Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Sunday, July 19, 2026 · 6:48 PM EDT

Key developments

TECHTIMES

Herta facial recognition runs on Indian cameras

TechTimes' Joshua Mitchell reported on a joint investigation by Investigate Europe, India’s Reporters’ Collective, and Tech Policy Press finding Barcelona-based Herta Security facial recognition operating across an estimated 4,000 cameras in India. The deployments include railway stations, prisons, pilgrimage sites, and municipal surveillance, with about 100 cameras at Kolkata’s Howrah station scanning commuters against a roughly one-million-person watchlist. Legal scholars told investigators the Eastern Railway and Ahmedabad deployments would violate the EU AI Act if operated in the EU, while Herta said EU grants did not subsidize its Indian commercial deployments.

Why it matters

The reporting exposes a gap between Europe’s domestic biometric-surveillance restrictions and the export of comparable systems abroad.

Sources & driving stories

TECHTIMES · Joshua Mitchell

TechTimes coverage
THE BOSTON GLOBE

Madison Square Garden sues Wired over tracking report

Madison Square Garden’s owners filed a defamation lawsuit against Wired after a July 9 article reported that Madison Entertainment Corp. maintained a roughly 40,000-person VIP talent database with some entries listing race, gender identity, or sexual orientation. Wired reported 93 entries marked “LGBTQIA” and tied the database to broader reporting on MSG surveillance and facial-recognition practices; MSG says the article falsely implied discriminatory tracking and seeks damages plus correction or retraction. The database was reportedly among documents released in June by ShinyHunters after an alleged ransom dispute.

Why it matters

The suit turns leaked sensitive-profile data and venue surveillance practices into a high-profile fight over privacy reporting, customer data governance, and reputational harm.

Sources & driving stories

TECH TIMES

EY tax files stolen through help-desk platform

Tech Times reported that attackers accessed Ernst & Young’s third-party IT service management platform from March 28 through April 12, downloading client tax files attached to employee support tickets. EY detected the activity on April 23, and filings in California, Massachusetts, Vermont, and Texas confirm at least 1,366 affected residents, with potentially exposed data including Social Security numbers, financial account codes, credit and debit account data, investment holdings, and tax records. Rescana reported EY sent client notification letters on July 13 and filed California breach notices on July 15, while offering 24 months of identity monitoring and restoration services.

Why it matters

The incident shows how support-ticket systems can become under-governed repositories of highly sensitive financial and tax data.

Sources & driving stories

Worth noting

WORTH NOTING

Abbott extortion claims remain unverified

Cyber Updates 365’s Uday Patil reported ShinyHunters claims of more than 30 million customer-data rows and more than one million Social Security numbers, while Abbott confirms only limited unauthorized access in a legacy Cancer Diagnostics environment inherited from Exact Sciences and says operations were not disrupted.

WORTH NOTING

Ohio Living says patient files were stolen

Qrcodepress reported that Ohio Living found files containing patient information were exfiltrated during unauthorized network access on April 16–17, with potentially exposed data spanning Social Security numbers, financial data, medical history, prescriptions, treatment details, and health insurance information.

WORTH NOTING

Korea breach enforcement spotlights identity-linking risk

EpicKor connected PIPC’s finalized Coupang enforcement action, involving about 33.22 million members and at least 4.33 million nonmembers, with the ongoing TVING investigation where government materials cited a possible 19.5 million affected people and exposure of identity-linking CI and DI values.

Still unclear

OPEN QUESTION

Can EU AI rules govern exports?

The Herta reporting highlights that facial-recognition uses barred or tightly restricted inside the EU may still be sold into jurisdictions with weaker biometric-surveillance safeguards.

OPEN QUESTION

How broad is Abbott’s actual exposure?

Abbott disputes ShinyHunters’ scale claims, but the alleged Entra-linked access to multiple cloud services would materially change the privacy risk if independently verified.