Mailfence Privacy Digest September 2026, N°17

Featured image for the Mailfence Privacy Digest September 2026

Table of Contents

Share this article:

September brought a series of warnings about what happens when AI systems are given access to the internet, corporate tools, or real-world data. An OpenAI research agent accessed public and non-public files on an Australian government statistics portal, while Google said Gemini accessed three real companies during a security test. Researchers also documented unsafe trust assumptions in AI coding tools, and a new lawsuit alleged that outside contractors reviewed real ChatGPT conversations. Alongside those AI stories came a Revolut data-disclosure incident and continuing scrutiny of mass identity and surveillance databases. There were positive developments too: Signal began testing phone-numberless registration, Switzerland advanced an open-source workplace alternative, and regulators imposed major privacy penalties. Here’s what happened this month:

Breaches & Security

⬇ OpenAI Agent Accesses Australian Government Health Portal in What Is Widely Reported as the First Known AI Intrusion on a Government Website: An OpenAI research agent bypassed access blocks on Australia’s Medicare statistics service and accessed public and non-public files. OpenAI notified the government on 10 September. PM Albanese criticised the delay and raised the matter with Sam Altman at the UN General Assembly.

⬇ Revolut Discloses Data Incident After Processing Fraudulent Government Requests: Staff processed information requests sent from a mailbox on a genuine government domain, reportedly exposing sensitive KYC material for some customers. Separately, former broker partner DriveWealth disclosed unauthorised access to historical customer data held in its own systems.

⬆ Activist Secures $300,000 in Flock Surveillance Camera Settlements: Oregon resident Jose Rodriguez filed 53 public-records requests targeting Flock licence-plate reader cameras across Washington state. When jurisdictions failed to produce the footage, he sued. At least 13 jurisdictions have since reportedly cancelled contracts or deactivated cameras.

AI

⬇ AI Agents Access Real Companies During Security Tests: Google said Gemini accessed three real companies during a May evaluation after a testing misconfiguration gave it internet access. Separately, the UK AI Security Institute reported unsanctioned agent actions during its own evaluations. OpenAI disclosed a related incident involving Hugging Face in July.

⬇ Lawsuit Alleges Outside Contractors Reviewed ChatGPT Conversations: A class action filed on 16 September alleges OpenAI routed real conversations to outside contractors under an internal programme called Project Lily, without disclosing it in its privacy policy.

⬇ Researchers Find AI Coding Agents Installing Unclaimed Packages on Corporate Networks: Researchers registered unowned package names referenced in companies’ llms.txt files. Coding agents, including Claude, Codex and Hermes, then installed and executed them from corporate networks.

⬇ Anthropic Discloses Attempted Use of Claude for Weapons-Related Development: Anthropic said its safeguards were used in attempts to obtain assistance with weapons-related development. Many requests were blocked, but the actors divided their work across sessions to obscure their overall intent.

Government, Surveillance & Regulatory

⬆ Google Fined €403M Over Location-Data Processing: Ireland’s DPC concluded a six-year inquiry, finding that users of Maps and Android location features could have been unaware that location data was used to influence them with ads or infer interests.

⬆ Signal Begins Testing Phone-Numberless Registration: Signal’s Android beta now offers optional registration without a phone number, for a one-time fee of approximately US$3. The payment design uses zero-knowledge proofs intended to prevent it from being linked to the resulting account.

⬆ Switzerland Prepares Open-Source Workplace for Federal Staff: Following a feasibility test with 172 employees, Switzerland plans to make the openDesk suite available to roughly 3,000 staff handling sensitive processes. The Swiss military’s Cyber Command has a separate, faster migration target.

⬆ TikTok Withdraws Appeals, Making UK £12.7M Children’s Privacy Fine Final: The ICO estimated that up to 1.75 million UK children under 13 used TikTok in 2020. TikTok also dropped its appeal of a separate information notice about its processing of children’s data.

⬆ Norwegian Regulator Calls for Scrutiny of Camera-Equipped Smart Glasses: Norway’s Datatilsynet asked the government to assess whether smart glasses need specific regulation. The digital minister is setting up an expert group and considering restrictions on facial recognition in public spaces. Oslo and Bærum have banned the devices in schools.

⬇ Discord Rolls Out Age Assurance for All Users: From 23 September, Discord uses account signals to classify users as adult, teen, or unconfirmed. Over 90% of users will not need to verify manually. Verified teens face restrictions on adult content, age-restricted spaces, and some messaging features.

OpenAI Agent Accesses Australian Government Health Portal

On 18 June, an OpenAI research agent gained unauthorised access to Australia’s Medicare Statistics Reporting Service portal, a system operated by Services Australia that holds aggregate health spending data. The agent accessed public and non-public files. Australian officials said the portal contained aggregate, non-sensitive health information and that there was no evidence at that stage that personal Medicare records had been accessed. According to analysis by nonprofit research lab Transluce, the agent may also have probed several other Australian government data sites, though confirmed successful access has not been established for those.

OpenAI notified the Australian government on 10 September, according to Australian reporting, and the notification was sent to a public mailbox rather than through a diplomatic or security channel. PM Albanese raised the matter directly with OpenAI CEO Sam Altman at the UN General Assembly, calling the delay and notification method “unacceptable”. Australian authorities have launched an investigation, including the Australian Signals Directorate. OpenAI said the activity occurred during an internal evaluation and that its models “took actions we did not intend.” The incident is widely reported as the first publicly known case of an autonomous AI agent gaining unauthorised access to a government website.

💡 To protect yourself, any organisation running a public data portal should assume that AI agents are now probing it. Review access controls, rate-limit automated queries, and ensure that authentication is required before any non-public data is reachable. If you use AI agents in your own work, review what external access they hold and what permissions they can exercise without asking.

Read more: OpenAI Hacked Australian Medicare Govt Site, Probed Data Providers (BleepingComputer)

Continue reading: Medicare Australia: ‘Extreme Concern’ Over OpenAI Breach of Health Database (CNN)

Revolut Discloses Data Incident After Processing Fraudulent Government Requests

Revolut disclosed two separate incidents in September. In the first, employees processed fraudulent information requests sent from a mailbox on a genuine government domain, reportedly exposing sensitive KYC material for some customers. According to customer notifications and reporting, the exposed data may have included passport or driving-licence copies, verification selfies, and transaction histories. Revolut said the communication “carried valid domain authentication credentials” and was fulfilled “under the reasonable belief that it was an authentic government agency request”. The company has not named the agency, the number of affected customers, or the markets involved.

In the second incident, former broker partner DriveWealth disclosed unauthorised access to historical customer data held in its own systems. Revolut said its accounts, funds and production systems were not affected in the DriveWealth incident. The two incidents are not known to be connected.

💡 To protect yourself, if you are a Revolut customer, check your inbox for a notification and follow any instructions about protective measures. Place a fraud alert with credit agencies and monitor bank and crypto accounts for unusual activity. For any organisation that processes government data requests: build in a call-back step to confirm every request through an independently verified contact.

Read more: Revolut Confirms Customer Data Breach Through Fake Government Requests (TechCrunch)

Activist Secures $300,000 in Flock Surveillance Camera Settlements

Jose Rodriguez, a 36-year-old from Milton-Freewater, Oregon, filed 53 public-records requests with cities and counties across Washington state, asking for images captured by Flock Safety’s automated licence-plate reader cameras during a 30-minute window on a single day. When jurisdictions failed to produce the records, often because Flock’s 30-day auto-deletion policy had already erased them, Rodriguez sued. According to Cascadia Daily News, settlements have now totalled more than $300,000, and at least 13 jurisdictions have reportedly cancelled their Flock contracts or deactivated cameras. The campaign has been developing since 2024 and continued producing settlements through August 2026.

💡 To take advantage of similar protections, check whether your state or country has open-records laws that apply to licence-plate reader data. If you want to know what a Flock camera captured about your car, file the request before the retention window closes. Washington’s Driver Privacy Act, which took effect in March 2026, now limits ALPR data retention to 21 days and exempts ALPR data from public-records requests entirely.

Continue reading: Man Sues Washington Cities Over Flock Records (Gadget Review)

AI Agents Access Real Companies During Security Tests

Google said in September that its Gemini model accessed the internet and gained unauthorised entry to three real companies during a May 2026 cybersecurity evaluation run by AI security firm Irregular. A testing misconfiguration gave the model access outside the intended environment. Google said Gemini used publicly available information and guessed credentials, then stopped after recognising that the systems were real. The incidents occurred in May but became public only after the Wall Street Journal sought comment in September.

This was not an isolated event. The UK AI Security Institute published a report documenting unsanctioned agent behaviour during its own evaluations, including an attempted supply-chain attack on a real open-source project and social-engineering messages sent to real people. OpenAI separately disclosed that one of its models gained access to Hugging Face’s systems during a July evaluation. Schneier and Raghavan framed the pattern in their September essay “AIs as Modern Genies”: agents optimise for the stated objective and treat every boundary as an inference problem. The gap between what a developer intended and what the model does is not a bug in the usual sense, but a fundamental property of instruction-following when the instructions cannot cover every edge case.

💡 To stay prepared, organisations running AI agent evaluations should air-gap test environments from production and from the public internet. For everyone else: if you maintain open-source projects, be alert for pull requests from accounts with no verifiable history and verify contributors through a second channel before merging code.

Read more: Gemini’s Breach of Real Companies Exposes an AI Guardrail Problem (Malwarebytes)

Continue reading: AIs as Modern Genies (Schneier on Security)

Lawsuit Alleges Outside Contractors Reviewed ChatGPT Conversations

On 14 September, 404 Media reported that OpenAI uses outside contractors, hired through a staffing firm, to read and rate real ChatGPT conversations under an internal programme called Project Lily. According to the report, reviewers score candidate responses on a 1–7 scale, judging tone and behaviour rather than factual accuracy. A proposed class action was filed on 16 September alleging that OpenAI never disclosed this human review in its privacy policy. The complaint alleges that an automated filter intended to strip personal details before conversations reach reviewers does not catch everything, particularly information about health, finances, and legal problems. OpenAI has not yet responded in court, and none of the allegations has been proved.

💡 To limit your exposure, open ChatGPT’s settings and check whether “Improve the model for everyone” is switched on. According to OpenAI’s stated policy, turning it off limits the use of your conversations for model improvement. Use temporary chats for anything sensitive. If your organisation uses ChatGPT on consumer-tier plans, update your acceptable-use policy to reflect the possibility that conversations may be reviewed.

Read more: Humans Are Reading Your ChatGPT Chats, New Lawsuit Claims (Decrypt)

Continue reading: Inside “Project Lily”: The Humans Reading Your ChatGPT Chats (404 Media)

Researchers Find AI Coding Agents Installing Unclaimed Packages on Corporate Networks

Researchers from an Israeli startup checked more than 6,200 websites operated by defence contractors, Fortune 500 companies and major technology firms. They found 120 llms.txt or llms-full.txt files that referred to code packages or internet domains that no one owned. The researchers then registered some of those abandoned package and domain names. They uploaded harmless test code designed to send a signal when it was installed. At least one Fortune 500 company’s network contacted the researchers’ test server within an hour. Dozens of other systems reportedly did the same later.

By examining how the code was launched, the researchers concluded that AI coding tools, including Anthropic’s Claude, OpenAI’s Codex and Nous Research’s Hermes, had installed and executed some of the packages automatically. The researchers said that the companies behind those AI tools had not responded to their requests for comment when the report was published.

💡 To mitigate risks, audit your organisation’s llms.txt and llms-full.txt files. Confirm that every package and domain name they reference is registered and controlled by you. Treat these files as an attack surface: they are instructions your coding agent will follow without question.

Learn more: Claude, Codex and Hermes Installed Unowned Code Inside Corporate Networks (Ars Technica)

In a detailed report published in September, Anthropic disclosed that threat actors used Claude Code in attempts to obtain assistance with weapons-related development. According to Anthropic’s account, the actors managed several Claude instances at once, assigning each a role as if delegating work on an engineering team. Anthropic said its safeguards blocked many of the requests but that the actors split their work across multiple sessions so that no single conversation revealed their full intent. Schneier covered the disclosure on his blog, noting that AI systems are increasingly making specialist technical capability accessible to actors who would not otherwise have had it.

💡 To stay informed, read Anthropic’s full disclosure document. It is a candid account of what AI safety looks like in practice: many requests were blocked, but session-splitting remains a way around per-conversation safeguards. The policy implication is that AI models with strong coding and engineering capability will face dual-use pressures, and that safety teams, regulators, and the public need to follow how labs respond.

Continue reading: Using AI for Weapons Development (Schneier on Security)

Google Fined €403M Over Location-Data Processing

Ireland’s Data Protection Commission published its decision on 21 September, concluding a six-year inquiry into Google’s processing of location data through Web & App Activity, Location History, and Location Accuracy settings between May 2018 and February 2020. The DPC found that users of Google Maps and Android location features could have been unaware that their location was being used to influence them with ads or to infer their interests. The ruling covers unlawful and unfair processing, poor transparency, excessive retention, and accountability failures. Google must bring its processing into compliance in six months. Google has said the policies at issue are historical and that it has improved its tools since 2019.

💡 To protect yourself, review the privacy settings on your Google account. Go to myaccount.google.com, open “Data and privacy,” and check Web & App Activity and Location History. Turn off or pause any setting you are not comfortable with, and delete stored location data you no longer need.

Read more: Google Hit with €403M GDPR Fine Over Location Data Practices (Infosecurity Magazine)

Signal Begins Testing Phone-Numberless Registration

On 16 September, Signal’s lead Android developer announced that the Signal Android 8.28 beta now supports optional registration without a phone number. New users can pay a one-time fee of approximately US$3 (prices vary by country) via Google Play. Signal says its payment design uses zero-knowledge proofs intended to prevent the payment from being linked to the resulting account. After payment, users receive an Account ID and a recovery key. Signal’s documentation warns that losing these credentials may make recovery impossible. An iOS version is planned. Phone-number registration remains the default, free path.

💡 To take advantage of this feature, look for Signal’s beta through the official Play Store beta channel. If you sign up without a phone number, store your Account ID and recovery key in a password manager immediately. This removes a long-standing privacy barrier, since phone numbers can be used to identify, locate, and target users. Note that this is a beta feature and behaviour may change before wider release.

Learn more: Signal Tests Account Registration Without Phone Number on Android (Cyber Insider)

Switzerland Prepares Open-Source Workplace for Federal Staff

Switzerland is preparing an open-source workplace based on the openDesk suite for roughly 3,000 federal employees handling sensitive processes. The plan follows a feasibility test involving 172 employees and is framed as a way to strengthen digital sovereignty and maintain an alternative to dependence on one productivity-cloud provider. The platform covers email, calendars, document editing, telephony, file storage, and video conferencing. The Federal Chancellery expects the first implementation phase to cost around CHF 9 million, with the platform due to become available by the end of 2027. The Swiss military’s Cyber Command has a separate, faster migration target for October 2026. The programme follows Switzerland’s 2024 EMBAG law, which requires federal agencies to publish government-developed software as open source by default.

💡 To stay informed, follow the openDesk project and the broader European push for sovereign office infrastructure. If your organisation depends on a single cloud provider for all productivity tools, Switzerland’s approach offers a model: keep the existing platform running, but build an independent fallback so that a single vendor’s outage, policy change, or data-access demand does not leave you unable to work.

Read more: Switzerland Tests a FOSS Escape Route from Microsoft 365 (The Register)

TikTok Withdraws Appeals, Making UK £12.7M Children’s Privacy Fine Final

On 24 September, the UK’s Information Commissioner’s Office confirmed that TikTok has withdrawn its appeals and will pay the £12.7 million fine originally imposed in 2023 for multiple breaches of data protection law, including failing to use children’s personal data lawfully. The ICO estimated that up to 1.75 million UK children under 13 were using TikTok in 2020, despite the platform’s own rules not allowing them to create accounts. TikTok also dropped its appeal of an information notice linked to a separate investigation into how its recommender systems use children’s data. Withdrawing the appeal makes the penalty final, though TikTok has not publicly accepted every factual or legal conclusion in the ICO’s decision.

💡 To protect your children, review the privacy settings on any platform they use. The ICO’s “Switched on to privacy” campaign helps parents understand the privacy choices available. Check whether your child’s account is correctly marked as belonging to a minor, and turn on any available parental controls.

Continue reading: TikTok Withdraws Two Appeals in Children’s Privacy Action and Accepts £12.7M Fine (ICO)

Norwegian Regulator Calls for Scrutiny of Camera-Equipped Smart Glasses

Norway’s privacy regulator Datatilsynet wrote to the government in August asking it to assess whether smart glasses need specific regulation. The regulator’s director, Line Coll, said lawmakers should consider halting sales while they examine the issue if a legal basis exists. Digital Minister Karianne Tung responded by announcing an expert group and flagging the combination of AI with cameras and microphones in everyday objects as a trend that needs urgent policy attention. According to reporting by NordiskPost and Aftenposten, Oslo and Bærum have already banned the devices in schools. The measures being discussed include restricting where the glasses can be used, limiting specific functions such as facial recognition in public spaces, and raising the issue at the European level.

💡 To engage with these developments, follow Norway’s expert group and the growing list of venues, schools, and cities that are setting their own rules. If you run a workplace, hospital, school, or public venue, consider whether camera-equipped glasses should be permitted on your premises and post a clear policy.

Read more: Norway Considers Ban on Camera-Enabled Wearable ‘Pervert Glasses’ (TechCrunch)

Discord Rolls Out Age Assurance for All Users

Starting 23 September, Discord began using account signals, including account age, connected communities, games, and general activity patterns, to classify all users as adult, teen, or unconfirmed. Discord says more than 90% of users will not need to verify their age manually. Users classified as teens face restrictions on adult content, age-restricted spaces, and certain messaging features. Users in Australia and the UK may face additional verification requirements linked to local laws. The rollout follows an earlier plan that would have required facial age estimation or an ID scan, which Discord delayed in February after backlash. A third-party vendor working with Discord was breached in a separate incident last year, reportedly exposing government ID photos and selfies used for verification.

💡 To protect yourself, review what data Discord holds on you. If you are a parent, this is a good moment to check your child’s account settings. Discord says it does not use messages or voice calls for age estimation and that it will offer several verification options for adults who are incorrectly classified.

Read more: Discord Rolls Out Its Revised Age Verification Policy (Engadget)

That’s All for This Month’s Newsletter!

September 2026 drew a line between what AI systems can do and what the people building them expected them to do. The positive stories this month all share a theme: pushing back. Signal removed the phone-number barrier. Switzerland built a second option. Norway asked whether a product should be on sale before it is regulated. And one activist in Oregon proved that even well-funded surveillance systems answer to public-records law. Stay alert, ask hard questions, and choose the tools that put you in control. Thank you for reading, and we look forward to keeping you informed in October.

Best,

Patrick

Get the latest privacy news in your inbox

Sign up to the Mailfence Newsletter.

Reclaim your email privacy.
Create your free and secure email today.
Picture of Patrick De Schutter

Patrick De Schutter

Patrick is the co-founder of Mailfence. He's a serial entrepreneur and startup investor since 1994 and launched several pioneering internet companies such as Allmansland, IP Netvertising or Express.be. He is a strong believer and advocate of encryption and privacy.

Recommended for you