Skip to main content

Activity

Incidents and actions from tracked entities.

On February 10, 2026, PayPal disclosed a data breach affecting approximately 100 PayPal Working Capital loan applicants due to a software coding error. Personal data including Social Security numbers, dates of birth, and business contact information was exposed from July 1 to December 13, 2025. Some customers experienced unauthorized transactions and received refunds. PayPal offered 2 years of free credit monitoring through Equifax.

In February 2026, Anthropic aired anti-OpenAI advertisements during the Super Bowl, criticizing OpenAI's announced plans to add 'Instagram-style' advertising to ChatGPT. The ads resulted in an 11% boost in Anthropic users. Sam Altman called the ads 'deceptive.' The rivalry escalated at the India AI Summit where Altman and Dario Amodei refused to hold hands during a group photo with PM Modi.

In February 2026, after FEC filings revealed Greg Brockman's $25 million combined donations to MAGA Inc., the QuitGPT boycott movement launched on February 5, 2026. The boycott attracted over 300,000 participants and was endorsed by actor Mark Ruffalo. The movement focused on Brockman's political donations and OpenAI's partnerships with ICE/DHS. It became part of a broader 'Resist and Unsubscribe' campaign organized by NYU Professor Scott Galloway targeting 10 tech companies.

SpaceX submitted an application to the U.S. Federal Communications Commission seeking approval to deploy as many as one million low-Earth-orbit satellites dedicated to artificial intelligence computing. The plan envisions orbital data centers powered by solar energy. Critics warn of escalating space debris, astronomical interference, and unresolved environmental costs. Astronomers raised alarms about the potential for further light pollution and space debris from a million-satellite constellation.

SpaceX announced a new Space Situational Awareness (SSA) system called Stargaze, offering it free to all satellite operators via its space-traffic management platform. The system can quickly detect satellite maneuvers and publish updated trajectories, generating new collision data messages distributed to relevant satellites. In late 2025, Stargaze detected a third-party satellite maneuver with just five hours notice that collapsed anticipated miss distance to ~60 meters, allowing a Starlink satellite to react within an hour and plan an avoidance maneuver.

In January 2026, Snap Inc. settled a bellwether case just days before trial, in which a 19-year-old woman and her mother alleged she developed mental health problems after becoming addicted to Snapchat. The suit accused Snapchat of engineering features like infinite scroll, Snapstreaks, and recommendation algorithms that made the app nearly impossible for kids to stop using, leading to depression, eating disorders, and self-harm. The settlement terms were confidential. The broader MDL included over 2,243 plaintiffs as of January 2026.

Microsoft issued out-of-band security patches for a high-severity Microsoft Office zero-day vulnerability tracked as CVE-2026-21509, with a CVSS score of 7.8 out of 10.0. The vulnerability allows attackers to bypass document security checks and is being actively exploited in the wild via malicious files. The emergency patch was released outside Microsoft's normal Patch Tuesday schedule due to active exploitation.

$186.0M

The FTC announced a proposed order to settle allegations that cryptocurrency company Nomad (Illusory Systems Inc.) failed to implement adequate security measures leading to a breach in which hackers stole $186 million from customers. The FTC alleged that Nomad prominently touted its security in advertising, claiming 'security-first' services, but failed to live up to these promises by failing to use secure coding practices, implement processes for receiving and addressing vulnerability reports, respond to security incidents, or utilize widely known technologies that might have helped mitigate consumer losses.

Researchers demonstrated that Google's Gemini AI model could be tricked using prompt-injection attacks to leak private details about a user's calendar. The vulnerability allows malicious actors to extract sensitive personal information through carefully crafted prompts, highlighting security risks in AI systems with access to private user data.

Dario Amodei, along with all six other Anthropic cofounders, pledged to donate 80% of their wealth, citing concerns about wealth concentration from the AI boom. In an essay titled 'The Adolescence of Technology,' Amodei wrote: 'The thing to worry about is a level of wealth concentration that will break society. Wealthy individuals have an obligation to help solve this problem.' Each cofounder's net worth is estimated at ~$3.7B, potentially directing tens of billions to philanthropy. The pledge is not legally binding and no donations have been made yet - equity is 'set aside' pending implementation.

$68.0M

Google agreed to pay $68 million to settle class action claims that Google Assistant-enabled devices (Google Home, Nest Hub, Pixel phones) surreptitiously recorded users' private conversations without consent. The recordings occurred due to 'false accepts' — the device mistakenly activating and recording when no wake word was spoken. Final approval hearing is scheduled for March 19, 2026.

A January 2026 Citizen Lab report found Cellebrite equipment was used in at least seven cases to extract data from phones seized from activists and a journalist detained during pro-Palestinian protests in Jordan between late 2023 and mid-2025. None of the individuals consented to the searches. All four devices forensically analyzed showed Cellebrite product use in 2024-2025.

On January 21, 2026, Cisco disclosed a critical code injection vulnerability (CVE-2026-20045, CVSS 8.2) affecting Unified Communications Manager, Webex Calling, and related products that was actively exploited as a zero-day before a patch was available. The vulnerability allowed attackers to send crafted HTTP requests to obtain user-level access to the underlying operating system and escalate privileges to root. Cisco's PSIRT was aware of attempted exploitation in the wild. The U.S. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and gave federal agencies until February 11, 2026 to deploy updates. The zero-day status indicates attackers discovered the vulnerability before Cisco's security teams, representing a failure to identify and remediate critical vulnerabilities before exploitation.

A widespread malware campaign abused Google's Chrome Web Store for months, exposing private AI chatbot conversations and browsing data from roughly 900,000 users. The campaign involved two malicious browser extensions identified as 'ChatGPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI' and 'AI Sidebar with DeepSeek, ChatGPT, Claude.' The extensions remained available in the Chrome Web Store despite the security vulnerabilities.

42 State Attorneys General issued a letter to Microsoft (along with other large technology companies) about the rise in sycophantic and delusional outputs from generative AI software. The letter highlighted that generative AI software has been involved in at least six deaths in the United States, and other incidents of domestic violence, poisoning, and hospitalizations for psychosis.

Crunchbase confirmed it was hacked in January 2026 after the cybercriminal group ShinyHunters published samples of stolen data. The company stated they detected a cybersecurity incident where a threat actor exfiltrated certain documents from their corporate network. Investigators linked the attack to a broader ShinyHunters campaign focused on voice phishing targeting Okta single sign-on credentials, with similar techniques tied to recent breaches at SoundCloud and Betterment.

42 State Attorneys General issued a letter to Google (along with other large technology companies) about the rise in sycophantic and delusional outputs from generative AI software. The letter highlighted that generative AI software has been involved in at least six deaths in the United States, and other incidents of domestic violence, poisoning, and hospitalizations for psychosis.

42 State Attorneys General issued a letter to Meta (along with other large technology companies) about the rise in sycophantic and delusional outputs from generative AI software. The letter highlighted that generative AI software has been involved in at least six deaths in the United States, and other incidents of domestic violence, poisoning, and hospitalizations for psychosis.

The Wikimedia Foundation announced commercial partnerships through Wikimedia Enterprise with Amazon, Meta, Microsoft, Mistral AI, and Perplexity for structured API access to Wikipedia data for AI training. This formalizes relationships that previously involved unpaid scraping, creating a sustainable revenue model.

VP Lisa Jackson, essentially Apple's chief sustainability officer, retired in January 2026 and Apple eliminated the CSO role rather than replacing her. This represents a significant organizational shift for one of the world's largest tech companies, removing dedicated executive leadership for sustainability despite Apple's strong environmental track record including 60% CO₂ emissions reduction since 2015 and 100% renewable electricity for all corporate operations since 2018.

Nike disclosed it is investigating unauthorized access that resulted in the extraction of approximately 1.4 terabytes of internal data. The incident involves a large volume of files taken from internal systems, which signals sustained access rather than a short-lived intrusion. The breach represents a significant compromise of Nike's internal systems and data.

Pinterest announced in January 2026 that it plans to cut 15% of its workforce, with approximately 700 employees expected to lose their jobs. A spokesperson stated the social media company is 'making organizational changes to further deliver on our AI-forward strategy, which includes hiring AI-proficient talent.' The layoffs represent a shift in capital allocation as the company pours money into AI.

In January 2026, YouTube CEO Neal Mohan announced that the platform has paid over $100 billion to creators, artists, and media companies in the past four years. YouTube now has over 3 million channels enrolled in its ad and subscription revenue-sharing program (YPP). Mohan also stated YouTube would lobby for policymakers to recognize creators in labor data and acknowledge them in industry forums, advocating that 'Being a creator is a full-time job with an international audience.'