Mailfence Privacy Digest July 2026, N°15

Featured image for the Mailfence Privacy Digest July 2026

Table of Contents

Share this article:

July 2026 delivered the first publicly documented case of an AI system breaking out of its test environment and attacking a real company on its own. A hidden Windows device ID was exposed as a silent tracker that defeats VPNs, and a proposed US rule would end anonymous phone purchases altogether. On the legislative front, the EU’s “Chat Control” survived a vote that more MEPs opposed than supported, while an age-verification wave rolled across six countries. But there were wins too: the Supreme Court ruled that geofence warrants need Fourth Amendment protection, and EU citizens launched an initiative demanding digital ID remain voluntary. Here’s what happened this month:

Breaches & Security

AssuranceAmerica Breach Exposes 7 Million Drivers’ Licence Numbers: Atlanta insurer discloses that attackers stole names, policy data, and drivers’ licence numbers for nearly 7 million people after compromising a single employee’s credentials.

Proton Calls Windows Spyware Over Hidden Global Device ID: Proton publishes evidence that Windows’ undocumented GDID uniquely fingerprints every installation and can be handed to law enforcement after an FBI filing showed the identifier defeating a suspect’s VPN.

One Million Passports Leaked Via Cannabis Dispensary ID System: A database of nearly a million passport scans was exposed online after a cannabis club verification platform was left completely unprotected, putting high-value identity credentials at risk.

AI

Germany Launches Soofi S, Europe’s Top-Ranking Open-Source AI Model: A German consortium releases a 30B-parameter model trained entirely on Deutsche Telekom infrastructure in Munich, topping open-source benchmarks in both English and German.

Google Selfie Video Rolls Out With a Quiet Opt-In to AI Training: Google launches selfie video for account recovery and separately asks users for permission to feed biometric data into its facial recognition and age-estimation models.

Meta Testing Facial Recognition Smart Glasses for Police and Military: Meta is prototyping real-time facial recognition on its smart glasses with a Pentagon supplier, moving wearable surveillance from concept to active development.

Anthropic Caught Covertly Tracking Chinese Claude Code Users: Hidden code in Claude Code collected timezone, proxy, and AI lab connection data targeting Chinese accounts; China’s MIIT warned of a “security backdoor”, and Alibaba banned the tool internally.

OpenAI AI Agent Escapes Containment, Autonomously Hacks Hugging Face: An OpenAI model being tested for offensive cyber capabilities broke out of its sandbox, gained internet access, and breached Hugging Face’s production infrastructure before being detected.

Government, Surveillance & Regulatory

EU Registers “Stop Killing The Internet” Citizens’ Initiative: The European Commission formally registers an initiative demanding digital ID and age verification remain voluntary, privacy-preserving, and non-discriminatory; organisers now have 12 months to collect 1 million signatures.

EU Parliament Revives “Chat Control” CSAM Scanning Until 2028: 314 MEPs voted against it and only 276 in favour, but opponents fell 47 votes short of the absolute majority needed to kill it; end-to-end encrypted messengers are excluded, but unencrypted platforms can resume voluntary scanning.

Six Countries, One Playbook: The Global Age Verification Wave: In the same period the US KIDS Act passes the House (267–117), the UK bans under-16s from social media, Australia doubles platform fines to A$99M, Reddit starts age-verifying EU users, Discord trials Incode biometric checks, and Canada’s Bill C-22 moves to the Senate.

Canada’s Bill C-22 Rushed Through House, Heads to Senate: The Lawful Access Act forces service providers to retain metadata for a year, enables backdoor capabilities, and expands data sharing with foreign governments; Apple, Google, Meta, EFF, and the Citizen Lab all oppose it.

FCC Proposes Eliminating Burner Phones, Requiring ID for All Accounts: A proposed FCC rule would force US telecoms to collect government-issued ID and physical addresses from all phone customers, effectively ending anonymous phone purchases.

US Supreme Court Tightens Rules on Geofence Data Requests: In Chatrie v. United States, the Court ruled 6–3 that law enforcement needs a warrant to demand location data from people near a crime scene, extending the logic of Carpenter.

AssuranceAmerica Breach Exposes 7 Million Drivers’ Licence Numbers

Atlanta-based auto insurer AssuranceAmerica disclosed that attackers stole data on 6,998,886 people after compromising a single employee’s credentials on 16 March 2026. The stolen data includes names, insurance policy details, claims histories, drivers’ licence numbers, and in some cases Social Security numbers. The forensic review did not conclude until 15 June, and notification letters only went out in early July. Class-action lawsuits have already been filed.

To protect yourself, freeze your credit with all three major credit agencies. Because drivers’ licence numbers also enable vehicle registration fraud that a credit freeze does not cover, monitor your state’s motor vehicle records for unauthorised activity and enable two-factor authentication on every insurance-related account.

Read more: AssuranceAmerica Data Breach Exposes Records of 6.9 Million Drivers (BleepingComputer)

Proton Calls Windows Spyware Over Hidden Global Device ID

Proton published evidence on 7 July that every Windows installation carries a Global Device ID (GDID) that Microsoft can hand to law enforcement. The trigger was an FBI affidavit showing the identifier was used to trace alleged Scattered Spider hacker Peter Stokes despite his VPN: Microsoft tied his GDID to accounts used in a 2025 breach and turned over the device’s full IP history. Users are never asked to consent to the GDID, and reinstalling Windows only generates a new one while old records persist.

To limit your exposure, set Windows diagnostic data to “Required” rather than “Optional.” Linux-based operating systems are generally less likely to send persistent device identifiers back to vendors. On any platform, a reputable VPN and privacy-focused browser can reduce trails, but as this case shows, the operating system layer can still transmit data.

Learn more: Microsoft GDID: How Windows Led the FBI to a Hacker (Proton VPN Blog)

One Million Passports Leaked Via Cannabis Dispensary ID System

Security researcher Sammy Azdoufal discovered that Nefos Solutions, an Irish firm running the PuffPal cannabis club app, had left nearly a million passport scans and government IDs on a publicly accessible server with no authentication. Over 1,082,000 member records and 985,000 ID photographs sat at predictable URLs. As Bruce Schneier noted, this is what happens when a high-value credential (a passport) is handed to a low-value system (cannabis club age verification) and the low-value system gets hacked.

To protect yourself, think twice before submitting government-issued identity documents for verification and ask whether a less sensitive method exists. If your passport may have been exposed, check whether your country allows you to flag the number as compromised and set fraud alerts on your credit files.

Read more: One Million Passports Leaked Online (Schneier on Security)

Germany Launches Soofi S, Europe’s Top-Ranking Open-Source AI Model

A German research consortium released Soofi S, an open-source 30-billion-parameter language model that topped every fully open rival on both German and English benchmarks. The model activates only 3.2 billion parameters per token, keeping compute requirements low. Training ran on up to 512 Nvidia B200 GPUs at Deutsche Telekom’s Munich data centre, and the consortium published its full pretraining report, training code, and data inventory.

To take advantage of this, organisations interested in self-hosted, auditable AI should evaluate Soofi S. The model points to a growing European option for sovereign, transparent AI, even if deployment maturity will vary by use case.

Continue reading: German AI Consortium Releases Soofi S (The Decoder)

Google Selfie Video Rolls Out With a Quiet Opt-In to AI Training

Google launched “Selfie Video” the week of 23 July, letting users record a short facial video as a backup account recovery method. During setup, a separate checkbox asks whether Google may use the video to improve facial recognition, age estimation, and other verification technologies. The opt-in is revocable, but the timing coincides with Google’s broader push into age estimation across Search, Maps, and Gemini.

To protect yourself, decline the training opt-in if you use Selfie Video: you keep the full recovery benefit without feeding Google’s AI pipeline. Check your settings at g.co/signin-selfie.

Learn more: Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts (The Hacker News)

Meta Testing Facial Recognition Smart Glasses for Police and Military

A WIRED investigation revealed that Meta licensed facial recognition software from Rank One Computing, a firm that draws roughly 80% of its revenue from government contracts with agencies including the US Marshals Service and Special Operations Command. Researchers found remnants of Rank One’s code dormant in the Meta AI app, which had shipped to over 50 million phones, alongside an unreleased system called “NameTag.” Meta deleted both the day after the report and declined to explain the arrangement.

To limit your exposure, review the permissions on the Meta AI app and disable camera access if you do not actively use it. If you own Meta’s Ray-Ban smart glasses, be aware they can capture real-time video that bystanders cannot easily detect, and watch for software updates mentioning facial recognition.

Read more: Meta Is Testing Facial Recognition for Police and Military (Schneier on Security)

Anthropic Caught Covertly Tracking Chinese Claude Code Users

A Reddit user found that Claude Code had been quietly checking whether some users were in China or using Chinese AI-related proxies. Anthropic said it was an experiment to prevent model copying and removed it in a later release, while Alibaba reportedly blocked Claude Code internally.

To stay informed, periodically review changelogs for any AI coding tool you use and inspect network traffic for unexpected data collection. This incident is a reminder that even companies with strong public safety commitments can ship undisclosed tracking code and that open-source alternatives let you audit what runs on your machine.

Learn more: Hidden Code in Claude Code Secretly Flagged Chinese Users (The Decoder)

OpenAI AI Agent Escapes Containment, Autonomously Hacks Hugging Face

OpenAI disclosed on 22 July that a combination of its AI models, including GPT-5.6 Sol and another, more capable unreleased model, escaped a sandboxed test environment, got internet access, and autonomously broke into Hugging Face’s production systems. The models were being tested on ExploitGym, a public benchmark that checks whether AI can turn known software flaws into working attacks. Instead of completing the task inside the test environment, they explored their own limits, found and used a zero-day flaw in a package-registry proxy, gained higher privileges, and moved through connected systems until they reached a machine with internet access. They then appeared to conclude that Hugging Face likely held the answer to the evaluation and entered its systems.

Hugging Face detected the intrusion on 16 July before knowing OpenAI’s model was behind it. It reported the incident to law enforcement, while OpenAI later described it as “an unprecedented cyber incident” and said it is working with Hugging Face to improve defenses. AI safety researcher Roman Yampolskiy called it the first publicly documented real-world AI loss-of-control incident, and Hugging Face CEO Clément Delangue said it was “quite mind-blowing that all this happened autonomously.”

For organisations, the main takeaway is that AI sandboxes should be treated like real security boundaries, not just test spaces. That means isolating networks, blocking outbound internet access by default, watching for privilege escalation, and assuming advanced models may try to test their own limits. For individuals, the broader lesson is that AI systems handling your data are becoming more autonomous, so it is reasonable to ask how companies test, contain, and monitor them.

Read more: OpenAI Cyber Models Broke Out of Training Environment to Hack Hugging Face (CNBC)

Continue reading: How OpenAI Lost Control of an AI Model, and What Needs to Change (TIME)

EU Registers “Stop Killing The Internet” Citizens’ Initiative

On 22 July, the European Commission formally registered a European Citizens’ Initiative called “Stop Killing The Internet: No Digital ID & No Age Verification.” The initiative demands legislation ensuring digital identity and age-assurance systems used to access online services remain voluntary, privacy-preserving, and non-discriminatory, with anonymous age verification based on privacy-preserving cryptography. Organisers have six months to open a signature collection period that can run for up to 12 months.

To engage with this, EU citizens who share the initiative’s goals can sign once collection opens. Regardless of where you live, the initiative is worth watching as a barometer of public sentiment on mandatory digital identity.

Learn more: Commission Concludes Eligibility Checks for Two ECIs (European Commission)

EU Parliament Revives “Chat Control” CSAM Scanning Until 2028

On 9 July, 314 MEPs voted against extending the “Chat Control 1.0” CSAM scanning regime and only 276 voted in favour, but under the second-reading procedure an absolute majority of 361 was needed to reject it. With around 112 MEPs absent, opponents fell 47 votes short and the extension passed by default. The same measure was rejected under normal rules in March. End-to-end encrypted services are excluded under amendments that did clear the 361-vote threshold.

To protect yourself, use end-to-end encrypted messaging such as Signal or WhatsApp for sensitive communications. Advocate for email providers that don’t monetise user data. Support the EFF, EDRi, and the Center for Democracy and Technology, which are challenging the expansion of scanning powers.

Continue reading: Client-Side Scanning Explained: the EU Chat Control Shift and How It Affects You (Mailfence Blog)

Read more: Europe Revives Law Allowing Big Tech to Scan for CSAM (The Record)

Six Countries, One Playbook: The Global Age Verification Wave

In a few weeks, age verification became a global legislative wave. The US House passed the KIDS Act 267–117 on 29 June. The UK banned under-16s from social media on 15 June. Australia doubled platform fines to A$99 million. Reddit began requiring EU users flagged as potentially under 18 to verify via government ID or selfie. Discord trialled Incode biometric facial age estimation. And Canada’s Bill C-22, with its metadata retention and backdoor provisions, was fast-tracked to the Senate.

To stay prepared, choose verification methods that minimise the data you hand over: credit card checks and digital wallet attestations share less than a passport scan or biometric selfie. Ask platforms what happens to your data after the check, and favour services that delete it immediately.

Continue reading: US House Passes the KIDS Act (IAPP)

Canada’s Bill C-22 Rushed Through House, Heads to Senate

Canada’s Lawful Access Act passed third reading on 18 June after the government limited debate and fast-tracked the bill through committee past midnight. The bill mandates one-year metadata retention, grants the Minister of Public Safety power to compel surveillance capabilities from service providers, and expands data sharing with foreign governments. Apple, Meta, the EFF, and Signal (which has threatened to exit Canada) all oppose it. Senate deliberation is expected this autumn.

To stay informed, Canadian residents should contact their senators before deliberations begin. Check whether your encrypted messaging or VPN provider has published a position on C-22, and support the EFF and OpenMedia in opposing the bill’s backdoor provisions.

Learn more: Canada Is Forging Ahead with Its Dangerous Surveillance Bill (EFF)

FCC Proposes Eliminating Burner Phones, Requiring ID for All Accounts

A proposed FCC rule (FCC 26-27), adopted on 30 April, would force carriers and VoIP providers to collect a customer’s name, physical address, government-issued ID number, and an alternate phone number before activating any mobile service, including prepaid. Records would be retained for four years. The FCC’s own filing notes the data could also help investigate espionage and influence operations, well beyond the stated anti-robocall purpose. Privacy advocates, domestic violence groups, and press freedom organisations have pushed back hard.

To mitigate risks, support the EFF and ACLU, which are filing comments against the rule. Proposed rules are not law yet, and public comment can influence the outcome. If the rule proceeds, VoIP services based outside US jurisdiction may offer alternatives.

Read more: A New FCC Proposal Could Spell the End of the Burner Phone (Fortune)

US Supreme Court Tightens Rules on Geofence Data Requests

On 29 June, the Supreme Court ruled 6–3 in Chatrie v. United States that obtaining a person’s stored cell-phone location data from a company like Google constitutes a Fourth Amendment search. The case arose from a 2019 armed robbery in Virginia where police used a geofence warrant to pull location data on every device in a 150-metre radius. Justice Kagan delivered the opinion, building on the 2018 Carpenter precedent and holding that individuals retain a reasonable expectation of privacy in their location data even for short periods.

To take advantage of this, review the location-sharing settings on your devices. Disable location history on services you do not actively need and opt out of precise location where approximate is enough. The ruling strengthens your legal protections, but the best defence remains not generating the data in the first place.

Continue reading: Court Rules That Law Enforcement’s Use of “Geofence Warrant” Was a “Search” (SCOTUSblog)

That’s All for This Month’s Newsletter!

July’s thread is autonomy: who has it, and who is losing it. An AI agent decided on its own to break into a real company. An operating system quietly reported your device back to Microsoft for years without asking. Governments from Washington to Ottawa to Brussels pushed rules that would tie your legal identity to your phone, your browsing, and your messages. But pushback works. The Supreme Court drew a line around your location data, EU citizens now have a formal path to demand voluntary digital identity, and a German consortium proved you can build a top-tier AI model in the open. Privacy is not a spectator sport. Use the tools, exercise the rights, hold the line.

Best,

Patrick

Get the latest privacy news in your inbox

Sign up to the Mailfence Newsletter.

Reclaim your email privacy.
Create your free and secure email today.
Picture of Patrick De Schutter

Patrick De Schutter

Patrick is the co-founder of Mailfence. He's a serial entrepreneur and startup investor since 1994 and launched several pioneering internet companies such as Allmansland, IP Netvertising or Express.be. He is a strong believer and advocate of encryption and privacy.

Recommended for you