This Week in Privacy: Jul 13-19, 2026
This week brought an uncomfortable reminder that even security features marketed as protective can fail, while breaches across healthcare, telecommunications, and critical infrastructure demonstrated that no sector is immune to determined attackers. From compromised medical records to exposed developer code, the week's events highlighted both sophisticated social engineering and fundamental security oversights.
Top Stories
Louisiana Becomes Latest State to Enact Consumer Privacy Law
On July 18, Louisiana's governor signed the Louisiana Data Privacy Act, making it one of more than twenty states with comprehensive consumer privacy protections. The law takes effect January 1, 2027, and establishes a controller/processor framework similar to other state privacy laws. It grants Louisiana residents rights over their personal data, with enforcement authority resting exclusively with the state attorney general. As the patchwork of state-level privacy laws continues to expand, businesses operating nationally face increasing complexity in compliance, while the absence of federal privacy legislation becomes more glaring.
Apple's Hide My Email Feature Allegedly Exposed in Class-Action Lawsuit
A lawsuit filed in California accuses Apple of false advertising related to its Hide My Email feature for iCloud Plus subscribers. Security researchers reportedly notified Apple in June 2025 of a vulnerability allowing anyone to uncover users' real email addresses behind the generated aliases using basic online identity search tools. According to the complaint, Apple continued marketing the feature as secure without resolving the issue or disclosing its limitations. This case raises questions about how companies communicate security limitations when vulnerabilities are discovered but not immediately fixed, and whether users are being given accurate information to make privacy choices.
Major Publishers Sue Google Over AI Training Practices
On July 16, Hachette Book Group, Cengage Learning, Elsevier, and author Scott Turow filed a lawsuit in federal court accusing Google of willful copyright infringement. The publishers allege Google used copyrighted books and scholarly articles originally provided under limited-use agreements for services like Google Books and Google Play to instead train its Gemini AI platform without authorization. Internal documents cited in the lawsuit reportedly show Google engineers warned that this practice was highly problematic and could result in fines up to $100 billion. The case represents a significant escalation in the ongoing tension between AI companies hungry for training data and content creators seeking control over how their work is used.
Healthcare Breaches Continue with Multiple Incidents
TriWest Healthcare Alliance disclosed that on April 16, 2026, an unauthorized individual accessed systems and downloaded protected health information for 11,844 Tricare beneficiaries. The compromised data included names, Department of Defense Benefits Numbers, and ZIP codes, with fewer than five cases also involving Social Security numbers and full addresses. The notification came roughly two and a half months after the discovery. Healthcare remains a persistent target due to the value of medical records, which contain comprehensive personal information useful for identity theft and insurance fraud.
In Brief
- The FBI arrested a 21-year-old Florida man for allegedly distributing fake video games on Steam that contained malware designed to steal passwords and drain cryptocurrency wallets, infecting around 8,000 victims and stealing at least $220,000 over two years.
- TikTok updated its U.S. Privacy Policy to add a teen-specific summary document and expand children's privacy protections to include 13-year-olds in Florida.
- Australia's Privacy Commissioner concluded that Qantas did not violate privacy laws despite a June 2025 social engineering attack that compromised information for approximately 5.7 million customers.
- Italy's data protection authority fined WINDTRE €1.7 million after a February 2025 social engineering attack compromised personal data of over 365,000 customers, including payment information for more than 41,000.
- Coca-Cola disclosed that its Fairlife dairy subsidiary experienced a ransomware attack forcing temporary suspension of all U.S. production facilities.
- UK regulator Ofcom launched a formal investigation into whether TikTok adequately protects children from harmful content, focusing on the platform's age inference system.
- A multistate settlement and $18 million penalty were reached with 23andMe following a 2023 data breach affecting 6.9 million customers.
- A hacker breached AI music generator Suno and obtained source code revealing the company scraped over 2 million music clips from YouTube Music plus content from Deezer and Genius.
- Comcast agreed to pay $117.5 million to settle a class-action lawsuit over a cybersecurity breach affecting Xfinity customers.
- Ransomware group World Leaks published nearly 19,000 files related to India's Kudankulam Nuclear Power Plant after breaching contractor Reliance Group.
- Lifeline Australia confirmed a data breach after a hacker posted over 10,000 records containing staff, volunteer, and client information.
- 26 former Meta employees filed a lawsuit alleging the company used AI systems to select approximately 8,000 workers for layoffs based on AI tool adoption metrics and keystroke monitoring.
- Security researcher Cereblab discovered that Grok Build, xAI's command-line tool, was uploading users' entire code repositories to Google Cloud Storage without permission until a server-side fix was implemented.
- The U.S. Treasury sanctioned VPN provider 1VPNS and its Ukrainian administrator for facilitating ransomware attacks on American critical infrastructure.
- Dutch fitness chain Basic-Fit disclosed that attackers accessed systems tracking member gym visits, compromising data for approximately one million customers.
The Big Picture
This week's events reveal an uncomfortable truth: many privacy and security problems stem not from sophisticated zero-day exploits but from human psychology and organizational failures. Social engineering attacks successfully compromised Qantas, WINDTRE, and TriWest by simply convincing employees to take harmful actions. Meanwhile, the lawsuits against Apple and Google suggest that even well-resourced technology companies may struggle to align their marketing promises with security realities or obtain proper consent for data use. The expansion of