Lawyers Get $147 Million, You Get $5 (09/04/2026)
- › A federal judge will let lawyers claim nearly $147 million of Google's $425 million tracking verdict while class members receive about $5 each.
- › Attackers reportedly had a live feed of every identity document an ID verification company scanned, for more than a year.
- › The ACLU settled with Sonoma County over code enforcement inspectors using drones to look at homes without a warrant.
- › A House Intelligence Committee report urges Customs and Border Protection to use land border biometrics to build profiles.
- › World released ProveKit, an open-source zero-knowledge toolkit that generates identity proofs on a person's own device.
Two numbers from today sit next to each other in a way worth pausing on. A jury decided Google owed $425 million for tracking more than 100 million people, and the people who were tracked will receive about $5 each. Whatever the class action system is currently doing, compensating the person whose data was taken is not the main thing.
Top 5 Critical Privacy Alerts
1. The $425 Million Verdict Reaches People as Five Dollars
A federal judge will allow the lawyers who led the privacy class action against Google to claim nearly $147 million in fees, close to a third of the $425 million a jury ordered the company to pay for allegedly tracking the data of more than 100 million people. Class members are looking at roughly $5 apiece. I do not think the lawyers are the problem here, since somebody had to carry a case like this for years, and the arithmetic still tells you that individual harm divided across 100 million people produces a number too small to function as a remedy. PogoWasRight has the fee ruling.
Operator Note: If your own breach exposure model assumes class actions will price the damage, look at what the damage actually prices at per person, and then look at what your regulator can levy instead.
2. Attackers Reportedly Watched an ID Verification Feed for a Year
Attackers had a live feed of every identity document one verification company scanned, running for more than a year before anybody noticed. This is the same trove that has been surfacing all week at rising counts, and the duration is the detail that changes its character. A stolen database is a copy of the past, while a live feed means every person who verified during that year was compromised on the day they did it, including people who had never heard of the company processing their license. Techdirt has the reporting.
Operator Note: Ask your verification vendor when their last independent assessment was and what it covered, because a year of undetected exfiltration is a monitoring failure rather than an exploit story.
3. Sonoma County Settles Over Warrantless Drone Inspections
The ACLU Foundation of Northern California settled its lawsuit against Sonoma County over a drone surveillance program in which code enforcement inspectors flew over residents’ homes and surrounding property without first getting a warrant, which the suit argued violated the California constitution. Code enforcement is the part of local government nobody watches, and it acquired an aerial capability without anybody deciding it should have one. The settlement curbs the program, and the more useful question is how many other counties bought the same drones for the same department. PogoWasRight has the settlement terms.
4. A House Report Urges CBP to Build Profiles From Border Biometrics
Twenty-five years after the 9/11 Commission called for a biometric system tracking foreign nationals entering and leaving the country, the House Intelligence Committee says the work is unfinished and is pressing Customs and Border Protection to use land border biometrics to build profiles. The phrase doing the work in that recommendation is “build profiles,” which describes something different from checking whether a person is who they claim at a border. A profile is retained, enriched, and consulted later, in contexts nobody at the crossing was told about. PogoWasRight has the committee’s language.
5. World Ships an Open-Source Toolkit for Proofs That Stay on the Device
World released ProveKit, described in its documentation as a production-ready zero-knowledge proving toolkit that lets people generate identity proofs on their own devices. The architecture matters more than the vendor, because a proof generated locally means the verifying party learns that you satisfy a condition without receiving the document that establishes it. Every story above this one exists because somebody centrally retained a scan they only needed to check once. Biometric Update has the technical detail.
Operator Note: When you next evaluate an age or identity check, ask whether the vendor can verify without retaining, because that single question separates the architectures that can leak from the ones that cannot.
Additional Privacy Alerts
Privacy Laws and Regulations
- Asia-Pacific digital identity is splitting into different models: A regional review finds countries adopting sharply different legal and digital identity approaches, creating inclusion gains in some places while leaving millions of stateless people outside every system. Biometric Update
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.