Skip to main content

Activity

Incidents and actions from tracked entities.

On February 10, 2026, PayPal disclosed a data breach affecting approximately 100 PayPal Working Capital loan applicants due to a software coding error. Personal data including Social Security numbers, dates of birth, and business contact information was exposed from July 1 to December 13, 2025. Some customers experienced unauthorized transactions and received refunds. PayPal offered 2 years of free credit monitoring through Equifax.

In February 2026, Anthropic aired anti-OpenAI advertisements during the Super Bowl, criticizing OpenAI's announced plans to add 'Instagram-style' advertising to ChatGPT. The ads resulted in an 11% boost in Anthropic users. Sam Altman called the ads 'deceptive.' The rivalry escalated at the India AI Summit where Altman and Dario Amodei refused to hold hands during a group photo with PM Modi.

In February 2026, after FEC filings revealed Greg Brockman's $25 million combined donations to MAGA Inc., the QuitGPT boycott movement launched on February 5, 2026. The boycott attracted over 300,000 participants and was endorsed by actor Mark Ruffalo. The movement focused on Brockman's political donations and OpenAI's partnerships with ICE/DHS. It became part of a broader 'Resist and Unsubscribe' campaign organized by NYU Professor Scott Galloway targeting 10 tech companies.

On February 4, 2026, Kakao notified KakaoTalk's 47M+ users it would begin collecting and analyzing usage records and patterns for targeted advertising. After public backlash over privacy invasion, Kakao revised its terms on February 11, deleting some controversial provisions. This followed a September 2025 redesign debacle that was rolled back in 5 days after user revolt, and criticism of a location-sharing feature that allegedly enabled stalking.

FEC filings show Peter Thiel contributed $1.5 million to Club for Growth Action, a conservative super PAC, on February 3, 2026 -- his first major federal-level political donation since sitting out the 2024 presidential cycle after previously helping fund Trump's first presidential run.

As CEO and co-founder of Sierra, an AI customer-service agent company, Taylor publicly argued that fears of AI-driven job losses reflect 'a failure of imagination,' comparing the shift to how ATMs changed bank teller roles and how agriculture's share of the workforce shrank historically. He cited a Sierra customer that rebranded call-center staff as 'AI Architects' who manage AI agents' decision logic rather than take calls directly, and advised customer-service workers to proactively steer their careers toward wherever AI savings get reinvested rather than 'waiting passively.' He did not describe company- or policy-level retraining or transition-support programs, instead placing the burden of adaptation on individual workers. Sierra's pricing model charges clients only when its AI agent resolves a case without transferring to a human, creating a direct financial incentive to minimize human involvement.

SpaceX submitted an application to the U.S. Federal Communications Commission seeking approval to deploy as many as one million low-Earth-orbit satellites dedicated to artificial intelligence computing. The plan envisions orbital data centers powered by solar energy. Critics warn of escalating space debris, astronomical interference, and unresolved environmental costs. Astronomers raised alarms about the potential for further light pollution and space debris from a million-satellite constellation.

In February 2026, Roelof Botha traveled to Washington, D.C. and participated in the bipartisan Hill and Valley Forum to discuss AI policy with lawmakers. In a podcast interview around the same time, he argued that AI policy should focus on regulating applications rather than 'basic technology,' comparing regulation of foundational AI models to regulating electricity or combustion engines in the abstract, and said Europe 'may be going more aggressively in this direction than it should.' He also said he is a 'staunch supporter' of open-source AI, citing competition with Chinese open-source models. Botha's position was not blanket anti-regulation -- he said 'reasonable regulation allows our country to thrive' and pointed to fair-lending rules as an example of appropriate application-level oversight -- but the thrust of his advocacy was to narrow the scope of regulatory oversight applied to frontier AI models themselves.

SpaceX announced a new Space Situational Awareness (SSA) system called Stargaze, offering it free to all satellite operators via its space-traffic management platform. The system can quickly detect satellite maneuvers and publish updated trajectories, generating new collision data messages distributed to relevant satellites. In late 2025, Stargaze detected a third-party satellite maneuver with just five hours notice that collapsed anticipated miss distance to ~60 meters, allowing a Starlink satellite to react within an hour and plan an avoidance maneuver.

The European Commission fined X (Twitter) EUR 120 million for violations of the Digital Services Act, with the decision published January 30, 2026. Violations included: deceptive blue checkmark design where verification review averaged only 53-79 seconds per account, deliberately obstructed ad transparency repository with artificial 3-minute delays (only 58% of French ads appeared), and blocked researcher data access (95.8% of applications rejected as of May 2024). The fine was levied against X Internet Unlimited Company, X Holdings Corp, X.AI Holdings Corp, and Elon Musk personally.

Venture firm Andreessen Horowitz contributed $50 million to the AI-industry-focused Leading the Future super PAC and $47.5 million to the cryptocurrency-focused Fairshake super PAC, plus over $1 million to the RNC and MAGA Inc., totaling $93.8 million in disclosed 2026 midterm-cycle political spending -- reported as the largest of any single donor tracked for the cycle -- aimed at electing candidates favorable to light-touch AI and crypto regulation.

In January 2026, Snap Inc. settled a bellwether case just days before trial, in which a 19-year-old woman and her mother alleged she developed mental health problems after becoming addicted to Snapchat. The suit accused Snapchat of engineering features like infinite scroll, Snapstreaks, and recommendation algorithms that made the app nearly impossible for kids to stop using, leading to depression, eating disorders, and self-harm. The settlement terms were confidential. The broader MDL included over 2,243 plaintiffs as of January 2026.

Microsoft issued out-of-band security patches for a high-severity Microsoft Office zero-day vulnerability tracked as CVE-2026-21509, with a CVSS score of 7.8 out of 10.0. The vulnerability allows attackers to bypass document security checks and is being actively exploited in the wild via malicious files. The emergency patch was released outside Microsoft's normal Patch Tuesday schedule due to active exploitation.

$186.0M

The FTC announced a proposed order to settle allegations that cryptocurrency company Nomad (Illusory Systems Inc.) failed to implement adequate security measures leading to a breach in which hackers stole $186 million from customers. The FTC alleged that Nomad prominently touted its security in advertising, claiming 'security-first' services, but failed to live up to these promises by failing to use secure coding practices, implement processes for receiving and addressing vulnerability reports, respond to security incidents, or utilize widely known technologies that might have helped mitigate consumer losses.

Researchers demonstrated that Google's Gemini AI model could be tricked using prompt-injection attacks to leak private details about a user's calendar. The vulnerability allows malicious actors to extract sensitive personal information through carefully crafted prompts, highlighting security risks in AI systems with access to private user data.

Dario Amodei, along with all six other Anthropic cofounders, pledged to donate 80% of their wealth, citing concerns about wealth concentration from the AI boom. In an essay titled 'The Adolescence of Technology,' Amodei wrote: 'The thing to worry about is a level of wealth concentration that will break society. Wealthy individuals have an obligation to help solve this problem.' Each cofounder's net worth is estimated at ~$3.7B, potentially directing tens of billions to philanthropy. The pledge is not legally binding and no donations have been made yet - equity is 'set aside' pending implementation.

$68.0M

Google agreed to pay $68 million to settle class action claims that Google Assistant-enabled devices (Google Home, Nest Hub, Pixel phones) surreptitiously recorded users' private conversations without consent. The recordings occurred due to 'false accepts' — the device mistakenly activating and recording when no wake word was spoken. Final approval hearing is scheduled for March 19, 2026.

On January 23, 2026, ByteDance and a consortium including Oracle, Silver Lake, and the Abu Dhabi state-backed MGX finalized TikTok USDS Joint Venture LLC, reducing ByteDance's stake in TikTok's US operations to 19.9% while Oracle became the venture's security partner storing US user data on its cloud and auditing compliance. However, ByteDance retained a licensing agreement covering TikTok's recommendation algorithm -- the kind of ongoing 'operational relationship' the 2024 Protecting Americans from Foreign Adversary Controlled Applications Act explicitly required be eliminated. National security experts, including former State Department official Michael Sobolik, called the arrangement a 'unilateral surrender to Beijing' that 'allows Beijing to manipulate content and steal Americans' data, even after today's announcement.' Sen. Ed Markey stated the deal 'maintained an operational relationship between ByteDance and TikTok USDS, violating the spirit, if not the letter, of the law' and said the White House had provided 'virtually no details' on whether the algorithm is truly free of Chinese influence, calling for Congressional investigation. Even Rep. John Moolenaar, chair of the House Select Committee on China and a supporter of the underlying law, said after the deal closed that 'questions... need to be answered' about whether China retains algorithmic influence and whether user data is secure.

A January 2026 Citizen Lab report found Cellebrite equipment was used in at least seven cases to extract data from phones seized from activists and a journalist detained during pro-Palestinian protests in Jordan between late 2023 and mid-2025. None of the individuals consented to the searches. All four devices forensically analyzed showed Cellebrite product use in 2024-2025.

At Intuit's January 22, 2026 Annual Meeting of Stockholders, a proposal submitted by the conservative National Center for Public Policy Research -- requesting the board report on the financial return and legal/reputational risk of Intuit's diversity, equity and inclusion programs -- was decisively rejected by shareholders. Per Intuit's SEC 8-K vote-results filing, 228,853,804 votes were cast against the proposal versus 1,753,458 for (~99.2% against). Intuit's board had recommended stockholders vote against the proposal, calling it 'unnecessary and wasteful' and affirming that employees are one of the company's four key 'True North' stakeholders. The rejection came amid a wave of similar anti-DEI shareholder proposals and corporate DEI rollbacks across the tech and broader corporate sector in 2025-2026, making Intuit's active defense of its programs a notable outlier.

On January 21, 2026, Cisco disclosed a critical code injection vulnerability (CVE-2026-20045, CVSS 8.2) affecting Unified Communications Manager, Webex Calling, and related products that was actively exploited as a zero-day before a patch was available. The vulnerability allowed attackers to send crafted HTTP requests to obtain user-level access to the underlying operating system and escalate privileges to root. Cisco's PSIRT was aware of attempted exploitation in the wild. The U.S. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog and gave federal agencies until February 11, 2026 to deploy updates. The zero-day status indicates attackers discovered the vulnerability before Cisco's security teams, representing a failure to identify and remediate critical vulnerabilities before exploitation.

A widespread malware campaign abused Google's Chrome Web Store for months, exposing private AI chatbot conversations and browsing data from roughly 900,000 users. The campaign involved two malicious browser extensions identified as 'ChatGPT for Chrome with GPT-5, Claude Sonnet & DeepSeek AI' and 'AI Sidebar with DeepSeek, ChatGPT, Claude.' The extensions remained available in the Chrome Web Store despite the security vulnerabilities.

42 State Attorneys General issued a letter to Microsoft (along with other large technology companies) about the rise in sycophantic and delusional outputs from generative AI software. The letter highlighted that generative AI software has been involved in at least six deaths in the United States, and other incidents of domestic violence, poisoning, and hospitalizations for psychosis.

Crunchbase confirmed it was hacked in January 2026 after the cybercriminal group ShinyHunters published samples of stolen data. The company stated they detected a cybersecurity incident where a threat actor exfiltrated certain documents from their corporate network. Investigators linked the attack to a broader ShinyHunters campaign focused on voice phishing targeting Okta single sign-on credentials, with similar techniques tied to recent breaches at SoundCloud and Betterment.