Danish Population Register Breached, Leaking Data of Nearly Nine Million People

Hackers are suspected of having cracked the Danish government’s national database containing the personal information of nearly nine million people, potentially exposing them to fraud or identity theft.

Copenhagen’s Ministry of Research, Education and Digitalisation said on Monday that the Central Register of Persons (CPR), the national civil registration database containing personal information for millions of citizens, has been compromised.

In Denmark, all legal residents have a unique 10-digit civil registration number, used to access public services, healthcare, banking, and taxes, and to store information on each citizen, including name, date of birth, address, marital status, citizenship, religious affiliation, and parentage.

The government said on Monday that unidentified people used a Danish business’s access to the system to wrongfully obtain the CPR numbers, names, and addresses of around 8.8 million people, the public Danish Broadcasting Corporation (DR) reported.

In a briefing on Monday, government minister Christina Egelund said that it was too early to tell whether it was a cyber attack or whether foreign state actors were involved in the leak.

“We are not ruling out any clues in the ongoing investigation. Nor that it may have an international character,” she said.

Egelund added that the government will review the entire CPR system and implement “adjustments and transformations” to re-establish security.

Keep reading

New Mexico Found a Way to Fine Platforms for Speech It Didn’t Delete

A civil jury has found Meta liable for violating New Mexico’s Unfair Practices Act, and now the judge is being asked to order the company to pay between $35 billion and $40 billion.

At a hearing on October 1 in Santa Fe, special prosecutor Randi McGinn asked Judge Francis Mathew of the First Judicial District Court to order Meta to pay this amount, while a lawyer for the social media giant said such a penalty would be “an astronomical” one, violating “a host of constitutional provisions.”

Meta is being punished for making false statements about user privacy, and also for not removing “hate speech” and “misinformation” fast enough.

The verdict was delivered on September 25, finding Meta had made 26 false or misleading statements, resulting in nearly 43.9 million violations of the state’s Unfair Practices Act.

This would translate to a maximum of $5,000 per violation, or $219 billion in all – more than the $206 billion the tobacco industry had to pay in a settlement in 1998. The state asked for about 20% of this amount.

The number of violations was arrived at by counting the number of people in New Mexico, and the number of Facebook users in the state, and then multiplying these numbers by the number of times Meta made false statements in news outlets and on its own platforms.

The state had to show only that harm was likely, not that it actually occurred.

Meta is being punished for lying about how it handled user data, and the Cambridge Analytica scandal that saw a third party harvest data from about 87 million profiles. The company is also being punished for not removing “hate speech” and “misinformation” fast enough – and the number of violations in this category is about a quarter of the total.

The New Mexico case is not the only one where Meta is being forced to pay up – in March, a Santa Fe jury ordered it to pay $375 million in a case involving child safety on Facebook and Instagram, and in August, the judge in that case added another $567 million for a youth mental health fund.

In August, 47 states reached a settlement with Meta, along with other social media companies, that will see them pay $17 billion. Judge Mathew mentioned this during the October 1 hearing, saying that due process suggests he should opt for a much lower amount than what the state of New Mexico is asking for.

During the hearing, Meta’s lawyer Matt Nicholson described the case as “about 26 statements over 11 years” and said that the state “made absolutely no showing that anyone in the state of New Mexico ever saw them, relied on them or were harmed by them in any way.”

McGinn countered that “the one thing you didn’t hear from counsel is an apology.”

Keep reading

Privacy concerns put smart glasses under scrutiny as Norway seeks temporary ban

A trip to the park. A day at the beach. A workout session at the gym. All in public spaces where smart glasses can snap photos, record conversations or stream video online — without people in the line of their lenses and microphones knowing about it.

Norway’s government wants to get a handle on both the promise and peril of AI glasses and is proposing that parliament enact a temporary ban on them in some places.

It’s the latest sign of growing concern in many countries about new technologies that are fundamentally changing the way people live. Some governments have banned the use of social media by children and young teens.

Norway’s government said the proposal for the temporary ban will be made to parliament, the Storting, “as soon as possible.”

AI glasses fan concerns — from showers to seashores and beyond

A key question is where to draw the line.

Norwegian authorities say a ban on the use of smart glasses could apply to places where “privacy is particularly important,” like healthcare facilities, or fitness centers with changing rooms and showers. A major focus is spaces where children congregate, such as schools, kindergartens, playgrounds and youth clubs.

But it could extend to public concerts and sports events, plus parks, beaches, museums and shopping centers.

A temporary ban would give authorities time to decide what types of devices might be affected, and debate whether permanent regulation is needed. The government was quick to note that it was not proposing a total ban and said such devices should still be allowed in some places and for private use.

The government also said it was considering exceptions to a ban for vulnerable groups, so that “socially beneficial uses” of smart glasses could be permitted in some circumstances.

Privacy advocates hail Norway’s move

Adam Smith, a technology advocacy officer at Britain-based Privacy International, said Norway’s move was “a welcome protection against big tech’s greedy attempts to extract ever more data, often in absence of any thought for the privacy or rights of others.”

“No reality exists in which people expect to be secretly surveilled going about their daily lives,” he said.

One effort to rein in the use of AI glasses has run aground — in the home of Silicon Valley.

California’s governor last week vetoed legislation that would have penalized the use of smart glasses to record people without their permission in places like changing rooms, doctor’s offices and other spaces people generally consider private.

Keep reading

DOJ Issues Requests For Documents to ERIC and Zuckerbuck-Funded CEIR Over Sharing of Private Voter Data

Last month, The Gateway Pundit reported that Department of Homeland Security Secretary Markwayne Mullin had sent a letter to Attorney General Todd Blanche urging him to renew calls for investigations into barcode/QR code voting systems and the Election Registration Information Center (ERIC) and its handling of sensitive motor-vehicle data.

DHS officials had previously met with the DOJ under then-Attorney General Pam Bondi in September 2025 regarding these concerns.  DHS’s previous concerns did not seem to produce any sort of resolution, legal determination, or any meaningful action.

Now, under recently confirmed Attorney General Todd Blanche, the Department of Justice has sent two letters requesting information related to the DHS concerns— one to ERIC and one to the Center for Election Innovation and Research (CEIR).

The DHS letter outlines concerns that ERIC may have violated the Driver’s Privacy Protection Act (DPPA) by providing drivers’ private data to the CEIR.  CEIR and ERIC both claim that this is a “permissible use” outlined in the DPPA and that the data was used for research.

The DOJ letter to ERIC states:

ERIC has maintained that its use of DPPA-protected personal information falls under a statutory permissible use.  But courts have construed exceptions to the DPPA’s protections narrowly, and the membership agreement’s vague references to “research projects” and “responding to requests for information from third parties” do not appear to be tethered to the DPPA’s limited permissible uses.  Even apart from the issue of disclosure to third parties, the scope of ERIC’s own use of DPPA-protected personal information remains unclear.  Although using such information for furtherance of government functions may be a permitted use, using protected information for certain partisan purposes is not a government function and is thus not permitted under the DPPA — regardless of whether a state consents.

Keep reading

Your Car Is Sharing More Private Data Than Your Smartphone. Who’s Getting It?

Modern vehicles, like every other technology device we own, from smartphones to fridges and even dog collars, are connected to the internet 24/7. They learn from us, know things about us, and most of the time use that information to make our lives easier. Cars, specifically, collect vital driving and behavior data that is borderline impossible to opt out of if you want to use your vehicle’s modern convenience features. And a new study recently found that your sensitive information (some of which isn’t even car-related) is being shared with far more parties than you realize.

The only way you’ll be surprised by what you’re about to read is if you’ve been in a coma for the last decade or two. But even for those of us who are mildly aware of how the technology we rely on every day interacts with us and the data we generate, this recent study by Boston’s Northeastern University in partnership with Consumer Reports will make you raise an eyebrow—several times.

The study covered 21 vehicles of 19 different brands (listed below) and 30 companion mobile apps that process and handle user data.

You can peruse the 18-page paper here, but you can also see the main takeaways below:

  • Companion Apps Share Data That Goes Beyond Car Stuff: 70% of companion apps contacted more than five unique ATA (advertising, tracking, analytics) domains, typically sharing location, timing, and other data packets. For most test vehicles, adding the automaker or third-party (usually pre-installed) app at least doubles the number of ATA companies exposed to the owner’s data. The Envista and Nissan Ariya, which were nearly silent on their own, each reach 20+ ATA companies once the app is counted. myCadillac contacted 51 ATA domains.
  • How Many Third-Party Apps Your Car Contacts Wildly Varies: Over Wi-Fi, vehicles contacted at most four first-party domains but averaged about 9 integrated third parties. The Tesla Model 3 contacted 34 ATA domains and the Cybertruck 23, while the Mercedes EQS and Buick Envista contacted no third parties. Thirteen of the 21 vehicles contacted Google ATA domains, including ones like doubleclick.net that aren’t needed for core services. Vehicles with Android Automotive and Google services contacted many more trackers, and even sibling brands differed; oddly enough, the Envista, Lyriq, and Blazer did not behave in the same manner.
  • Some Apps Share Your VIN With Vendors, Something Not Even Your Smartphone Can Do: Seven apps (19 of 21 cars) transmitted personal information to ATA third parties: all four GM apps, HondaLink, Lincoln, and MyNissan. VINs were the most common, sent to recipients including Google, Microsoft, and Meta. The worry is that a VIN plus an email, phone number, or location lets an ad company link a specific person to their browsing and purchase history. The study also highlights that a VIN can’t be reset the way a phone’s advertising ID can. Also, I just published a blog this week about how I enjoyed Honda’s infotainment with Google Built-in, and cracked a joke about the price I am willing to pay for convenience.
  • OEMs Mostly Pass the Buck to Their Partners and Vendors: Of 17 manufacturers contacted for the study, 14 responded. All said their vendor contracts covered data flows. Five blamed embedded browsers in their apps, and seven said reading third-party terms is the consumer’s responsibility. Of course, if you opt out or simply don’t use the features, then you wouldn’t be utilizing your car to its full potential. Tesla warned about reduced functionality or inoperability, while Rivian warned about disabled navigation and over-the-air updates. The privacy policies disclosed that data may go to third parties but not which ones or why. Only Honda changed course. It had Amplitude delete the location data it received and stopped the app from sending it. Go Honda.
  • Gathering This Data Wasn’t Easy: Even if you only use the official apps pre-installed in your car, some of these may connect to your phone and ultimately open your browser. Once it does, the whole flow of data changes because it follows your phone’s browser settings, not your car’s. This means your car is now receiving cookies and browsing data and sharing them in ways you weren’t aware of or expected.

Keep reading

EU Piracy Watch List Targets YouTube Downloader and VPNs

The European Union (EU) continues to be a major world player in the war on copyright infringement, and the next salvo is the EU’s updated Counterfeit and Piracy Watch List.

Rights holders have been busy submitting their input, and the European Commission (EC) published their contributions on September 24. Some of the suggestions are an open source tool, four major VPN companies, and several internet infrastructure firms.

The Commission says the list “will identify and describe the reportedly most problematic online services and marketplaces in order to encourage their operators and owners, as well as the responsible local authorities and governments to take the necessary actions and measures to reduce the availability of IPR infringing goods or services.”

However, the same page is at pains to explain that the list “does not purport to make findings of legal violations.” It’s not clear how the EC expects to prove that a site or service is “problematic” without establishing whether it is in fact breaking the law, but this is not the first time that the EU has tried to have its cake and eat it, too, on copyright.

The consultation opened on June 11 and closed on September 21. Those who wish to react to what has been submitted can do so until October 28, and the next Watch List is due in the second quarter of 2027.

One of the submissions came from the International Federation of the Phonographic Industry (IFPI), which represents the recorded music industry globally. On September 11, IFPI asked the EC to include yt-dlp, a command-line program used to download videos and audio from sites like YouTube, in the Watch List.

In fact, it is the openness of the project, and the fact it is maintained by a community of developers that makes it difficult to control, IFPI said in its submission. The document also reveals that the music industry has been keeping a close eye on the project’s development, and knows that it was originally created by a developer using the username “pukkandan”, and that the current maintainers are “coletdjnz”, “bashonly” and “Grub4K.”

IFPI also names several infrastructure companies as being “problematic” – Cloudflare, Njalla, GoDaddy, and Verisign.

On Verisign, IFPI notes that the company “is the registry for the .com and the .net top-level domains.”

Meanwhile, Spain’s top football league LaLiga has asked that four VPN providers – NordVPN, ProtonVPN, ExpressVPN, and Surfshark – be included in the Watch List.

The football league does not object to VPNs as such, but to the way they are marketed by affiliates. The submission says that these affiliates publish guides on how to use the VPNs to watch LaLiga matches for free, and that the VPN companies are aware of this and profit from it through their affiliate programs.

In fact, the guides are written by third parties who have affiliate deals with the VPNs, and who earn a commission when they sell subscriptions. The “guides” rank VPNs and link to their discounted offers.

LaLiga’s submission puts it this way: “The conduct that takes these services beyond neutral technical provision is the deliberate marketing of circumvention, conducted at arm’s length through affiliate programmes.”

LaLiga does not name or link to a single one of these guides, nor does it say that the VPN companies are behind them.

In the past, LaLiga tried to get NordVPN to pay a fine for not blocking IP addresses that were accessing its content, but a Spanish court refused the request.

The nature of the submissions made by IFPI and LaLiga also shows that the targets are now no longer only sites accused of piracy and their operators, but also perfectly legitimate and lawful technology and services – such as VPNs and open source software – that happen to be used in ways that cut into the profits of the entertainment and sports industries.

Keep reading

Censorship Advocates Seek To Use Bots And Anonymous “Sock Puppet” Accounts For Themselves While Denying Them To Others

Political leaders across the West have said for a decade that governments must end online anonymity to shut down fake accounts known as bots, particularly those from Russia. “I want to see real names on the internet,” said German Chancellor Friedrich Merz in February. “In a democracy, citizens have the right to privacy,” said Spanish Prime Minister Pedro Sánchez at Davos in January 2025, and “not to anonymity or impunity,” proposing to tie every social media account to a European digital identity wallet. Greece’s digital governance minister proposed in April 2026 to link every profile to a verified identity because “The major problem behind anonymity is toxicity.” French President Emmanuel Macron declared that his priority was “to demand the disappearance of fake accounts” and “these famous bots, these troll farms.”

But now the advocates of government censorship of legal speech are demanding the legal power to wage information warfare through anonymous accounts and an explicit “sock puppet” strategy. Buried in the Australian government’s new censorship bill is a definition: “A sock puppet identity is a false or fictitious identity assumed by a person in the course of using, or carrying out any activity in relation to, an online service.” The legislation goes on not to warn of bad actors using sock puppets but rather to authorize the eSafety Commissioner, Julie Inman Grant, to create and use sock puppets to “disseminate” information.

Keep reading

OpenAI admits another rogue agent incident

OpenAI’s agents have leaked 53 images uploaded by ChatGPT users, the company has said, without specifying whether the pictures were AI-generated or depictions of real people, or when they were posted online.

The incident comes amid a series of cases in recent months involving autonomous AI agents, which can independently plan and carry out tasks using external tools. OpenAI, Anthropic, and Google have all revealed instances in which their models accessed real systems during testing, including coordinated cyberattacks against government resources.

In a post on X on Friday, OpenAI said most of the leaked pictures had been removed, adding that it was working with hosting providers to take down the remaining content.

The agents had access to the images because OpenAI relies on anonymized user data for part of its model-training process, Reuters reported on Friday, citing the company, its former employees and outside researchers.

Keep reading

The Pentagon Flocked Itself. Should Big Brother Be Worried?

As the headquarters to the U.S. military, the Pentagon is surrounded by billions of dollars worth of surveillance and security technology.

These systems provide multiple layers of protection for the building but they also carry a risk of backfiring: any surveillance system that is vulnerable to intruders could potentially provide unauthorized users with details about the activities of the Defense Department (DOD) and its employees. This risk is higher than usual right now because of the decision to install a controversial piece of equipment all over the Pentagon grounds: Flock cameras.

There are at least nine Flock automated license plate readers (ALPRs) currently monitoring the traffic lanes used by drivers entering the Pentagon’s parking lots, including many of the DOD’s own employees. The purpose of these cameras is to give the Pentagon’s security forces the ability to automatically record information about incoming vehicles that may pose a security risk. But if the alleged vulnerabilities of Flock cameras are as serious as the company’s critics allege, then this equipment could be exploited to obtain a detailed list of the national security officials seen entering the Pentagon each day. In this way, the Pentagon’s rush to obtain security equipment from private contractors may pose a national security risk of its own.

Concerns about the ability of Flock products to track people alongside cars has produced backlash from privacy-minded citizens, resulting in both protests and contract cancellations. Others have criticized Flock’s devices for security vulnerabilities that expose them to unauthorized users, flaws which could be especially dangerous in the context of military facilities. Flock Safety has sought to downplay these issues, insisting that they have “never been hacked.” Critics dispute this claim, pointing to multiple different ways that Flock’s devices can be accessed by unauthorized users.

These concerns prompted two members of Congress’ Intelligence committees – Senator Ron Wyden (D-Ore.) and Rep. Raja Krishnamoorthi (D-Ill.) – to write a letter last year asking for an investigation into Flock’s “negligent cybersecurity practices.” The duo alleged that the company “needlessly exposes Americans to the threat of hackers and foreign spies tapping this data.” When asked about the Pentagon’s Flock cameras, Sen. Wyden said that “Installing internet-connected cameras in the Pentagon parking lot is obviously a dumb idea. In particular, given Flock’s troubling cybersecurity track record, the Pentagon might as well send the data from those cameras directly to China, Russia and Iran.”

Keep reading

This Group Made Tech to Protect Users’ Privacy. Trump Labeled Them Terrorists.

When the government puts a target on your back, every corner of online organizing becomes a puzzle. How do you ensure that your emails are private, when Google will hand over the contents of your emails to prosecutors, sometimes without ever notifying you? How do you keep your comrades informed, when maintaining an email list poses a security risk? How do you share information online without compromising the security of your web visitors?

Until September 6, the Autistici/Inventati (A/I) Collective provided privacy-focused digital infrastructure that allowed aligned groups around the world to evade government surveillance. Under siege, groups from Hamas to the Seattle Anarchist Book Fair sought refuge from the prying eyes of three-letter agencies through the use of A/I Collective email addresses, websites, mailing lists, and blogs. The users of A/I Collective technology were no strangers to the United States counterterrorism apparatus, but on August 26, 2026, the Trump administration took the unusual escalatory step of listing the technology provider itself as a Specially Designated Global Terrorist organization.

Legal uncertainty and disruption ensued immediately after the designation. The sanctions framework maps far more cleanly onto groups directly engaged in violence than it does onto a group providing anti-surveillance technology. Under the post-9/11 executive order establishing the Specially Designated Global Terrorist list, fundraising for ISIS or holding joint press conferences with al-Qaeda is verboten. But could posting on blogs hosted by the A/I Collective trigger a $1 million fine and 20 years of imprisonment? Official communications provide little assistance; the Treasury Department’s Office of Foreign Assets Control FAQ unhelpfully states that the exchange of information may be either blocked or exempt.

In a press release, the State Department pointed to the A/I Collective’s vetting of users for “ideological affinity,” folding the targeting of the organization into the enforcement of Donald Trump’s National Security Presidential Memorandum 7 (NSPM-7), which has initiated a crackdown on the global left. Civil society groups immediately noted the escalation into targeting not only those accused of violence, but their purported backers. “The designation of A/I Collective is significant because Treasury is applying counterterrorism sanctions not only to organizations it alleges engage directly in violence, but also to entities it characterizes as providing enabling infrastructure to designated or terrorist-linked groups…[G]roups and individuals that rely on the A/I Collective’s infrastructure may now need to assess whether continued use creates sanctions exposure,” wrote the Charity & Security Network, a coalition that has helped nonprofits navigate sanctions risk since 2009.

While users of A/I Collective services struggled to interpret the sanctions, the hammer came down immediately on the volunteer collective. Within 48 hours of the designation, the United States-based holder of the autistici.org domain shuttered the website, leaving A/I Collective to flee to an alternate domain. The Italian Banca Etica suspended the bank account the volunteer collective used to collect donations, citing sanctions risk. Backed into a corner, with no way to protect users and collect the donations needed to fund its €13,000 annual budget, the A/I Collective announced the shutdown of all of its services on September 6, 2026. In a statement, the A/I Collective wrote: “The possibility that our work may cause legal and financial consequences to those who are close to us — or even only have something to do with us — leaves us no choice.” On September 20, an estimated 10,000 NoBlogs sites went dark, stranding the radical activists who used the A/I Collective-hosted blogging platform to share everything from zines to direct-action tactical communiques.

Keep reading