A Pegasus Whistleblower, a Period Tracker & the 23andMe Payout (07/16/2026)
- › A whistleblower from Morocco's DGST intelligence agency described the service deploying Pegasus against journalists and opponents after a 2017 demonstration in Rabat.
- › Mozilla found the period tracker Stardust sharing users' health data with an analytics firm, while another tracker it tested was clean.
- › Iowa joined 41 other states in an $18 million settlement with 23andMe over the 2023 breach that exposed 6.9 million people's data.
- › Ofcom opened a formal investigation into TikTok over age checks it believes are leaving children exposed to suicide and self-harm content.
- › French police worked around European privacy law to catch a serial rapist, which is the hardest version of this argument.
A man who spent ten years inside Morocco’s intelligence service came forward to describe what his colleagues did with Pegasus, starting in 2017, and who they pointed it at. Elsewhere a period tracker handed your cycle to an analytics firm, 42 states settled for $18 million over 6.9 million stolen genetic profiles, and French police caught a serial rapist by going around the privacy law rather than through it. Every one of these is a question about who gets to know a thing about you, and who decided.
Top 5 Critical Privacy Alerts
1. A Moroccan Intelligence Insider Describes Years of Pegasus Use
A whistleblower using the pseudonym “Safir,” a former agent at Morocco’s internal intelligence agency, the Direction Générale de la Surveillance du Territoire (DGST), described the service deploying Pegasus against journalists and opponents after officials attended a demonstration at a villa in Rabat in 2017 (The Guardian, Forbidden Stories). The account comes through Forbidden Stories, Amnesty International’s Security Lab, and 13 international outlets, built on leaked emails, targeting records, internal training material, and victim testimony. On how Morocco got it, Safir described an Emirati intermediary footing the bill, though the consortium notes the funding claim is unverified: “Millions are nothing to the Emiratis. They bought it and redistributed it to friendly agencies. You could say it’s like Netflix: One friend pays for the subscription, and the others use his account” (Forbidden Stories).
Operator Note: We normally learn about this class of tool from forensics on a victim’s phone, years late. This time it arrives with the training material and the emails, which means we get to see the decision-making. Commercial spyware is sold as a counterterrorism instrument and lands on journalists and rivals, and the tool does not make that choice. People do. The record of who they picked is the only honest measure of the tool.
2. Mozilla Finds a Period Tracker Sharing Health Data
Mozilla researchers found the period tracking app Stardust sharing users’ health data with an analytics company, while a different tracker they tested came back “squeaky clean” (TechCrunch). That gap matters more than the finding. Two apps in the same category, doing the same job, and one treats your cycle as a record to sell. The user cannot see the difference from the app store page.
3. Iowa and 41 Other States Settle With 23andMe
Iowa is among 42 state attorneys general reaching an $18 million settlement with 23andMe over the October 2023 breach that exposed 6.9 million people’s data, including genetic ancestry information (PogoWasRight, The Record). The investigation found the company had no protections against attacks using stolen credentials, and no logging or monitoring to catch one. A password gets rotated and a card gets reissued. Your genome does neither, and it implicates relatives who never used the service and never agreed to anything.
Operator Note: $18 million across 42 states works out to roughly $2.60 per exposed person. Set that against what the data is worth to the people it describes, and you have the whole problem in one number.
4. Ofcom Opens a Formal Investigation Into TikTok
The UK regulator opened a formal investigation into TikTok over concerns its age verification is ineffective, leaving children exposed to content on suicide, self-harm, and pornography (The Guardian, The Record). Ofcom chief executive Melanie Dawes said “Age checks are a cornerstone of the UK’s online safety laws. Too many services have no or inadequate age checks in place, which is not good enough.” The harm here is real and specific, which is exactly why the mechanism deserves scrutiny rather than applause: proving a child is a child means checking everyone.
5. French Police Went Around Privacy Law to Catch a Serial Rapist
French investigators skirted European privacy law to identify a man who kidnapped and raped a teenage girl in 1998 and attacked four more over the following decade (PogoWasRight). This is the hardest case anyone can put in front of a privacy argument, and it deserves an honest answer rather than a slogan. The question is never whether the outcome was good. It is whether the method becomes routine once it works, and applied to whom next.
Additional Privacy Alerts
Privacy Laws & Regulations
- EFF Presses the Commission on DSA Trusted Flaggers: EFF and ARTICLE 19 filed joint comments on draft European Commission guidelines for the Digital Services Act’s trusted flagger mechanism, arguing for expression protections alongside intermediary liability. EFF
Regulatory Fines & Enforcement Actions
- Hopper Pays $35 Million Over Hidden Fees: The travel booking company and its Canadian parent settled FTC allegations under Section 5 and the Fees Rule, including charging “Tip” and VIP Support fees without consumers’ knowledge or express informed consent. Inside Privacy
Data Minimization & User Consent
- xAI Sues a User Over Grok-Generated Abuse Material: Elon Musk’s AI company sued a South Carolina man, already arrested on exploitation charges, for allegedly using Grok to generate child sexual abuse material, one of the first suits an AI company has brought against its own user. The Guardian
The Axe Report is a daily briefing from Grab The Axe. Need help assessing your organization’s security posture? Take our free Human Attack Surface Score assessment.
A PhD candidate in Health Psychology and former Corrections Officer, Jeff founded GTA to dismantle passive security models. He focuses on the 'Human Zero-Day', mitigating executive burnout and decision fatigue before they become security breaches.
View Profile →Media Inquiries
For expert commentary, interview requests, or high-res assets regarding this announcement, initialize the terminal.