Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Friday, July 10, 2026 · 11:50 AM EDT

Key developments

MASHABLE

New York bans smart glasses as Meta weighs face ID

Mashable's James Paul reports that the New York State Unified Court System will ban smart glasses in more than 1,240 courthouses across 62 counties starting July 20, 2026. The rule applies to litigants, attorneys, witnesses, court employees and other entrants, and covers devices with embedded cameras, microphones or recording-capable computers unless a judge authorizes electronic recording. Separately, Social Media Today's Andrew Hutchinson reports that Meta CTO Andrew Bosworth confirmed Meta is considering locally encrypted facial-identification features for Meta AI glasses to recognize people already known to the wearer.

Why it matters

Courts are moving to restrict covert recording just as consumer wearables are adding biometric-identification capabilities.

Sources & driving stories

MASHABLE · James Paul

Mashable coverage

SOCIAL MEDIA TODAY · Andrew Hutchinson

Social Media Today coverage
HEAVY

MSG leak exposes secret venue risk scoring

Heavy's Jonathan Vankin, citing WIRED reporters Noah Shachtman and Maddy Varner, reports that ShinyHunters published internal Madison Square Garden Entertainment files after MSG declined to pay a ransom. The exposed material reportedly includes a talent database with about 39,539 entries, risk ratings for roughly 400 celebrities, labels ranging from low risk to "DO NOT HOST," and 93 entries marked "LGBTQIA." The leak also reportedly included a Salesforce dataset with nearly 10.5 million unique email addresses and a cases database containing a threat-check request on NYPD Commissioner Jessica Tisch that included her home address at the time.

Why it matters

The leak shows how private venue security operations can combine reputational scoring, sensitive personal labels and large-scale ticket-buyer data.

Sources & driving stories

HEAVY · Jonathan Vankin

Heavy coverage
INSURANCE BUSINESS

AssuranceAmerica breach estimate reaches 6.9 million

Insurance Business's Josh Recamara reports that class-action investigations have opened after breach filings estimated about 6.9 million people were affected by a cyberattack at AssuranceAmerica Managing General Agency. The company detected suspicious activity on March 17, 2026, traced the intrusion to credential-stealing phishing against one employee the previous day, and said an unauthorized party accessed systems and copied files. McAfee's Brooke Seipel reports the exposed information included names, contact details, driver's license numbers, insurance policy details, vehicle information and claims data; Insurance Business also cites possible Tax ID information and Social Security numbers.

Why it matters

Driver's license, Social Security and insurance data are difficult to reset and create long-tail identity-theft and litigation exposure.

Sources & driving stories

INSURANCE BUSINESS · Josh Recamara

Insurance Business coverage

MCAFEE · Brooke Seipel

McAfee coverage

Worth noting

WORTH NOTING

Japan advances AI consent carveout

CryptoBriefing reports that Japan's Cabinet approved APPI amendments allowing AI training on sensitive personal data without individual consent if data meets a government-defined pseudonymization standard.

WORTH NOTING

KDDI breach exposed millions of credentials

Tech Insider's Nadia Dubois reports that a zero-day affecting a shared KDDI email platform exposed 12,233,087 email addresses and 7,616,173 passwords across KDDI and five Japanese ISPs, with no vendor or CVE disclosed as of July 10.

WORTH NOTING

23andMe payout approved in bankruptcy

MassLive reports that a U.S. bankruptcy judge ordered Chrome Holding, 23andMe's parent company, to pay $46.75 million to compensate victims of the 2023 genetic-data breach affecting as many as 6.9 million people.

Still unclear

OPEN QUESTION

Will wearable biometrics trigger venue-by-venue bans?

New York courts are restricting smart glasses now, while Meta is still exploring facial-identification features that could force schools, courts, hospitals and private venues to set their own rules before broader regulation arrives.

OPEN QUESTION

Who bears risk in shared data platforms?

KDDI's partner ISPs inherited exposure from software they did not control, while AssuranceAmerica's agency network magnifies breach-notification, remediation and litigation costs across multiple organizations.