This Week in Privacy: Jul 13-19, 2026

·26 events covered
AppleFacebookGoogleIndustryTikTokX (Twitter)

This week brought an uncomfortable reminder that even security features marketed as protective can fail, while breaches across healthcare, telecommunications, and critical infrastructure demonstrated that no sector is immune to determined attackers. From compromised medical records to exposed developer code, the week's events highlighted both sophisticated social engineering and fundamental security oversights.

Top Stories

Louisiana Becomes Latest State to Enact Consumer Privacy Law

On July 18, Louisiana's governor signed the Louisiana Data Privacy Act, making it one of more than twenty states with comprehensive consumer privacy protections. The law takes effect January 1, 2027, and establishes a controller/processor framework similar to other state privacy laws. It grants Louisiana residents rights over their personal data, with enforcement authority resting exclusively with the state attorney general. As the patchwork of state-level privacy laws continues to expand, businesses operating nationally face increasing complexity in compliance, while the absence of federal privacy legislation becomes more glaring.

Apple's Hide My Email Feature Allegedly Exposed in Class-Action Lawsuit

A lawsuit filed in California accuses Apple of false advertising related to its Hide My Email feature for iCloud Plus subscribers. Security researchers reportedly notified Apple in June 2025 of a vulnerability allowing anyone to uncover users' real email addresses behind the generated aliases using basic online identity search tools. According to the complaint, Apple continued marketing the feature as secure without resolving the issue or disclosing its limitations. This case raises questions about how companies communicate security limitations when vulnerabilities are discovered but not immediately fixed, and whether users are being given accurate information to make privacy choices.

Major Publishers Sue Google Over AI Training Practices

On July 16, Hachette Book Group, Cengage Learning, Elsevier, and author Scott Turow filed a lawsuit in federal court accusing Google of willful copyright infringement. The publishers allege Google used copyrighted books and scholarly articles originally provided under limited-use agreements for services like Google Books and Google Play to instead train its Gemini AI platform without authorization. Internal documents cited in the lawsuit reportedly show Google engineers warned that this practice was highly problematic and could result in fines up to $100 billion. The case represents a significant escalation in the ongoing tension between AI companies hungry for training data and content creators seeking control over how their work is used.

Healthcare Breaches Continue with Multiple Incidents

TriWest Healthcare Alliance disclosed that on April 16, 2026, an unauthorized individual accessed systems and downloaded protected health information for 11,844 Tricare beneficiaries. The compromised data included names, Department of Defense Benefits Numbers, and ZIP codes, with fewer than five cases also involving Social Security numbers and full addresses. The notification came roughly two and a half months after the discovery. Healthcare remains a persistent target due to the value of medical records, which contain comprehensive personal information useful for identity theft and insurance fraud.

In Brief

  • The FBI arrested a 21-year-old Florida man for allegedly distributing fake video games on Steam that contained malware designed to steal passwords and drain cryptocurrency wallets, infecting around 8,000 victims and stealing at least $220,000 over two years.
  • Coca-Cola disclosed that its Fairlife dairy subsidiary experienced a ransomware attack forcing temporary suspension of all U.S. production facilities.
  • Security researcher Cereblab discovered that Grok Build, xAI's command-line tool, was uploading users' entire code repositories to Google Cloud Storage without permission until a server-side fix was implemented.

The Big Picture

This week's events reveal an uncomfortable truth: many privacy and security problems stem not from sophisticated zero-day exploits but from human psychology and organizational failures. Social engineering attacks successfully compromised Qantas, WINDTRE, and TriWest by simply convincing employees to take harmful actions. Meanwhile, the lawsuits against Apple and Google suggest that even well-resourced technology companies may struggle to align their marketing promises with security realities or obtain proper consent for data use. The expansion of

This Week in Privacy: Jul 13-19, 2026 | PrivacyWire