Robin’s Newsletter #428

30 August 2026. Volume 9, Issue 35
UK gov giving itself powers to secretly block foreign tech. Alabama opens investigation into OpenAI hacking. Manchester Airport Group data breach.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

Need to Know, 30th August 2026

  • UK Gov reviewing “home defence” resilience plans; granting itself powers to block foreign tech.
  • Alabama AG opens investigation into OpenAI hacking spree
  • Manchester Airport Group data breach affects 8.7 million passengers

Interesting stats

X% your personal estimated identifiability, according to a diagnostic tool created by a researcher to show how identifiable you are (or aren’t!), based on common fingerprinting techniques used by data brokers and ad tracking firms to follow you around the internet: Glassbox. 

~Five~ Three things

  1. The UK government is revising “home defence” plans and will urge citizens to store bottled water and tinned food to boost resilience against extreme weather events and cyber threats. The government also made amendments to the Cyber Security and Resilience Bill, currently at committee stage in the House of Lords, to give itself powers to block technology suppliers deemed to be a national security risk. The powers change those used to keep Huawei gear out of the UK’s 5G core networks and allow the government to order a company (e.g., a telco, water, or electricity company) not to use a specific vendor. The vendor wouldn’t need to be notified and can be subject to non-disclosure, preventing public discussion of the order. In a similar move, this week the Trump Administration banned foreign-made equipment from power generation and electricity management systems, because “certain foreign actors are increasingly creating and exploiting vulnerabilities”.

  2. Alabama has launched an investigation into OpenAI’s compromise of Hugging Face, with the state’s attorney general citing the alleged “complete lack of oversight and adequate safeguards” in a subpoena to the AI firm. OpenAI has admitted that its agents managed to gain internet access 11 days before it started attacking Hugging Face on 11 July, and the company didn’t notice the issue until over a week later on 19 July, all the time a ‘squad’ of around 700 agents were communicating on an improvised message board, via “disallowed internet access” but for which OpenAI staff decided there was no need to stop the test.

  3. Manchester Airport Group, which owns Manchester, London Stansted, and East Midlands airports, says attackers have stolen the personal data of 8.7 million passengers. While “at no point has passenger safety or aviation security been compromised,” data captured for car park, lounge and fast-track bookings, and airport wi-fi access was accessed. Payment and bank details were not held on the affected system. A group calling itself FulcrumSec has claimed responsibility and says it pilfered 86GB of data.  

In brief

And finally

Robin
  Critical National Infrastructure (CNI) Energy Grid Artificial Intelligence (AI) Transport Cyber Security and Resilience Bill (CSRB) General Data Protection Regulation (GDPR)