Is your phone spying on you? Just a few years back this was the common question as smart phone adoption spread across the globe.

Nowadays, of course, the answer is yes; but this also applies to just about any service we can think of. Google, a recidivist, has fallen into hot water again, this time fined over €400 million by the Irish Data Protection Commission (DPC) over improper processing of location data, and accusations from users that Google was following their every digital step. Furthermore, Google is accused of using trickery to mislead users into always enabling location history and online activity, then using that data to influence them with ads.
Judging by an earlier report by Forbrukerrådet, the Norwegian consumer organization and member of the European Consumer Organisation (BEUC), users lacked straightforward information and stayed in the dark about Google’s data collection practices. The company is also ordered to come into compliance with GDPR’s rules for data processing.
It was this earlier report in 2018 that would soon prompt action from the DPC. This of course begs the question: what took them so long? The DPC began its inquiry in 2020, to see if Google had a valid basis for its use of location data. According to Agustín Reyna, director general of BEUC, “the time needed to come to this conclusion is disproportionate with the seriousness of the infringement,” and “late enforcement can be as harmful as no enforcement at all.”
Speaking of enforcement, the FBI continues to grapple with its own embarrassing data breach, which has recently made major headlines. When ShinyHunters took aim at the bureau this time, they had already claimed to “have data on mostly all of the FBI.” Now, thanks to an exploit in an Oracle PeopleSoft server, they have ended up stealing federal employees’ names, addresses, Social Security numbers, and job titles (this is evidenced by internal notifications to staff rather than public acknowledgement). Some medical information such as psychiatric reports was also accessed.
Oddly, ShinyHunters is not demanding any financial payment this time, rather the “correction” of a previous FBI report that supposedly mischaracterizes their activities and warned organizations to be on guard. ShinyHunters wants that warning rescinded. As a result, thousands of FBI personnel are now exposed to phishing, profiling, and even foreign intelligence approaches.
Of course, even if the warning is taken back, it’s not as if ShinyHunters tries to fly under the radar or put an altruistic face to their operations. No less than your phone, no less than Google, cyber criminals want your data for their own profitable ends. Even today, enterprise data is still left insecure and vulnerable, as organizations look to detect, prevent and respond to attacks. Unfortunately, this too often leaves the data itself unprotected when the attackers break through. NetLib Security advocates for a data-centric approach that integrates strong data encryption with traditional cybersecurity defenses: protecting information at the data level and leaving nothing to chance.