Some weeks in privacy are quiet. This was not one of them. Between July 19 and July 26, 2026, three separate storylines advanced at once — regulators got teeth, attackers got faster, and the surveillance buildout got funded. Here’s the full ledger.
The breach ledger
Suno — 55.3 million users. The AI music platform was compromised in November 2025. Users found out on July 20, 2026, when Have I Been Pwned loaded the dataset. Exposed: names, physical addresses, emails, phone numbers, purchase histories, and partial card numbers with expiry dates pulled from the company’s Stripe account. Also stolen: source code revealing Suno’s AI training practices. Entry vector: malware on a developer’s laptop via third-party code, then lateral movement into outdated systems. Suno did not notify anyone, saying individual notice wasn’t legally required. Eight months of silence. → Full analysis
Abbott Laboratories — 30+ million rows. ShinyHunters took names, emails, phone numbers, addresses, dates of birth, and over one million Social Security numbers from Abbott’s Cancer Diagnostics business. A separate actor hit the LabCentral portal (corporate data only). Presence in an oncology diagnostics database is itself a health disclosure, and that inference cannot be retracted.
Estée Lauder — full HR files. An Oracle E-Business Suite vulnerability gave attackers access from August 2025 until detection in June 2026. Ten months. Exposed: SSNs, passport numbers, addresses, dates of birth, financial accounts, health information, and payroll records — almost entirely belonging to employees and former employees.
Ernst & Young. A third-party support ticket system compromised in March–April 2026 exposed personal and financial data “contained in or used to prepare tax filings.” Count undisclosed. → The health and HR data breaches, in depth
Hugging Face. A malicious dataset chained two remote code execution flaws in the platform’s dataset-processing pipeline, yielding cloud and cluster credentials and lateral movement into internal clusters. Public models, user-facing datasets, and Spaces were verified unaltered; container images and packages verified clean. The attacker ran an autonomous agent framework, executing thousands of actions from disposable sandboxes and generating decoy activity to slow investigators. Hugging Face’s own words: machine-speed offensive tooling has moved “from research demo to production incident.” → What that precedent means
RevolutionParts — 5+ million records. Automotive dealer e-commerce platform, disclosed July 22.
Origin Energy (Australia). Names, addresses, dates of birth, phone numbers, account details, last four card digits, last three bank account digits. The company has 4.8 million customers; the affected count wasn’t stated.
Chick-fil-A. Credential stuffing in June 2026 exposed names, emails, membership numbers, QR codes, account credit, last four card digits, and potentially birth dates and addresses. Credential stuffing means reused passwords did the work.
Craneware. UK healthcare billing software firm; employee, customer, and partner data stolen.
South Korea National Diplomatic Academy. Between April 2025 and February 2026, attackers took data on 6,000+ Ministry of Foreign Affairs employees — including 360 diplomats currently posted abroad. IDs, names, emails, hashed passwords.
The enforcement ledger
July 21 — CalPrivacy opens its first formal audit. California’s privacy regulator launched a sectoral compliance audit of gig economy platforms — app-based transportation, delivery, and task services. Under examination: geolocation, behavioral metrics, biometrics, financial data, and communications records, with a specific focus on whether access requests are answered on time, completely, and in a form that lets people meaningfully exercise their rights. CalPrivacy stood up its Audits Division in February 2026 and says more sectors are coming. This is proactive examination rather than complaint-driven investigation — a structural change in how US privacy law gets enforced. → Why gig platforms went first
Nine states’ cure periods have expired. Twenty state comprehensive privacy laws are in effect; in nine of them, a first violation now means enforcement, not a warning letter.
Connecticut’s amended DPA took effect July 1 with no cure period. It widens applicability, requires public disclosure when personal data is used to train LLMs, and classifies neural data, government IDs, and financial credentials as sensitive.
The FTC’s Kochava location settlement is weaker than reported. The final order narrows the list of protected sensitive locations, drops the prohibition on merely using sensitive location data (as opposed to selling it), and removes the requirement that retention timeframes tie to a business purpose. The use-versus-sale gap leaves the inference business intact.
Trump v. Slaughter (6-3) — presidents may now remove FTC commissioners at will. The federal government’s de facto privacy regulator no longer has structural independence, which pushes durable enforcement pressure toward the states. → The end of the grace period
The surveillance ledger
Border towers: 830 → 2,300 by 2034. A GAO report shows DHS plans to nearly triple its Integrated Surveillance Tower footprint, backed by roughly $1 billion from the 2025 spending law. The towers combine radar, thermal infrared, and optical sensors with autonomous AI tracking. GAO also found CBP failed to address six out of six baseline privacy protections for towers, aerostats, and ground sensors.
Police drones: 1,000+ agencies cleared. By February 2026, over a thousand public safety agencies held the FAA waivers needed to run automated drone-as-first-responder programs. After the FAA streamlined approvals in April 2025, it issued more waivers in ten months than in the previous seven years combined. Flock Safety and Axon dominate the market, and Flock has converted drones into flying ALPRs. Deployment data from Chula Vista — the longest-running program — shows most flights go to low-risk calls involving unhoused people, mental health concerns, and loud music, not the emergencies used to justify procurement. → The permanent aerial layer
The law ledger
Chatrie aftermath. Three weeks after the Supreme Court held 6-3 that geofence warrants are Fourth Amendment searches, the practical picture is mixed. The ruling extends Carpenter to precise device location history regardless of duration — closing a real loophole. But the Court declined to decide whether the warrant before it satisfied particularity or probable cause, leaving the hardest questions to lower courts. Google has separately told the Court it can no longer respond to Location History geofence warrants and has objected to more than 3,000 on constitutional grounds. Reverse keyword warrants are the next fight, and the data-broker purchase loophole remains entirely untouched. → What the ruling did and didn’t settle
EU Digital Omnibus stalls. The Cyprus Presidency withdrew its GDPR compromise text on June 30 after it failed to command a qualified majority. Ireland took over July 1 with the file unresolved and simplification measures “weakened, removed or redirected towards future guidance.” Meanwhile the AI Omnibus — delaying AI Act high-risk deadlines — was adopted June 29 and takes effect this month. noyb’s assessment of the GDPR package: the Commission is “about to wreck core principles.” The provisions to watch are the definition of personal data and legitimate interest as a basis for AI training. → Why a Council deadlock in Brussels matters everywhere
What to actually do this week
Ranked by leverage:
- Freeze your credit at all three bureaus. Free, federally mandated, ~15 minutes. Between Abbott’s million-plus SSNs, Estée Lauder’s HR files, and EY’s tax data, this is the single highest-value action available. A freeze prevents fraud; credit monitoring only reports it after the fact.
- Get an IRS Identity Protection PIN. Any US taxpayer can request one. It blocks fraudulent returns — the specific attack tax-prep data enables.
- Enable Global Privacy Control. Built into Firefox and Brave, an extension elsewhere. Legally binding in California, Colorado, Connecticut, and Texas, and it opts you out automatically on every site.
- Check Have I Been Pwned, then change any reused passwords. Chick-fil-A’s breach was credential stuffing; reuse is what made it possible.
- Rotate Hugging Face tokens if you build with AI tooling. Pin model revisions by commit hash. Prefer
safetensorsover pickle. - Turn off location history and audit app permissions. Chatrie protects you from a compelled dragnet, not a purchased one. The broker pipeline runs on apps you gave “Always” location to.
- File an access request. California gig workers especially — with an audit underway, an incomplete response is worth a complaint to CalPrivacy.
- Show up to a city council meeting if your department is buying drones. Procurement is the decision point; deployment is too late.
The pattern
Three trends collided this week, and they aren’t independent.
Enforcement is finally arriving — locally. Cure periods expiring, CalPrivacy’s audits division, Connecticut’s no-grace-period amendment. This is real, and it’s the most substantive improvement in US privacy in years. It’s also entirely at the state level, arriving in the same month the Supreme Court removed the federal regulator’s independence and the EU’s Council failed to hold its own line. Protection is fragmenting by jurisdiction.
Attackers got a capability upgrade. The Hugging Face intrusion was not novel in structure — untrusted input, code execution, credential theft, lateral movement. What was novel was tempo: thousands of automated actions, disposable infrastructure, and deliberate noise generation to exhaust human responders. Defenders are still staffed for adversaries who get tired.
The surveillance buildout is fully funded and fully public. No leaks required. The towers are in a GAO report, the money is in an appropriation, the drone waivers are in an FAA docket, the vendors publish case studies. It proceeds because documentation was never the same as consent, and because the privacy safeguards meant to bridge that gap turned out to be optional — six out of six.
The connective tissue: every one of these stories is about data that already exists. The breaches lost data that was retained longer than any purpose required. The audits are testing whether people can even see what’s held on them. The surveillance systems generate new permanent records. The GDPR fight is over how much of it counts as personal data at all.
Retention is the variable that touches all of it. Abbott’s thirty million rows are thirty million rows because nothing was deleted. Suno’s November breach reached eight months of unnotified users because nothing forced disclosure. The towers will run until 2034 because nothing scheduled their removal.
Data that was never collected cannot be breached, subpoenaed, audited, purchased, or reclassified out of scope. Everything else is mitigation.
Sources:
- Data Breach Roundup (July 17–23, 2026) — Privacy Guides
- California Privacy Protection Agency Launches First Sectoral Audit — privacy.ca.gov
- Privacy Dispatch July 2026 — DataGrail
- An Explosion of Surveillance Towers is Coming to U.S. Borders — EFF
- Hundreds of Drone-as-First-Responder Programs Could Soon Be Launched — EFF
- Hugging Face confirms breach affected internal datasets and credentials — TechCrunch
- AI music generator Suno breach affects 55M users — TechCrunch
- Digital Omnibus Negotiations (GDPR) – July 2026 Update — Privacy Next
- Supreme Court restricts use of geofence warrants — NPR



