This Week in Privacy: Jul 27 - Aug 2, 2026
This week brought the most serious enforcement action yet under Europe's Digital Markets Act, plus a cascade of data breaches affecting millions from banks to schools to grocery chains. The message is clear: both regulators and hackers are escalating their attacks on how companies handle our data.
Top Stories
The European Commission fined Google €890 million on July 23 for violating the Digital Markets Act, marking the first and largest DMA penalty against the tech giant. The fine targets Google's practice of favoring its own shopping, hotel, transport, and sports services in search results while blocking app developers from directing Google Play users to cheaper offers elsewhere. The consequences are multiplying: price comparison sites across Europe, including Idealo, Kelkoo, PriceRunner, and Trovaprezzi, have now filed or escalated private damages claims in courts across Germany, Sweden, the UK, Italy, the Netherlands, and other countries. Total claims could reach $10 billion, turning what started as a regulatory penalty into an existential threat to Google's business model in Europe.
South Korea's telecommunications giant KT Corporation suffered a security breach that lasted nearly 11 months between October 2024 and September 2025. Hackers obtained a valid authentication certificate from a lost cellular base station device and used it to create a rogue station that intercepted customer communications, including phone numbers, device identifiers, and SMS authentication codes. This enabled fraudulent mobile payments totaling approximately $167,400 affecting at least 368 customers, with personal data of over 16,000 subscribers exposed. The government fined a related company, Lotte Card, 5 billion won ($3.38 million) for its own 2023 breach that exposed 2.97 million customers, and KT announced it will replace SIM cards for all 16 million subscribers at no cost.
Four families filed a wrongful death lawsuit on August 1 against Meta, TikTok, Snap, and Google, alleging the companies' platforms contributed to the deaths of four children between July 2024 and September 2025. The Social Media Victims Law Center claims these companies ignored internal research warnings, concealed evidence of harm, and built systems that profiled minors during vulnerable moments to increase engagement. The lawsuit spans deaths in Texas, North Carolina, Minnesota, and Tennessee, representing the latest effort to hold social media companies legally accountable for teen mental health harms.
In Brief
- Sumner County Schools in Tennessee delayed the school year start from August 4 to August 10 after discovering unauthorized network access on July 20, with FBI, TBI, and Homeland Security investigating.
- Fresno County's social services department disclosed a former employee caused a breach exposing personal information of 1,114 In-Home Supportive Services clients, including 636 phone numbers and six addresses.
- A federal judge allowed Reddit to proceed with claims against AI startup Perplexity AI and web-scraping firm SerpApi for allegedly bypassing technical security to scrape user-generated content for AI training.
- The FTC sued telehealth platform Hims & Hers, alleging it shared users' sensitive health information with Meta and Snap while engaging in deceptive billing practices.
- Analog Devices Inc. is investigating claims by hacking group ExfilSquad that it stole hundreds of files containing customer information and is threatening to release the data.
- Origin Energy confirmed a breach affecting an unknown number of its 4.7 million Australian customers, exposing names, addresses, dates of birth, and partial payment information.
- Three class action lawsuits allege Google transmitted US consumers' browsing data to Chinese companies including Temu and ByteDance through its advertising network, potentially violating the federal Bulk Sensitive Data Rule.
- 23andMe will pay $18 million to settle lawsuits over an October 2023 breach that compromised genetic information of 6.4 million users after hackers exploited the DNA Relatives and Family Tree features.
- Coca-Cola confirmed hackers stole data from dairy subsidiary Fairlife, with the Anubis ransomware gang releasing approximately one terabyte publicly after the company refused to negotiate.
- Bank of Baroda confirmed hackers accessed customer data through a compromised employee email account, with dark web posts claiming over 700GB of stolen data including identification documents and loan papers.
- Lidl disclosed a breach affecting customers in Germany, Belgium, and the Netherlands after criminals accessed customer data at an external IT service provider, though payment information and passwords were not compromised.
- Vermont enacted the Vermont Data Privacy and Online Surveillance Act, becoming the 23rd state with comprehensive consumer privacy law, set to take effect January 1, 2028.
The Big Picture
This week reveals two parallel crises in data protection. On the enforcement side, regulators are moving from warnings to weapons: Europe's €890 million DMA fine against Google, plus potential $10 billion in follow-on damages, shows that privacy and competition violations now carry business-threatening consequences. Meanwhile, the sheer volume of breaches (eight this week alone, from schools to banks to grocery stores) demonstrates that our data protection infrastructure remains fundamentally broken. The KT breach, which ran undetected for 11 months, is particularly alarming because it compromised the very SMS codes we rely on for two-factor authentication. When the security systems meant to protect us become attack vectors, we're not just losing data, we're losing the foundation of digital trust itself.