This Week in Privacy: Sep 7-13, 2026
The past week brought a reminder that privacy battles from years ago continue to reverberate through courtrooms today, while new threats demonstrate that even our strongest security measures remain vulnerable. From a long-awaited trial over the Cambridge Analytica scandal to government interventions on device-level protections, this week's events span the full spectrum of privacy challenges.
Top Stories
New Mexico's Cambridge Analytica Case Finally Goes to Trial
Eight years after the scandal and five years after filing suit, New Mexico's lawsuit against Facebook over Cambridge Analytica began with jury selection on September 8, 2026. The state alleges that Meta violated New Mexico's Unfair Practices Act by failing to protect hundreds of thousands of residents' Facebook data during the 2016 election cycle, when the political consulting firm harvested information from millions of users to develop voter profiles and target political advertising.
Opening arguments were expected September 9, with New Mexico claiming Facebook misrepresented how user data was collected, shared, and exploited. The state is seeking maximum civil penalties under state law. While the Cambridge Analytica story may feel like ancient history to some, this trial demonstrates that accountability for privacy violations can take years to materialize, and that state-level enforcement remains a crucial tool when federal action stalls.
Phishing Service Defeats Multi-Factor Authentication, Steals 5,000+ Credentials
A sophisticated criminal operation called BigBear 2.0 used man-in-the-middle tactics to bypass multi-factor authentication and steal over 5,000 Microsoft 365 credentials from 258 organizations through September 2026. The phishing-as-a-service platform intercepted login sessions and authentication cookies even after users completed MFA, then replayed those session cookies to hijack accounts and access email, files, and connected applications.
What makes this particularly concerning is the business model: CloudSEK discovered that BigBear was being leased to at least five different criminal operators who received stolen credentials in real time via Telegram. This industrialization of credential theft, combined with the defeat of MFA (often presented as a silver bullet for account security), underscores that authentication alone cannot fully protect sensitive accounts. Organizations need layered defenses including anomaly detection and conditional access policies that look beyond just username and password.
UK to Mandate Explicit Image Blocking on Phones for Under-18s
After three months of failed voluntary negotiations with Apple and Google, the UK government announced on September 8 that it will introduce legislation requiring the companies to block explicit images on smartphones used by people under 18. The proposed law would require protections to be built into devices by default, with age verification required before adults can take, view, or send nude images.
This represents a significant expansion of government mandates into device-level content filtering. Questions remain about implementation: How will age verification work without creating new privacy risks? Will the technology distinguish between legitimate content (medical images, art) and harmful material? And how will it affect encrypted messaging services? The decision to move from voluntary cooperation to mandatory compliance signals growing impatience among regulators with the pace of tech industry self-regulation.
The Big Picture
This week illustrates three persistent challenges in digital privacy. First, accountability moves slowly: the Cambridge Analytica trial arrives eight years after the events in question, demonstrating that legal remedies lag far behind technological harm. Second, security tools we rely on remain vulnerable to determined attackers, as the BigBear operation's defeat of multi-factor authentication shows. Third, governments are increasingly willing to mandate device-level controls when companies won't act voluntarily, raising new questions about the balance between protection and surveillance. Together, these stories remind us that privacy isn't a problem we solve once, it's a constant negotiation between users, companies, criminals, and governments.