Cybersecurity · Thursday, 23 July 2026
01 · Briefing · what happened
Your period tracker isn't hacked — that's the business model
A study of six popular period-tracking apps found some quietly share intimate health data with ad and analytics firms — no break-in required. Plus fresh breaches at Suno, Ernst & Young and a hospital-software firm, a rare regulator's fine, and CISA racing to close holes already under attack.
Key takeaways
- A study of six popular period-tracking apps found some quietly share intimate health data with ad and analytics firms — not a hack, but how free apps make money.
- Fresh breaches hit AI music platform Suno (55M+ accounts), Ernst & Young, and a software firm serving 2,000+ US hospitals — in each, users carry a risk the company chose.
- Spain fined 23andMe €2.4M for weak login security, a rare case of the cost landing on the company; CISA raced to patch flaws already under active attack.
When the leak isn’t a break-in
The Mozilla Foundation studied six popular period-tracking apps — Flo, Clue, Stardust, Spot On, Period Calendar and Euki
Stardust was the only app found sending detailed reproductive-health data — pregnancy status, birth control, moods, symptoms like cramps — to an outside data company not named in its privacy policy
None of this is a hack. It is how many free apps make money: they collect what you do and pass it to advertising and analytics firms — outside companies that profile people to sell ads
Why it matters: since the US Supreme Court overturned federal abortion protections in 2022, researchers warn this data could surface in criminal cases, and police have already pulled other tech-company data to help jail women
There is good news too. Mozilla found some apps had cleaned up, and called one — Euki — “squeaky clean”
The bank version of the same leak
Financial firms do a quieter version of the same thing. Researchers at Jscrambler found European and US banks transmitting customer data to advertising and analytics platforms through tracking pixels — often, it appears, without the banks realising
Across 14 cases the researchers documented, tracking fired without a valid consent choice at nine companies — sometimes before the cookie banner was touched, sometimes after the user had said no
And when data leaks by force, the numbers are large. A breach at AI music platform Suno exposed more than 55 million user accounts, mostly email addresses, plus some names, physical addresses and partial card details
In each case the company made the security choices. The people whose data spilled — Suno’s users, hospital staff, accounting clients — had no say, and carry the risk.
When someone finally sends the bill
Occasionally the cost lands back on the company that made the choices. Spain’s data-protection regulator fined the genetics firm 23andMe €2.4 million (about $2.7 million) over its 2023 breach, which exposed data on 6.9 million people worldwide
The regulator’s decision is pointed. It blames the firm’s lack of mandatory two-step login — a second check beyond the password — for letting attackers reuse stolen passwords to walk in
The cost isn’t always a fine. Nichirei, a Japanese frozen-food giant, had operations disrupted by a cyberattack, cutting supply to thousands of clients including major chains like KFC
The holes already being used
Meanwhile CISA, the US cyber-defence agency, spent the week ordering urgent patches
One of the Fortinet flaws lets an attacker with no login run commands on the device through a specially crafted web request
02 · Lesson · why it matters
The one who decides how safe you are isn't the one who pays
When the person choosing how well your data is protected isn't the person harmed if it leaks, protection loses every time it costs them money.
Two different people
Look at what these stories share. An app decides how carefully to guard your health data. A bank decides whether its website leaks to advertisers. A genetics firm decides whether to require a second login step. In every case, one person makes the choice — and a different person feels it if the choice is wrong.
You are the second person. Your pregnancy status, your card details, your DNA sit in systems whose owners don’t share your downside. When the app maker or the bank or the firm decides how much to protect that data, they are spending your risk, not their own.
That single gap — the decider and the payer are not the same person — explains more security failures than any clever attack does.
Why “free” points one way
Start with the period trackers. A free app has to make money somehow, and the usual way is to collect what you do and pass it to firms that profile people to sell ads. So the app’s incentive runs one direction: collect more, share more, guard less. Every scrap of data shared is a little more revenue; every wall built to protect it is a cost with no matching payoff.
This is not villainy. It is arithmetic. When sharing pays and protecting costs, and the harm from a leak lands on someone else, a rational company drifts toward sharing. Point the same arithmetic at a bank adding a marketing tracker, and you get customer data quietly firing off to ad platforms — often, the researchers found, without the bank even noticing. Nobody chose to harm you. Nobody had a reason to stop.
The gap has a name
Economists call this an externality — a cost of your decision that falls on somebody else, so you don’t weigh it. Security is the textbook case. The person who sets the defence doesn’t pay for the breach, so they under-build the defence. Not sometimes. Systematically.
23andMe is the gap in one sentence. The company warned about cyber threats at length in its own financial filings — it clearly understood the risk. And its systems still didn’t require a second login step, the cheap, standard protection that would have blunted the very attack that hit it. Understanding the risk didn’t fix it, because the risk wasn’t the company’s to carry. The exposure fell on 6.9 million people. The boardroom felt almost none of it.
Who is actually inside this
That is the part worth sitting with. The frightening numbers in the news — 55 million accounts at one music app, employee records across 2,000 hospitals — are not the company’s loss. They are yours, and people like you. The breach is counted in the company’s press release and paid for in your inbox, your bank calls, your years of watching for fraud.
The harm lands on whoever had the least say. You didn’t pick the app’s data-sharing partners. You didn’t design the bank’s website. You can choose the squeaky-clean tracker over the leaky one — and that is worth doing — but you cannot opt out of being the party who absorbs decisions made in rooms you’ll never enter.
The arrangement is a choice, not a law
Here is the part that hides in plain sight: who pays when data leaks is itself something people decided. For years the arrangement put almost none of the cost on the company that collected the data. That wasn’t nature. It was a set of rules, and rules can be rewritten.
That is what a fine is. When Spain’s regulator moved €2.4 million onto 23andMe, it wasn’t punishment for its own sake — it was an attempt to close the gap, to make the decider feel a slice of the harm so that guarding your data finally competes with the money saved by not guarding it. Breach-disclosure laws and privacy rules do the same thing: they drag some of the cost back toward the person who made the choice. The arrangement can serve the collector and still be renegotiated. Every fine is that negotiation, out loud.
What seeing this leaves you with
Knowing the shape doesn’t make you safe. It makes you steadier when the next breach headline arrives with your name somewhere inside it — because you’ll understand it wasn’t bad luck or a genius hacker. It was a gap that was always there, between the person who decided and the person who pays.
You are inside a system where safety is cheap for you to want and expensive for someone else to provide. Until those two are the same person — pushed together by a fine, a law, a market that finally rewards it — the gap holds, and it holds against you. That’s not a reason to despair. It’s a reason to hold the reassurances loosely, to notice who profits from the setting you’re being asked to trust, and to remember that the arrangement pointing the cost at you was written, which means it can be written differently.
03 · Lab · your turn
You Set the Security Budget
Rehearse how a decider who won't pay for a breach under-protects — until a fine moves the cost back onto them.
04 · Hope · carry this
The setup that let companies decide your safety and hand you the bill was written by people, not by nature — and every fine like Spain's is a quiet sign that people are starting to rewrite it.
More from Cybersecurity