|
|
Why Are You Getting This?
You signed up to receive The Privacy Professor® Tips, or initiated contact to stay in touch with Rebecca and/or Privacy & Security Brainiacs® (PSB) and consented to receive the Tips. Please read our Privacy Notice & Communication Info at the bottom of this message for more information. You may unsubscribe from there as well.
| | Image created by Rebecca Herold using Canva. | | |
There is nothing quite like a milestone birthday to make you reflect on the past…and apparently, to make hackers reflect on your data. As the U.S. celebrates its monumental 250th anniversary throughout the year, and the world gathers throughout two months for the summer's massive World Cup tournament, we are surrounded by reasons to celebrate. Whether it’s a global sports championship, a major wedding anniversary, or a prestigious professional award, these events fill our calendars and our social media feeds. Regrettably, digital pirates view this festive atmosphere as open season for data harvesting. They craft sophisticated scams wrapped in the guise of exclusive anniversary discounts, commemorative freebies, or urgent ticket alerts, betting that your holiday distraction will lead to a security slip-up. Celebrating safely requires a shift in perspective. By treating your personal data with the same vigilance as you would show a suspicious package on your doorstep, you can keep the pirates at bay. This month, we are diving into the anatomy of celebratory scams so you can protect your privacy while still enjoying every single toast.
We receive dozens of questions each month. Because we do take a significant amount of time to consider all aspects and then provide a thoughtful answer (that we wrote using our own expertise and experience, not using AI) that is as succinct as possible, we decided to limit the number of questions answered to four. As we are making changes in our business, later this year we will also start regularly posting to our blog again, and we will answer more questions there, and point to them from our Tips.
This month our Question of the Month asks about video surveillance systems, and related security, privacy and legal compliance issues. The other three questions cover how the current economic challenges impact physical security, most harmful U.S. 250th birthday crimes, and real-life 2026 World Cup privacy and security crimes. Thank you for sending them in!
Please read to the end where we provide some important information.
Since 2005, we have been freely distributing the Privacy Professor Tips monthly publication to help both businesses and individuals, of all ages, identify risks throughout their daily lives, within their own businesses, and to help them know how to prevent security incidents, privacy breaches, and to keep from being a victim of scams.
By sharing this Tips issue with others in your organization, you are also supporting a wide range of regulatory and other legal compliance requirements to sending such awareness communications. Thank you for reading and sharing!
| | |
We would love to hear from you!
Did you find the tips we provided useful? Did you like this issue? Do you have questions for us to answer? Please let us know at info@privacysecuritybrainiacs.com.
| | |
July Tips of the Month
- News You May Have Missed
- Privacy & Security Questions and Tips
- Where to Find the Privacy Professor
| | |
Milestone birthdays are supposed to be joyful—whether it’s the USA turning 250, a graduation celebration, a championship win, or your own big day. But wherever there’s a celebration, there’s also a cybercriminal ready to turn the confetti into chaos. As the U.S. celebrates its semiquincentennial, scammers have been crafting fake commemorative coins, bogus patriotic giveaways, and phishing emails disguised as “official” anniversary announcements. The same tactics pop up around birthdays, anniversaries, and even global events like the World Cup. Criminals know people are distracted, emotional, and more likely to click before thinking. This month, we’ll explore how to keep your data safe while still enjoying the festivities—because nothing ruins a celebration faster than identity theft or a drained bank account. Consider this your guide to spotting celebration themed scams before they blow out your privacy candles.
Many readers are sending us alerts of privacy related news on a wide range of privacy topics. Thank you! We love getting your notices. With your help we are finding more unique news stories to share with you than ever before, along with news items that we believe are important for most folks to know, but that often do not get much mention in traditional news, or even in security and privacy news outlets.
Here are just a few of the 150+ news stories we discovered throughout the past month that provide a wide range of interesting security and privacy related news. These news items demonstrate that such types of risks exist basically anywhere in the world, and that everyone needs awareness.
We have grouped the 40 news items into four broad categories: the first expands upon this month’s topic of “Don’t Let Data Pirates Make You Walk the Privacy Plank Instead of Celebrating” with tips and news to raise privacy awareness for everyone. Followed by privacy related news in the categories, “Of Broad Interest,” “Privacy in Businesses, Governments, and Other Organizations,” and “Laws, Legal Issues, and Lawsuits About or Significantly Involving Privacy and/or Security Issues.”
Within each category the items are in no particular order. Some include “INSIGHTS” to provide some advice or additional insights to specific news items. Thanks to those many readers who sent your positive feedback; we appreciate it!
Do you have interesting, unusual, bizarre or odd stories involving security and privacy? Some of the most surprising items are in local news! Or questions about any of the notes we included for the stories we listed this month? Let us know!
| | Don’t Let Data Pirates Make You Walk the Privacy Plank Instead of Celebrating | | Image created by Rebecca Herold using Adobe Firefly. | | |
1. A flood of fake seed listings on eBay, Amazon, and Etsy, which has been running for years. However, they have increased dramatically in sales this year as a wide range of different “patriotic" red, white and blue flowers and plants are being offered for sale to help celebrate the U.S. 250th anniversary year. Here and here are a couple of articles and associated AI generated plants that are fooling a lot of people this year. Be aware!
2. BBB warns of fake online products; fake patriotic merchandise tied to the 250th anniversary is being used in scam storefronts. According to the Better Business Bureau (BBB) serving West Florida, scammers are placing America 250 logos on various products, including wreaths, whiskey decanters, hats, and T-shirts. "The advertisement for that product looks great and looks very pristine and high-end," Bryan Oglesby of the Better Business Bureau serving West Florida said. "But when the consumers receive the product, it’s flimsy garbage. It’s not what they expected." The organization says some online purchases never arrive at all.
3. NYPD and federal agencies increase ATM-skimmer investigations before America's 250th celebration because criminals are expected to target visitors. Comprised of the Secret Service and other federal and local agencies, the task force hits stores across the city looking for the devices, investigates when the thefts are reported, and tries to educate business owners and potential victims. “The thieves — roughly 95% of whom are from Eastern Europe — use skimmers that are inserted into ATMs or point of purchase machines at stores to steal banking information that can then be added to gift cards and used to withdraw cash from ATMs.”
4. How Fraudsters Are Exploiting the Taylor Swift and Travis Kelce Engagement. McAfee threat researchers have identified a deepfake video circulating across social media platforms, all capitalizing on the engagement buzz. These AI-generated videos, some featuring a likeness of Selena Gomez, are commenting on the engagement, overlayed on video clips of Taylor Swift, but they’re entirely fabricated. The sophistication of these deepfakes is concerning. They feature realistic facial movements and convincing audio that can fool even discerning viewers. Fortunately, McAfee’s Scam Detector technology has been successfully identifying these fraudulent videos, alerting users with notifications that read “Deepfake detected” and advising viewers to “take a moment to double-check if the video is real and accurate.”
5. World Cup Scams Surge As Meta Fights Phony Ads On Facebook & Instagram. The FBI is warning fans about widespread scams utilizing fake FIFA websites to defraud individuals seeking tickets or merchandise, often leading to identity theft. Scammers employ AI to create convincing sites with similar URLs, like "fiffa.com," and use fake login pages to steal account details. Cybersecurity firm Group-IB has identified over 4,300 such fraudulent sites. Beyond fake sales, phony lotteries demand fees or personal information for prizes victims never entered.
6. Threat actors are aggressively targeting fans via Telegram channels and malicious third-party Android application files (APKs). Posing as "free match livestreams" or betting platforms, these files often hide info-stealing malware designed to quietly pull saved credentials and crypto wallet data from the victim’s device.
7. The FTC is getting reports about unexpected “You’re invited” texts and emails that are actually phishing scams. These fake invitations ask for your email login credentials or a special pass code to open them, but don’t do it. Learn how these phishing scams work and how to protect yourself if you get one. Scammers send unexpected messages that look like they're from well-known invitation platforms like Evite or Paperless Post. Some messages list someone you know as the host and make you enter your email username and password to see event details. Some messages tell you to enter a phone number and share a special code to RSVP.
8. Rajasthan Police warn against scams through wedding invites on WhatsApp. ‘Fraudsters are sending malicious links and ‘APK’ files in the name of wedding invitations, which can compromise personal data and even lead to bank fraud’. Once installed, the fraudsters gain control of the phone, enabling them to steal OTPs and access bank accounts.
9. The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate indicators of compromise (IOCs) and identified tactics, techniques, and procedures (TTPs) associated with the First VPN Service. The service has been active since approximately 2014 and currently provides 32 exit node servers in 27 countries. At least 25 ransomware groups, such as Avaddon Ransomware, have used First VPN Service infrastructure to perform network reconnaissance and intrusions. First VPN Service IP addresses have been used for scanning activity, botnets, denial of service attacks, scams, and hacking. First VPN Service was almost exclusively advertised in known criminal dark web forums such as Exploit[.]in and XSS[.]is, two of the most prominent Russian-language online forums which provide marketplaces for cyber criminals to buy and sell unauthorized access to computer systems, stolen personal identifying information, hacking tools, and contraband. This reporting applies solely to the First VPN Service and does not extend to other VPN providers with similar naming.
10. Fake ticket websites selling nonexistent concert, festival or sporting-event tickets. 2:41min news report video.
| | Image created by Rebecca Herold using ChatGPT Image | | |
11. Are You Being Secretly Recorded? Here's How to Spot Smart Camera Glasses in the Wild. Cameras built into smart glasses like the Ray-Ban Meta can discreetly record you. Learn the signs that someone may be filming you and ways to protect your privacy.
12. This AI Kidnapping Scam Is Every Parent's Worst Nightmare. A frantic call. Your child's voice. A demand for money. Scammers are weaponizing AI-generated voices, and parents are in the crosshairs. Here's how the scam works—and how to stop it.
13. Over 900 US gas station tank gauge systems exposed to attacks. Automatic tank gauge (ATG) systems are electronic monitoring devices used to remotely track fuel, chemicals, or other liquids in storage tanks, automating inventory control, environmental leak detection, and regulatory compliance. While they're commonly used at gas stations to monitor fuel tank levels, they can also be found in industrial settings to track chemical storage tanks. The Cybersecurity and Infrastructure Security Agency (CISA), the FBI, the NSA, the Department of Energy, and other U.S. government partners issued a joint advisory warning critical infrastructure organizations to secure internet-exposed ATG systems against ongoing attacks. INSIGHTS: Attackers could exploit these vulnerabilities to disable system alerts, increasing the risk of fuel leaks or equipment failures, and even causing permanent damage to the targeted tank systems. This could disrupt fuel availability to the general public.
14. Police investigate hidden card skimmers at Des Moines gas stations. "Somehow they figured out how to get a key and they're going in. They're opening up those machines, putting those devices inside of there, closing them. And the consumer will never know," Sgt. Paul Parizek of the Des Moines Police Department said.
15. Why Dorothy, a 93-year-old SF woman, was bombarded with mysterious mail for nearly a year. Three companies were using her address for their business. 6:39 minute video. A man named Carlos was listed as the owner of all three businesses, with an address in Oakland, CA. But no one was living at the address. Dorothy reported this situation to half a dozen state and federal agencies. No one helped, so she called ABC7 On Your Side. No resolution was achieved. INSIGHTS: This type of activity, to link one address to multiple businesses, is often used to commit scams or do money laundering. Also, foreign entities use a local address to avoid the checks that would otherwise be done. This also highlights the lack of state and federal oversight of businesses to situations such as this.
16. Smart Home Devices from Amazon, Walmart Arrive Pre-Wired for Crime: 20 Million at Risk. WSJ reporters bought five bargain gadgets; factory-installed residential proxy software were on each. “That $35 digital photo frame cycling through vacation snapshots on your shelf may already be renting your home internet connection to criminals — and nothing you do after plugging it in will stop it.” INSIGHTS: Nation-state attackers and other types of cyber criminals are increasingly sneaking past traditional network defenses by routing attacks through trusted U.S. residential IP addresses. This makes it important for everyone who has an internet connection to be more aware of these threats, and to implement stronger identity-based security controls, such as using multi-factor authentication (MFA), blocking known geographic locations that are malicious, etc.
17. How Hackers Found A Back Door Into the American Living Room. Nation-state cyberattackers are increasingly using residential proxy networks to mask their traffic, turning everyday electronics into a massive global threat.
18. 15 Worst Things to Carry in Your Wallet. With identity theft rampant, keep only the essentials in your pocket or purse.
19. FBI Warns of Banking Spoofing Scams. Identity criminals are using spoofing technology to make their phone calls appear to come from your actual bank. They can even make the number on your caller ID match the one on the back of your debit card. To make the bank spoofing scam call feel real, they might read back your exact account balance or your account number to prove they are official. They could claim your money is at risk and that you must immediately move it to a secure or safe account to protect it. That “safe” account is controlled by the scammer. Remember: a legitimate bank will never ask you to move your money to another account to keep it safe. INSIGHTS: To protect yourself, switch to passkeys since they generally cannot be “phished” or stolen by a caller. Set up multi-factor authentication (MFA) on your financial accounts for extra security.
20. This Company Will Add Phone, AirPod, and Smartwatch Trackers to License Plate Readers. SignalTrace “links devices that regularly travel together, correlating them to license plate.” It is a surveillance product that will sweep up and add all sorts of Bluetooth and other data to license plate readers, linking specific devices—and people—to cars.
| | Image created by Rebecca Herold using Gemini Image. This shows how data pirates are often all around us, especially in crowded events. For example at the wedding of a famous couple where most people are trying to get a glimpse of the celebrities, the data pirates are busy collecting videos, photos, audios, and taking physical items from the unsuspecting victims. | | Privacy In Businesses, Governments, and Other Organizations… | |
21. ITRC 2026 Trends in Identity Report. According to the report, identity crimes have evolved from isolated events into "multi-layered" crises, with 25.6 percent of victims now managing two or more concurrent incidents, up from the previous year. Also, for the first time, unauthorized device access has surpassed scams as the primary threat for adults aged 35–64.
22. MAY NOTABLE BREACHES. In May, there were 347 total compromises, with Instructure Holdings, Inc. – Canvas topping the list, resulting in 275M victim notices. The Carnival Corporation & PLC and New York City Health & Hospitals compromises also led to nearly an additional 7 million victim notices.
23. How Desktop AI Hubs Could Deflect Over 56.23 TWh of Industrial Data Center Load by 2035. Desktop AI Hubs Could Be the Answer to Not Only Our AI-related Power Grid Infrastructure Challenges but Scalable Robotics Deployments As Well. INSIGHTS: Security, and in some use cases privacy, is improved by distributing power usage to edge devices, to reduce the centralized load from the major energy sources, and helping to prevent network (and the associated data and services) outages.
24. Secret Service phone security lapses put US officials at risk, watchdog says. "The Department of Homeland Security’s inspector general determined Secret Service employees routinely relied on personal phones for official work, including during domestic and overseas protective assignments, because government-issued devices lacked key tools needed to communicate with law enforcement, foreign partners and other officials. Those personal devices were not managed or secured by the government, creating vulnerabilities that could expose operational details, employee information, contacts, location data, photos and other sensitive material, the report said. Adversaries “could have intercepted and exploited Secret Service information, placing at risk our Nation’s leaders, other protectees, and employees — especially when unsecured devices were used overseas,” the inspector general wrote."
25. Hidden in plain sight: Surveillance at the Arizona border. From hidden license plate readers to AI-powered cameras, federal agents have built a vast monitoring network that stretches deep into Arizona.
26. Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked. The exploit shows the extreme risk of offloading technical support to AI. "Hackers say that they used Meta’s AI support chatbot to break into a host of high-profile Instagram profiles by asking the support bot to change the email address associated with the target account. The claims coincide with a series of high-profile Instagram account takeovers, including the Barack Obama White House account, the Chief Master Sergeant of Space Force’s account, and Sephora’s account."
27. Here is the Contract for Palantir’s Super API for the IRS. The API would make IRS data available to any app the agency wishes. The Criminal Investigation arm of the IRS is also modernizing its own systems. "In September, the Department of the Treasury announced: “To continue improving data integrity and technical infrastructure, Treasury has awarded a contract to Palantir. This partnership will enable a common API layer that supports developer platforms, workflow automation, and data analytics. This work supports federal employees, increasing efficiency for their professional duties.”"
28. High-profile Instagram AI chatbot breach spotlights security risks of automation. Meta pushed an emergency patch after Instagram accounts were taken over and briefly defaced with pro-Iranian imagery. The attack was simple. Attackers worked out where the account owner lived (there are lists of account owners’ home cities online, or they could just research the target). Then they used a VPN to match the target account’s geographic region, which avoided raising flags with Instagram’s security systems. Then they started a normal password reset and opened the support chat. They asked the AI bot providing support to change the email address on the account, and it did exactly that, sending a one-time code straight to the attacker’s inbox.
29. Companies Are Using Reddit to Manipulate Searches Using ChatGPT and Google AI. Peptide companies have been doing AI-engine optimization by spamming the biohackers subreddit to manipulate ChatGPT and Google. “Reddit claims it does not allow misleading or spam content and is working on tools to detect such content. But moderators say there is an ongoing struggle between spammers and the communities that want to maintain reliable online spaces—especially in realms such as health or personal finance.”
30. Balancing privacy and AI legislation with retail safety technology. Retail and tech partners must commit to governance and communication on use and benefits.
| | Laws, Legal Issues, and Lawsuits About Or Significantly Involving Privacy and/or Security Issues… | Image created by Rebecca Herold using Magnific. | | |
31. The German government is mulling allowing new AI systems to be trained on unaltered citizens’ data, despite it currently being prohibited by European privacy regulations. But the Ministry says training AI on fictitious data leads to inaccurate results. “However, the International Bureau of Fiscal Documentation (IBFD) warns of significant privacy and security risks stemming from tax authorities’ use of AI, as they handle large volumes of sensitive and personal data that can be leaked or misused. In addition, the foundation emphasizes that AI biases can lead to unfair treatment of taxpayers due to flawed or incomplete training data.”
32. Amazon Ring sued over facial recognition feature that stored faces without consent. A Virginia man is seeking class-action status and at least $5 million in damages for those whose faces were stored without consent. The suit, “pursues class-action certification and demands a minimum of $5 million on behalf of the proposed class. At the center of the complaint is a Ring feature called "Familiar Faces," which applies AI to build a database of recognized individuals, sending homeowners or business owners personalized alerts that name the person when that individual appears again.”
33. In an appeal hearing last month, a court’s live stream captured this happening on camera in real time, with an attorney caught for likely using AI-fabricated citations. On May 20, in the Supreme Court of the State of New York Appellate Division, Justices Valerie Brathwaite Nelson and Hector LaSalle reamed out that lawyer and his opposing counsel for more than 20 minutes, calling the situation “striking, concerning, disappointing, and saddening.” INSIGHTS: In the last few years, we’ve heard case after case where attorneys used generative AI and were caught including fake citations, quotes, and other major errors in their filings. 2:47 min video.
34. FCC Wants to Kill Burner Phones By Forcing Telecoms to Get All Customers’ IDs. "The FCC wants to legally force telecoms to collect new and renewing customers’ government issued identity number and physical address, impacting everyone from the privacy-conscious to domestic abuse survivors. “We never thought that would happen here.”"
35. Cops Keep Getting Arrested for Using Flock to Stalk People. "Jarmarus Brown, an Orange City, Florida police officer, ran his ex-girlfriend's license plate through the Flock automated license plate reader (ALPR) system lookup database at least 69 times. He searched for the license plate belonging to her mom at least 24 times, and searched for the license plate belonging to her dad at least 15 times." "Many of the known cases of police abuse were only discovered after the victim reported being stalked or after data crunching by journalists or local government transparency groups; many of the cases of abuse happened over the course of months."
36. New Iowa law first step in efforts to combat fraudulent businesses, Iowa secretary of state says. The law targets fraudulent businesses that use Iowans’ names and addresses to register their companies. This new law will allow the Iowa Secretary of State office to address and resolve situations where a fraudulent business chooses a random individual and home address as their “registered agent” in the state, an act that directs creditors and legal action to the unaffiliated homeowner based on the business’ actions. INSIGHTS: This is one type of business identity theft. In essence, the crooks doing this make the unsuspecting property owner or resident responsible and accountable for the fraudulent business's debts. People have had their property seized, liens put on their property, and other harms as a result of this type of fraud.
37. Justices say Constitution protects people’s location history. The 6-3 decision ruled police need a warrant to get people's location data, even if it's shared with companies like Google and Apple. “An individual has a reasonable expectation of privacy in records about his cell phone’s location, and police intrude on that constitutionally protected interest when they demand the information — even though for only a limited time, and from a third-party tech company,” Justice Elena Kagan wrote for the majority.
38. On June 16, 2026, Vermont Governor Phil Scott signed S.71 into law, enacting the Vermont Data Privacy and Online Surveillance Act (the “VDPOSA” or the “Act”), which is the 24th state to pass a comprehensive data privacy law. The VDPOSA, which takes effect on January 1, 2028, largely tracks the established framework for consumer privacy laws outside California; however, the Act includes a few notable nuances, including relatively low applicability thresholds, a broad definition of sensitive data, heightened protection for consumer health data, a right to obtain a list of third parties to whom personal data was sold, and a right to question certain uses of profiling. INSIGHTS: A "comprehensive” privacy law is generally a set of rules that gives you control of your personal data across almost all types of covered businesses. It establishes rights for you to see the information companies collect about you, force them to delete it, stop them from selling your data to others, and restrict how to use your data. Most of the other comprehensive state privacy laws do not explicitly include surveillance within them. It will be interesting to see how soon it will be before those 23 other laws are updated with similar types of surveillance rules.
39. Individuals who used the Flo app in the United States between Nov. 1, 2016, and Feb. 28, 2019, and entered menstruation or pregnancy information may qualify to submit a claim for a cash payment from a class action settlement totaling $59.5 million. Flo Health Inc. agreed to pay $8 million, Google LLC will pay $48 million and Flurry LLC will pay $3.5 million to settle a class action lawsuit alleging they shared users’ sensitive health information with third parties through the Flo app without proper notice or authorization. INSIGHTS: More and more of these types of judgments, for not giving notice and/or not obtaining authorization/consent to collect personal data from individuals are increasing. Pay attention to what data organizations are collecting from you and see if they gave you notice or obtained your explicit consent. If you are an organization, check to see if you are giving notices and obtaining explicit authorizations/consent to obtain personal information.
40. On June 13, 2026, the U.S. government’s authorization under Section 702 of the Foreign Intelligence Surveillance Act (FISA) to monitor communications of noncitizens outside the country without a warrant expired. “The expiration doesn’t necessarily mean U.S. intelligence agencies no longer have that tool, because the provision was court-approved in March for another year.” However, “Telecommunications companies, concerned about getting into legal trouble, might not want to provide information needed for that intelligence-gathering,” because it was not renewed. However, a “substantial group of Republicans agree that Section 702 should be reformed, and Republican Sen. Rand Paul of Kentucky is content to let it expire without meaningful changes that ensure Americans’ privacy.” INSIGHTS: As of this publication on Tuesday, July 7, Section 702 of FISA is still expired. We agree that there needs to be meaningful changes to help ensure more privacy protections are required so collection and use of personal information are limited to only specific purposes and timeframes, authorized, documented, accountable, and audited by independent and objective certified and experienced auditors.
| | Check out our Privacy & Security Brainiacs blog page for more unique security and privacy news items. Have you run across any surprising, odd, offbeat or bizarre security and/or privacy news? Please let us know! We may include it in an upcoming issue. | | |
Privacy & Security Questions and Tips
Rebecca answers hot-topic questions from Tips readers
July 2026
| | |
We continue to receive a wide variety of questions about security and privacy. Questions about current hot topics in society, and increasingly more about healthcare privacy and security. Thank you for sending them in! This month, our Question of the Month asks about video surveillance systems, and related security, privacy and legal compliance issues. The other three questions cover how the current economic challenges impact physical security, most harmful U.S. 250th birthday crimes, and real-life 2026 World Cup privacy and security crimes.
Are the answers interesting and/or useful to you? Please let us know! Keep your questions coming!
| | Image created by Rebecca Herold using Gemini Image. | Q1: Do today’s video systems generally require more cameras or fewer cameras, and why? What are the associated privacy, cybersecurity, and data protection legal requirements risks? | | |
A1:
Current and emerging types of video systems are undergoing a massive architectural shift. The question of whether today’s video systems require more or fewer cameras doesn't have a single blanket answer because it depends on the primary product and business objective for using any particular video system. There are two distinct, parallel trends driven by advanced video technology:
First, for organizations needing fewer cameras for basic situational awareness and perimeter security the options include advanced hardware and panoramas. Favorite tech include multi-sensor and panoramic cameras. A single multi-sensor or 360-degree fisheye camera can cover an entire parking lot or retail floor, replacing 3 to 4 legacy fixed bullet cameras. For pan-tilt-zoom (PTZ) optimization, high-resolution 4K and thermal PTZ cameras can scan massive areas and zoom in dynamically, eliminating the need for interstitial filler cameras to cover blind spots.
Second, for organizations needing more cameras, the number of AI and data fabric tech is increasing dramatically. When video surveillance moves from a passive security tool to an operational data source, the physical camera count often spikes. Granular video AI and the associated analytics that provide organizations with computer vision to track operational efficiency (monitoring specific manufacturing assembly steps, analyzing precise retail queue wait times, executing facial recognition, etc.) require highly specific, uncompromised viewing angles, which then necessitates more cameras. Also, as organizations shift toward AI-driven video analytics, cameras are increasingly treated like data sensors. Capturing high-quality, continuous feeds for machine learning algorithms require installing more targeted cameras across facilities to collect more data and feed into the data ecosystem.
As these systems migrate to IP-based networks they are creating “video surveillance as a service” (VSaaS) cloud architectures with AI-enabled platforms, that are then inherently creating many digital security, privacy and compliance risks.
Privacy risks: There are many! Here are a few. Video footage that includes capturing individuals and areas where individuals are demonstrably located establish new types and huge amounts of personal information. Video cameras are also processing biometric data (facial geometry, gait analysis, automated behavioral tracking, etc.), which then makes the personal information particularly sensitive. Organizations are also increasingly using video systems to dynamically profile individuals (automated content, behavior recognition, etc.), which crosses a major privacy violations threshold. If a system collected data for "building security" but is quietly repurposed for "employee productivity tracking," it violates core privacy principles. Continuous 24/7 high-resolution cloud storage creates massive honey pots of personal data which attracts the attention of growing numbers of cybercrooks. Without enforcing strict retention and automated deletion cycles ensures that unnecessary, sensitive personal data is permanently exposed to risk.
Cybersecurity risks: Surveillance cameras are basically specialized internet-of-things (IoT) computers hanging on walls. Outdated firmware, unpatched vulnerabilities, and default credentials that are never changed make them prime targets for threat actors looking to gain access into a corporate network or recruit devices into massive botnets. Legacy systems often stream video over unencrypted protocols (like basic real-time streaming protocol (RTSP)). Without modern transmission security (SRTP, TLS, etc.), malicious actors can easily intercept, view, or inject spoofed video feeds into the video management system (VMS). Many global camera manufacturers have faced significant regulatory scrutiny and bans due to hidden backdoors, proprietary vulnerabilities, and nation-state-sponsored security concerns.
Legal and regulatory compliance risks: Landmark legal frameworks like the EU AI Act strictly regulate or outright ban certain high-risk video AI use cases (biometric categorization, real-time public facial recognition, etc.). In the US, state-level privacy updates continue to heavily restrict the processing of biometric identifiers without explicit, opt-in consent. Many different regulators (the FTC, state Attorneys General, European DPAs, etc.) are aggressively checking organizations’ security and privacy claims. Under current standards, failing to implement basic security hygiene (multi-factor authentication (MFA) on VMS access, encryption for backup databases, etc.) can trigger multi-million-dollar penalties for deceptive or unreasonable security practices, even if a formal breach hasn't occurred. Also, centralizing video data in the cloud frequently triggers cross-border data transfer violations if the cloud architecture routes biometric or sensitive footage through restricted jurisdictions or "countries of concern" under national security directives.
| | |
(Somewhat) Quick Hits:
Here are three more questions, most of which we are answering at a comparatively high level. We provide more in-depth information and associated details about these topics in separate blog posts, videos on our YouTube channel, in infographics and e-books, LinkedIn posts to our business page, and within our online training and awareness courses.
| | |
Q2: How is the broader economic climate impacting physical security?
A2:
Physical security is a significant information security tool, in addition to providing safety to property and people. Broader economic shifts directly shape physical security by constraining budgets, altering risk tolerance, and changing threat landscapes. Inflation, tariffs, and reduced demand have forced many organizations to scale back guard staffing, delay security system upgrades, and consolidate facilities, creating coverage gaps at entrances, monitoring stations, and critical infrastructure points. These reductions are often visible to adversaries. For example, in 2024, several U.S. retail chains reported massive increases in organized theft after reducing in-store security presence, while a Midwest manufacturing plant experienced a break-in targeting copper and network hardware during a temporary shutdown where physical security posts were left unattended and systems unmonitored. Similarly, healthcare facilities have reported unauthorized physical access incidents linked to reduced staffing and relaxed access control enforcement. Economic strain also increases insider risk as job insecurity rises. Insurers then raise premiums and tighten requirements for both physical and cyber protections, further pressuring organizations to balance cost control with maintaining layered security programs.
If you want to discuss the details in more depth or get more information about how physical security impacts privacy and information security, let us know. We’d be happy to help you.
| | Q3: What are the most privacy harmful U.S. 250th birthday crimes or scams that are currently being used? | | |
A3:
The most privacy-harmful scams tied to America 250 right now appear to be fake commemorative merchandise and coins, bogus event or fireworks ticket offers, and patriotic charity/donation scams. Here are some current commonly reported America 250 frauds, red flags, and associated harms to those who fall victim to these criminal tactics:
- Fake “official,” America 250 branding. They typically are from unknown sellers, with prices that seem too good to be true, lookalike websites for legitimate brands, and demands for payments with gift cards, wire transfers, or cryptocurrency. Once the money is sent, the victims either receive counterfeit or low-quality items, or do not receive them at all. And besides having the victims’ money, they also typically collect a lot of personal data that they then put on the dark web and sell to as many other crooks as they can to make even more money off the victims.
- Ticket and event fraud. Communities across the U.S. planned massive festivals, historical reenactments, and fireworks displays. Cybercriminals tried capitalizing on the hype by setting up fake event pages, selling counterfeit tickets, or offering non-existent "VIP front-row access" passes to major national events. Some scams push fireworks or event tickets through social media posts, direct messages, or resale links instead of official venues. Beyond financial loss, these fake ticket and event portals frequently use malicious forms designed to harvest account credentials and an abundance of other valuable personal data, including financial, health, and location data. They are also tricking users into downloading malicious PDF "e-tickets" that install spyware or infostealers on their devices.
- Donation and charity scams. Fraudsters may imitate patriotic or veteran-related causes to collect money and personal information. Scammers are spoofing legitimate veteran foundations or establishing completely bogus patriotic funds claiming to support "historic 250th education programs" or "wounded service members' holiday celebrations." Ultimately the money that victims sent intended for a good cause goes straight to a fraudster, and the donor's financial profile is added to "sucker lists" shared among global phishing networks.
Don’t fall for these unpatriotic tactics. Only buy from official brands and sources, verify the charities independently, and use a credit card so you can dispute fraudulent purchases. The U.S. Mint (USmint.gov) is the only authorized manufacturer of official 250th coins, and the official national organization operates strictly through Store.America250.org. For charities, always look up the organization on Give.org before donating a single dime.
| | |
Q4: What are some examples of actual 2026 World Cup privacy and information security crimes that have already occurred?
A4:
There have been many privacy and data security scams related to the 2026 World Cup, throughout the past year, and also going on right now, and for the coming weeks. Here are some examples of actual World Cup-related privacy and information security crimes or active criminal campaigns that have been reported so far during the 2026 FIFA World Cup. Most are designed to steal personal data, financial information, login credentials, or install malware. Here are just a few of the hundreds that have and continue to be targeting soccer (football) fans.
1. Fake FIFA ticket websites. The FBI warned that criminals created spoofed FIFA websites selling fake tickets and hospitality packages. Harms included the cybercrooks stealing names, addresses, passport information, payment cards, login credentials, and identity information.
2. AI-enhanced phishing campaigns. Security researchers identified thousands of fraudulent World Cup domains using AI-generated content, cloned websites, and fake QR codes. Harms included credential theft, identity theft, malware delivery, and account compromise.
3. Fake streaming platforms. Criminals promoted unofficial streaming sites that harvested credentials or installed malware on users' devices. Password theft, banking malware, browser credential theft, and financial fraud.
4. FIFA employment phishing scam. Multiple communities warned residents about fraudulent FIFA hiring emails inviting recipients to "interviews" that collected personal information. Identity theft through collection of resumes, Social Security numbers, addresses, and employment information.
5. Large-scale ticket fraud in Mexico. Mexican authorities arrested or sought suspects accused of defrauding fans of nearly US$1.7 million through fake World Cup ticket sales; one incident reportedly escalated to armed robbery. Financial fraud combined with theft of personal and payment information.
6. ATM skimming operations. Law enforcement in New York expanded operations against ATM and point-of-sale skimming ahead of World Cup matches and related celebrations. Theft of payment card numbers, PINs, and banking credentials.
7. Fake visas, travel packages, and cryptocurrency scams. Researchers documented fraudulent "World Cup visa" services, counterfeit travel bookings, and fake cryptocurrency projects claiming affiliation with FIFA. Identity theft, passport theft, financial fraud, and credential harvesting.
Here are my “Top 10 Red Flags” for these types of scams:
a. "Only a few tickets left!" or other urgent pressure statements.
b. Requests for payment by gift card, cryptocurrency, wire transfer, or peer-to-peer payment apps.
c. Unsolicited emails or text messages with links or QR codes.
d. Requests for your Social Security number, passport, or driver's license when it's not clearly necessary.
e. Requests for one-time passcodes or multifactor authentication (MFA) codes.
f. Websites with misspelled URLs or unfamiliar domains.
g. Deals that seem too good to be true.
h. Unexpected requests to download an app or software.
i. Requests to log in through a link instead of the organization's known website.
j. Poor grammar, generic greetings, or inconsistent branding.
| | We hope you found the previous news items and questions/answers interesting and/or useful! Please send us any other security, privacy and/or compliance questions you have. We thank you for reading the monthly Privacy Professor Tips! | | |
Security Informed included a short article I wrote answering their question, “How Do Changes in the Broader Economic Climate Impact Security.”
We are excited to provide ways for MSPs, law firms, and other professional services organizations to offer our monthly tips to their clients! It is already working well for some such organizations. Get in touch with us for the details!
| | If you are a HIPAA business associate (BA) have you and the others in your organization taken your HIPAA security and privacy training for the year yet? If you are a HIPAA covered entity (CE), have you checked to ensure your Bas have taken their training? HIPAA requires security and privacy training, and the HHS OCR has indicated in all their HIPAA non-compliance settlements that such training needs to occur at least once a year. We can help you! Take our “HIPAA Basics for Business Associates: 2026 Edition”, which includes many supplemental materials you can use during the course of your business activities. Click here for more information. | |
What topics would you like to see us create videos, and more formal online courses, for? Let us know!
Have questions about our education offerings? Contact us!
| | |
Permission to Share
If you would like to share, please forward the Tips message in its entirety. You can share excerpts as well, with the following attribution:
Source: Rebecca Herold. July 2026 Privacy Professor Tips
www.privacysecuritybrainiacs.com.
NOTE: Permission for excerpts does not extend to images.
Privacy Notice & Communication Information
You are receiving this Privacy Professor Tips message as a result of:
1) subscribing through PrivacyGuidance.com or PrivacySecurityBrainiacs.com or
2) making a request directly to Rebecca Herold or
3) connecting with Rebecca Herold on LinkedIn.
When LinkedIn users invite Rebecca Herold to connect with them, she sends a direct message when accepting their invitation. That message states that in the spirit of networking and in support of the communications that are encouraged by LinkedIn, she will send those asking her to link with them her monthly Tips messages. If they do not want to receive the Tips messages, the new LinkedIn connections are invited to let Rebecca know by responding to that LinkedIn message or contacting her at rebeccaherold@rebeccaherold.com.
If you wish to unsubscribe, just click the SafeUnsubscribe link below.
| | | | |