in Iraqi Kurdistan. The U.S. military had evacuated many bases and moved personnel to hotels and civilian office spaces. Iranian-backed militias attacked several hotels in Iraqi Kurdistan with drones, and Iranian forces directly bombed the Crowne Plaza in Bahrain, wounding two Pentagon employees. It is not clear which attacks on Americans were targeted based on ad data. Iran also used the Signalling System No. 7 (SS7) protocol for international telecom communications. Senator Ron Wyden stated that the U.S. Department of Homeland Security knew Iran used this technique to find American phones. Ad tracking occurs via real-time bidding (RTB) exchanges, where apps sell targeted advertisements that display users’ location and other attributes. The Federal Trade Commission disciplined Mobilewalla for scraping such data, and the settlement agreement included a carveout for location data ‘collected outside the United States and used for National Security purposes conducted by federal agencies.’ In response to a customer lawsuit, Google agreed to create a new setting called RTB Control that allows users to limit data sent to ad auctions.
Iran used ad tracking to hunt American soldiers: Report →
Mozilla Review Flags Privacy Risks in Period Trackers
The Mozilla Foundation published a privacy review of six popular period tracker apps on July 16, 2026, finding that period trackers can expose reproductive health data to advertisers through persistent identifiers when an app broadcasts usage to ad networks. In-app browsers may bypass the app’s privacy protections, allowing third-party trackers to collect data when users open a web page inside the app. The app Stardust once marketed itself as ‘encrypted’ and a privacy-safe sanctuary after the Roe decision, but reporters later found it offered only standard encryption rather than end-to-end protection, and the company quietly removed the claim. One app, Euki, earned a perfect score because it keeps all user data on the device, leaving ‘almost nothing to leak.’
[Period and Ovulation Apps Privacy Review 2026: Is Your Period Tracker Safe?
- Mozilla Foundation →](https://www.mozillafoundation.org/en/nothing-personal/period-ovulation-trackers)
Qantas Breach: Regulator Says Airline Did Everything Right
The Office of the Australian Information Commissioner (OAIC) closed its year-long preliminary inquiry into the June 2025 Qantas data breach, concluding that the evidence did not indicate Qantas had failed to take reasonable steps to protect personal information. Australian Privacy Commissioner Carly Kind stated that after more than a year of inquiries, the evidence does not support the likelihood of a breach of privacy law, so a full investigation was not commenced. The breach began with a vishing call to an overseas contact center agent, where a threat actor posing as ‘Qantas IT help’ convinced the agent to visit a website tied to the CRM platform and walk through steps framed as necessary to close an IT support ticket. That interaction connected the agent’s CRM session to a data extraction tool controlled by the attacker, who then pulled data from every contact profile the agent could access. The attack involved pure social engineering — no malware or exploited vulnerability. Qantas detected the breach quickly when a staff member spotted an unusual spike in login-attempt alerts on the morning of June 30, two days after the call, and escalated it. Within hours, the company froze the compromised account, assessed for data exfiltration, and triggered incident response. Approximately 5.67 million customer records were compromised, including names, phone numbers, email addresses, Frequent Flyer details, and in some cases addresses, dates of birth, gender, and meal preferences. No credit card numbers, financial information, passport details, or login credentials were exposed. The OAIC found that social engineering training generally targets credential theft, not the rarer tactic of talking an employee into authorizing a legitimate-looking system connection, meaning the attack likely would have succeeded even with standard training. The CRM vendor has since changed a default configuration that allowed the agent to authorize a third-party app connection. Commissioner Kind warned that agentic and advanced AI will increase cybersecurity risks businesses face, making continuous review of security posture non-negotiable.
Qantas Did Everything “Right” — And Got Breached Anyway. Regulators Say That’s the Point. →