Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Wednesday, July 8, 2026 · 11:48 AM EDT

Key developments

AMNEWYORK

Chatrie ruling leaves surveillance loopholes unresolved

The Supreme Court’s 6-3 decision in Chatrie v. United States held that compelled production of cellphone location history is a Fourth Amendment search requiring a warrant. amNewYork’s Sadie Brown reports the ruling is already being read against New York surveillance practices involving geofence warrants, license plate readers, CCTV and facial recognition. The Future of Privacy argues the decision does not close the government’s ability to buy similar location data from brokers, while Section 702 lapsed on June 12 amid disputes over warrant requirements for searches of Americans’ data.

Why it matters

The ruling strengthens constitutional protection for location data but leaves major statutory questions around data brokers and foreign-intelligence databases unresolved.

Sources & driving stories

AMNEWYORK · Sadie Brown

amNewYork coverage

THE FUTURE OF PRIVACY

The Future of Privacy coverage
BLEEPINGCOMPUTER

KDDI confirms 12.2 million email addresses exposed

BleepingComputer’s Sergiu Gatlan reports that Japanese telecom giant KDDI disclosed updated breach figures for an email platform used by STNet, JCOM, Chubu Telecommunications C, NIFTY Corporation and BIGLOBE. KDDI said attackers exploited a zero-day in third-party software on May 16; a July 6 update confirmed access to email addresses for 12,233,087 people and passwords for 7,616,173 others. The company said it deployed EDR, confirmed remediation on June 23, notified Japanese regulators and is forcing password resets for affected accounts.

Why it matters

The breach affects a large population across multiple ISPs and involves credential exposure that can drive account takeover and secondary fraud.

Sources & driving stories

BLEEPINGCOMPUTER · Sergiu Gatlan

BleepingComputer coverage
CNET

FBI and Google disrupt NetNut proxy botnet

CNET’s Joe Hindy reports that the FBI, Google, Lumen Technologies and the Shadowserver Foundation disrupted NetNut, a residential proxy service tied to the Popa botnet. A July 2 court-authorized seizure targeted domains and infrastructure associated with NetNut administrators and users; Google said the action significantly degraded a proxy network using roughly 2 million Android TVs and smart-home devices. Researchers previously found Popa installed on hacked Android TV devices without consent, enabling credential attacks, password spraying, malicious task execution and data scraping.

Why it matters

Residential proxy botnets turn consumer devices and home IP addresses into privacy-invasive infrastructure for masked cybercrime.

Sources & driving stories

CNET · Joe Hindy

CNET coverage

Worth noting

WORTH NOTING

Four states add privacy laws

Davis+Gilbert’s Catherine Nagle reports Alabama, Louisiana, Oklahoma and Vermont enacted comprehensive privacy laws with differing thresholds, sensitive-data rules, assessments and effective dates from 2027 to 2028.

WORTH NOTING

Apple faces new BIPA suit

Legalnewsline’s Jonathan Bilyk reports a July 4 Illinois federal class action alleging Apple’s Face ID consent materials cover facial scans but not separate iris or retinal scans.

WORTH NOTING

23andMe settlement gets approval

Bloomberg Law reports an Eastern District of Missouri bankruptcy judge approved a $46.7 million settlement for customers affected by the company’s data breach.

Still unclear

OPEN QUESTION

Will Chatrie reach data-broker purchases?

The ruling addresses compelled disclosure of location data, but sources identify unresolved questions over warrantless government purchases of similar data from brokers.

OPEN QUESTION

Can proxy takedowns produce lasting disruption?

Google warned that residential proxy operators may share and resell botnet access, meaning single-provider seizures may not eliminate the broader privacy and abuse ecosystem.