| ____|| ____|| ____|___ __ | |_ ___ _ _
| ____|| ____|| ____|/ -_)/ _|| _|/ _ | '_|
|______||_| |_| ___| __| __| ___/|_|
EFFector Vol. 38, No. 1 Wednesday, Jan 14, 2025
[email protected]
A Publication of the Electronic Frontier Foundation
ISSN 1062-9424
effector: n, Computer Sci. A device for producing a desired change.
: . : . : . : . : . : . : . : . : . : . : . : . : . : . :
💾 The Worst Data Breaches of 2025—And What You Can Do
Welcome to an all-new EFFector, your regular digest on everything digital rights from the Electronic Frontier Foundation.
In our 836th issue: A deep dive into ICE's spy tech shopping spree, how to follow the money on Homeland Security spending, and the most noteworthy data breaches of 2025.
When you lose your rights online, you lose them in real life. Become an EFF member today!
[link removed]
: . : . : . : . : . : . : . : . : . : . : . : . : . : . :
Featured Story: The Worst, Weirdest, Most Impactful Data Breaches of 2025
Another year has come and gone, and, with it, thousands of data breaches affecting millions of people. These days, the question generally isn't *if* your information was compromised in a breach this year, it's *how many* different breaches compromised your private data.
Some data breaches, however, are more noteworthy than others. While one might affect a small number of people and include little useful information, another might include specific location information or even a potential medical diagnosis. To bring attention to these breaches we created the Breachies, a series of tongue-in-cheek awards highlighting each year's most egregious data breaches.
This year's honors include the I Didn’t Even Know You Had My Information Award (bestowed upon location data broker Gravy Analytics for a hack that exposed tens of millions of mobile phone coordinates), the Hacker's Hall Pass Award (given to PowerSchool for a breach that compromised personal information of over 60 million students and teachers), and the Annual Microsoft Screwed Up Again Award (awarded to, duh, Microsoft). [1] [2] [3]
Of particular note is Discord's prize, the We Still Told You So Award. EFF has repeatedly warned that age verification laws create serious security risks (on top of being harmful censorship and surveillance regimes). [4] These mandates require users to hand over some of their most sensitive information (like government IDs and faces) before accessing content online—sensitive information that can then be compromised by hackers. And, sure enough, much of Discord’s age verification data was breached in 2025, including users’ real names, selfies, ID documents, and email and physical addresses. [5]
While the seemingly endless number of data breaches can make it feel like there's nothing you can do to protect your information, it's actually a good reason to take action. On our blog, we name a number of steps you can take right now to protect yourself from the next data breach. Some simple ones include using unique passwords on all your accounts, using two-factor authentication when it's offered, and deleting old accounts.
Of course, individual self-protection only addresses the symptoms of a world where companies gobble up as much data as they can, store it for as long as possible, and don't do enough to protect it. Companies need to do a better job of only collecting the information they need to operate, and properly securing what they do store. And, as we've said before and will say again and again, lawmakers need to pass comprehensive privacy protections. [6]
READ MORE: [link removed]
[1] [link removed]
[2] [link removed]
[3] [link removed]
[4] [link removed]
[5] [link removed]
[6] [link removed]
: . : . : . : . : . : . : . : . : . : . : . : . : . : . :
‌EFF Updates
🧊 ICE SPY TECH: With billions more dollars at their disposal, the U.S. Immigration and Customs Enforcement (ICE) has been going on a surveillance tech shopping spree. In recent months, ICE has inked contracts for location, social media, phone, and face surveillance tools. On our blog, we dig into each of these—and what EFF and others are doing to stop the spying.
[link removed]
đź’°FOLLOW THE MONEY: Hundreds of companies are looking to cash in on increased spending by the U.S. government on immigration enforcement and border surveillance. Recently, we updated our database of vendors selling their tech to the U.S. Department of Homeland Security (DHS). Now, we're also sharing our research methods so that you, too, can follow the DHS spending trail.
[link removed]
🤓 HACKERS AGAINST ICE: It can be hard to imagine how to defend oneself against such an overwhelming force like ICE, which is spending hundreds of millions of dollars to spy on anyone—and potentially everyone—in the United States. But a few enterprising hackers have started projects to do counter-surveillance against ICE, and hopefully protect their communities through the clever use of technology.
[link removed]
🪪 AGE VERIFICATION: Age verification mandates are spreading fast, and they’re ushering in a new age of online surveillance, censorship, and exclusion for everyone—not just young people. Join our free livestream on Thursday, January 15, at 12pm PT: "EFFecting Change: The Human Cost of Online Age Verification." Speakers from EFF, Gen-Z for Change, and the Collaborative Research Center for Resilience will discuss what we stand to lose as more and more governments push to age-gate the web.
[link removed]
: . : . : . : . : . : . : . : . : . : . : . : . : . : . :
Don’t Let Tyrants Co-opt Tech
Technology is supercharging the attack on democracy by making it easier to spy on people, block free speech, and control what we do. The Electronic Frontier Foundation’s activists, lawyers, and technologists are fighting back.
Join the movement to Take Back CTRL. For a limited time, join EFF for as little as $20. As our thanks, you’ll get a Take Back CTRL Camera Cover Set with any member gift.
[link removed]
: . : . : . : . : . : . : . : . : . : . : . : . : . : . :
"The biggest thing is data minimization. It's collecting less. It is asking less from us and storing it less."
EFF's Thorin Klosowski in ​this week's ​EFFector audio companion​ on what companies need to be doing to protect us from the threat constant data breaches pose. Hear our discussion with Thorin ​here​​:
[link removed]
: . : . : . : . : . : . : . : . : . : . : . : . : . : . :
MiniLinks
🗣️ Free Speech
- "How to Make Sense of Trump’s TikTok Deal" (Tech Policy Press)
[link removed]
- "Why Are Grok and X Still Available in App Stores?" (Wired)
[link removed]
đź”’ Privacy
- "'Worst in Show' CES products include AI refrigerators, AI companions and AI doorbells" (Associated Press)
[link removed]
🔍 Transparency
- "Cops Forced to Explain Why AI Generated Police Report Claimed Officer Transformed Into Frog" (Futurism)
[link removed]
🌎 International
- "Iran’s internet shutdown is chillingly precise and may last some time" (The Guardian)
[link removed]
🗝️ Security
- "Founder of spyware maker pcTattletale pleads guilty to hacking and advertising surveillance software" (TechCrunch)
[link removed]
: . : . : . : . : . : . : . : . : . : . : . : . : . : . :
Announcements
* Events
- EFFecting Change: "The Human Cost of Online Age Verification" 🪪 Livestream | Jan. 15
[link removed]
- "Democracy: How AI Will Transform Our Politics, Government, and Citizenship" Book Discussion đź“– Livestream | Jan. 24
[link removed]
- EFF at CactusCon 🌵 in Mesa, AZ | Feb. 6-7
[link removed]
- EFF at BSides Seattle đź’ż in Seattle, WA | Feb. 27-28
[link removed]
* EFF Opportunities
- Summer 2026 Legal Internship
[link removed]
* Corporate Giving and Sponsorships
EFF thanks Binary Ninja, SerpApi, Wilson Sonsini Goodritch Rosati, Fenwick & West, AdeliaRisk, and Zellic for their generous support of our work fighting for your privacy online. Learn how your team can join the fight for digital rights at [link removed].
: . : . : . : . : . : . : . : . : . : . : . : . : . : . :
Fresh EFF Gear Is Here
Show off your support for EFF with hot digital rights merch from ​our online store​. Just in: A "Let's Sue the Government" ringer tee to send the signal that our rights are not optional.
In addition to EFF shirts and hoodies, we have a wide variety of freedom-supporting swag in stock, including (extremely popular) ​liquid core gaming dice​​, ​HTTP playing cards​​, and a ​​tactile Lady Justice braille sticker​.
[link removed]
: . : . : . : . : . : . : . : . : . : . : . : . : . : . :
Administrivia
Editor:
[email protected]
Membership & donation queries:
[email protected]
General EFF, legal, policy, or online resources queries:
[email protected]
Reproduction of this publication in electronic media is encouraged. MiniLinks do not necessarily represent the views of EFF.
Back issues of EFFector are available via the Web at:
[link removed]
Unsubscribe from future mailings or change your email preferences: [link removed]
Opt out of all EFF email: [link removed]
815 Eddy Street, San Francisco, CA 94109 USA​