HeadFlash

Privacy

Trezor Breach Expands to 81,000; DHS Subpoenas 17M Driver Records

Trezor's logistics breach now hits 81,000 customers, while California fights a DHS subpoena for 17 million commercial driver records.

Listen

This edition was produced with artificial intelligence. Text and voice are generated automatically.

Trezor Data Breach Impact Widens to 81,000 Customers After Vendor Fails to Delete Data

Trezor has disclosed that a data breach at its shipping and logistics provider, ShipMonk, now affects 81,000 customers total. The company initially reported on August 13 that attackers accessed the data of nearly 14,000 customers, including full names, shipping addresses, email addresses, and phone numbers, affecting customers in Brazil, Colombia, Italy, Portugal, Sweden, and the United Kingdom who received orders between May 10 and August 8, 2026. On Friday, Trezor published an update confirming the expanded impact after ShipMonk failed to delete exposed data from its systems as required by Trezor’s contract and data policy.

An additional 67,000 U.S. customers who ordered between November 2019 and August 2021 had their full details exposed, including name, email, phone number, shipping address, and order number. Trezor stated that it repeatedly requested and received written assurance from ShipMonk confirming data deletion, and expressed disappointment that the data was not deleted despite those confirmations. Trezor said the breach did not affect its operations or services, that its systems were not compromised, and that all Trezor devices are secure. It warned affected customers to be wary of messages requesting personal information, citing an increased risk of phishing, scam emails, fraudulent calls or letters, and potential physical security risks. Breach notification emails said attackers exploited a vulnerability in the third-party analytics platform Metabase, which revealed that threat actors exploited a critical SQL injection zero-day vulnerability to breach customer instances. BleepingComputer also learned that ShipMonk received extortion emails from the ShinyHunters extortion gang, and other affected companies in the Metabase campaign include Tally and Framework.

Trezor data breach impact now reaches 81,000 customers →

Homeland Security Subpoenas 17 Million Commercial Driver Records for Immigration Enforcement

California lawmakers voted in June to let the DMV share driver data with the American Association of Motor Vehicle Administrators (AAMVA), a nonprofit clearinghouse for state motor vehicle information, amid fears that state IDs would not be accepted at airports and federal buildings without compliance with the 2005 REAL ID Act. Unbeknownst to lawmakers at the time, the Trump administration had already demanded bulk commercial driver data from AAMVA and planned to use it for immigration enforcement. Federal agencies first requested, then subpoenaed, the data this summer, and the demands became public in August through a lawsuit in which 22 state attorneys general, including California’s, sued to block the subpoena.

The U.S. Department of Homeland Security’s Aug. 11 subpoena sought data on 17 million people with commercial driver’s licenses, including name, date of birth, state of record, license number, and Social Security number for every driver in AAMVA’s commercial license database going back five years. The subpoena stated its purpose as civil immigration enforcement and asked AAMVA not to discuss it for an indefinite period of time. AAMVA initially agreed to hand over the information, prompting state officials to threaten legal action, then planned to let state DMVs decide whether to share the data in bulk, leading the Trump administration to threaten cancellation of grants and contracts by the U.S. Department of Transportation and to issue the subpoena. On Aug. 21, Judge Anthony Trenga of the U.S. District Court for the Eastern District of Virginia temporarily blocked AAMVA from complying, calling the demand unlawful, and is scheduled to hear arguments Sept. 10 on a preliminary injunction. California has shared commercial license data with AAMVA for some time, and under the plan lawmakers funded in June, the DMV expects to begin uploading data on all non-commercial California license holders, including more than 1 million immigrants licensed under a 2013 state law allowing undocumented people to obtain driver’s licenses. A sworn declaration by Kristin Triepke, chief of the California DMV’s Licensing Policy branch, said the DMV first learned of the federal demand on July 23, 10 days after Newsom signed the enabling bill. Governor Gavin Newsom’s office called concerns overblown, emphasizing differences between the commercial driver information requested and the broader pool of non-commercial data, while the Electronic Frontier Foundation’s Saira Hussain said AAMVA’s response was insufficient, as it took a full month to inform states of the demand and contemplated complying.

As CA Legislators Debated, Homeland Security Subpoenaed 17M Driver Records | San Jose Inside →

Facewatch Facial Recognition in Scottish Stores Operates Without Specific Oversight

Scotland’s only formal safeguard governing public-space surveillance cameras is a national strategy written in 2011, before algorithmic facial recognition had entered Scottish supermarkets, and it has not been updated. Sainsbury’s plans to expand Facewatch from roughly 55 stores to 200 across the United Kingdom by the end of 2026, and Scotland’s 5.5 million residents who shop there have no Scotland-specific code of practice protecting them from it. Scottish Biometrics Commissioner Dr. Brian Plastow published a viewpoint on September 1 calling Scotland’s public-space surveillance strategy hopelessly outdated and urging Scottish ministers to replace it with a framework built for AI-powered cameras.

Plastow’s office has authority over three bodies only: Police Scotland, the Scottish Police Authority, and the Police Investigations and Review Commissioner. His remit does not extend to local authorities operating CCTV, retailers deploying Facewatch, or any commercial operator scanning faces in Scotland. The only oversight mechanism applying to Facewatch in Scottish supermarkets is UK GDPR. On August 6, 2026, Matt Arnold, a 46-year-old comedy promoter, was stopped at a Sainsbury’s self-checkout in East Dulwich, London, and told to leave despite having scanned his purchases and loyalty card; Facewatch flagged him as a match for a known shoplifter. Sainsbury’s apologized and attributed the incident to human error, and temporarily suspended Facewatch use at that location while investigating. A UK National Physical Laboratory study found the false positive identification rate for Black subjects was approximately 5.5%, compared with 0.04% for white subjects, a 137-fold disparity. The Scottish Government is reviewing whether to extend Plastow’s remit and whether to introduce a Scotland-specific surveillance camera code of practice, but legislating a new public-space surveillance strategy requires parliamentary time at Holyrood and political consensus that does not yet fully exist.

Facewatch Is Already Scanning Scottish Shoppers: No Rule Exists to Stop It →

Switzerland Pilots Microsoft 365 Alternatives to Protect Sensitive Data and Cut Costs

Switzerland’s federal government is testing alternatives to Microsoft 365 as part of an effort to reduce reliance on the American-made software suite and protect its most sensitive data. The pilot is expected to move 7% of federal administrative staff and their 3,000 workstations to whichever alternative suites are selected. Rising license costs are also cited as a reason for the switch. Professor Matthias Stürmer at Bern University of Applied Sciences described concerns about the implied risk of data leaks from a system controlled by foreign governments, stating that foreign governments can access this data at any time, and listed rising license costs as a secondary problem.

The trial could yield unsatisfactory results, potentially leading the Swiss government to stick with Microsoft 365. Microsoft’s own Sovereign Cloud platform ensures customer data stays in Europe, under European Law, with encryption under full control of customers, but that has not convinced the governments of Germany, France, and Switzerland.

Switzerland begins testing alternatives to Microsoft 365 to protect its “most sensitive data” and strengthen digital sovereignty →

Welsh Environmental Regulator Exposes Diversity Data of 2,000 Staff in FoI Blunder

Natural Resources Wales (NRW) disclosed that diversity data belonging to around 2,000 current and former employees who worked at the environmental regulator between April 2013 and March 2018 was exposed. The Welsh government-sponsored body confirmed on Friday that the information was inadvertently disclosed in a spreadsheet published on a website, but its statement did not identify the site, explain how the sensitive data came to be posted there, or say how many people were affected. NRW told The Register that around 2,000 people were affected and said it had released the information in 2021 as part of a response to a request under the Freedom of Information Act 2000.

The exposed information may have included ethnicity, disability status, religion or belief, sexual orientation, Welsh language ability, caring responsibilities, and other equality monitoring information, although not every category applied to each affected employee. Some of these details constitute special category personal data and are subject to additional protections under the UK GDPR. NRW said it reported the breach to the Information Commissioner’s Office, removed the information from the website, and obtained confirmation that it had been permanently deleted. The organization said it was alerted to the issue by a member of the public on 23 August 2026, and while it is not aware of any evidence that the information has been misused, it encourages individuals to remain vigilant for any unexpected communications.

Welsh environment regulator’s FoI blunder exposes diversity data of 2,000 staff →

Daily tech-news flash

The flash, every weekday.

Five minutes on AI, privacy and security — one short email per niche you pick, with a podcast to match.

Your niches