Key developments
Texas investigates Carnival over massive breach
Texas Attorney General Ken Paxton announced an ongoing investigation into Carnival Corporation after an April 14, 2026 breach compromised personal information for an estimated 6 million people, including 800,060 Texans. Carnival told the Texas OAG that unauthorized activity involved an employee account accessed through social-engineering techniques. Exposed categories included names, contact details, dates of birth, payment information, passport information, driver's license information and health information; Carnival submitted its breach notification 44 days after the breach.
Why it matters
The investigation tests Texas enforcement expectations for breach response, notification timing and reasonable safeguards at a major travel company holding highly sensitive identity and health data.
Sources & driving stories
TEXAS ATTORNEY GENERAL
Texas Attorney General coverageJudge blocks federal voter-screening database
ABC News reported that U.S. District Judge Sparkle Sooknanan blocked the Trump administration's use of the Systematic Alien Verification for Entitlement database for purging non-citizens from voter rolls. The court found that the government unlawfully consolidated personal information of millions of Americans and violated the Social Security Act, the Privacy Act and the Administrative Procedure Act. Plaintiffs including the League of Women Voters had sued DHS in March, alleging illegal voter surveillance and comprehensive citizen data collection.
Why it matters
The ruling curbs a government identity-screening system that plaintiffs said created large-scale voter surveillance and led states to remove U.S. citizens based on inaccurate information.
Sources & driving stories
ABC NEWS
ABC News coverageMSG sued after biometric surveillance breach
BiometricUpdate.com reported that Madison Square Garden Entertainment faces a federal class action, Avalo v. MSG Entertainment, after hacker group ShinyHunters claimed it stole 45GB of data spanning 26 million visits to MSG venues. The data allegedly came from facial-recognition-powered surveillance systems and included biometric tracking logs, background check information, internet threat assessment data and customer emails from people who had criticized MSG's facial-recognition practices. Plaintiffs filed after an alleged June 15 ransom deadline passed and seek at least $5 million in initial damages.
Why it matters
The case ties biometric surveillance, ransomware extortion and venue security practices into a concrete privacy liability dispute.
Sources & driving stories
BIOMETRICUPDATE.COM
BiometricUpdate.com coverageWorth noting
WORTH NOTING
Meta glasses face-recognition code surfaced
Northeastern Global News' Hannah Morse reported on WIRED's finding that Meta had quietly added, then removed after reporting, dormant smart-glasses face-recognition code in the Meta AI app that could create phone-stored biometric faceprints and alert wearers when recognized people appeared.
WORTH NOTING
Peregrine funds public-safety AI expansion
Fortune's Lily Mae Lazarus reported that Peregrine raised $250 million at a $6.8 billion valuation while serving up to 400 agencies and running security fusion centers for eight of 11 2026 World Cup host cities, amid civil-liberties concerns over AI-powered public-safety data integration.
WORTH NOTING
Texas license breach exceeds three million
Spectrum News 1 South Texas and FRPA reported that a Texas Parks and Wildlife Department vendor breach may have exposed driver license information, passport numbers and contact details for more than 3 million hunting and fishing license holders, while Social Security numbers, birth dates and financial data were not affected.
Still unclear
OPEN QUESTION
Will regulators punish slow or partial breach notices?
Carnival's 44-day Texas notification, Cherry Health's preliminary notice without affected-person counts and London Hydro's limited disclosure all leave open questions about timeliness, scope and transparency.
OPEN QUESTION
What consent standard fits wearable recognition?
The Meta smart-glasses reporting and MSG biometric lawsuit both show that indicator lights, audit trails or post-hoc policies may not address bystanders whose biometric data is captured without opt-in consent.
