Robin’s Newsletter #430

13 September 2026. Volume 9, Issue 37
ID Scan source of 150 million stolen drivers' licenses. Peers propose personal liability in CSRB. Apple introduces 'audio intelligence' feature.
Join hundreds of subscribers who get this first, every Sunday. Subscribe

This week

This week marks Cydea’s 7th birthday. I founded the company back I n2019 to bring the world more positive security. Over 30 people have been part of the team in that time, delivering over 250 projects to customers starting with every letter of the alphabet but X (please get in touch if you can help with this! 😉). A big thank you to all colleagues, customers, and collaborators past and present!

Need to Know, 13th September 2026

  • ID Scan source of 150 million breached driver’s licenses
  • Backlash against LG harvesting data from smart TVs for advertising purposes
  • Revolut handed over customer data to fraudulent requestor
  • Apple’s ‘audio intelligence’ feature tests its privacy footing
  • Peers question why CSRB doesn’t include personal liability for execs

Interesting stats

85% of CISOs told Proofpoint that ensuring the safe use of AI assistance, copilots, and other automation is a top priority over the next two years,  8/10 of them say they’re being expected to do so without receiving a proportional increase in resources LINK … meanwhile… 10% chance that AI “could kill all humans” in the next decade, says one of Anthropic’s top safety researchers

Five things

  1. ID Scan has confirmed it is the source of a data breach comprising 150 million drivers’ licenses. The original compromise apparently occurred over a year ago, and the Louisiana-based company says the information includes full names, license numbers, and other government-issued identity documents provided to verify people’s identities. This is a staggeringly large breach, and the fact that it was ongoing for so long also suggests pretty poor monitoring within the firm’s production infrastructure.

  2. Smart TVs from LG are harvesting audio and watching habit data to target ads. “Automatic content recognition” has been a known thing for a while, and works by analysing the content on the screen, meaning it can detect things you may be playing from an HDMI source, not just reporting the channel selected in the EPG. This is a whole new class of potentially invasive techniques, including the apparent buffering of audio recordings while the device is offline to upload once a connection is reestablished. LG has refuted the claims, saying audio is only recorded following a ‘wake word’ or when a button on the remote is pressed. I haven’t verified the claims; however, the wake word/button doesn’t appear to be pressed in the video published by the security researchers. Most tellingly, regardless of the claims, LG’s terms (and industry marketing videos) say they “own the glass” in its TVs and all the data associated with what you watch on them in your living room.

  3. Challenger bank Revolut handed over sensitive customer data to threat actors who sent fraudulent requests from emails on a legitimate government domain. The fintech says the number of customers affected is “limited”, but not how many or by what. The information included names, DoB, post, email, and phone contact information, plus identity documents, account statements and transaction histories. Thousands of law enforcement and other government agencies globally may have legitimate reasons to request data. This is a failure to verify the requestor’s authenticity properly.

  4. Apple debuted a new ‘audio intelligence’ feature for its newest smartwatches that will listen to conversations and provide high-level recaps. The Cupertino-based company has gone to great lengths to try and reassure people that the feature is optional and audio recordings aren’t stored or shared. Apple has made privacy a point of differentiation from competitors like Google, so this feature jars with that positioning.

  5. Cyber Security and Resilience Bill: Peers in the House of Lords have questioned why personal liability doesn’t feature in the UK’s forthcoming cyber legislation. Punishment for non-compliance is proposed to be up to £17 million, or 4% of annual turnover (whichever is greater). But Baronesses Kidron and Ludford backed looking at changes to introduce personal civil liability for CNI executives who are complicit, through deliberate action or careless neglect, in failing to adequately secure their organisations. Adding to the debate, Lord Clement-Jones said: “If an individual is fit to draw a multimillion-pound executive salary running a critical national provider, they must be prepared to carry personal responsibility for securing it.” I agree: culture starts at the top, and an additional tool in the enforcement toolbox seems useful.

In brief

And finally

Robin
  Critical National Infrastructure (CNI) Artificial Intelligence (AI) Cyber Security and Resilience Bill (CSRB) Identity Verification Automatic Content Recognition Privacy Audio Intelligence Personal Liability Smart TVs Cyber Resilience Act