News Blog

The issues, the events on file, the research behind them, and the cases that show it.

ISSUE No. 03

Post 23 Sept 2026

What dating apps keep, and how the way you write can name you

A dating or matrimony profile holds your face, your faith, who you're drawn to and years of private messages. Some of that has already been shared, sold, scraped, handed to an AI company and leaked. Taking your name off doesn't hide you, because AI can now work out who wrote a text from the way it's written. Here's what these apps hold, where it has gone, and what to ask for.

Dating & Matrimony

ISSUE No. 02

Post 16 Jun 2026

De-identified does not mean what it used to

Every privacy policy lets a company pass on what it holds once your name is off it. The law allowed that because putting a name back took an expert, days and money. It now takes an AI model and a few seconds, and years of messages and profiles went out under the old assumption.

ISSUE No. 01

Post 16 Jun 2026

You proved you were real. Where did the proof go?

To open an account, watch a video, or start a job, you hand your face and your ID to a company you never chose. Here is what they keep, why 'we delete it' is a claim you can't check, and what a regulator found when it looked.

Latest

The newest from the three desks.

ASOS

Notice 8 Oct 2026

Notice October 2026

Customer profiles with addresses and site searches taken through a phished staff login

ASOS emailed customers on 8 October 2026 that someone "impersonating a trusted contact" got an employee's login and used it "to access information on certain third-party platforms used by Asos". A sample the attackers sent to BBC News holds names, addresses, phone numbers, emails, customer numbers and searches made on the site. Searches next to a name and an email are a record of what someone was looking at, including things they might never tell anyone. The attackers claimed to the BBC they got in through Simon AI, a marketing data platform. ASOS has named no platform; Simon AI's website lists ASOS as a customer. ASOS has given no numbers.

Notice · Retail

ASOS

Incident 6 Oct 2026

Incident October 2026

Attackers sent a push alert through its own app, threatening to leak its data

At about 10am on 6 October 2026, ASOS customers received a push notification through its app from attackers who said they had "fully compromised the Snowflake instance" and threatened to leak it. ASOS told the London Stock Exchange that day it was investigating unauthorised activity on "third-party platforms that we use to communicate with customers" and that "basic personal information including name and contact details may have been accessed". It said it did not believe payment card details or passwords were affected. Snowflake said its own platform had not been breached. The UK's National Cyber Security Centre tells every ASOS customer to assume they are affected, even without the notification.

Incident · Retail

Geon Media

Notice 29 Sept 2026

413,576 names on the rental list

Buyers of business opportunity programmes at seminars offered for rent as a list

A mailing list called Millennium Business Opportunity Buyers, managed by Geon Media, is offered for rent on the NextMark list directory. Its card describes 413,576 people who bought business opportunity products and services at webinars or seminars, spending $49.95 to $10,000 on programmes about real estate, online stock investing, the internet, social media and vending. The card suggests the names for business opportunities, self-improvement programmes, multi-level marketing, sweepstakes and credit card offers. The same manager rents webinar registrant, seminar registrant and mentor club buyer files from named programmes.

Notice · Advertising & Marketing

Money apps

Case study 1 Oct 2026

4 purchases, each a shop and a day, singled out 90% of people in card records with no names

You connect your bank to cut your bills. Other businesses pay for what your spending shows.

Snoop reads the bank and card accounts its users connect, and its policy lets it give their spending data to other companies to build advertising audiences. Since 2023 it has belonged to a bank, and it shares data with that bank for "credit or savings behavioural analysis".

Case study · 2015 to 2026 · Finance & Banking

Stim Money

Notice 29 Sept 2026

320,000 names on the rental list

Sign-ups for a free money e-book offered for rent to warranty and debt sellers

A mailing list called Free Guide to Financial Stability is offered for rent on the NextMark list directory. Its card says the people on it signed up for a free e-book from Stim Money on building a more solid financial foundation, covering credit scores, housing help, insurance and coping with unemployment. It lists 320,000 names, 70,000 of them added in the last month, sold at $80 to $85 per thousand. The card names them as targets for prepaid cards, auto and car warranties, debt consolidation, discount memberships, rebates, insurance offers and low end catalogues.

Notice · Finance & Banking

Openai

Incident 25 Sept 2026

53 user images posted online

Users' private images posted online by its own research agents

On 25 September 2026 OpenAI said its AI agents had posted 53 images uploaded by ChatGPT users to image-hosting sites, as links that were not publicly listed. The images came from users who had not opted out of having their data used to train OpenAI's models, and OpenAI kept them in anonymised form for that purpose. OpenAI said it had taken most of the images down and was working to remove the rest. It said it could not link the images back to the people who uploaded them and would not notify them. It declined to say when the images were posted.

Incident · Generative AI & AI Assistants

Times Car

Incident 25 Sept 2026

6.6 million accounts affected

6.6 million car-sharing accounts taken, driving licence images included

Park24, which runs the Times Car car-sharing service in Japan, said on 25 September 2026 that an outsider had got into the Times Car web system. Its second report, on 28 September, put the affected accounts at about 6.6 million, covering current and former members and corporate users. The data included names, addresses, dates of birth, phone numbers, email addresses, driving licence details, images of identity documents, linked service IDs and passwords, which Park24 said were stored in a form that cannot be restored. Its third report said about 1.6 million accounts had document images taken. Park24 said card details were not leaked. Access was blocked on 26 September.

Incident · Transportation

Dating app reports

Case study 1 Oct 2026

40+ moderators interviewed across three dating companies

You report a match. Someone else's staff reads it.

Dating apps send reports, with the messages and photos in them, to outside moderators and software. The firm that moderated Grindr now belongs to an AI company whose contract makes de-identified client data its own.

Case study · 2023 to 2026 · Dating & Matrimony

Labcorp

Enforcement 25 Sept 2026

$2,287,455 paid to 43 states and the District of Columbia

Pays 44 attorneys general over 10.2 million patients' data taken from a vendor

Labcorp agreed an Assurance of Voluntary Compliance with the attorneys general of 43 states and the District of Columbia over the breach at its former debt collection vendor, American Medical Collection Agency, announced in June 2019. About 10.2 million Labcorp patients were notified that an unauthorised person may have reached AMCA systems. HIPAA Journal reports the exposed data included names, Social Security numbers, financial data and medical test information. Labcorp will pay $2,287,455 and must appoint a chief information security officer and require security testing and audits of its vendors. The agreement takes effect on 1 October 2026.

Enforcement · Healthcare

Bromcom

Incident 25 Sept 2026

Incident September 2026

Pupils' and staff sign-in emails taken from a school software service

Bromcom, which supplies the management information system used by many UK schools, says an unauthorised party took staff and pupil registration data from its legacy single sign-on service, used to link Microsoft or Google accounts to a school. Some functions could be called without checking who was asking. Suspicious activity began on 24 August 2026 and most of the data was taken between 3 and 7 September. The data includes email addresses, some of them pupils' personal addresses, sign-in provider, sign-in dates and school identifiers. Bromcom says passwords and sign-in tokens were not taken and parents were not affected.

Incident · Education

Arizona Courts

Incident 25 Sept 2026

Incident September 2026

Protective order records copied after a staff member clicked a phishing link

The Arizona court system said attackers got in on 24 September 2026 after a court employee clicked a link in a phishing email. Staff shut the attack down within two hours, but the attackers copied backup files. The courts say the copied files include records on active and inactive protective orders with sensitive details, and that jurors, witnesses and court staff were not affected. Chief Justice Ann Scott Timmer said the hackers "copied personally identifiable information about many Arizonans." The FBI is investigating and the courts are notifying the people affected.

Incident · Government

Grindr

Case study 30 Sept 2026

$4 million spent on app data to find priests

A Catholic group bought app data to find priests who used Grindr

Phone data with no names on it, showing which devices used Grindr and where they went, was on sale through brokers. A Catholic group in Denver bought it, matched phones to parishes and seminaries, and passed what it found to bishops.

Case study · 2018 to 2023 · Faith & Religion · Dating & Matrimony

The next issue, by email

One email per issue, nothing else. Unsubscribe any time.

DÆTRAX · news blog "The issues, the events on file, and the research behind them." 3 issues