FTC threatens fines for health apps that fail to report compromised data

App developers and device operators that collect health data about Americans must alert consumers in the event their personal information is compromised or shared without permission, the Federal Trade Commission ruled Wednesday. The U.S. consumer protection agency voted 3-2 on a new regulation that is meant to clarify the 2009 Health Notification Rule, which details how companies should tell consumers if their data is improperly shared or breached. The decision Wednesday extends the 2009 rule to cover health apps, fitness trackers and other connected devices that have risen in popularity over the past decade. “The global pandemic has hastened the adoption of virtual health assistants, with Americans placing their trust in various technologies to track and manage their personal health,” FTC chair Lina Khan said in a statement. “As we have seen, however, digital apps are routinely caught playing fast and loose with user data, leaving users’ health information susceptible […]

The post FTC threatens fines for health apps that fail to report compromised data appeared first on CyberScoop.

Continue reading FTC threatens fines for health apps that fail to report compromised data

FTC proposes first stalkerware ban, promises to toughen stance on abusive apps

The Federal Trade Commission is seeking its first ban of a “stalkerware” company, signaling an intent to crack down on surveillance technologies that expose individuals’ real-time activities to snoops, hackers and dangerous people. A complaint released by the agency Wednesday alleges that SpyFone, an app that markets itself as a tool to monitor loved ones’ internet activity, and its CEO Scott Zuckerman sold real-time access to illegally harvested phone data including location and email, enabling surveillance by stalkers and domestic abusers. The FTC also accused SpyFone of failing to enact basic security measures to safeguard the data it collects, leading to a 2018 data breach that exposed the personal data of roughly 2,200 customers. The FTC alleges that the company failed to follow through on promises to customers that it would upgrade its security after the incident. In addition to a ban on any future sales or marketing of surveillance […]

The post FTC proposes first stalkerware ban, promises to toughen stance on abusive apps appeared first on CyberScoop.

Continue reading FTC proposes first stalkerware ban, promises to toughen stance on abusive apps

Spyware Company Leaves ‘Terabytes’ of Selfies, Text Messages, and Location Data Exposed Online

A company that sells surveillance software to parents and employers left “terabytes of data” including photos, audio recordings, text messages and web history, exposed in a poorly-protected Amazon S3 bucket. Continue reading Spyware Company Leaves ‘Terabytes’ of Selfies, Text Messages, and Location Data Exposed Online