Mailfence Privacy Digest August 2026, N°16

Featured image for the Mailfence Privacy Digest August 2026

Table of Contents

Share this article:

August 2026 was the month the rules caught up. On 2 August, the EU began enforcing AI Act transparency obligations; on 18 August, the e-Evidence Regulation went live, letting EU judges demand electronic evidence from providers in other member states in as little as eight hours. The Dutch privacy authority fined Uber €825 million for automated account deactivations without human review, and TikTok took hits on both sides of the Atlantic: a DSA minors-protection finding in the EU and a record $559 million children’s privacy settlement in the US. There were bright spots too: Ring made user-controlled encryption the default, and Python shipped post-quantum cryptography as a one-line install. Here’s what happened this month:

Breaches & Security

⬇ RingCentral: ShinyHunters Breach Exposes 1.6 Million Accounts: Attackers voice-phished a single employee, stole 623 GB of data, and dumped 280 GB on the dark web after the company refused to pay a ransom.

⬇ CareCloud: Healthcare Breach Hits 3.75 Million Patients: Intruders spent six days in an AWS environment in March, but the full scale of the breach, now the fifth-largest US health data theft of 2026, was only confirmed in August.

AI

⬆ EU AI Act: Transparency Obligations Take Effect: From 2 August, AI chatbots must disclose they are AI, synthetic content must carry machine-readable labels, and deepfakes must be identified, with fines of up to €15 million or 3% of global turnover.

⬆ Ring Defaults to User-Controlled Encryption on All Cameras: Amazon’s Ring will roll out “TAKE” encryption as the default from September, a step forward, but the new system is not true end-to-end encryption, and Ring retains temporary key access for up to 24 hours.

⬆ Python Gets a Post-Quantum Encryption Library: Python’s standard security toolkit now includes the new, officially standardised encryption methods designed to withstand future quantum computers, making it easy for millions of developers to protect their apps before quantum machines become a real threat.

Government, Surveillance & Regulatory

⬇ EU e-Evidence Regulation Goes Fully Operational: From 18 August, judicial authorities in any EU member state can order service providers in another member state to hand over electronic evidence in 10 days, or 8 hours in an emergency, bypassing the provider’s home authorities.

⬇ EU: TikTok Found in Breach of DSA for Failing to Protect Minors: The European Commission’s preliminary findings say minors’ accounts default to public, exposing children to unwanted contact and long-term privacy risks, with a potential fine of up to 6% of global turnover.

⬆ TikTok Pays $559 Million in US Children’s Privacy Settlement: The largest children’s privacy settlement in US history resolves claims that the platform collected and kept minors’ data without parental consent.

Uber Fined €825 Million in Second-Largest GDPR Penalty Ever: The Dutch Data Protection Authority ruled that Uber auto-deactivated driver accounts by algorithm with no human review, breaching the GDPR’s protections against solely automated decisions.

⬇ US: American Prosecuted for Wiping Phone Before Border Search: A GrapheneOS user entered a duress password that erased his device when officers demanded access, and now faces federal charges despite not being under arrest at the time.

⬇ UK: ICO Pushes Police on Facial-Recognition Governance: A five-force audit produced 107 recommendations after finding inconsistent compliance, while the Metropolitan Police scanned 1.7 million faces in 2026 so far, up 87% on last year.

RingCentral: ShinyHunters Breach Exposes 1.6 Million Accounts

The ShinyHunters extortion group claimed responsibility on 27 July for breaching RingCentral, the cloud-based business communications platform. The attackers gained access by voice-phishing a single employee and tricking them into handing over a password. ShinyHunters claimed to have stolen 623 GB of data and demanded a ransom. When RingCentral refused to pay, the group published a 280 GB archive on its dark web leak site. On 13 August, Have I Been Pwned confirmed the leak contained records for roughly 1.6 million unique email addresses, along with names, physical addresses, and phone numbers. RingCentral stated the breach affected “a limited portion” of its customers and that no new unauthorised activity had been seen since its remediation efforts.

To protect yourself, check whether your email address appears in the breach via Have I Been Pwned. If it does, change the password on your RingCentral account and any other service where you reused the same credentials. Enable two-factor authentication wherever it is available, and be alert for targeted phishing attempts that use your name, address, or phone number to appear legitimate.

Read more: RingCentral Data Breach Exposed Info of 1.6 Million Accounts (BleepingComputer)

Learn more: 1.6 Million Likely Impacted by RingCentral Data Breach (SecurityWeek)

CareCloud: Healthcare Breach Hits 3.75 Million Patients

US healthcare technology firm CareCloud confirmed in August that an intrusion earlier this year affected 3,756,469 individuals, making it the fifth-largest health data theft disclosed in 2026. An unauthorised third party accessed one of CareCloud’s Amazon Web Services environments between 10 and 16 March, causing an eight-hour disruption to its electronic health record platform. The company initially reported the incident to the SEC in March without specifying the scope. By August, the Department of Health and Human Services breach tracker had updated the count from an earlier estimate of roughly 345,000 to the final figure of 3.75 million. The exposed data includes names, Social Security numbers, medical records, banking details, and passport information. No ransomware group has publicly claimed responsibility.

To protect yourself, take advantage of the free identity-protection service CareCloud is offering through IDX (redeemable until 17 December 2026). Place a credit freeze with all three major credit agencies, monitor your bank statements and explanation-of-benefits documents for unfamiliar charges, and be on guard for phishing attempts that reference specific medical information, as stolen health data makes social-engineering attacks far more convincing.

Continue reading: CareCloud Confirms 3.7M Patients Had Their Medical Records Stolen (TechCrunch)

EU AI Act: Transparency Obligations Take Effect

On 2 August, the EU AI Act’s transparency rules under Article 50 became enforceable across all member states. AI systems that interact directly with users, such as chatbots and virtual assistants, must now clearly disclose that the user is communicating with a machine. Providers of systems that generate or alter text, images, audio, or video must ensure that AI-created content carries machine-readable marks, and deployers of deepfakes and AI-generated public-interest content must label it accordingly. The European Commission published implementation guidelines on 20 July and released a set of standardised icons that providers can use for labelling. More than 180 organisations have signed a voluntary Code of Practice on transparency of AI-generated content. Non-compliance can trigger fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.

To stay informed, check whether AI tools you use at work or at home now display disclosure notices, and treat their absence as a red flag. If you run a business that deploys AI-powered chatbots, customer-facing tools, or content-generation systems in the EU, review the Commission’s guidelines and assess your systems against Article 50 now. The high-risk AI obligations originally expected on the same date have been pushed back to December 2027, but the transparency rules apply today.

Read more: Commission Starts Enforcing AI Act Rules and New Transparency Requirements (European Commission)

Learn more: EU AI Act Transparency Obligations Are Now in Force (Goodwin)

Ring Defaults to User-Controlled Encryption on All Cameras

Amazon’s Ring announced on 26 August that it will roll out a new encryption standard called TAKE (Throw Away the Key Encryption) as the default for all Ring cameras worldwide, beginning in September. Until now, Ring video was encrypted in transit and at rest, but Ring’s own cloud services could access the footage, a setup that allowed the company to power features like video search and shared access but also meant that footage could, in principle, be turned over to law enforcement. TAKE uses rotating encryption keys that are temporarily held in the cloud and deleted after the request is completed, typically after 24 hours. Ring says the approach is “inspired by the privacy principles of E2EE” but allows cloud features that true end-to-end encryption does not. Full E2EE remains available as an optional setting for users who want it.

To take advantage of this, update your Ring app when the TAKE rollout reaches your account and review your encryption settings. If you want the strongest possible protection, where not even Ring can access your footage, enable full end-to-end encryption in the Ring app under Control Centre. Be aware that doing so will disable some cloud features, including video search and shared user access. For anyone evaluating home security cameras, the broader takeaway is positive: encryption defaults are moving in the right direction, even if the fine print still matters.

Continue reading: Ring Introduces a New Encryption Standard, Makes It the Default (TechCrunch)

Read more: Ring Hopes New Encryption Tech Will Ease Surveillance Fears (CNN)

Python Gets a Post-Quantum Encryption Library

Trail of Bits, with support from the Sovereign Tech Agency, has added new future-proof security tools to cryptography, a widely used Python security library. This makes it easier for Python developers to protect their software against future quantum computers, which could one day break some of today’s encryption. The update includes ML-KEM, which helps two systems create a secure connection, and ML-DSA, which helps confirm that a message or software update really came from the right sender and was not changed. Both are official standards from NIST. Developers can now use these tools simply by installing the updated library. The goal is also to help software switch to stronger security methods later without needing a complete rebuild.

To stay prepared, developers should start exploring post-quantum libraries now, while there is no emergency. For non-developers, the takeaway is that the building blocks for quantum-safe encryption are being laid across the tools and languages that underpin the internet. Ask your software and service providers whether they have a post-quantum migration plan, and favour products that are already building crypto agility into their roadmaps.

Learn more: Shipping Post-Quantum Cryptography to Python (Trail of Bits)

EU e-Evidence Regulation Goes Fully Operational

On 18 August, Regulation (EU) 2023/1543 became directly applicable across every EU member state except Denmark, which has an opt-out. The e-Evidence Regulation is the largest structural change to cross-border law enforcement access to electronic evidence in decades. Under the new rules, a judicial authority in one member state can issue a European Production Order directly to a service provider, or its designated legal representative, in another member state, compelling it to hand over subscriber data, traffic data, or even content data within 10 days, or in just 8 hours in cases of emergency. Previously, the same process required a mutual legal assistance request that could take up to 10 months. A second tool, the European Preservation Order, allows authorities to require that a provider freeze specific data for 60 days while a formal production request follows.

The regulation also reaches beyond EU borders: non-EU service providers that offer services within the EU must now designate an EU-based legal representative to receive and process orders. Readiness, however, is patchy. In March, the European Commission sent letters of formal notice to 22 member states for failing to transpose the accompanying Directive on time, and the decentralised IT system designed for submitting orders is not yet operational, meaning the first orders are likely to arrive by post or email. Despite these gaps, countries including Germany, Sweden, Italy, and Slovakia have adopted their implementing legislation, and orders from those jurisdictions can be issued immediately.

To engage with these developments, know that this regulation affects any service that processes electronic data in the EU, including email, cloud storage, messaging, and hosting providers. If you run or work for such a service, check whether your organisation has designated an EU legal representative and established a process for handling production orders. As an individual, understand that the data you store with EU-based providers can now be requested by law enforcement authorities in any member state, not just the one where your provider is based. Favour providers that publish transparency reports, so you can track how often such orders are received and complied with.

Read more: The EU e-Evidence Regulation Enters Into Force: What Companies Need to Know (Houthoff)

EU: TikTok Found in Breach of DSA for Failing to Protect Minors

On 24 July, the European Commission issued preliminary findings that TikTok’s account settings for minors do not meet the safety standards required under the Digital Services Act. The Commission found that children can set their accounts to public, letting anyone, including people without a TikTok account, view their content. Content from users aged 16 and 17 can also be recommended to strangers through the For You feed. The Commission’s preliminary view is that minors’ accounts should default to being visible only to contacts the child has accepted, and that TikTok should stop recommending minors’ content in its recommendation feed. This forms part of a wider investigation opened in February 2024 covering addictive design, advertising transparency, and researcher access. If confirmed, TikTok could face a fine of up to 6% of its global annual turnover.

To protect yourself and your family, review the privacy settings on any TikTok accounts used by minors in your household. Set accounts to private, disable the “Suggest your account to others” option, and turn off personalised ads. Parents should enable TikTok’s Family Pairing feature and have a conversation with younger users about what being “public” actually means for their content and personal safety.

Read more: Commission Finds TikTok in Breach of DSA for Failing to Ensure Safe Accounts for Minors (European Commission)

TikTok Pays $559 Million in US Children’s Privacy Settlement

TikTok has agreed to pay $559 million to settle a US class-action lawsuit over allegations that the platform collected and retained personal data from users under 13 without parental consent. It is the largest children’s privacy settlement in US history. The case centred on TikTok’s handling of minors’ data, including location information, biometric identifiers, and browsing activity. The settlement comes at a moment when TikTok faces intensifying global scrutiny over how it treats young users, as the parallel EU DSA findings above illustrate.

To engage with these developments, check whether minors in your household have accounts on platforms that collect biometric or location data, and review the data-sharing permissions granted to each app. Under US law, COPPA (the Children’s Online Privacy Protection Act) gives parents the right to review and delete data collected from children under 13. Exercise that right, and keep an eye on similar enforcement actions that may expand protections to older teens.

Continue reading: TikTok to Pay $559M in One of the Largest Child Privacy Settlements (ABC News)

Uber Fined €825 Million in Second-Largest GDPR Penalty Ever

The Dutch Data Protection Authority fined Uber €824,990,000 on 21 August for deactivating driver accounts through automated systems between 2018 and 2022 without human review and without telling drivers the decisions were automated. The fine is the second-largest ever issued under the GDPR, trailing only the €1.2 billion penalty Ireland imposed on Meta in 2023. It brings Uber’s cumulative Dutch fines to over €1.1 billion, after earlier penalties in 2018, 2023, and 2024. The case began when 171 French drivers complained through the Ligue des droits de l’Homme; the Dutch regulator handled it as the lead authority because Uber’s European headquarters is in Amsterdam. Deputy chair Monique Verdier said a “computer should not make decisions on its own that have such major consequences.” Uber has appealed, arguing that most suspensions are temporary and that permanent deactivations involve human review.

To stay informed, remember that the GDPR gives everyone the right not to be subject to a decision based solely on automated processing that has significant effects on them (Article 22). If you are a gig-economy worker and your account is suspended or deactivated without explanation, ask the platform for a meaningful explanation of the logic involved and request human review. For organisations, this ruling is a clear warning: automated decision-making systems need documented human oversight, audit trails, and transparency, or the fines will keep getting bigger.

Learn more: Uber Faces Fine of Nearly $1B Over Automated Driver Suspensions (TechCrunch)

A US citizen is facing federal charges after entering a “duress password” on his GrapheneOS phone during a border search, which triggered the device to erase its contents. GrapheneOS, a privacy-focused Android operating system for Google Pixel devices, includes a feature that lets users set a secondary passcode that wipes the device if entered instead of the real one. The man was not under arrest at the time. The case raises sharp questions about what constitutional protections apply at the US border, where the government has long asserted that travellers’ devices can be searched without a warrant. GrapheneOS responded publicly, calling its software “completely legal” and describing it as strongly protected by the US Constitution.

To prepare for border crossings, back up your device before travelling and know your rights: in many jurisdictions, officers can inspect devices but cannot compel you to decrypt them in every circumstance. Consider travelling with a minimal device that holds only what you need for the trip. If you use features like GrapheneOS’s duress password, understand the legal risks in advance. For everyone, this case is a reminder that the legal framework around device searches at borders is evolving, and the outcome could set a precedent for digital privacy rights at the frontier.

Learn more: A Feature That Makes Your Phone Data Self-Destruct May Soon Have Its Day in Court (Gizmodo)

UK ICO Pushes Police on Facial-Recognition Governance

On 18 August, the UK Information Commissioner’s Office published a report on the responsible use of facial-recognition technology by police forces in England and Wales. Between June 2025 and March 2026, the ICO audited five forces: South Wales and Gwent, Essex, Leicestershire, West Yorkshire, and Greater Manchester. The regulator made 107 recommendations, all of which were accepted or partially accepted. While some good practice was found, the ICO described compliance as “inconsistent overall” and flagged urgent work needed around senior oversight, accountability, and record-keeping. Separately, testing by the National Physics Lab revealed bias in the algorithm used for retrospective facial-recognition searches, increasing the likelihood of incorrect matches for people in certain demographic groups. The Metropolitan Police, which has scanned more than 1.7 million faces so far in 2026 (up 87% on the same period last year), has its own audit scheduled for later in 2026.

To engage with these developments, keep track of whether your local police force uses live or retrospective facial recognition. In the UK, the ICO’s report is publicly available, and its recommendations apply to all forces, not just the five that were audited. If you are concerned about how the technology is being used in your area, you can submit a Subject Access Request to find out whether your image has been processed. For organisations operating in public spaces, the ICO’s message is clear: strong data-protection governance is not optional; it is the foundation of public trust.

Read more: Facial Recognition in Policing: Earning Public Trust Through Strong Data Protection Governance (ICO)

Learn more: ICO Urges Police to Improve Data Governance in Facial Recognition Roll (Infosecurity Magazine)

• Crypto-Gram, August 2026 (Schneier on Security)

• List of Recent Data Breaches in 2026 (Bright Defense)

• Cybersecurity & Privacy News and Analysis (Law360)

• Secure Email for Lawyers (Mailfence Blog)

• What Is a Rainbow Table Attack (Mailfence Blog)

That’s All for This Month’s Newsletter!

August’s throughline is enforcement at scale. The EU e-Evidence Regulation rewrites the rules on cross-border access to your data. Uber’s €825 million fine and TikTok’s twin accountability moments on two continents show that regulators are backing their words with numbers that hurt. The AI Act’s transparency obligations are now enforceable, and the UK’s data protection watchdog is pressing police forces that have been scanning millions of faces without consistent governance. On the defence side, Ring’s new encryption default and the Python ecosystem’s post-quantum library are reminders that the tools to protect yourself are getting better, even if you have to look past the marketing to find the real encryption setting. Stay vigilant, stay encrypted, and we’ll see you next month.

Best,

Patrick

Get the latest privacy news in your inbox

Sign up to the Mailfence Newsletter.

Reclaim your email privacy.
Create your free and secure email today.
Picture of Patrick De Schutter

Patrick De Schutter

Patrick is the co-founder of Mailfence. He's a serial entrepreneur and startup investor since 1994 and launched several pioneering internet companies such as Allmansland, IP Netvertising or Express.be. He is a strong believer and advocate of encryption and privacy.

Recommended for you