HeadFlash

Privacy

Carhartt breach hits 12.9M accounts; Manchester Airports loses 86GB

Carhartt breach exposes 12.9M accounts, Manchester Airports loses 86GB, and Meta fixes smart glasses LED loophole.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Carhartt Data Breach: ShinyHunters Claims 50GB Stolen, 12.9M Accounts Affected

Edelson Lechtzin LLP is investigating data privacy claims arising from a Carhartt data breach reported on or about August 13, 2026. The extortion group ShinyHunters claimed it stole more than 50GB of documents containing personal customer and employee data, though Carhartt has not acknowledged this claim. Reports indicate the breach affected over 12.9 million Carhartt accounts, potentially compromising names, email addresses, phone numbers, and addresses.

Carhartt Data Breach: Edelson Lechtzin LLP Launches Investigation Into Exposure of Personal Information →

Manchester Airports Operator Confirms Data Theft Affecting 8.7M Customers

Manchester Airports Group (MAG), the UK’s largest airport operator, disclosed on August 27 that an unauthorized third party had stolen customer data related to Manchester, London Stansted, and East Midlands airports. The affected information came from car park, lounge, and Fast Track bookings and in-airport Wi-Fi registrations. Extortion group FulcrumSec claimed responsibility, telling BleepingComputer it stole approximately 86 GB of data, and the company confirmed around 8.7 million customers were affected, making it the largest known customer data breach affecting a British airport operator.

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data →

Meta Updates Smart Glasses to Stop Recording When LED Is Covered

Meta updated its smart glasses so the camera shuts off when someone covers the recording light. Alex Himel, who runs Meta’s wearables division, posted the change on Threads on 27 August. The loophole closed involved starting a recording and then placing a finger or tape over the LED. It is the second fix of the summer; an earlier update disabled the camera when users drilled the LED out of the frame entirely.

Meta’s glasses now stop recording if you cover the LED →

Proton Analysis Finds Trackers in 85% of US VPN Apps

Proton VPN analyzed more than 7,000 mobile VPN apps worldwide and found that 85% of VPNs in its US analysis contain trackers used for analytics, advertising, or profiling. Some of these apps can access device ID, phone model, network type, mobile carrier, and physical location. Proton found 64 VPN apps capable of accessing GPS and other geolocation data, and these apps accounted for more than 3 million US downloads in June alone.

Proton found trackers inside most VPN apps downloaded in the US →

Cabinet Secretary Orders Government-Wide DPDP Act Implementation Plans

Cabinet Secretary T.V. Somanathan has directed Union ministries, state governments, and Union Territory administrations to draw up time-bound implementation plans for the Digital Personal Data Protection (DPDP) Act, 2023. The August 20 communication calls for senior officials to oversee implementation, nodal officers to coordinate with MeitY, and phased plans with defined responsibilities and timelines. Departments have been asked to identify their personal-data processing activities, prepare data inventories, and review privacy notices, consent mechanisms, and grievance-redressal arrangements.

Is the government ready for the DPDP Act? Ministries and states face a sweeping data-compliance test →

GAO Report: 401(k) Providers May Sell Your Personal Data

A Government Accountability Office (GAO) report found that 401(k) service providers may use participant personal information for marketing or sell it to third parties such as data brokers. The GAO reviewed privacy disclosures for 31 service providers from January 2024 through February 2026. Of those, 15 had policies permitting the sharing of participant data for marketing purposes, 14 did not specify, and only two prohibited such sharing. More than half (17 of 31) did not limit their ability to sell participant data to data brokers or other third parties.

Your 401(k) provider could be selling your personal data, warns the Government Accountability Office — are you at risk? →

Indonesia’s New Data Rules Set 2% Revenue Fine Ceiling

Government Regulation No. 33 of 2026, Indonesia’s implementing regulation for the 2022 Personal Data Protection statute, was signed in Jakarta on 16 July 2026 by President Prabowo Subianto. The 225-article instrument takes effect six months after promulgation, placing the compliance date in mid-January 2027. Article 185 sets the fine ceiling at 2 percent of annual revenue or receipts, and the regulation sets a 72-hour deadline for nine obligations including breach notification.

Data controllers face 2% revenue fines under Indonesia’s new data rules →

Crowdsourced Maps Show Over 132,000 Flock Cameras in US

As of August 20, 2026, crowdsourced mapping services listed 132,225 automated license plate readers (ALPRs) in the contiguous U.S. on FlockHopper, while DeFlock had mapped 133,607, of which roughly 110,000 (82%) belong to Flock Safety. Both tallies are likely incomplete because they rely on user-submitted information. Flock cameras are solar powered, use LTE, and capture license plates plus vehicle features such as damage, bumper stickers, and roof racks. Law enforcement accounts for more than 5,000 of Flock’s customers.

How Many Flock Cameras Are In The US? Here’s Why It’s Hard To Know For Sure →

American Vision Partners Agrees to $1.75M Settlement Over 2023 Data Breach

Medical Management Resource Group, which does business as American Vision Partners, agreed to a $1.75 million cash settlement in June 2026 to resolve a class action lawsuit over a data breach that occurred between November 14 and December 6, 2023. The breach exposed patient names, birth dates, contact information, medical history, clinical records, medications, and health insurance details. Social Security numbers were exfiltrated for a subgroup of 258,070 people. The deadline to file a claim is November 12, 2026.

Arizona Eye Care Giant’s Data Breach Settlement Offers Up to $3,000 to 258,000 Patients →

Brave Browser Adds Email Alias Support to Protect User Privacy

Brave has added support for email aliases, allowing users to sign up for websites and online services without sharing their personal email addresses. To use the feature, users create a Brave account with their real email address, then, when logged into the browser, a pop-up appears when clicking an email field on a website offering the option to use an alias. Brave said the feature protects privacy because websites use email as a personal identifier for ad targeting. Users are currently offered five free email aliases.

Brave’s browser one-ups Chrome with its new support for email aliases →

Poll: 93% of Brits Believe in Right to Private Online Conversations

Polling commissioned by the Center for Democracy & Technology (CDT) found that 93 percent of British adults believe they have a right to private conversations online, and 89 percent think nobody should be able to access their personal messages without a court order. Two-thirds of respondents said they would not trust either the current government or any future one with the power to access encrypted messages. The findings come amid the UK government’s push for access to encrypted data and tech industry opposition.

Turns out Brits would quite like their private messages to stay private →

Privacy-Focused App Kibu Targets Military Customers with Device-to-Device Encryption

Kibu, a new encryption-based app, is available to U.S. military operators and foreign military partners. Its co-founder, Eftychis Gregos Mourginakis, said government executives tend to use personal devices and commercial messaging apps such as Signal. The app uses device-to-device encryption, biometric authentication, and, for military members, other forms of identification. It includes special passcodes for situations where someone is forcing the user to access their device.

Privacy-focused communication app aims for military customers and beyond →

Australia to Release Draft Privacy Law Updates Targeting AI and Smart Glasses

The federal government will release draft legislation on Monday, August 31, 2026, to update Australia’s privacy laws for new technologies including smart glasses and artificial intelligence. Attorney-General Michelle Rowland will unveil the draft, which includes new online safeguards for identity documents, called IDLock, and a right for individuals to have their personal information destroyed by social media and search companies.

Privacy laws target AI, smart glasses right to erase Australians’ data →