8776363957
Connect with us:
LinkedIn link
Facebook link
Twitter link
YouTube link
Gigabit Systems logo
Link to home
Who We AreManaged ServicesCybersecurityOur ProcessContact UsPartners
The Latest News in IT and Cybersecurity

News

A cloud made of diagonal linesA cloud made of diagonal lines
A pattern of hexagons to resemble a network.
Cybersecurity
Technology

Remote access doesn’t let someone watch your computer. It can let them operate it.

August 31, 2026
•
20 min read

Remote Access: The Moment You Click “Allow,” They Can Become You

Remote access doesn’t let someone watch your computer. It can let them operate it.

One of the most dangerous sentences you can hear on the phone is:

“I just need to connect to your computer for a minute.”

Remote access itself isn’t malicious.

IT departments and managed IT providers use remote-access software every day to troubleshoot computers, install software, maintain servers and help employees.

But scammers use many of the exact same tools.

And that’s what makes remote-access scams so effective.

There may be no sophisticated hacking involved.

No zero-day vulnerability.

No attacker breaking through your firewall.

You install the software. You approve the connection. You open the door yourself.

Once you understand what remote access can actually give another person, you’ll understand why that approval should be treated almost like handing someone your unlocked computer.

What Does “Remote Access” Actually Mean?

Remote-access software allows another computer to interact with yours over the internet.

Depending on the software and permissions granted, the remote person may be able to see your screen, move your mouse, type on your keyboard, open applications, browse files, download or upload information, change settings, install software, access websites you’re already signed into and potentially establish persistent access.

In other words:

They may be sitting 5,000 miles away, but your computer can behave as though they’re sitting in your chair.

Common legitimate remote-support products include TeamViewer⁠, AnyDesk⁠, ConnectWise ScreenConnect⁠ and Microsoft’s built-in Quick Assist⁠.

These are legitimate tools.

The danger is who you’re giving control to.

The Scam Can Start With Something Completely Innocent

You get a phone call.

“This is your bank’s fraud department.”

Or a popup:

“Your computer has been infected. Call Microsoft immediately.”

Or an email:

“There’s a problem with your account.”

Or someone claiming to be:

Your company’s IT department.

Microsoft.

Apple.

Amazon.

Your bank.

QuickBooks support.

Your internet provider.

The IRS.

A software vendor.

The attacker doesn’t necessarily need to hack your computer.

They need to convince you to give them access.

The FTC specifically warns about tech-support scammers asking victims to provide remote access to their computers, and the FBI has repeatedly warned about criminals using remote-desktop software in financial scams.

Then They Ask You to Install Something

This is the moment that should immediately raise your defenses.

They may tell you:

“Go to this website.”

“Download this support tool.”

“Read me the number on your screen.”

“Click Allow.”

The software might be completely legitimate.

That’s important.

Your antivirus might not block it because there’s nothing inherently malicious about the application.

The scammer is abusing a legitimate administrative tool.

That’s sometimes called living off trusted tools.

Instead of breaking into the house:

They convince the homeowner to hand them the key.

What Can They See?

Potentially, almost anything you can see.

Your desktop.

Your email.

Your browser.

Documents.

Photos.

Accounting software.

Customer information.

Company files.

Browser tabs.

Cloud applications.

Depending on the environment and authentication state, that could include sensitive business systems.

Remember something extremely important:

Being logged in is itself valuable.

Suppose your Microsoft 365 account has MFA.

Excellent.

But you’re already logged into Outlook.

The attacker remotely controls your computer and opens Outlook.

Your MFA hasn’t been “hacked.”

Your authenticated session may already be sitting there waiting for them.

The same concept can apply to other applications and websites.

Can They See Your Passwords?

Sometimes.

If you type a password while someone can view or control the computer, assume they may be able to observe it.

They may also try to get you to reveal credentials directly, access passwords stored insecurely, manipulate browser sessions, install additional malware or convince you to authenticate something yourself.

This is why a scammer might say:

“For security, please log into your bank.”

That sentence should terrify you.

You’re authenticating yourself.

For them.

Can They Access Your Bank Account?

If you’re logged in—or they convince you to log in—the consequences can be severe.

A common remote-access scam involves convincing the victim that a refund, fraud investigation or account correction requires access to online banking.

The scammer may manipulate what appears on the screen or attempt to persuade the victim to transfer money.

The FBI has specifically warned that criminals use remote desktop software in fraudulent schemes involving financial accounts.

Your bank account didn’t necessarily get “hacked.”

You logged into it from your legitimate computer, and someone else was controlling that computer.

That’s an important distinction.

Can They Steal Files?

Potentially, yes.

Many remote-access platforms support file transfer.

Even without an obvious file-transfer feature, an attacker with sufficient access could potentially copy information through other means or install additional software.

For businesses, that means remote access can expose:

Customer records.

Employee information.

Tax documents.

Contracts.

Financial statements.

Legal documents.

Medical information.

Intellectual property.

Passwords and credentials.

Cyber insurance information.

And potentially access to other systems.

This is where a simple scam can become a data breach.

Can They Install Something That Lets Them Come Back Later?

This is one of my biggest concerns.

There’s an enormous difference between:

One-time support access

and:

Unattended access.

Some remote-management products are intentionally designed so authorized IT personnel can reconnect later without someone sitting at the computer approving every session.

That’s extremely useful for legitimate IT management.

It’s also extremely dangerous when configured by an attacker.

A scammer may attempt to install additional remote-management software, configure unattended access, create accounts, establish persistence or deploy malware.

So closing the window does not necessarily answer the important question:

Can they get back in?

“I Disconnected Them. Am I Safe?”

Don’t assume so.

If an unknown person had remote access to your computer, treat the incident seriously.

The question isn’t only what you watched them do.

It’s:

What could they have done while they had access?

If you realize you’ve given a scammer remote access, disconnect the computer from the internet if practical and contact your organization’s IT department or MSP immediately.

For a personal computer, get trusted technical assistance and review the machine for unauthorized remote-access software or other persistence before using it for sensitive activity again.

Then, from a known-clean device, change passwords for accounts that may have been exposed, beginning with email and financial accounts, review MFA methods and active sessions, and contact your bank immediately if financial information or banking access was involved.

If it’s a business computer, don’t simply uninstall the remote-access application and declare victory.

It may now be an incident-response issue.

Businesses Have an Additional Problem

Remote-access software isn’t only a scam problem.

It’s an administrative-security problem.

Ask your MSP:

“Which remote-access applications are permitted on our computers?”

Then ask:

“Can employees install another one?”

If every employee can download arbitrary remote-control software, your carefully designed cybersecurity stack has an enormous hole.

An attacker doesn’t necessarily need to defeat your approved remote-management system.

They can convince an employee to install their own.

Your Cybersecurity Tools May See Legitimate Software

This is what makes the problem tricky.

An EDR platform may recognize TeamViewer or another tool as legitimate software.

Because it is.

The malicious part is intent.

A hammer isn’t malware.

Neither is a remote-support application.

The question is:

Who is holding it?

Organizations should therefore control which remote-management tools are permitted, restrict unauthorized applications, monitor their installation and use, remove unnecessary software, enforce least privilege and train employees to recognize unexpected support requests.

For healthcare IT, law firms and schools, this becomes especially important because a single remotely controlled endpoint may expose highly sensitive patient, client or student information.

Create One Simple Company Rule

Every employee should know this:

Never grant remote access because someone unexpectedly called, emailed or texted you.

If “Microsoft” calls:

Hang up.

If “your bank” calls:

Hang up and call the number you already trust.

If someone says they’re your MSP:

Call your MSP using the number you already have.

If your CEO supposedly needs someone connected urgently:

Verify independently.

The legitimate technician won’t be offended by verification.

Your employees don’t need to become cybersecurity experts.

They need permission to say:

“I’ll call our IT department first.”

And Never Trust Caller ID

A phone displaying your bank’s name does not prove your bank is calling.

A Microsoft logo doesn’t prove Microsoft created the popup.

An email signature doesn’t establish identity.

A person’s knowledge of your name, company or computer doesn’t establish identity either.

Attackers build credibility before asking for access.

The remote-access request is often simply the final step.

There’s a Powerful Cybersecurity Principle Here

We spend enormous amounts of money trying to keep attackers outside.

Firewalls.

MFA.

EDR.

Email security.

DNS filtering.

Zero Trust.

Conditional Access.

Encryption.

Then someone calls an employee and says:

“Click Allow.”

And suddenly the attacker may be operating from an endpoint we’ve already trusted.

That’s why cybersecurity cannot only protect machines.

It has to prepare people.

Before You Give Anyone Remote Access, Ask One Question

Did I initiate this support request?

If you called your trusted IT provider because your printer isn’t working and they ask to connect:

Normal.

If somebody unexpectedly contacts you and then asks to control your computer:

Stop.

Verify them independently.

Because once somebody remotely controls your computer, the important question is no longer:

“Can they hack me?”

It’s:

“What can I do on this computer that they can now potentially do too?”

And that’s why remote access should be treated like a physical key.

You wouldn’t let a stranger who called you unexpectedly into your office and leave them alone at your desk.

Don’t do the digital equivalent.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #ManagedIT #RemoteAccess #ScamAwareness #DataProtection


If a stranger gets remote access to your computer, assume they can do almost anything you can. Here’s what that actually means.

Technology
Cybersecurity
Must-Read

China Hacked NASA. Your Router May Have Helped.

August 30, 2026
•
20 min read

China Hacked NASA. Your Router May Have Helped.

The hackers didn’t need their own infrastructure. They borrowed ours.

NASA.

The Federal Reserve.

The Department of Justice.

The Department of Energy.

The Department of Health and Human Services.

The National Institutes of Health.

The United States Senate.

Hospitals.

Financial institutions.

Power companies.

Defense contractors.

According to the U.S. government, Chinese state-sponsored hackers have spent years attacking some of America’s most sensitive networks.

This week, the Justice Department and FBI announced that they had disrupted two of the platforms allegedly helping them do it:

QScan and QTRouter.

And buried underneath the spectacular list of government targets is a cybersecurity lesson every small business should understand.

The infrastructure used to hide these attacks wasn’t necessarily sitting inside some secret Chinese intelligence facility.

It included ordinary compromised devices scattered around the world.

Routers.

Security cameras.

Other Internet of Things equipment.

Potentially the same kinds of devices sitting inside millions of American businesses right now.

First, Meet QScan

According to the Justice Department, a China-based group known as QTFY operated QScan.

QScan essentially searched the internet looking for vulnerable IoT devices.

When it found exploitable equipment, it could automatically compromise those devices.

Thousands of infected devices could then be fed into the second part of the operation:

QTRouter.

Now things get considerably more interesting.

QTRouter Made China Look Like Your Neighborhood

Imagine I’m sitting in China and want to attack an organization in New York.

If I connect directly from China, defenders might immediately become suspicious.

They see:

Login from China.

Block.

Investigate.

Alert the SOC.

So instead, imagine I’ve compromised a router inside a completely unrelated American business.

I route my attack through that router.

The target doesn’t necessarily see:

Attacker in China.

It sees:

Traffic coming from somewhere in America.

Potentially somewhere very close to the victim.

That’s essentially the purpose of an obfuscation network.

The Justice Department says QTRouter combined compromised IoT devices with commercial proxy devices and leased virtual private servers to conceal the Chinese origin of malicious activity.

The FBI says compromised equipment existed across more than 130 countries.

The hacker is thousands of miles away.

The attack appears to be coming from down the street.

That’s an Extremely Powerful Cybersecurity Weapon

Security systems use context.

Where is this connection coming from?

Has this IP address been malicious before?

What country is it in?

Does the geography make sense?

Is it associated with a hosting provider?

Is it a known VPN?

Is it a residential ISP?

Attackers understand those controls.

So they disguise themselves.

A compromised router inside a legitimate American network gives an attacker something valuable:

Reputation.

The IP address may not look malicious.

The geography may not look suspicious.

The device may have existed there for years.

Nobody bought infrastructure specifically for the attack.

Nobody necessarily noticed anything strange.

It’s someone else’s equipment.

That’s why compromised routers and IoT devices have become such useful infrastructure for sophisticated attackers.

Now Look at Who They Targeted

According to court documents, QTFY’s activity dates back to at least 2018.

Targets and victims identified by U.S. authorities included NASA, the Federal Reserve, DOJ, DOE, HHS, NIH and the U.S. Senate, along with organizations in critical infrastructure and the private sector.

Reuters reports that investigators traced an attempted 2019 NASA intrusion involving exploitation of a Pulse Secure VPN vulnerability back to infrastructure and accounts connected to China.

The campaign continued for years.

The FBI was still investigating activity connected to an attack targeting the U.S. Senate in 2026.

Think about that timeline.

  1. 2018.

  2. 2019.

  3. 2020.

  4. 2021.

  5. 2022.

  6. 2023.

  7. 2024.

  8. 2025.

  9. 2026.

Cyber espionage isn’t necessarily somebody smashing through your firewall one night.

Sophisticated campaigns are infrastructure businesses.

Attackers build systems.

Maintain access.

Develop tools.

Acquire vulnerable devices.

Build proxy networks.

Sell services.

Replace infrastructure that gets discovered.

Then keep operating.

This Was Apparently a Business Too

This is another fascinating part.

The Justice Department alleges QTFY works through a Chinese company called Nanjing Xinjiuwei Network Technology Company.

According to U.S. authorities, the company offered hacking services to paying customers—including China’s Ministry of State Security and People’s Liberation Army.

Think about what that means.

We sometimes picture nation-state hacking as government employees sitting inside military buildings.

Modern cyber operations can be much messier.

Private contractors.

Hackers-for-hire.

Government customers.

Commercial infrastructure.

Stolen infrastructure.

Compromised consumer equipment.

Proxy services.

Botnets.

It’s an ecosystem.

The FBI described the company as operating within a complex network of hackers-for-hire and government customers.

Cybercrime and cyber espionage have supply chains too.

So How Did America Shut It Down?

This part is wonderfully simple.

The FBI didn’t need to find every compromised camera and router around the world.

Investigators identified something the system depended upon:

Three domain names.

According to the FBI affidavit, they were:

qtproxy.xyz

qt-proxy.org

qt-team.com

Those domains performed essential functions for QScan and QTRouter, including communication and authentication.

The government obtained court-authorized seizure warrants.

Then it seized them.

And because those domains were hard-coded into the platforms, DOJ says the seizures rendered QScan and QTRouter inoperable.

That’s a beautiful incident-response lesson.

You don’t necessarily have to destroy every component of an attack.

Find what the system depends on and break that dependency.

Your $80 Router Can Become Part of a Nation-State Operation

Here’s where this stops being a Washington story.

Imagine you run a 25-person business.

You have:

A firewall.

Three wireless access points.

Six security cameras.

A network video recorder.

Two smart TVs.

A door-access controller.

A printer.

A thermostat.

A conference-room system.

Maybe an old router installed by a vendor six years ago.

Which of those devices are being patched?

Who manages them?

What firmware versions are running?

Are default credentials still configured?

Can they be reached from the internet?

Do they have unnecessary remote-management services enabled?

Does your MSP even know they exist?

If you can’t answer those questions:

Neither can your cybersecurity program.

IoT Devices Are Computers

Businesses don’t think about them that way.

That’s the problem.

A security camera looks like a camera.

A printer looks like a printer.

A thermostat looks like a thermostat.

A router looks like an appliance.

But increasingly they’re all:

Computers connected to your network.

They have:

Operating systems.

Processors.

Memory.

Passwords.

Network services.

Firmware.

Cloud connections.

Remote-access capabilities.

Vulnerabilities.

And sometimes extraordinarily poor security.

The attacker doesn’t care that you call it a camera.

They see a Linux computer connected to the internet.

This Is Why Asset Inventory Matters

Here’s a cybersecurity exercise every SMB should perform.

Ask your MSP:

“Show me everything connected to my network.”

Not just Windows computers.

Everything.

Laptops.

Servers.

Phones.

Printers.

Cameras.

Access points.

Switches.

Firewalls.

Door controllers.

HVAC equipment.

Conference-room systems.

Smart TVs.

IoT devices.

Vendor equipment.

Unknown devices.

Then ask:

“Which of these are we actually responsible for securing?”

That second question usually gets more interesting.

Find the Forgotten Equipment

Some of the riskiest technology inside a business isn’t new.

It’s forgotten.

The camera installer put something in five years ago.

The HVAC contractor installed a gateway.

The phone vendor left a box.

The previous MSP installed a router.

Nobody remembers the password.

Nobody knows whether firmware updates exist.

Nobody knows whether the manufacturer still supports it.

But it’s still:

Powered on.

Connected.

Talking to the internet.

Attackers love forgotten technology.

Because defenders aren’t watching it.

Cameras Deserve Special Attention

Security cameras are particularly interesting.

Companies install them specifically to improve physical security.

Then forget that they’re network devices.

Check:

Are they segmented from employee computers?

Can they reach the internet?

Can the internet reach them?

Are default passwords gone?

Is remote access enabled?

Is firmware supported?

Who has administrator access?

Does the installer still have access?

Where does footage go?

What cloud services are involved?

If your camera gets compromised, the problem isn’t merely somebody potentially watching it.

It can become somebody else’s computer inside your network.

That’s a much bigger problem.

Stop Exposing Things Directly to the Internet

This lesson keeps appearing across cybersecurity incidents.

If something does not need to accept unsolicited connections from the public internet:

Don’t let it.

Especially:

Routers.

Cameras.

NAS devices.

Remote-management interfaces.

Industrial controllers.

Building automation.

Old VPN appliances.

Remote Desktop.

Internet-connected storage.

Reduce the attack surface.

Use secure remote-access architectures.

Patch internet-facing equipment aggressively.

Replace unsupported devices.

Disable unnecessary services.

Segment IoT networks.

Monitor outbound connections.

Use strong unique credentials.

And where supported, enable MFA.

Basic cyber hygiene becomes extremely powerful when performed consistently.

Network Segmentation Matters Here Too

Imagine an attacker compromises your security camera.

What can that camera reach?

If the answer is:

Employee laptops.

Servers.

Accounting systems.

Backups.

Domain controllers.

Printers.

Everything.

You have another problem.

IoT equipment should generally live on networks appropriate to its function, with tightly controlled communication to other environments.

Your cameras don’t need to talk to accounting.

Your guest Wi-Fi doesn’t need to reach your server.

Your smart television doesn’t need access to your backup infrastructure.

Your thermostat doesn’t need to communicate with employee laptops.

Make attackers cross walls.

Don’t hand them a flat network.

Geographic Blocking Isn’t Enough

This attack also demonstrates an important limitation of country blocking.

I like geographic restrictions where appropriate.

If your 30-person New York business has no employees, customers or vendors in certain countries, there may be very little reason to accept authentication attempts or remote-management traffic from them.

That’s useful.

But don’t confuse it with complete protection.

Because sophisticated attackers know exactly what you’re doing.

They route through:

Compromised American routers.

Residential proxies.

Cloud infrastructure.

VPNs.

Other victims.

The attacker can be sitting in Beijing while your firewall sees:

New Jersey.

That’s why cybersecurity can’t rely on IP geography alone.

Identity.

Device health.

Behavior.

MFA.

Conditional Access.

Least privilege.

Endpoint security.

Logging.

Those layers matter.

This Is Also Why “Trusted IP” Can Be Dangerous

Businesses love allowlists.

This IP address belongs to our vendor. Trust it.

Be careful.

IP addresses aren’t identities.

Infrastructure gets compromised.

Credentials get stolen.

Cloud systems change.

VPN exit points get abused.

A request coming from an expected network location does not automatically mean:

The expected human generated it.

Modern Zero Trust architecture is built around exactly this assumption:

Don’t trust something simply because of where it came from.

Verify.

The Government Didn’t End Chinese Cyber Espionage

Another important distinction:

The FBI disrupted these platforms.

That doesn’t mean the underlying threat disappeared.

The seized domains were important enough that DOJ says QScan and QTRouter became inoperable.

That’s significant.

But sophisticated threat actors rebuild.

New domains.

New malware.

New exploits.

New proxies.

New compromised devices.

New contractors.

This is why cybersecurity isn’t a project you finish.

It’s an operating function.

We’ve Seen This Movie Before

This isn’t even the first time the FBI has disrupted Chinese state-backed infrastructure built from other people’s compromised devices.

In 2023, the FBI disrupted a botnet used by Volt Typhoon to conceal attacks against critical infrastructure.

In 2024, authorities disrupted infrastructure involving hundreds of thousands of compromised IoT devices associated with Flax Typhoon.

In 2025, the FBI removed PlugX malware from more than 4,000 U.S. computers associated with the China-linked Mustang Panda operation.

And now:

QScan and QTRouter.

There’s a pattern here.

Other people’s vulnerable devices are useful national-security infrastructure.

Make sure yours aren’t among them.

Cybersecurity Isn’t Just About Protecting Your Data

This is the bigger lesson.

Most business owners think cybersecurity means:

Protect my company from being hacked.

That’s obviously important.

But an insecure device can create another problem.

Your infrastructure can be weaponized against somebody else.

Your router.

Your camera.

Your server.

Your compromised cloud account.

Your website.

Your email.

Your IP address.

Suddenly your company isn’t necessarily the ultimate target.

You’re infrastructure.

That’s why patching a forgotten router matters even if there’s “nothing important on it.”

The attacker may not want what’s inside the router.

They want where the router is.

A legitimate American IP address.

A foothold.

A proxy.

A place to hide.

And according to the U.S. government, Chinese state-sponsored hackers built an entire operation around exactly that idea.

NASA and the Federal Reserve make spectacular headlines.

But the cybersecurity lesson is sitting somewhere much closer to home:

That forgotten camera or router in the corner isn’t too insignificant for a nation-state hacker.

It might be exactly what they’re looking for.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #ManagedIT #IoTSecurity #DataProtection #SMB


China hacked NASA and the Federal Reserve by hiding behind ordinary routers and cameras. Is yours patched?

Technology
AI
Cybersecurity

Meta didn’t just settle. It agreed to change the product.

August 28, 2026
•
20 min read

Meta Just Agreed to Pay $17 Billion. The Money Isn’t the Biggest Part.

Meta didn’t just settle. It agreed to change the product.

Last week, I wrote about what was being called social media’s “Big Tobacco moment.”

Meta was heading into federal court in California facing accusations from states across America that Facebook and Instagram were deliberately designed in ways that encouraged compulsive use among children and teens.

Meta denied the allegations.

The numbers being discussed were almost absurd.

Meta’s attorneys warned that the states’ theories could theoretically produce penalties reaching:

$1.4 trillion.

The states suggested something closer to $200 billion.

The trial began August 18.

Eight days later:

It’s over.

Meta has agreed to a landmark multistate settlement worth up to approximately $17.1 billion, along with significant mandatory changes to Facebook and Instagram. The agreement resolves claims involving 47 states plus Washington, D.C. and U.S. territories, although the federal case itself involved claims from 29 states.

And once again, I think everybody is going to focus on the wrong number.

$17 Billion Is Enormous

Let’s not minimize it.

State officials are calling this the largest state consumer-protection settlement in American history outside the tobacco settlements of the 1990s.

Texas alone says it will receive more than:

$1 billion.

Tennessee expects approximately:

$752 million.

Washington, D.C. says it will receive somewhere between approximately:

$90 million and $129 million.

Meta is also resolving separate privacy litigation involving the Cambridge Analytica scandal, with California, Illinois, New Mexico and Washington, D.C. receiving another $459.3 million related to those cases.

This is real money.

But Meta makes real money.

That’s why the more consequential sentence in this settlement may not contain a dollar sign.

Meta Has to Change Instagram and Facebook

This wasn’t simply:

Pay the states and continue doing business.

Meta agreed to change how its platforms operate for younger users.

According to Reuters, the settlement requires nationwide safeguards including:

Daily usage limits.

Restrictions on nighttime usage.

Additional protections intended to prevent minors from accessing age-inappropriate material.

Other reporting on the settlement describes additional changes involving school-hour notifications, parental controls and certain appearance-altering filters.

Think about what that means.

For years, the central question was:

Should parents control how much social media their children consume?

This settlement pushes the conversation somewhere very different:

What responsibility does the company designing the product have to prevent children from consuming too much of it?

That’s a profound shift.

The Product Was the Case

This distinction is critical.

The states weren’t simply arguing:

“Bad content exists on Instagram.”

That becomes complicated because Section 230 has historically provided technology platforms substantial protection from liability for content created by third parties.

Instead, prosecutors attacked the design of the product itself.

The algorithms.

Notifications.

Engagement mechanisms.

Features designed to keep people returning.

Age verification.

Data collection.

The allegation was essentially that the harm wasn’t merely happening on the product.

The states argued portions of the harm were being created by how the product was engineered.

Meta has denied wrongdoing in agreeing to the settlement.

But agreeing to redesign parts of Facebook and Instagram is very different from simply paying a fine.

Think About the Business Model

Social-media platforms have an unusual economic incentive.

You generally aren’t paying Instagram every month.

Advertisers are paying Meta.

That makes one resource extraordinarily valuable:

Your attention.

The longer you stay:

More content can be served.

More advertisements can be displayed.

More behavioral information can be gathered.

More opportunities exist to bring you back.

That doesn’t mean every engagement feature is malicious.

Notifications can be useful.

Recommendations can be useful.

Autoplay can be convenient.

Personalization can improve a product.

But when the user is a child, society is increasingly asking whether the same engagement-maximizing machinery should operate under different rules.

The Meta settlement suggests regulators believe the answer is:

Yes.

Imagine This Rule Applied to Other Industries

This is where the precedent gets interesting.

For decades, technology companies have essentially optimized:

Make the product as engaging as possible.

That’s considered good product design.

More daily active users.

More time in the app.

More engagement.

Higher retention.

Those are metrics executives celebrate.

But what happens when maximizing engagement becomes legally dangerous for certain users?

Now the product team has competing objectives:

Increase engagement.

But enforce time limits.

Increase return visits.

But restrict notifications.

Personalize content.

But restrict what younger users can encounter.

Grow the user base.

But improve age assurance.

Suddenly:

Safety isn’t merely a feature. It’s an engineering constraint.

That idea could spread far beyond Meta.

The AI Part Shouldn’t Be Overlooked

There was another fascinating allegation in the case.

The states alleged Meta collected personal information from children under 13 without proper parental notification or consent in violation of the Children’s Online Privacy Protection Act.

And according to Reuters, prosecutors alleged that some of that information was used to train:

Machine-learning and generative AI models.

This was one of the most important parts of our previous article.

AI has changed the meaning of data retention.

Twenty years ago, if a company improperly collected a database, remediation might mean:

Find it.

Delete it.

Confirm deletion.

Done.

AI complicates that.

What happens when information has already contributed to training a model?

Deleting the original record doesn’t necessarily reverse whatever influence it had during training.

That’s going to become one of the defining data-protection questions of the AI era.

Every Business Using AI Should Learn From This

Your company probably isn’t Meta.

You probably aren’t training a frontier AI model.

But employees are increasingly putting company information into AI systems.

Customer records.

Contracts.

Meeting transcripts.

Email.

Support tickets.

Employee information.

Financial information.

Patient information.

Student information.

Source code.

Internal documents.

Before allowing that, ask:

Do we actually have the right to use this data this way?

That’s the question businesses keep skipping.

“We Already Had the Data” Doesn’t Mean “We Can Train AI With It”

This distinction will become enormously important.

Imagine a customer gave you their information to process an order.

That doesn’t automatically mean:

Use my information to train an AI system.

An employee gave HR personal information.

A patient gave a healthcare provider medical information.

A parent gave a school information about a child.

A client gave an attorney confidential documents.

The organization may legitimately possess that information.

That doesn’t automatically authorize every possible future use of it.

Data governance needs to distinguish between:

We possess it.

and:

We’re permitted to use it for this purpose.

Those aren’t the same thing.

Healthcare Needs to Be Extremely Careful

Healthcare organizations are rushing toward AI because the productivity possibilities are enormous.

Summarize records.

Draft notes.

Analyze documents.

Automate administrative tasks.

Assist clinicians.

But healthcare IT teams need to know exactly what happens when patient information enters an AI system.

Is the vendor permitted to receive PHI?

Is there an appropriate agreement?

Is information retained?

Can humans review it?

Can the provider use it to improve or train models?

Where is it processed?

Can it be deleted?

What logs exist?

Who has access?

A clever AI feature isn’t worth accidentally creating a data-protection problem.

Law Firms Have the Same Issue

Law firms possess some of the most sensitive information imaginable.

Attorney-client communications.

Litigation strategy.

M&A documents.

Financial records.

Trade secrets.

Evidence.

Personal information.

Uploading a document into an AI tool isn’t merely:

“Using software.”

You’re potentially transferring highly sensitive information into another computing environment.

Law Firm IT needs approved AI platforms, defined policies and technical controls rather than simply hoping every attorney understands the difference between consumer and enterprise AI services.

Schools Should Pay Particular Attention to This Settlement

This case is literally about children.

Meanwhile, schools are rapidly introducing:

AI tutoring.

Learning analytics.

Cloud platforms.

Student monitoring.

Educational applications.

Automated assessments.

Behavioral systems.

School Technology departments need to understand what those systems collect and what happens afterward.

What student information does the vendor retain?

Does it train models?

Can parents request deletion?

Does deleting the student’s account delete the underlying information?

Who owns generated data?

How long is it retained?

Can the vendor change its terms later?

Schools shouldn’t discover the answers after millions of student records have already entered a platform.

SMBs Need AI Governance Before They Think They Need AI Governance

This sounds like something only giant corporations need.

It isn’t.

A 30-person company can create an AI data problem remarkably quickly.

All it takes is one employee discovering:

“ChatGPT can summarize these customer files for me.”

Now hundreds of documents are being uploaded.

Was that approved?

Which account did they use?

What data was inside?

Was confidential information included?

What are the provider’s data controls?

Nobody knows.

That’s Shadow IT accelerated by AI.

Your MSP or managed IT provider should help establish:

Approved AI tools.

Acceptable-use rules.

Data classifications.

Access controls.

Employee training.

Logging where appropriate.

Vendor security reviews.

And clear rules governing confidential information.

Don’t wait until an employee has already uploaded three years of company history.

The Settlement Also Shows Why Regulators Care About Defaults

Cybersecurity professionals understand this extremely well.

Defaults matter.

Most people don’t change settings.

Give someone optional MFA?

Many won’t enable it.

Make MFA mandatory?

Almost everyone suddenly has MFA.

Give parents an optional screen-time control buried six menus deep?

Some will find it.

Change the platform’s default behavior?

Now you’ve changed behavior at scale.

That’s why product design can become more powerful than a warning label.

The architecture determines what happens automatically.

That’s a Lesson for Cybersecurity Too

Businesses frequently make the same mistake.

They tell employees:

Don’t click suspicious links.

Use strong passwords.

Don’t share confidential information.

Be careful.

Wonderful.

Then they leave the environment configured so one mistake can destroy the company.

Good cybersecurity doesn’t merely tell users to behave correctly.

It builds systems where mistakes are harder to make and less catastrophic when they happen.

MFA.

Least privilege.

EDR.

Email filtering.

Immutable backups.

Network segmentation.

DNS filtering.

Conditional Access.

Application controls.

Data Loss Prevention.

That’s the cybersecurity equivalent of changing the product rather than merely changing the warning.

Don’t just tell people to be safe. Design safety into the environment.

Meta Still Faces More Litigation

This settlement doesn’t make Meta’s legal problems disappear.

Reuters reports that Meta, Snap, YouTube and TikTok still face thousands of lawsuits from individuals, governments and school districts alleging that their platforms contributed to harms among children and teenagers.

Meta also suffered major losses earlier this year.

A New Mexico jury ordered the company to pay $375 million.

A judge later ordered another $567 million and imposed youth-safety requirements.

That’s $942 million in that case alone, although Meta has said it will appeal.

So today’s settlement isn’t necessarily the end of social media’s legal reckoning.

It may be the beginning of the template.

This Is Bigger Than Meta

Watch what happens next.

If one of the largest technology companies in the world agrees to:

Usage limits.

Nighttime restrictions.

Stronger protections for minors.

More parental oversight.

Age-related safeguards.

Other platforms will face a simple question:

Why aren’t you doing the same thing?

That’s how standards change.

First something is considered optional.

Then responsible.

Then expected.

Then regulators ask why everyone isn’t doing it.

Cybersecurity followed exactly the same path with MFA, encryption, breach notification and other protections.

AI governance may follow it next.

The Most Important Number Isn’t $17 Billion

The $17 billion headline is spectacular.

It will dominate the coverage.

But Meta once warned that its theoretical exposure could reach $1.4 trillion.

The states suggested roughly $200 billion.

Meta ultimately agreed to something dramatically smaller.

Financially, settling eliminated enormous uncertainty.

Meta’s stock actually rose following news of the agreement.

But here’s what Meta couldn’t purchase with the settlement:

The ability to keep everything exactly as it was.

That’s what makes this historic.

The government didn’t merely say:

You owe us money.

The settlement says, in effect:

The product has to change.

And that should get the attention of every technology company building systems designed to capture human attention, collect personal information or train AI.

Because the regulatory question is evolving.

It isn’t simply:

Did you protect the data?

It’s becoming:

Should you have collected it?

Should you have used it that way?

What did you build from it?

And did you design the technology itself to protect the people using it?

Meta agreed to pay billions.

But the precedent may ultimately be worth considerably more.

For Big Tech, “we gave users a choice” may no longer be enough.

Regulators increasingly want safety built into the product itself.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #DataProtection #ArtificialIntelligence #OnlineSafety #TechRegulation


Meta faced a theoretical $1.4 TRILLION bill. It settled for $17 billion—and agreed to change how Instagram works.

Cybersecurity
Technology

Your work emails may outlive the company that employed you.

August 26, 2026
•
20 min read

Google Just Put a $10 Million Price Tag on Employees’ Old Emails

Your work emails may outlive the company that employed you.

Spirit Airlines is gone.

Its planes are being dealt with.

Its employees have been laid off.

Its operations have stopped.

But something remarkably valuable survived:

The conversations its employees left behind.

Google has agreed to pay $10 million in Spirit Airlines’ bankruptcy proceedings for access to a massive collection of the airline’s internal business data.

The reason?

Among other product-development uses:

Training artificial intelligence.

And the scale of what’s being sold is extraordinary.

Approximately:

100 million emails.

500 million Microsoft Teams messages.

Plus internal documents, spreadsheets, calendars, operational information, marketing data, productivity data and software.

Think about what that actually represents.

Years of employees:

Asking questions.

Solving problems.

Arguing.

Making decisions.

Explaining procedures.

Scheduling meetings.

Fixing mistakes.

Writing reports.

Collaborating.

Managing an airline.

Spirit’s aircraft were obviously valuable physical assets.

But in the AI economy, there was apparently another asset sitting quietly on its servers:

A gigantic recording of how thousands of humans actually work.

Why Would Google Want 500 Million Teams Messages?

Because AI companies have an enormous problem.

The internet contains staggering amounts of information.

But internet text isn’t necessarily a good representation of how employees actually perform their jobs.

Wikipedia can teach an AI about aviation.

A corporate archive can potentially teach it how people operate an airline.

Consider what exists inside years of internal communications.

Someone reports a problem.

Someone else diagnoses it.

A manager escalates it.

Employees debate possible solutions.

A decision gets made.

Someone implements it.

Something goes wrong.

They fix it.

Multiply that across millions of conversations.

You’re no longer looking at a collection of messages.

You’re looking at something resembling an enormous dataset of:

Problem → reasoning → decision → action → outcome.

That’s incredibly interesting training material for AI systems designed to perform knowledge work.

The Runner-Up Tells You Something Important

Google wasn’t alone.

Mercor reportedly bid $7.5 million for the dataset and is the backup purchaser if Google’s transaction doesn’t close.

Mercor operates in the AI ecosystem and works with human expertise and data used to improve AI systems.

That makes this more interesting than Google simply buying leftover corporate software.

There was competitive bidding for the information itself.

Corporate exhaust has become an asset class.

We’ve Seen a Tiny Version of This Before

There’s a fascinating precedent.

Enron.

When Enron collapsed, roughly half a million employee emails eventually became a famous public research dataset.

The Enron Email Dataset has subsequently been used for decades by researchers studying:

Natural-language processing.

Spam detection.

Social networks.

Organizational communication.

Email classification.

Machine learning.

It became extraordinarily valuable precisely because authentic corporate email is difficult to obtain.

Now compare roughly half a million Enron messages with:

100 million Spirit emails.

And then add:

500 million Teams messages.

The difference isn’t merely size.

Teams captures a different kind of communication.

Shorter.

Faster.

More conversational.

More informal.

More collaborative.

Many workplace conversations that would once have occurred verbally or disappeared entirely are now permanently recorded in Slack, Teams and similar platforms.

We created an extraordinarily detailed dataset of how modern offices function without necessarily realizing we were creating one.

The Employees Weren’t Writing AI Training Data

This is where the story becomes uncomfortable.

An employee writing:

Hey, did we ever figure out why that report keeps failing?

isn’t thinking:

“I’m contributing another sample to a future machine-learning corpus.”

They’re doing their job.

When employees communicated with coworkers, they understood they were using corporate systems.

They presumably understood the company retained those records.

But there’s a meaningful difference between:

“My employer stores my Teams messages.”

and:

“Years after I write this, these conversations might become an asset sold during bankruptcy to train someone else’s artificial intelligence.”

That’s the ethical question this case puts directly on the table.

The Data Is Supposed to Be De-Identified

There is an important safeguard.

Reporting says a third party will process the information before delivery to Google.

Personally identifiable information is supposed to be removed, and customer information isn’t part of the transaction.

That’s significant.

This isn’t Google simply receiving a searchable inbox containing employee names, customer records and credit-card information.

But de-identification doesn’t eliminate the larger question.

Who owns the knowledge created through everyday work?

The employee?

The employer?

The bankruptcy estate?

And if that information has economic value after the company dies, should employees have any say in how it’s subsequently used?

Legally, workplace communications created on company systems generally belong to the employer, subject to applicable contracts, policies and privacy laws.

AI is making the implications of that old reality much more visible.

Bankruptcy Changes How You Look at Data

Imagine a company shuts down.

What remains?

Buildings.

Computers.

Vehicles.

Furniture.

Patents.

Domain names.

Software.

Customer relationships.

Traditionally, those are the assets people expect to see sold.

Now add:

Every email employees ever wrote.

Every Teams conversation they ever had.

Every internal document they created.

Every workflow they developed.

Every operational problem they solved.

AI has potentially changed the liquidation value of information.

A database that once represented storage expense can now represent training material.

That’s a remarkable economic shift.

Your Company May Be Sitting on an AI Dataset Right Now

Forget Spirit for a moment.

Think about your own Microsoft 365 environment.

How many years of email exist?

How many Teams messages?

How many SharePoint documents?

How many support tickets?

How many meeting transcripts?

How many recorded calls?

How many internal procedures?

How many customer-service conversations?

How many Slack messages?

How many CRM notes?

Ten years ago, much of that was considered historical business data.

Today it can potentially be something else:

A dataset describing how your organization thinks.

That’s valuable.

And anything valuable needs governance.

This Creates a New Data-Protection Question

Most businesses ask:

How long do we need to retain this data?

AI gives us another question:

What could someone eventually do with it?

That’s much harder.

Your employee handbook may explain that corporate email belongs to the company.

But does your privacy policy explain whether employee communications can someday be:

Analyzed by AI?

Used to train models?

Licensed?

Sold?

Transferred during an acquisition?

Transferred during bankruptcy?

De-identified and monetized?

Most organizations wrote their data-retention policies before anyone seriously contemplated these possibilities.

They should revisit them.

“Deleted” and “Gone” Aren’t Always the Same Thing

Businesses should also understand where information actually exists.

An employee deletes an email.

Is it gone?

Maybe not.

It might still exist in:

Retention policies.

Litigation holds.

Backups.

Archives.

Security platforms.

Journaling systems.

Cloud repositories.

Third-party backup products.

eDiscovery systems.

The same applies to Teams and other collaboration platforms.

Modern businesses deliberately retain enormous amounts of information for legal, compliance and operational reasons.

That’s often necessary.

But retention has a security consequence:

You cannot lose data you no longer possess.

Every year of retained information increases the historical dataset that potentially exists during a breach, acquisition, lawsuit—or bankruptcy.

Don’t Retain Everything Forever Just Because You Can

This is where your MSP, cybersecurity team, attorneys and compliance professionals need to work together.

Data retention shouldn’t be:

“Storage is cheap, keep everything.”

Organizations should establish defensible retention schedules based on:

Legal requirements.

Regulatory obligations.

Operational needs.

Litigation requirements.

Contractual commitments.

Security risk.

Privacy.

Different information deserves different retention periods.

Keeping unnecessary information indefinitely creates unnecessary liability indefinitely.

There Is Also a Cybersecurity Gold Mine Here

Think about this dataset from an attacker’s perspective.

Corporate communications can reveal:

Internal terminology.

Organizational structure.

Vendor relationships.

Technology platforms.

Business processes.

Employee behavior.

Escalation procedures.

Historical incidents.

Internal projects.

Security discussions.

Even when obvious personal information is removed, organizational knowledge can remain extraordinarily valuable.

That’s why companies shouldn’t think about email security only as:

“Prevent someone from reading today’s inbox.”

A compromised Microsoft 365 environment may expose years of corporate memory.

Law Firms Should Be Extremely Careful

Imagine this principle applied to a law firm.

Years of internal email and Teams messages could contain:

Litigation strategy.

Client discussions.

Negotiation approaches.

Privileged information.

M&A activity.

Personnel matters.

Investigations.

Even where legal and ethical rules impose substantial restrictions on transferring or using such information, the underlying lesson remains:

Corporate communications can become enormously valuable datasets.

Law Firm IT needs retention, classification and access controls designed around that reality.

Healthcare Has an Even Higher Bar

Healthcare organizations face HIPAA and other privacy obligations that make sensitive patient information fundamentally different from ordinary corporate communications.

But they also generate massive quantities of operational data.

Internal workflows.

Scheduling communications.

Billing processes.

IT tickets.

Administrative conversations.

AI makes previously mundane operational information potentially valuable.

Healthcare IT teams therefore need clear data classification.

What is PHI?

What is employee information?

What is operational data?

Who owns it?

How long is it retained?

Who can use it?

Could it ever be provided to an AI system?

“It’s internal” is no longer a sufficient data classification.

Schools Should Think About This Too

Schools increasingly generate enormous digital archives.

Email.

Google Workspace.

Microsoft 365.

Student systems.

Staff chats.

Learning platforms.

Documents.

Recordings.

AI tools.

School Technology leaders need policies covering not merely storage and cybersecurity, but future use.

Especially when student information or employee communications are involved.

Employees Need to Understand One Brutal Rule

Don’t use company systems as if they’re personal systems.

Your corporate email account isn’t your diary.

Teams isn’t your private living room.

Slack isn’t disappearing conversation.

Your work laptop isn’t your personal computer.

That doesn’t mean employees should be paranoid.

It means they should understand the environment they’re communicating in.

If something is deeply personal and unrelated to work, don’t put it in the corporate archive unnecessarily.

Because corporate information can survive:

Your resignation.

Your termination.

Your manager.

The CEO.

An acquisition.

And apparently:

The company itself.

Businesses Need an AI Data Governance Policy Now

This shouldn’t wait until bankruptcy.

Every organization adopting AI should answer:

What corporate information may be submitted to AI systems?

Which AI vendors are approved?

Can vendors train on our information?

How long do they retain prompts?

Are employee communications included?

What happens to uploaded documents?

Can confidential information be used?

Can customer information be used?

Who approves new AI tools?

What happens when an employee leaves?

And critically:

What rights exist over our data if the vendor—or we—cease operations?

This is becoming part of cybersecurity and data protection.

Your MSP shouldn’t merely secure where your data lives.

Organizations increasingly need to understand where their data can go.

The $10 Million Lesson

Spirit’s wind-down began in May 2026 after years of financial problems.

But its digital history didn’t disappear when the airplanes stopped flying.

Google looked at that history and reportedly saw enough potential value to offer:

$10,000,000.

Not primarily for passenger profiles.

Not for a pile of old laptops.

For internal business information and software that could help develop products and train AI.

That’s the part every executive should understand.

Your organization’s emails, chats, documents and workflows aren’t merely records anymore.

Collectively, they may represent a model of how your company operates.

And models of how humans actually perform work are becoming extremely valuable in the AI economy.

So before you hit Send on the next Teams message, remember something uncomfortable:

The company may eventually disappear.

Your message might not.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #ArtificialIntelligence #DataPrivacy #DataProtection #ManagedIT


Spirit Airlines died. Its employees’ emails didn’t. Google just bid $10 million for them.

Cybersecurity
Technology

Iranian Hackers Just Turned Off a British Power Plant

August 25, 2026
•
20 min read

Iranian Hackers Just Turned Off a British Power Plant

The hackers didn’t steal the data. They stopped the machine.

For years, we’ve talked about cyberattacks as though the worst thing that can happen is somebody stealing your information.

Your passwords get stolen.

Your customer database gets leaked.

Your files get encrypted.

Your credit card gets compromised.

But there’s another category of cyberattack that should make every business owner considerably more uncomfortable:

The computer gets hacked—and something in the physical world stops working.

That reportedly just happened in Britain.

Iran-linked hackers successfully forced a small British energy facility offline for four days, according to reporting this weekend.

Employees reportedly spent those four days getting the facility operational again.

The plant hasn’t been publicly identified.

The exact vulnerability hasn’t been disclosed.

And British officials say the facility was small enough that the attack never threatened the country’s overall electricity supply.

That’s reassuring.

But don’t miss what actually happened.

Someone sitting behind a computer reportedly reached across the internet and stopped an energy facility from operating.

This Wasn’t a Nationwide Blackout

That’s important.

Some headlines make this sound as though Iranian hackers nearly turned Britain’s lights off.

That’s not what the available reporting says.

A government source characterized the affected generator as extremely small relative to overall grid capacity, and the government says there was “at no point” a risk to the wider British energy system.

So this wasn’t:

London goes dark.

Hospitals lose electricity.

Millions of homes lose power.

The national grid collapses.

But cybersecurity professionals shouldn’t dismiss the incident because it was small.

In some ways, the small scale is what makes it interesting.

You Don’t Test a Capability on the Biggest Target First

We don’t yet know the attackers’ actual objective, so this part is important to distinguish from the reported facts.

But from a cybersecurity perspective, a smaller facility can be an attractive target.

Why?

Potentially weaker security.

Older operational technology.

Fewer cybersecurity personnel.

Legacy remote-access systems.

Less sophisticated monitoring.

Third-party vendors.

Equipment designed decades before anyone imagined connecting it to the internet.

An attacker doesn’t necessarily begin by trying to shut down an entire national grid.

They may begin by proving:

Can we get in?

Can we reach operational systems?

Can we manipulate them?

Will anyone detect us?

Can we force the operator to shut something down?

Those answers can be extraordinarily valuable.

The Difference Between IT and OT

This story is a perfect example of something businesses increasingly need to understand.

IT is Information Technology.

Laptops.

Email.

Microsoft 365.

Servers.

Databases.

Applications.

OT is Operational Technology.

These are computers controlling physical processes.

Pumps.

Valves.

Generators.

Motors.

Production equipment.

HVAC systems.

Industrial machinery.

Water treatment systems.

Electrical infrastructure.

Building automation.

When someone compromises IT, information can disappear.

When someone compromises OT:

Things can move.

Things can stop.

Pressure can change.

Production can halt.

Buildings can become unusable.

And in extreme environments, people can get hurt.

This Is Why Critical Infrastructure Is Such an Attractive Target

Imagine trying to pressure another country using conventional military force.

Aircraft.

Missiles.

Ships.

Personnel.

Logistics.

Enormous expense.

Enormous geopolitical consequences.

Now compare that with cyber operations.

A relatively small team may potentially probe thousands of organizations remotely.

Find exposed infrastructure.

Search for known vulnerabilities.

Steal credentials.

Compromise vendors.

Establish persistence.

Wait.

That’s what makes cyber capabilities so strategically valuable.

The attacker doesn’t necessarily need to destroy infrastructure.

Sometimes merely demonstrating that they can reach it changes the calculation.

The Timing Makes This More Interesting

The British incident reportedly occurred in July, around the same period as attacks against water and wastewater infrastructure across 12 U.S. states that were also linked in reporting to Iranian actors.

That doesn’t automatically prove every incident was coordinated by the same people.

But it reinforces a broader point.

Critical infrastructure is now part of the cyber battlefield.

Water.

Electricity.

Telecommunications.

Transportation.

Healthcare.

Manufacturing.

These aren’t hypothetical targets.

They’re networks.

And networks can be attacked.

Your Business Probably Has OT Too

This is where SMB owners tend to tune out.

They hear:

“Iran hacked a British power plant.”

Interesting story.

Nothing to do with me.

Except many businesses have their own miniature versions of operational technology.

Your building may have:

Internet-connected HVAC.

Door-access systems.

Security cameras.

Elevators.

Lighting controls.

Generators.

Environmental monitoring.

Manufacturing equipment.

Warehouse systems.

Refrigeration.

Building management systems.

Network-connected controllers.

And there’s one question I love asking:

Who is responsible for securing them?

IT?

Facilities?

The HVAC company?

The electrician?

The alarm company?

Your MSP?

The equipment manufacturer?

Nobody?

That last answer appears far too often.

Please Stop Putting Industrial Equipment Directly on the Internet

This should be basic cybersecurity hygiene.

If a piece of equipment doesn’t need to be publicly accessible from the internet:

Don’t expose it.

Operational systems should be segmented.

Remote access should be tightly controlled.

Default passwords should be removed.

MFA should be used wherever technically possible.

Vendor accounts should be reviewed.

Unused services should be disabled.

Firmware should be maintained.

Logs should be collected.

Internet-facing devices should be inventoried.

Backups of critical configurations should exist.

And businesses should know how to operate manually when automation disappears.

That last one matters enormously.

Ask Yourself One Uncomfortable Question

Suppose your building automation system stopped working tomorrow.

Not forever.

Four days.

What happens?

Can you still enter the building?

Can employees work?

Does refrigeration continue?

Does manufacturing stop?

Can you control HVAC?

Can doors be opened manually?

Can alarms function independently?

Can equipment be operated locally?

Do you even know who to call?

Cybersecurity resilience isn’t merely preventing an attacker from getting in.

It’s knowing how the business operates after they do.

Network Segmentation Can Turn a Disaster Into an Annoyance

Imagine a manufacturing company.

Its office computers and production equipment all sit on essentially the same flat network.

Someone compromises an employee laptop.

Now the attacker begins moving laterally.

Production controllers are reachable.

Security cameras are reachable.

Building systems are reachable.

Servers are reachable.

Backups are reachable.

One compromised employee becomes a company-wide problem.

Now imagine proper segmentation.

Employee computers live here.

Servers live here.

Production equipment lives here.

Security cameras live here.

Building automation lives here.

Guest Wi-Fi lives somewhere completely separate.

Traffic between those environments is tightly controlled.

The attacker compromises the same laptop.

But now:

The walls matter.

Segmentation doesn’t magically prevent cyberattacks.

It prevents one cyberattack from automatically becoming everybody’s problem.

Vendor Remote Access Is a Huge Blind Spot

This deserves special attention.

Operational equipment often needs maintenance.

So the installer says:

Don’t worry. We can remote into it if anything breaks.

Wonderful.

Now ask:

How?

What remote-access product?

Whose account?

Is MFA enabled?

Is the account shared?

Does the vendor have permanent access?

Can you see when they connect?

Is access restricted to their equipment?

When was the password last changed?

What happens when one of their employees leaves?

Does your MSP even know this connection exists?

Businesses routinely secure their own employees while leaving a permanent digital side door open for a vendor.

Attackers know that too.

Healthcare Should Pay Particular Attention

Healthcare IT doesn’t exist entirely in laptops and servers.

Modern healthcare environments contain enormous amounts of connected technology.

Building controls.

Medical devices.

Imaging systems.

Environmental controls.

Access systems.

Pharmacy systems.

Network-connected equipment.

A cyberattack doesn’t have to steal patient records to become an emergency.

If technology affects the delivery of care, availability becomes a cybersecurity issue.

Healthcare organizations need downtime procedures that assume certain technology simply won’t work.

Not for ten minutes.

For days.

Schools Have the Same Problem

Schools increasingly contain connected:

Door systems.

Cameras.

HVAC.

PA systems.

Phones.

Digital signage.

Attendance systems.

Network infrastructure.

Classroom technology.

A cyberattack against a school isn’t merely a data-protection issue.

It can become an operations problem very quickly.

School Technology teams need to know which systems are critical, which networks they’re connected to and how the building functions if those systems become unavailable.

SMB Manufacturers Should Be Extremely Careful

Manufacturing is where the IT/OT distinction becomes particularly dangerous.

Production equipment may last:

10 years.

20 years.

30 years.

Sometimes longer.

The machine may still work perfectly.

The operating system controlling it may be ancient.

That’s a cybersecurity nightmare.

You can’t simply tell the owner:

“Replace the $900,000 machine because Windows is old.”

Instead, cybersecurity architecture becomes critical.

Isolate it.

Restrict communication.

Monitor it.

Control remote access.

Prevent unnecessary internet connectivity.

Limit who can reach it.

Assume it cannot defend itself.

Legacy equipment needs modern protection around it.

Have a Manual Mode

One detail from recent attacks on critical infrastructure keeps coming back to the same lesson:

Manual operations matter.

If automation fails, can humans continue?

Businesses have become extraordinarily dependent on technology.

That’s efficient.

Until the technology disappears.

Your incident-response planning should include:

How do we operate without this system?

Print the procedure.

Don’t store the only copy on the server that just got encrypted.

Keep emergency contacts somewhere accessible.

Know how to disconnect critical equipment.

Know how to restore configurations.

Know who has authority to shut something down.

And practice it.

Four Days Is a Long Time

Think about your own business.

Imagine your core operational system disappeared tonight.

Tomorrow: unavailable.

Day two: unavailable.

Day three: unavailable.

Day four: still unavailable.

Payroll.

Orders.

Phones.

Email.

Production.

Customer records.

Scheduling.

Building access.

What starts breaking?

That’s the exercise I want SMB owners to perform.

Not:

“Could Iran hack my company?”

That’s the wrong question.

Ask:

“What technology could shut my business down for four days?”

Then protect that technology accordingly.

Cybersecurity Is No Longer About Protecting Computers

That’s the larger lesson.

Twenty years ago, cybersecurity largely meant protecting information stored on computers.

Today computers control the physical world.

Electricity.

Water.

Factories.

Hospitals.

Buildings.

Transportation.

Communications.

Supply chains.

When those computers are compromised, the consequences don’t necessarily stay inside the computer.

According to the current reporting, this particular attack involved a small British generator and never threatened the national power supply.

Good.

But somebody reportedly still demonstrated that they could turn a functioning energy facility into a nonfunctioning one for four days.

That’s the line businesses should pay attention to.

The next cyberattack may not steal your data.

It may simply turn off the thing your business cannot operate without.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #CriticalInfrastructure #ManagedIT #DataProtection #CyberAttack


Iranian hackers didn’t steal files from this power plant. They turned the plant off—for four days.

Cybersecurity
Technology
Tips

Someone Hid a Camera in a Hotel Charger. Would You Spot It

August 23, 2026
•
20 min read

Someone Hid a Camera in a Hotel Charger. Would You Spot It?

The charger beside your bed may not just be charging.

You check into a hotel.

Drop your suitcase.

Connect to Wi-Fi.

Plug in your phone.

Lock the door.

Maybe check that the deadbolt works.

And then you assume you’re alone.

A hotel guest recently reported discovering something considerably more disturbing:

A Wi-Fi-enabled camera concealed inside what appeared to be an ordinary power adapter.

According to the person who reported finding it, the device was capable of transmitting live video remotely. Hotel management denied involvement.

Whether every technical detail of that individual incident can ultimately be verified or not, the hardware behind the threat is very real.

Tiny cameras can be hidden inside everyday objects.

Chargers.

Alarm clocks.

USB adapters.

Smoke detectors.

Picture frames.

Pens.

Wall clocks.

And other objects you’d barely notice in a hotel room.

The cybersecurity lesson is uncomfortable:

Sometimes the device watching you doesn’t look like a camera.

You Don’t Need to Become a Spy Hunter

I don’t think people should spend the first hour of every vacation dismantling hotel rooms.

That’s not practical.

And you absolutely should not start unscrewing smoke detectors, opening electrical equipment or taking apart hotel property.

Instead, add something simple to your normal check-in routine.

You already:

Lock the door.

Put valuables in the safe.

Check where the exits are.

Now spend a few minutes checking the things pointed toward places where you reasonably expect privacy.

Here’s how.

Step 1: Stand at the Foot of the Bed

Before unpacking, stop.

Look around the room from the perspective of someone trying to record you.

Don’t inspect everything equally.

Ask:

What has a clear line of sight to the bed?

Then the bathroom.

Then the changing area.

Look closely at:

Smoke detectors.

Alarm clocks.

USB chargers.

Power adapters.

Picture frames.

TV equipment.

Air vents.

Lamps.

Wall fixtures.

Anything strangely positioned.

You’re looking for something simple:

A tiny unexplained opening or dark reflective circle.

A camera needs to see.

That means somewhere, somehow, there generally needs to be an optical path between the lens and the room.

Physical inspection remains one of the most useful first checks.

Step 2: Audit the Things Plugged Into the Wall

This is particularly relevant to the reported hotel incident.

Look at electronics you didn’t bring.

An ordinary USB charger shouldn’t have a mysterious pinhole pointed toward your bed.

Neither should an alarm clock.

Neither should a random power adapter.

Pay attention to objects that seem unnecessary.

Why is this here?

What does it power?

Why is it positioned this way?

Does it have a tiny lens-like opening?

Does it have an unexplained microSD slot?

Does the object look modified?

Don’t open suspicious electronics.

Don’t destroy them.

And don’t start pulling apart hotel electrical fixtures.

If something looks genuinely suspicious, stop handling it and document what you see.

More on that in a minute.

Step 3: Turn Off the Lights and Use a Flashlight

Here’s a trick that doesn’t depend on the camera being connected to Wi-Fi.

Darken the room.

Take your phone’s flashlight and slowly shine it toward suspicious objects while looking from roughly the same direction as the light.

Camera lenses can produce a sharp reflection.

You’re looking for a tiny, unusual glint.

Move around slightly because lens reflection depends heavily on angle.

This isn’t foolproof.

A screw, LED or shiny piece of plastic can reflect light too.

But unlike a Wi-Fi scan, a flashlight doesn’t care whether the suspected camera is:

Wireless.

Wired.

Recording to an SD card.

Connected to another network.

Or disconnected from the internet.

You’re looking for the lens itself.

Step 4: Try the Infrared Trick

This is the trick that gets shared all over social media.

And yes, it can work.

Many inexpensive security cameras use infrared LEDs for night vision.

Your eyes can’t see infrared light.

Some smartphone camera sensors can.

First, test whether yours does.

Grab a TV remote.

Open your phone’s camera.

Point the remote at it and press a button.

If you can see the remote’s emitter flashing on your screen while you press it, you’ve confirmed that particular camera can detect at least some infrared.

Now darken the hotel room.

Slowly scan suspicious areas through your phone.

You may see tiny purple, white or pinkish points of light that aren’t visible with your eyes.

Investigate those locations visually.

But here’s the part TikTok videos often leave out:

No purple dots does not mean no camera.

A hidden camera may not use infrared.

Its IR LEDs may be turned off.

It may record perfectly well using visible light.

And different phone cameras filter infrared differently.

So this is a useful test.

It is not an all-clear button.

Step 5: See What’s on the Wi-Fi

A network scanner such as Fing⁠ can identify devices visible to you on a network.

You might see:

Smart TVs.

Access points.

Streaming devices.

Printers.

Phones.

IoT equipment.

And potentially cameras.

Names containing terms such as camera, IPCam, ESP32 or an unfamiliar device manufacturer can give you something worth investigating.

But again:

Don’t treat an unfamiliar device as proof somebody is spying on you.

Hotels can have enormous numbers of legitimate connected devices.

And there is an even bigger limitation.

Hotel Wi-Fi commonly isolates guests from other devices on the network.

A hidden camera might also:

Use another Wi-Fi network.

Create its own hotspot.

Use cellular connectivity.

Record locally.

Be wired.

Or simply be offline while you’re checking.

Fing itself describes network scanning as one method among several for detecting hidden cameras.

A clean network scan does not mean a clean room.

Don’t Forget the Bathroom

People instinctively check around the bed.

Check areas where someone would reasonably expect to undress too.

Look at anything with an unobstructed view toward:

The shower.

Toilet.

Changing area.

Bathroom mirror.

Again, don’t dismantle fixtures.

You’re looking for obvious anomalies:

Unexpected electronics.

Unexplained holes.

Oddly positioned objects.

Tiny reflective surfaces.

Something that simply doesn’t belong.

Here’s What I Would NOT Do

If you discover what genuinely appears to be a hidden camera, resist the cybersecurity instinct to become the investigator.

Don’t connect to it.

Don’t try default passwords.

Don’t scan its ports.

Don’t reset it.

Don’t remove its SD card.

Don’t log into it.

Don’t attempt to determine where it’s uploading footage.

Don’t take it home.

And don’t smash it.

You may destroy evidence or complicate an investigation.

One of the strongest responses to the original poster made exactly this point: preserve the evidence and get law enforcement involved rather than contaminating the chain of custody yourself.

If You Actually Find One, Do This Instead

First, leave the private area of the room and avoid changing clothes or having sensitive conversations there.

Photograph the suspicious object in place from multiple angles without unnecessarily manipulating it.

Record:

Your hotel.

Room number.

Date.

Time.

Where the object is located.

What made you suspicious.

Then contact hotel management and local law enforcement.

If you booked through a travel platform, report it there as well.

Request another room—or another hotel.

If you’re concerned about immediate privacy while waiting for help and can do so without disturbing evidence, simply leave the room.

The goal isn’t proving the case yourself.

Preserve what you found so someone qualified can investigate it.

Don’t Immediately Blame the Hotel

This is another important distinction.

Finding a camera inside a hotel room does not automatically prove the hotel installed it.

Hotels have:

Employees.

Contractors.

Maintenance workers.

Previous guests.

Outside vendors.

Large numbers of people moving through rooms.

That’s part of what makes the situation difficult.

If something suspicious is found, determine who installed it through an investigation rather than an assumption.

The hotel itself may also be a victim.

The Cybersecurity Parallel Is Bigger Than Hidden Cameras

There’s a reason I find this story interesting beyond travel safety.

The same security principle applies to businesses:

Know what’s connected to your environment.

Businesses routinely discover devices nobody in IT knew existed.

Security cameras.

Door controllers.

HVAC equipment.

Printers.

Digital signage.

Cheap IoT devices.

Conference-room equipment.

Vendor-installed gateways.

Random Wi-Fi equipment.

Each one is another computer.

Each one may have:

A password.

Firmware.

Network access.

A cloud account.

Remote administration.

Known vulnerabilities.

And potentially a camera or microphone.

Yet someone installed it three years ago and nobody remembers who owns it.

Your $40 Device Can Become My Cybersecurity Problem

Cheap connected devices are especially dangerous because they’re easy to deploy.

Plug it in.

Connect Wi-Fi.

Download an app.

Done.

Nobody calls IT.

Nobody calls the MSP.

Nobody performs a cybersecurity review.

Nobody changes the default configuration.

Nobody asks where the data goes.

Nobody asks how long the manufacturer supports it.

Nobody asks what country the cloud service operates from.

Then three years later:

“What is this thing on our network?”

That’s Shadow IT in physical form.

Businesses Should Inventory IoT Devices

Your managed IT provider should know what’s connected to your network.

At minimum, identify:

What the device is.

Who owns it.

Why it’s there.

What network it’s connected to.

Whether it needs internet access.

How it’s authenticated.

Whether firmware is current.

Who can remotely access it.

Whether it contains a camera or microphone.

Where its data is stored.

When it should be replaced.

If nobody can answer those questions:

Why does the device have network access?

Hotels Have an Especially Difficult Security Problem

Think about the environment.

Hundreds of rooms.

Thousands of guests.

Contractors.

Housekeeping.

Maintenance.

Televisions.

Access-control systems.

Wi-Fi.

Smart thermostats.

Digital locks.

Cameras.

Building automation.

Payment systems.

Guest networks.

Corporate networks.

It’s an enormous attack surface.

Hotel cybersecurity cannot stop at protecting the reservation system and front-desk computers.

Physical technology needs governance too.

Four Minutes Won’t Guarantee You’re Safe

I wouldn’t promise that.

Anyone who tells you a phone app can guarantee a hotel room contains no surveillance equipment is giving you false confidence.

A sophisticated camera can be:

Extremely small.

Wired.

Recording locally.

Dormant.

Not using infrared.

Connected through a network you cannot see.

No consumer trick detects everything.

But that’s not a reason to do nothing.

Security is rarely about eliminating 100% of risk.

It’s about making simple habits routine enough that obvious threats don’t succeed.

Make It the New Hotel Check-In Routine

You don’t need to become paranoid every time you travel.

Make the process boring.

Walk in.

Lock the door.

Check the bed’s line of sight.

Look at unfamiliar electronics.

Darken the room and do a flashlight sweep.

Test for infrared if your phone supports it.

Optionally check visible network devices.

Then enjoy your trip.

It takes a few minutes.

And just like checking that your hotel-room door actually latched behind you, eventually it becomes something you barely think about.

Because cybersecurity isn’t always:

Firewalls.

MFA.

EDR.

Encryption.

Sometimes it’s standing at the foot of a hotel bed and asking one extremely simple question:

“What in this room can see me?”

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #TravelSafety #DataPrivacy #IoTSecurity #DataProtection


Before you plug into that hotel charger, look closely. Someone recently found a Wi-Fi camera hiding inside one.

Cybersecurity
News
Technology

This Shirt Is Designed to Poison Surveillance Databases Like Flock

August 24, 2026
•
20 min read

This Shirt Is Designed to Poison Surveillance Databases

The camera sees clothing. The computer sees license plates.

Automatic License Plate Readers are supposed to recognize cars.

Point a camera toward traffic.

Identify a license plate.

Read the characters.

Record the location.

Record the time.

Store the result in a searchable database.

But cybersecurity professional and designer Kate Rose asked a very hacker-like question:

What happens if you give the machine exactly what it’s looking for—but put it somewhere it doesn’t belong?

Her answer was adversarial fashion: clothing covered with patterns designed to resemble license plates closely enough that some automated plate-reading systems could mistake the shirt itself for a collection of vehicles.

The goal isn’t to become invisible.

It’s almost the opposite.

Make the surveillance system see too much.

Your Shirt Becomes a Database-Pollution Device

Rose showcased the concept at DEF CON in 2019.

The garments use repeating rectangular designs containing alphanumeric characters resembling license plates.

That’s important because an Automatic License Plate Reader, or ALPR, isn’t looking at the world the way you do.

You see:

A person wearing a weird shirt.

A computer-vision system may instead be looking for features associated with its assigned task:

Rectangular region.

Plate-like proportions.

Characters.

Expected visual patterns.

Potential plate detected.

Read characters.

Record.

Rose’s experiment exploited that difference.

If the system incorrectly recognizes patterns on the clothing as plates, it could generate false detections.

Now the database contains information that shouldn’t exist.

That’s Much More Interesting Than Hiding Your Face

Most people’s instinct when thinking about defeating surveillance is concealment.

Hide your face.

Cover the plate.

Avoid the camera.

Rose’s approach demonstrates a completely different security concept:

Don’t hide from the sensor. Manipulate what the sensor believes.

In cybersecurity and machine learning, this broader concept is often associated with adversarial examples—inputs deliberately designed to cause automated systems to classify something incorrectly.

The human observer may immediately understand what’s happening.

The algorithm may not.

And that difference can become an attack surface.

Imagine One Shirt Creating Dozens of “Cars”

Consider the basic concept.

You walk past an ALPR camera wearing a pattern containing numerous fake plates.

The system correctly captures your physical location.

But instead of recording one legitimate vehicle plate, a vulnerable recognition system might generate multiple false plate readings associated with that location and time.

Those records could then become noise inside the larger dataset.

Rose described the project as a way of introducing junk data into surveillance systems.

That’s what makes the idea so clever.

The clothing isn’t attacking the camera.

It isn’t hacking the network.

It isn’t breaking into a server.

It’s attacking the assumption behind the data collection.

The system assumes:

If I recognize something as a license plate, a license plate was actually there.

Adversarial fashion asks:

What if that assumption is wrong?

Why ALPR Data Is So Powerful

License-plate readers don’t merely answer:

“What cars are driving past this camera right now?”

Their real power comes from retention and aggregation.

A plate observation can contain:

The plate number.

Date.

Time.

Location.

Potentially vehicle characteristics or associated imagery, depending on the system.

One observation isn’t necessarily remarkable.

But repeated observations can begin creating a history.

Car ABC123 was here Monday morning.

Here Tuesday evening.

Here Wednesday.

Here again Friday.

Now combine observations from many cameras.

The result can potentially reveal movement patterns.

That’s why privacy advocates are so interested in ALPR deployments.

The sensitivity isn’t necessarily contained in any single photograph.

It’s created by connecting thousands or millions of observations together.

Flock Safety Has Helped Scale This Model

Flock Safety⁠ is one of the best-known companies operating in this space today.

Its license-plate recognition technology is used by law-enforcement agencies and communities to help investigate crimes.

Supporters argue that these networks give investigators a powerful tool for identifying suspect vehicles, locating stolen cars and reconstructing events.

Privacy advocates see another side.

A sufficiently large network of cameras creates a searchable record of where vehicles have been observed.

And that creates an unavoidable cybersecurity and privacy question:

Who gets to search it?

Surveillance Databases Need Cybersecurity Too

This is where this story becomes relevant beyond a novelty shirt.

Whenever an organization builds an enormous database of sensitive information, cybersecurity professionals should ask:

Who can access it?

How is access authenticated?

Are searches logged?

How long is information retained?

Can employees misuse it?

Can accounts be compromised?

Can agencies share access?

Can inaccurate information be corrected?

Can the underlying sensor be manipulated?

That last question doesn’t get enough attention.

We spend tremendous effort securing databases against unauthorized access.

But a perfectly secured database filled with bad information is still a bad database.

Data integrity matters as much as data confidentiality.

Garbage In, Surveillance Out

This is one of the oldest principles in computing:

Garbage in, garbage out.

AI doesn’t magically eliminate that problem.

It can magnify it.

If an automated system incorrectly identifies an object and nobody catches the mistake, that incorrect observation can potentially become a permanent database record.

Now imagine millions of automated decisions.

Computer vision.

Facial recognition.

Fraud detection.

Security cameras.

License-plate recognition.

Medical imaging.

AI-generated threat alerts.

The question isn’t merely:

How accurate is the system?

It’s also:

What happens when somebody intentionally tries to make it wrong?

That’s adversarial thinking.

And every organization deploying AI needs people asking that question.

Your Business Probably Uses Computer Vision Already

This isn’t only about police cameras.

Businesses increasingly rely on automated recognition systems for:

Building access.

Warehouse monitoring.

Inventory.

Manufacturing.

Security cameras.

Package identification.

Vehicle access.

Fraud detection.

Document processing.

Schools and healthcare facilities are adopting increasingly sophisticated physical-security systems as well.

If an automated decision has security consequences, you need to understand how that decision can fail.

Can a badge reader be fooled?

Can an image-recognition system misclassify something?

Can somebody manipulate a QR code?

Can an AI document processor be given malicious instructions?

Can false information poison an automated workflow?

The more decisions we delegate to machines, the more valuable manipulating the machine’s perception becomes.

AI Security Isn’t Only About Protecting the AI

This distinction matters.

When businesses talk about AI cybersecurity, they often think about:

Someone stealing the model.

Someone stealing training data.

Employees uploading confidential information.

An attacker compromising the AI provider.

Those are legitimate concerns.

But there’s another category:

Making the AI confidently do the wrong thing.

That might involve adversarial images.

Poisoned training data.

Prompt injection.

Manipulated documents.

False sensor inputs.

Carefully constructed text.

The exact attack changes depending on the system.

The principle doesn’t.

An attacker doesn’t always need to break the machine. Sometimes they only need to control what the machine sees.

Humans Need to Remain Part of High-Stakes Decisions

Suppose an automated system reports:

Vehicle XYZ was at this location at 11:42 PM.

That information can be valuable investigative intelligence.

But automated recognition shouldn’t magically transform probability into certainty.

For high-consequence decisions, organizations need procedures for validation.

Review the underlying image.

Corroborate the location.

Check timestamps.

Look for additional evidence.

Understand the system’s error rates.

Preserve audit logs.

Know whether the detection was automated.

Because the computer saying:

“93% confidence”

doesn’t mean:

“This happened.”

It means the computer is 93% confident according to the way it was designed to calculate confidence.

Those are very different statements.

The Shirt Is Really a Cybersecurity Lesson

Rose’s clothing is funny.

It’s provocative.

And it’s visually brilliant.

But underneath the novelty is a serious security principle.

She didn’t need to compromise the database.

She challenged the input.

That’s exactly how cybersecurity professionals are supposed to think.

Don’t merely ask:

How is this system supposed to work?

Ask:

How could somebody abuse it?

What assumptions does it make?

What happens if those assumptions aren’t true?

What inputs does it trust?

Can those inputs be manipulated?

What happens downstream when they’re wrong?

Those questions apply to practically every emerging AI system businesses are deploying today.

The Machines Watching Us Can Be Fooled Too

We increasingly live surrounded by automated systems attempting to interpret reality.

They read:

Faces.

Voices.

License plates.

Documents.

Emails.

Transactions.

Behavior.

Network traffic.

And increasingly, businesses are trusting those interpretations enough to make decisions automatically.

That creates incredible efficiency.

It also creates a new attack surface.

Kate Rose’s adversarial fashion demonstrates the problem beautifully.

A human sees someone wearing a shirt covered in fake license plates and immediately understands:

Those aren’t cars.

The machine may see something completely different.

And once its mistake enters a database, that mistake can become part of the system’s version of reality.

The next generation of hacking won’t always attack computers.

Sometimes it will attack what computers think they’re seeing.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #ArtificialIntelligence #DataPrivacy #ComputerVision #DataProtection


This shirt doesn’t hide you from surveillance. It tries to make the surveillance system hallucinate.

Technology
Cybersecurity
News

Exactly how much should the government be able to learn about where our cars go

August 20, 2026
•
20 min read

Have You Been Flocked? Your License Plate May Already Be Searchable

You don’t have to commit a crime to enter the database.

You drive to work.

The grocery store.

Synagogue.

Your doctor’s office.

Your child’s school.

A restaurant.

Your attorney’s office.

You aren’t being followed.

You haven’t been pulled over.

You haven’t committed a crime.

But along the way, cameras mounted beside roads may photograph your vehicle, read your license plate, record where and when it was seen and temporarily place that observation into a searchable database.

That’s the technology behind Flock Safety⁠.

And Americans are beginning to ask a very reasonable question:

Exactly how much should the government be able to learn about where our cars go?

What Exactly Is Flock?

Flock Safety operates automated license plate recognition cameras, commonly called ALPRs.

They’re different from ordinary security cameras.

Rather than simply recording hours of video, an ALPR is designed to identify vehicles passing the camera.

According to Flock, its system can capture:

License plate images.

Vehicle characteristics.

Date and time.

Camera location.

Flock says its ALPR product does not collect facial-recognition or biometric data.

So imagine your car passes one at:

8:13:42 AM.

The system might create a record essentially saying:

Plate ABC123 — observed here — at this time.

One observation sounds boring.

Thousands of cameras are where things become interesting.

One Camera Isn’t Really the Controversy

Imagine your local police department puts a camera at the entrance to town.

A stolen car drives past.

The plate matches a hot list.

Police receive an alert.

They recover the vehicle.

That’s an easy use case to understand.

Flock and law-enforcement agencies point to cases involving stolen vehicles, wanted suspects and missing people as examples of why ALPRs can be valuable.

But now expand the concept.

Flock reportedly has approximately:

120,000 cameras.

Across:

49 states.

Suddenly we’re not discussing a camera anymore.

We’re discussing a network.

And networks can answer questions individual cameras cannot.

The Camera Doesn’t Need to Follow You

This is the fascinating part.

Imagine cameras record your car at five different locations:

8:02 AM — near your neighborhood.

8:37 AM — near your office.

12:18 PM — across town.

5:41 PM — near a particular building.

6:27 PM — heading home.

No camera physically followed you.

But connect the observations and you’ve potentially reconstructed part of your day.

Do that repeatedly and patterns can emerge.

That’s why privacy advocates are concerned.

Tracking doesn’t necessarily require one camera watching you continuously.

A sufficiently large number of cameras can potentially reconstruct movement from individual observations.

“Have I Been Flocked?” Lets You Search Something Different

There’s now a website called Have I Been Flocked?⁠

It has compiled public-record audit logs containing approximately:

241 million Flock searches

involving roughly:

4.7 million license plates.

You can enter your license plate and see whether it appears in the audit information they’ve collected.

But there’s an extremely important distinction:

A result does not mean police were investigating you.

The website is searching collected audit logs of searches performed in Flock systems.

And its records aren’t necessarily complete because they’re assembled from public-record requests to agencies.

So don’t enter your plate, see a result and immediately conclude:

“The government was following me.”

That’s not what the result establishes.

Can Regular Citizens Search Flock?

Generally, no.

There isn’t supposed to be a public Flock law-enforcement search engine where you can type:

“Show me everywhere ABC123 traveled.”

Flock says access is restricted to authorized users, searches are tied to individual accounts, and search activity is logged.

For law-enforcement systems, Flock says searches must have an investigative purpose and the general public cannot browse the database.

The new Have I Been Flocked site isn’t giving you direct access to Flock.

It’s aggregating audit records obtained through public-record requests.

That’s an important difference.

So Could Someone Abuse It?

That’s one of the biggest concerns.

Any database powerful enough to help find criminals is potentially powerful enough to be misused.

Imagine someone with access searching:

An ex-spouse.

A girlfriend.

A journalist.

A political opponent.

A neighbor.

Someone attending a protest.

Someone visiting a particular medical facility.

That’s why audit logs matter.

Flock says every search is associated with a specific account and recorded for review.

And amid mounting criticism, the company has announced additional safeguards scheduled to take effect around the beginning of 2027.

Among them are requirements for stronger search justification, mandatory auditing intended to detect abnormal searches, and the ability to restrict or suspend suspicious users.

Flock CEO Garrett Langley has publicly warned people abusing the system:

“You will get caught.”

That’s reassuring.

But privacy advocates ask a different question:

Should misuse merely be detectable—or should certain searches require stronger authorization before they happen?

That’s where this debate becomes much harder.

What If Flock Gets My License Plate Wrong?

This is a legitimate concern.

ALPR systems aren’t infallible.

Flock’s own License Plate Reader Policy acknowledges that plate translation can occasionally be incomplete or inaccurate and specifically instructs users to confirm the computer-generated translation before acting on an alert or search.

That safeguard matters enormously.

Imagine your plate is:

ABC1238

and a wanted vehicle is:

ABC1288.

Or perhaps the vehicle has:

The same color.

Similar body style.

Similar make.

A plate that is partially obscured.

An automated match should be an investigative lead—not unquestionable proof.

A computer alert should never magically become probable guilt.

Could an Innocent Person Actually Get Stopped?

Potentially, yes.

Automated plate-reader errors and mistaken vehicle identifications have contributed to wrongful or highly problematic stops in the broader ALPR ecosystem, and recent reporting on Flock has highlighted concerns involving misreads and improper use.

But that doesn’t mean:

“Flock sees your car and police will arrest you.”

The appropriate process is for an ALPR hit to be independently verified.

Look at the actual photograph.

Confirm the plate.

Confirm the vehicle.

Evaluate the circumstances.

Then act.

Technology should help an officer investigate.

It shouldn’t replace the officer’s judgment.

Do Law-Abiding Citizens Have Anything to Worry About?

This deserves a nuanced answer.

If you’re asking:

“Does Flock automatically consider me suspicious because it photographed my car?”

No.

The cameras routinely capture vehicles belonging to completely innocent people.

That’s inherent to how ALPR systems operate.

But if you’re asking:

“Does the existence of a searchable record of innocent people’s movements create legitimate privacy concerns?”

Absolutely.

Those are two completely different questions.

You can simultaneously believe:

Flock can help solve serious crimes.

and:

Large-scale searchable location databases need extremely strong safeguards.

Those positions aren’t contradictory.

“But I’m Not Doing Anything Wrong”

This is where privacy conversations often get stuck.

Someone says:

“I don’t care. I’m not a criminal.”

But privacy isn’t synonymous with hiding criminal behavior.

Imagine somebody could request a list showing every vehicle that visited:

An addiction-treatment facility.

A fertility clinic.

A religious institution.

A political meeting.

A divorce attorney.

A mental-health provider.

A domestic-violence shelter.

You don’t have to be doing anything illegal for location information to be sensitive.

Privacy is the ability to live an ordinary lawful life without every movement becoming somebody else’s searchable history.

Don’t We Have Constitutional Rights?

Yes—but the legal question surrounding vehicle movements is complicated.

Courts have long recognized that people generally have a reduced expectation of privacy in license plates displayed publicly on vehicles.

A police officer standing beside a road can obviously see your plate.

The harder question is what happens when technology changes the scale.

There’s a meaningful practical difference between:

An officer happened to see your car on Tuesday

and:

A database can potentially reconstruct weeks of your vehicle’s movements across many locations.

American courts have increasingly wrestled with this broader issue in other forms of location surveillance.

The constitutional debate isn’t simply:

“Can police see a license plate?”

Of course they can.

The emerging question is:

At what point does automated, aggregated surveillance become something fundamentally different?

That issue is far from settled everywhere.

Can You Opt Out?

For ordinary drivers passing public-facing ALPR cameras, generally there isn’t a personal Flock opt-out button that prevents your plate from being captured.

Your license plate is intentionally displayed on your vehicle and visible from public roads.

The “Do Not Sell” option in Flock’s website privacy policy concerns personal information governed by that privacy policy; it should not be confused with a universal ability to tell roadside ALPR cameras:

“Don’t photograph my vehicle.”

If your local government operates Flock cameras, the meaningful controls are largely civic:

Local ordinances.

Police policies.

Retention requirements.

Sharing restrictions.

Public-record laws.

City council decisions.

State legislation.

And ultimately whether your community chooses to deploy the technology at all.

More than 50 jurisdictions have reportedly ended or suspended Flock relationships amid the current controversy.

How Are These Cameras Even Powered?

This part is surprisingly clever.

Many Flock cameras don’t require traditional wired infrastructure.

Flock says its cameras can use:

Solar power.

Battery power.

And cellular LTE connections for communications.

That dramatically simplifies deployment.

No fiber connection is necessarily required.

No nearby network closet.

No trenching Ethernet down the road.

Put the camera on suitable infrastructure.

Give it power.

Connect through cellular service.

That architecture is part of what allows ALPR networks to expand relatively quickly.

Flock’s deployment documentation also supports installations using AC power and existing infrastructure such as utility, traffic-signal and light poles.

Does Flock Pay Cities to Use Their Poles?

I wouldn’t make that blanket claim.

Installation arrangements vary by municipality and contract.

Flock’s own deployment documentation explicitly contemplates cameras being mounted on existing utility, light and traffic-signal poles, as well as other suitable infrastructure.

But whether Flock pays a particular city for pole access, the city pays Flock under a camera contract, another entity owns the pole, or some other arrangement exists depends on the specific deployment.

That’s something residents can investigate through:

Contracts.

Procurement records.

City council minutes.

Public-record requests.

If you’re curious about cameras in your neighborhood, look at the actual municipal contract.

That’s far more useful than guessing.

What Happens to Your Data?

Currently, Flock says ALPR information is typically retained for 30 days, although customers and applicable laws can require different retention periods.

But that is changing.

Beginning January 1, Flock has announced plans to reduce its standard retention period from 30 days to seven days as part of its new safeguards.

That’s a major reduction.

Thirty days can provide a month-long movement history.

Seven days dramatically shrinks that window.

But critics still argue the fundamental concern remains:

Why should movements of people suspected of absolutely nothing enter a searchable system in the first place?

The Cybersecurity Question Nobody Should Ignore

Now imagine the database itself gets compromised.

This is something I think deserves more attention.

Whenever we create a centralized repository containing sensitive information, we create something attackers may want.

Vehicle movements can potentially reveal:

Where executives work.

Where employees live.

When facilities are occupied.

When someone travels.

Relationships between locations.

Operational routines.

Flock says its data is encrypted during transmission and storage and that criminal-justice information is stored in AWS GovCloud.

Those are important safeguards.

But cybersecurity professionals operate from a simple assumption:

Any valuable database deserves to be treated as a potential target.

The more powerful the database becomes, the more serious access control, logging, MFA, encryption, retention and incident response become.

There’s Another Risk: Legitimate Credentials

A database doesn’t need to be “hacked” in the Hollywood sense.

Someone could steal an authorized user’s credentials.

Phish an officer.

Compromise an endpoint.

Abuse an existing account.

Exploit excessive permissions.

That’s why every sensitive search should be attributable.

Who searched?

When?

Why?

What did they access?

What happened afterward?

Good cybersecurity isn’t merely keeping outsiders outside.

It’s making sure insiders—and compromised insider accounts—can’t operate invisibly.

This Is the Real Flock Debate

Flock presents an extraordinary example of the tradeoff technology continually forces society to confront.

Imagine a child is kidnapped.

Police know the suspect’s vehicle.

A camera detects it ten minutes later.

Nobody is going to complain that technology helped bring that child home.

Imagine instead that someone searches a journalist’s vehicle because they want to know who she’s meeting.

Same technology.

Very different use.

That’s why the question:

“Is Flock good or bad?”

isn’t particularly useful.

Ask better questions.

Who can search?

For what crimes?

With what justification?

For how long is information retained?

Who can share it?

Are searches audited?

Does a warrant ever become necessary?

What happens when someone abuses access?

How are false matches handled?

Can citizens see the policies governing their community?

And who gets to decide when surveillance has gone too far?

Convenience Changes the Scale of Surveillance

A police officer has always been able to stand on a public street and read your license plate.

That’s not new.

What’s new is making that observation:

Automatic.

Cheap.

Continuous.

Searchable.

Shareable.

And potentially available across enormous geographic areas.

Technology didn’t invent surveillance.

It removed much of the friction that used to limit it.

That’s the distinction worth debating.

Because friction sometimes protects privacy without anyone realizing it.

It used to require people, time and effort to reconstruct someone’s movements.

Now software can potentially do portions of that work in seconds.

Before You Decide Whether Flock Scares You, Ask One Question

Don’t ask:

“Do I trust the police?”

And don’t ask:

“Do I have anything to hide?”

Those oversimplify the issue.

Ask:

“What rules would I want governing this database if someone I didn’t trust eventually controlled it?”

That’s a much better cybersecurity question.

Because governments change.

Employees change.

Technology changes.

Databases get larger.

Capabilities expand.

And once surveillance infrastructure exists, removing it can be considerably harder than installing it.

Flock may help investigators solve crimes.

It may help recover stolen vehicles.

It may help find missing people.

Those are meaningful benefits.

But a network capable of producing extraordinarily useful investigative intelligence also deserves extraordinarily serious oversight.

The debate isn’t whether technology can watch us.

It clearly can.

The debate is who gets to look back—and under what rules.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #DataPrivacy #Surveillance #DataProtection #Technology


You don’t need to commit a crime to enter a police-searchable database. You just need to drive past the camera.

Cybersecurity
AI
Technology
News

Meta’s 1.4 Trillion Dollar Trial Could Change Social Media Forever

August 19, 2026
•
20 min read

Meta’s $1.4 Trillion Trial Could Change Social Media Forever

The biggest threat to Meta may not be the fine.

A potentially historic trial against Meta begins in California this week.

Twenty-nine state attorneys general are part of a consolidated case accusing Meta of designing Facebook and Instagram in ways that foster addictive behavior among children and teens, while allegedly misleading users and families about the risks.

Meta denies the allegations and says the states’ claims are unsubstantiated and their financial demands vastly disproportionate.

But here’s the number getting everyone’s attention:

$1.4 trillion.

That’s the potential damages figure Meta’s attorneys have previously calculated based on the states’ theories of penalties.

Lawyers representing the states reportedly told the judge that something closer to $200 billion is more realistic.

Either number is extraordinary.

But money may not actually be Meta’s biggest problem.

The states aren’t merely asking Meta to write a check.

They’re asking a federal court to potentially force changes to how Facebook and Instagram actually work.

This Is Being Called Social Media’s “Big Tobacco” Moment

That’s a powerful comparison.

For decades, tobacco companies faced accusations that they understood risks associated with their products while publicly minimizing them.

Eventually, litigation fundamentally changed the industry.

Now critics argue social media is approaching a similar reckoning.

The allegation isn’t simply:

“Bad things exist on Instagram.”

That’s important legally because Section 230 has historically provided online platforms broad protection from liability for content posted by users.

Instead, the states are focusing heavily on something different:

The product itself.

How was it designed?

What did Meta know?

What representations did it make about safety?

And were specific design features intentionally optimized in ways that harmed children?

That distinction could have enormous consequences for the technology industry.

The Government Is Going After the Mechanics of Engagement

According to the filing described by CNBC, the states are seeking changes involving features including:

Infinite scroll.

Autoplay.

Ephemeral content.

Beauty filters.

Engagement-optimized recommendation algorithms.

Those features may seem completely ordinary because we’ve been using them for years.

That’s exactly what makes this case fascinating.

Consider infinite scroll.

There is no natural stopping point.

You don’t reach:

Page 10.

You simply continue.

Swipe.

Swipe.

Swipe.

The next piece of content arrives automatically.

Then another.

Then another.

Autoplay removes another stopping point.

Recommendation algorithms continuously determine what might keep you engaged next.

Individually, these are product features.

Collectively, the states argue they can become part of a system deliberately designed to maximize engagement in ways that are particularly harmful to young users.

Meta disputes that characterization.

A jury will now begin weighing the evidence.

New Mexico Just Gave Other States a Blueprint

California isn’t happening in isolation.

Meta recently lost a significant case in New Mexico involving child-safety allegations.

A New Mexico jury had already ordered $375 million in penalties, and the judge subsequently ordered Meta to pay another $567 million into an abatement fund.

Combined, that’s approaching:

$1 billion.

Meta says it disagrees with the ruling and plans to appeal.

But perhaps more consequential than the money are the remedies.

According to CNBC’s reporting, Meta is being required to improve its age-assurance systems, attempt to develop an AI model specifically capable of predicting whether users are under 13, make reporting underage accounts easier and establish additional reporting mechanisms.

New Mexico Attorney General Raúl Torrez believes that case provides other states with a roadmap.

And California is a radically larger battlefield.

$1.4 Trillion Needs Some Context

The headline is breathtaking.

But it needs to be presented carefully.

Meta has not been fined $1.4 trillion.

Meta’s lawyers calculated that figure based on how they believe the states’ proposed penalty theories could be applied.

The states reportedly put a more likely figure at around $200 billion.

And even that isn’t a judgment.

The trial is only beginning.

There could be appeals.

The eventual damages could be dramatically different.

But the sheer size of the theoretical exposure tells you how seriously both sides are treating this case.

New Mexico has roughly two million residents.

California has nearly 40 million.

Scale the underlying legal theories across California and potentially other states, and relatively small per-user or per-violation penalties can become enormous numbers.

That’s how technology companies encounter a unique regulatory problem:

Software scales instantly. So can liability.

But Imagine Being Forced to Delete the AI

There’s another demand buried inside this case that may be far more interesting than the trillion-dollar headline.

The states are seeking remedies under the Children’s Online Privacy Protection Act, or COPPA.

If Meta is found to have improperly collected personal information from children under 13, the states aren’t merely seeking deletion of that information.

According to the filing described by CNBC, they also want Meta to delete:

“Algorithms and models” trained using that information.

Read that again.

Not just:

Delete the data.

Potentially:

Delete what the machine learned from the data.

That represents an enormous emerging issue for artificial intelligence.

Deleting Data Is Easy. Untraining AI Isn’t.

Imagine discovering that 10,000 prohibited records exist in a database.

Traditional remediation might be straightforward.

Identify the records.

Delete them.

Confirm deletion.

Document what happened.

Now imagine those records were mixed into a dataset containing billions of examples and used to train a machine-learning model.

The original records can be deleted.

But what about their influence on the resulting model?

That’s a completely different technical problem.

A trained model isn’t simply a searchable folder containing copies of every training document.

Training changes model parameters based on patterns learned across enormous datasets.

So regulators increasingly face a difficult question:

If data shouldn’t have been collected in the first place, what happens to an AI system that already learned from it?

That question reaches far beyond Meta.

Every Business Experimenting With AI Should Pay Attention

This isn’t only a Facebook problem.

Businesses everywhere are racing to implement AI.

Employees are uploading:

Customer information.

Contracts.

Meeting transcripts.

Internal emails.

Support tickets.

Medical information.

Legal documents.

Financial data.

Intellectual property.

Source code.

Sometimes nobody has seriously asked:

Are we allowed to use this information this way?

That’s dangerous.

The question shouldn’t simply be:

“Can our AI tool ingest this?”

It should be:

“Do we have the legal and contractual right to let it?”

Those are very different questions.

Your AI Governance Needs to Start Before Training

Businesses implementing AI should document several things before sensitive information enters a system:

What data is being used?

Where did it come from?

Who owns it?

Did the individual consent to this use?

Does it contain regulated information?

Can the AI provider train on it?

Where is it stored?

How long is it retained?

Can it be deleted?

Can derived models be affected by deletion requests?

Can the vendor demonstrate that deletion actually occurred?

These questions belong in vendor reviews now.

Not after the lawsuit.

Healthcare Has an Obvious Problem

Imagine feeding patient information into an AI system.

The model works beautifully.

Six months later someone asks:

Was the vendor authorized to receive that PHI?

Was a proper agreement in place?

Was the information retained?

Was it used for training?

Can it be removed?

Where was it processed?

Who else had access?

Healthcare IT teams need to understand the entire lifecycle of information entering AI platforms.

“The AI was useful” isn’t a compliance strategy.

Law Firms Have the Same Problem With Different Data

Attorneys are increasingly using AI for:

Research.

Document review.

Summarization.

Drafting.

Discovery.

Contract analysis.

But legal documents can contain:

Attorney-client privileged information.

Trade secrets.

Personally identifiable information.

Confidential business information.

Litigation strategy.

Uploading information into the wrong AI environment can create serious confidentiality and data-protection issues.

Law firms need approved AI platforms and explicit rules governing what attorneys and employees can submit.

Schools Should Be Watching California Closely

The lawsuit is directly concerned with children.

And schools increasingly sit at the intersection of:

Student data.

Social media.

AI.

Educational technology.

Behavioral analytics.

Cloud platforms.

Digital identity.

School Technology teams should understand what vendors collect, how that information is used and whether it contributes to machine-learning systems.

Parents are increasingly asking these questions.

Regulators are too.

“Free” Technology Is Usually Paid for Somehow

Meta generates roughly 98% of its revenue from advertising, according to CNBC.

Facebook doesn’t charge most users a monthly subscription.

Instagram doesn’t send teenagers an invoice.

The economic engine depends heavily on attention and advertising.

That creates an unavoidable tension.

Platforms want engagement.

Parents want healthy boundaries.

Advertisers want attention.

Regulators want safety.

Users want useful products.

Algorithms sit in the middle deciding what people see next.

This California trial could help determine how far governments can go in regulating the design decisions behind those systems.

This Could Affect Meta’s AI Ambitions Too

There’s another interesting financial layer.

Meta is simultaneously making one of the largest infrastructure bets in corporate history.

The company could spend as much as $145 billion this year as Zuckerberg pours enormous resources into artificial intelligence infrastructure.

That investment is funded largely by the cash machine created by Meta’s advertising business.

So consider the collision:

Meta wants to spend extraordinary amounts building its AI future.

Meanwhile, states are seeking potentially enormous financial penalties and changes to the products generating the cash financing that future.

That’s why New Mexico’s attorney general told CNBC he believes Wall Street may be underestimating the California case.

A giant fine hurts.

A forced change to the engine producing your money can hurt differently.

Cybersecurity Has Been Heading Toward This Same Problem

For years, cybersecurity professionals have focused heavily on protecting data from outsiders.

Don’t let attackers steal it.

Encrypt it.

Back it up.

Monitor it.

Control access.

That’s still essential.

But AI introduces another category of data protection:

Preventing authorized people from using legitimate data in unauthorized ways.

An employee doesn’t have to be malicious.

They can copy confidential information into an AI tool because they’re trying to work faster.

No malware.

No hacker.

No phishing email.

No ransomware.

The data still potentially went somewhere it shouldn’t.

That’s why modern Data Loss Prevention needs to account for generative AI.

Give Employees Clear AI Rules

Don’t tell employees:

“Be careful with ChatGPT.”

That’s too vague.

Create specific rules.

Define approved AI platforms.

Explain what information cannot be uploaded.

Restrict sensitive categories technically where possible.

Use enterprise AI products with appropriate contractual protections.

Monitor shadow AI usage.

Train employees.

Review vendors.

Maintain data classification.

And involve legal, cybersecurity and compliance teams before deploying systems that ingest sensitive information.

AI governance cannot simply be:

Everybody experiment and we’ll figure it out later.

Know Where Your Data Goes

This is the larger lesson underneath the Meta case.

Data has a lifecycle.

It gets:

Collected.

Stored.

Copied.

Analyzed.

Shared.

Backed up.

Processed.

Used for training.

Derived into other information.

Eventually deleted.

Good cybersecurity and managed IT need visibility across that entire lifecycle.

Because deletion is becoming more complicated.

It isn’t always enough to ask:

“Did you delete my record?”

Increasingly, we may need to ask:

“What did you build with it before you deleted it?”

California Could Set an Enormous Precedent

Meta may win.

The states may win.

Damages may ultimately be nowhere near the numbers currently being discussed.

Appeals could reshape whatever happens at trial.

But the underlying legal fight matters far beyond one company.

Can governments regulate engagement-optimized product design?

Can they force platforms to eliminate features they consider harmful?

Can improperly collected information contaminate models trained on it?

Can courts require those models to be deleted?

And how much responsibility does a technology company bear for designing products specifically engineered to keep people using them?

Those questions are becoming central to the next era of technology regulation.

The Most Expensive Data May Be Data You Never Should Have Collected

Businesses tend to view data as an asset.

More customer information.

More analytics.

More history.

More training data.

More insights.

AI has intensified that instinct.

Collect everything. Train on everything. Learn from everything.

But information can simultaneously be an asset and a liability.

If you don’t need it:

Why collect it?

If you’re not permitted to use it:

Why feed it into AI?

If there’s no retention requirement:

Why keep it forever?

And if you couldn’t explain your use of that information to a regulator, customer, employee or parent:

Why are you doing it?

Meta is heading into court facing numbers ranging from hundreds of billions to a theoretical $1.4 trillion.

But the most consequential outcome may have nothing to do with the final dollar amount.

It may be whether a court tells one of the world’s largest technology companies:

You don’t just have to delete the data.

You may have to delete what your algorithms learned from it.

That’s a warning every company racing into AI should hear.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #ArtificialIntelligence #DataProtection #DataPrivacy #TechRegulation


Meta faces a landmark California trial over child safety, addictive design and data use that could reshape social media and AI governance.

Previous
Next
About
Managed ServicesCybersecurityOur ProcessWho We AreNewsPrivacy PolicyTerms & Conditions
Help
FAQsContact UsSubmit a Support Ticket
Social
LinkedIn link
Twitter link
Facebook link
Have a Question?
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Copyright © {auto update year} Gigabit Systems All Rights Reserved.
Website by Klarity
Gigabit Systems Inc. BBB Business Review