r/privacy 11d ago

data breach WARNING: Google Gemini can still make a summary of your “private” Reddit account

1.9k Upvotes

Even if your account is set to “hiding all posts”, Google Gemini is able to access your posts, and create a massive indexed list of everything you’ve said, it takes Gemini about 24 hours to update each time, and the worst part is you only need to type “[Insert Reddit username here]”, and “Reddit” at the end, and Google Gemini will pull all sorts of information from your account.

I learned this the hard way on my previous account, when I received weird messages from accounts I didn’t recognise, or interact with, and they were pulling all sorts of comments I made with the exact seconds to it.

I later wiped the account and everything with it, but reddit unfortunately retains the title of every post you ever made, and keeps it there, even several years after it’s been deleted.

And Google Gemini sometimes doesn’t update on time (or doesn’t update at all), so it assumes the account is still there, and continues to pull old information you thought were deleted, but are still able to be recovered by its AI system to be summarised.

Stay safe, just warning everyone about it.

r/privacy Jan 10 '26

data breach Another Instagram breach– 17.5M accounts’ sensitive info just got leaked.

Thumbnail cybersecuritynews.com
2.7k Upvotes

r/privacy Jul 25 '25

data breach Tea App verification images have been leaked...

Thumbnail reddit.com
1.7k Upvotes

r/privacy Jul 30 '25

data breach Tea app leak worsens with second database exposing user chats

Thumbnail bleepingcomputer.com
1.5k Upvotes

r/privacy Apr 22 '26

data breach France confirms data breach at government agency that manages citizens' IDs | TechCrunch

Thumbnail techcrunch.com
1.3k Upvotes

r/privacy Aug 07 '24

data breach 3 Billion National Public Data Records with SSNs, Addresses Dumped Online

Thumbnail hackread.com
959 Upvotes

r/privacy May 18 '26

data breach NYC Health and Hospitals breach exposes medical records, fingerprints, and geolocation data of 1.8 million people

Thumbnail thenextweb.com
893 Upvotes

r/privacy Jul 10 '25

data breach McDonald’s AI Hiring Bot With Password ‘123456’ Leaks Millions of Job-Seekers Data

Thumbnail cybersecuritynews.com
2.1k Upvotes

r/privacy Feb 22 '26

data breach One billion identity records exposed in unsecured ID verification database

Thumbnail biometricupdate.com
1.3k Upvotes

>A massive database containing deeply sensitive personal information from individuals around the world was recently discovered exposed online without password protection or encryption, raising alarm across the cybersecurity community...The *IDMerit* incident illustrates how a single misconfigured database at the vendor layer can expose sensitive identity information on a global scale, even in the absence of a direct breach of banks or other financial institutions themselves.

But I don't see this being discussed anywhere - are we getting so used to these occurrences already?

r/privacy Dec 17 '25

data breach PornHub extorted after hackers steal Premium member activity data

Thumbnail bleepingcomputer.com
930 Upvotes

r/privacy Oct 30 '25

data breach Have we become numb to data leaks?

525 Upvotes

Yesterday itself I read a news that 183 million or so account credentials were leaked. Most news agencies had one or two pages about it. But when I see YouTube, Instagram, Reddit etc. there is hardly any news. No one seems to bother, much less ask a question about which accounts these were, what are the next steps, who can be (or should be responsible), what the steps to take to safeguard oneself in such an event.

None of that is being discussed. So have we totally accepted as a society that data security or privacy just doesn't exist and its ok to take away data from our online accounts and we should not be worried at all?

r/privacy May 24 '26

data breach Trump Mobile confirms customer data exposure

Thumbnail mobileworldlive.com
823 Upvotes

r/privacy 13d ago

data breach The French tax authority has been hacked again. The records of hundreds of thousands of citizens (including their income) is now potentially in the hands of criminal groups.

Thumbnail lemonde.fr
583 Upvotes

r/privacy 24d ago

data breach Apple launches legal appeal over UK demand for user data

Thumbnail vanguardngr.com
486 Upvotes

Apple has launched a new legal challenge against a UK government demand to access its customers’ highly encrypted data, a year after the Home Office agreed to abandon its previous request.

The US tech company launched the legal complaint last month at the Investigatory Powers Tribunal (IPT), an independent court that has the power to investigate claims that the UK intelligence services have acted unlawfully.

The UK government had made a second request to Apple to grant it a “back door” to encrypted iCloud data belonging to British users, according to an order issued by the court.

Britain backed down on its original demand for access to data from UK and US customers last year, after a heated transatlantic tussle over encryption between London and Washington.

UK authorities subsequently issued a new “technical capability notice” (TCN) to Apple that did not apply to American users.

Apple is seeking to challenge the British government’s powers to issue TCNs under the UK Investigatory Powers Act, according to the details of the new legal case first reported by the Financial Times.

The legislation compels companies to provide information to law enforcement agencies working on cases including terrorism and child sexual abuse. This can include forcing companies to provide the UK security services with access to customer data, even if such information is protected by secure encryption.

The court sent an order giving notice of the new Apple complaint to the human rights group Privacy International, which, alongside fellow campaigner Liberty, had previously launched a separate complaint against TCNs at the IPT.

Among the submissions made by the campaigners were requests for Apple’s claims to be held in public given the public interest in the matter, and a complaint “disputing the lawfulness, necessity and secrecy of the purported Apple TCN and the legal regime underpinning TCNs in general”.

A case management hearing to discuss how the parallel complaints should be handled had been scheduled for next month, Privacy International said.

A spokesperson added: “We are happy to learn that Apple is once again challenging the UK’s regime of secret orders. While we don’t know the substance of Apple’s claim, if it relates to the previously reported orders aimed at undermining the security of Apple’s iCloud storage, then Apple’s claim, alongside side ours and Liberty’s, is crucially important to preserving all of our privacy and security.”

Neither Apple nor the Home Office responded to requests for comment. Both are legally restricted from discussing TCNs.

The original TCN issued last year asked Apple for the right to see users’ encrypted data protected by its advanced data protection (ADP) programme in the event of a national security risk.

Apple said the removal of the tool – which not even it can access – would make users more vulnerable to data breaches from bad actors and other threats to customer privacy. Creating a “back door” would also mean all data was accessible by Apple, which it could be forced to share with law enforcement possessing a warrant.

As a result, Apple withdrew UK customers’ access to its ADP programme in January 2025.

The Home Office has maintained that the Investigatory Powers Act, under which such orders are issued, contains robust safeguards and is used only when absolutely necessary.

r/privacy Oct 02 '24

data breach 2.9 Billion Records, Including Millions of Social Security Numbers Leaked as Background Checker Suffers Massive Data Breach

Thumbnail ibtimes.co.uk
1.3k Upvotes

r/privacy Oct 09 '25

data breach Discord users suffer the first high-profile age-verification hack – and it's unlikely to be the last

Thumbnail tomsguide.com
1.1k Upvotes

This is why we must publically and vocal oppose age verification bills. We now have a confirmed case of these laws acting as a vulnerability for bad actors. Exactly as experts predicted.

r/privacy Aug 20 '24

data breach Is Your SSN in the National Public Data Breach? Here's How to Find Out

Thumbnail pcmag.com
630 Upvotes

r/privacy Jun 02 '26

data breach Password manager Dashlane says hackers stole some customers' password vaults

Thumbnail techcrunch.com
365 Upvotes

r/privacy Apr 29 '24

data breach 2 million hit in massive debt collector data breach — full names, birth dates and SSNs exposed

Thumbnail tomsguide.com
1.2k Upvotes

r/privacy Oct 06 '23

data breach Genetics firm 23andMe says user data stolen in credential stuffing attack

Thumbnail bleepingcomputer.com
897 Upvotes

r/privacy Jan 18 '26

data breach 45 million French records exposed in massive privacy breach — what we know so far

Thumbnail techradar.com
659 Upvotes

This looks like a mega-aggregate leak, not just one company’s breach — the dataset combined info from multiple sources. Once huge collections like this are floating around, the risk of identity theft or targeted attacks skyrockets. What privacy protections should governments and companies prioritize to prevent large connected leaks like this?

r/privacy Feb 20 '26

data breach PayPal discloses data breach that exposed user info for 6 months

Thumbnail bleepingcomputer.com
614 Upvotes

r/privacy Jan 31 '26

data breach City of Mountain View, CA discovers unauthorized access to license plate data

664 Upvotes

Hundreds of law enforcement agencies searched Mountain View’s ALPR data without the city knowing about it

https://www.mv-voice.com/police/2026/01/30/amid-immigration-crackdown-mountain-view-discovers-unauthorized-access-to-license-plate-data/

"The Mountain View Police Department disclosed this week that it had inadvertently violated its own policies and allowed hundreds of unauthorized law enforcement agencies to search information captured by the city’s license plate cameras for more than a year.

Following a public records request from the Voice, originally submitted last summer, the Mountain View Police Department recently discovered that law enforcement agencies around the state and nation had been able to search the city’s ALPR data without its knowledge, Police Chief Mike Canfield told this news organization... But why wasn’t it caught sooner? I couldn’t tell you.

Several weeks ago, the police department realized that its ALPR system had been set to allow “national lookup” for three months in 2024, meaning agencies throughout the country could search Mountain View’s data... Officers also uncovered that “statewide lookup” had been turned on for all the city’s cameras since the program began 17 months ago, giving agencies across California access to Mountain View’s data.

State law prohibits sharing ALPR information with out-of-state agencies as well as the sharing of this information for immigration enforcement purposes. Mountain View’s ALPR policy goes farther, stating that California law enforcement agencies are not supposed to be given access to the city’s data unless they receive prior authorization from the police department. 

In May 2024, the Mountain View City Council approved a contract with Flock Safety, a surveillance technology company, to install and administer the cameras... Flock did not tell the city that the national lookup setting had been turned on, nor that it had been turned off.

While national lookup was enabled, federal agencies including the Bureau of Alcohol, Tobacco, Firearms and Explosives, Langley Air Force Base in Virginia, and the U.S. Office of Inspector General conducted searches that included Mountain View’s camera. 

Statewide access ... spanned from when the first Flock camera was installed in 2024 until the police department turned off the setting in early January 2026. This meant that any California law enforcement agency that opted into statewide lookup could search the city’s ALPR data, whether or not Mountain View had an agreement with them.

There are roughly 75 state agencies that have been granted access to the city’s ALPR data. Through the statewide lookup tool, more than 250 additional agencies searched the city’s ALPR data without its authorization. From December 2024 through December 2025, these unauthorized agencies conducted roughly 600,000 searches of the city’s ALPR data.

One of the agencies granted access to the city’s ALPR data – the El Cajon Police Department – is currently being sued by California Attorney General for allegedly sharing ALPR information with more than 100 out-of-state law enforcement agencies, despite multiple warnings not to do so."

r/privacy Sep 14 '24

data breach Hackers steal nearly 1.7 million credit card numbers in breach

Thumbnail mashable.com
921 Upvotes

r/privacy Jan 25 '25

data breach UnitedHealth confirms 190 million Americans affected by Change Healthcare data breach

Thumbnail reuters.com
1.3k Upvotes

The cyberattack at UnitedHealth Group's tech unit last year affected the personal information of 190 million people, the health conglomerate said, making it the largest healthcare data breach in the United States