Last Update: 08/01/2026 at 1:34 PM EST

Mid-day Briefing: Privacy

Monday, July 20, 2026 · 11:49 AM EDT

Key developments

MINNESOTA STAR TRIBUNE

Twin Cities plate cameras searched for immigration enforcement

Minnesota Star Tribune reporters Allison Kite and Sarah Ritter found that license-plate camera data from at least eight Twin Cities suburbs was searched during the federal immigration crackdown known as Operation Metro Surge. More than 30 state, county and federal agencies accessed the data between November and March, with hundreds of searches labeled as civil immigration enforcement. Fridley audit data showed more than 390,000 searches in the month before the department restricted access, and several local governments have since limited sharing, required warrants, or ended Flock contracts.

Why it matters

The reporting shows how local surveillance networks can become de facto federal immigration-tracking infrastructure even without a direct federal contract with the vendor.

Sources & driving stories

MINNESOTA STAR TRIBUNE · Allison Kite and Sarah Ritter

Minnesota Star Tribune coverage
POST AND COURIER

States secure limited 23andMe breach settlement

Post and Courier reporter Maddy Quon reported that South Carolina will receive $280,000 from a 42-state settlement over 23andMe’s 2023 genetic-data breach. The breach affected 6.9 million customers worldwide, including 80,181 South Carolina residents, and state attorneys general alleged unreasonable security practices, including inadequate safeguards against credential-stuffing attacks. Although the settlement structure allows states to claim $150 million, only about $18 million is expected to be distributed because of 23andMe’s bankruptcy estate and competing claims.

Why it matters

The case tests how privacy enforcement can deliver accountability when the compromised data is highly sensitive and the company is in bankruptcy.

Sources & driving stories

POST AND COURIER · Maddy Quon

Post and Courier coverage
SECURITYWEEK

EY notifies clients of tax-platform data breach

SecurityWeek’s Ionut Arghire reported that Ernst & Young has begun notifying clients after a breach of a third-party service management platform used for tax-related work. EY discovered anomalous activity on April 23 and said attackers accessed the platform between March 28 and April 12, downloading client documents submitted through support tickets. The exposed information may include names, addresses, Social Security numbers, account numbers, credit or debit card numbers, and tax-preparation data; EY says it has not identified misuse and is offering two years of monitoring services.

Why it matters

Tax-support workflows can concentrate identity and financial records, making third-party platform compromise a high-impact privacy failure.

Sources & driving stories

SECURITYWEEK · Ionut Arghire

SecurityWeek coverage

Worth noting

WORTH NOTING

Paidwork leak reaches breach-notification service

Technadu’s Lore Apostol reported that Have I Been Pwned added a Paidwork breach on July 19 involving nearly 11GB of leaked data and more than 23 million unique email addresses, with reported exposure of bank account numbers, payout histories, dates of birth, IP/device data and bcrypt-hashed passwords.

WORTH NOTING

ACLU targets hidden police AI

The Tech Buzz reported that the ACLU has issued a Massachusetts defense-attorney toolkit with discovery requests, motions and case-law citations aimed at forcing disclosure of facial recognition, AI-generated police reports and other algorithmic tools used in criminal cases.

WORTH NOTING

Estée Lauder confirms Oracle EBS exposure

CyberInsider reported that Estée Lauder is notifying current and former employees after an August 2025 Oracle E-Business Suite HR compromise, with employee data access confirmed on June 19, 2026 and the incident linked to the broader Clop-attributed Oracle EBS exploitation campaign.

Still unclear

OPEN QUESTION

Can local data-sharing rules block federal workarounds?

The Minnesota plate-reader investigation suggests federal and out-of-state agencies may reach local surveillance data through agency partnerships even when vendors deny direct relationships.

OPEN QUESTION

What happens to genetic privacy in bankruptcy?

The 23andMe settlement offers limited recovery while company assets, including customer genetic data, have been sold, raising unresolved questions about durable privacy protection after corporate distress.