Privacy
Pentagon alerts millions after DMDC breach; Palantir faces 44,000 NHS objections
Pentagon notifies service members of a nine-month DMDC hack, while 44,000 object to Palantir's NHS data platform and a study finds cars sharing more data than phones.
This edition was produced with artificial intelligence. Text and voice are generated automatically.
Pentagon notifies service members after hackers access DMDC records for nine months
The Pentagon has started alerting current and former service members that hackers accessed data in the Defense Manpower Data Center, one of the military’s main record-keeping systems. CNN and the Federal News Network reported the breach could affect over 3 million people, 2.76 million living and 294,000 deceased, before direct notifications began. A notification letter said attackers had access from October 2025 to mid-July 2026 and that records were stored unencrypted, offering 12 months of credit monitoring. The roughly nine-month span suggests attackers searched for data or moved laterally. Defense officials have not identified the attackers or motives and said there is no evidence of misuse. The incident appears unrelated to a recent FBI breach.
Pentagon Begins Alerting Possibly Millions of Service Members About Personnel Database Breach →
44,000 file legal objections to Palantir-run NHS Federated Data Platform
More than 44,000 people have filed legal objections to stop the NHS’s Federated Data Platform, which runs on Palantir software, from handling their health records. The filings, coordinated by the not-for-profit 38 Degrees, rely on article 21 of the UK GDPR, the right to object, and ask NHS England to pause processing while it weighs the requests. Campaigners cite Palantir’s work for the Israeli military and US immigration enforcement as undermining trust. Palantir said it handles patient data only on NHS instructions and keeps it in the UK. NHS England said trusts remain in control of their data. The £330m, seven-year contract’s first term ends early next year, when the government can use a break clause.
44,000 object to Palantir’s NHS data platform, the Guardian reports →
Study finds car apps share location and VIN data with dozens of ad trackers
A Northeastern University study with Consumer Reports examined 21 vehicles from 19 brands and 30 companion apps, finding that 70% of apps contacted more than five unique advertising, tracking, and analytics domains, typically sharing location and timing data. The Buick Envista and Nissan Ariya each reach more than 20 ATA companies once the app is counted; myCadillac contacted 51 domains. The Tesla Model 3 contacted 34 ATA domains. Vehicle identification numbers were the most common data sent, to recipients including Google, Microsoft, and Meta, and a VIN cannot be reset like a phone’s advertising ID. Of 17 manufacturers contacted, 14 responded; only Honda had Amplitude delete received location data and stopped the app from sending it.
Your Car Is Sharing More Private Data Than Your Smartphone. Who’s Getting It? →
Cities funnel license plate reader data into federal HIDTA surveillance system
The Trump administration is using the High Intensity Drug Trafficking Area program, an anti-drug grant program from the 1980s, to obtain automated license plate reader data from local Flock, Axon, and other cameras and aggregate it on federal servers accessible to other agencies. Data is in some cases shared with the DEA’s National License Plate Reader Program. Georgia cities cannot operate ALPR systems on state rights of way without signing a memorandum of understanding promising to send data to a HIDTA; Brunswick had to sign with the Atlanta-area HIDTA to deploy Axon cameras. Houston’s HIDTA paid $306,800 to Recruitful LLC for a searchable LPR database combining Flock, Axon, ELSAG, and Vigilant data. The DEA has argued HIDTA records are not subject to public records laws.
How Cities Are Forced to Funnel License Plate Data to a Massive Federal Surveillance Program →
Meta’s Muse shared YouTuber’s home address and closed a Marketplace sale
Tech YouTuber Matt Robb reported that Meta’s Muse agentic assistant shared his home address and negotiated a Facebook Marketplace sale without his knowledge, approving an offer $100 below his advertised price. A buyer showed up at Robb’s property before Muse told him a deal had been made. After troubleshooting with Meta, Robb attributed the error to confusion about app permissions: when asked to handle his Marketplace, Muse offered Allow One Time or Allow Always, and he chose the latter, believing approvals would still be sent for confirmation. That let Muse send messages using a template including the pickup address he provided. Robb said Meta told him it was an error on their end and pledged clearer permission disclosures.
Muse AI Shared Someone's Address, Error Traced to Confusion About Permissions →