Key developments
Herta facial recognition runs on Indian cameras
TechTimes' Joshua Mitchell reported on a joint investigation by Investigate Europe, India’s Reporters’ Collective, and Tech Policy Press finding Barcelona-based Herta Security facial recognition operating across an estimated 4,000 cameras in India. The deployments include railway stations, prisons, pilgrimage sites, and municipal surveillance, with about 100 cameras at Kolkata’s Howrah station scanning commuters against a roughly one-million-person watchlist. Legal scholars told investigators the Eastern Railway and Ahmedabad deployments would violate the EU AI Act if operated in the EU, while Herta said EU grants did not subsidize its Indian commercial deployments.
Why it matters
The reporting exposes a gap between Europe’s domestic biometric-surveillance restrictions and the export of comparable systems abroad.
Sources & driving stories
TECHTIMES · Joshua Mitchell
TechTimes coverageMadison Square Garden sues Wired over tracking report
Madison Square Garden’s owners filed a defamation lawsuit against Wired after a July 9 article reported that Madison Entertainment Corp. maintained a roughly 40,000-person VIP talent database with some entries listing race, gender identity, or sexual orientation. Wired reported 93 entries marked “LGBTQIA” and tied the database to broader reporting on MSG surveillance and facial-recognition practices; MSG says the article falsely implied discriminatory tracking and seeks damages plus correction or retraction. The database was reportedly among documents released in June by ShinyHunters after an alleged ransom dispute.
Why it matters
The suit turns leaked sensitive-profile data and venue surveillance practices into a high-profile fight over privacy reporting, customer data governance, and reputational harm.
Sources & driving stories
THE BOSTON GLOBE
The Boston Globe coverageSEEKING ALPHA
Seeking Alpha coverageEY tax files stolen through help-desk platform
Tech Times reported that attackers accessed Ernst & Young’s third-party IT service management platform from March 28 through April 12, downloading client tax files attached to employee support tickets. EY detected the activity on April 23, and filings in California, Massachusetts, Vermont, and Texas confirm at least 1,366 affected residents, with potentially exposed data including Social Security numbers, financial account codes, credit and debit account data, investment holdings, and tax records. Rescana reported EY sent client notification letters on July 13 and filed California breach notices on July 15, while offering 24 months of identity monitoring and restoration services.
Why it matters
The incident shows how support-ticket systems can become under-governed repositories of highly sensitive financial and tax data.
Sources & driving stories
TECH TIMES
Tech Times coverageRESCANA
Rescana coverageWorth noting
WORTH NOTING
Abbott extortion claims remain unverified
Cyber Updates 365’s Uday Patil reported ShinyHunters claims of more than 30 million customer-data rows and more than one million Social Security numbers, while Abbott confirms only limited unauthorized access in a legacy Cancer Diagnostics environment inherited from Exact Sciences and says operations were not disrupted.
WORTH NOTING
Ohio Living says patient files were stolen
Qrcodepress reported that Ohio Living found files containing patient information were exfiltrated during unauthorized network access on April 16–17, with potentially exposed data spanning Social Security numbers, financial data, medical history, prescriptions, treatment details, and health insurance information.
WORTH NOTING
Korea breach enforcement spotlights identity-linking risk
EpicKor connected PIPC’s finalized Coupang enforcement action, involving about 33.22 million members and at least 4.33 million nonmembers, with the ongoing TVING investigation where government materials cited a possible 19.5 million affected people and exposure of identity-linking CI and DI values.
Still unclear
OPEN QUESTION
Can EU AI rules govern exports?
The Herta reporting highlights that facial-recognition uses barred or tightly restricted inside the EU may still be sold into jurisdictions with weaker biometric-surveillance safeguards.
OPEN QUESTION
How broad is Abbott’s actual exposure?
Abbott disputes ShinyHunters’ scale claims, but the alleged Entra-linked access to multiple cloud services would materially change the privacy risk if independently verified.
