Daylila

Cybersecurity · Thursday, 23 July 2026

01 · Briefing · what happened

Your period tracker isn't hacked — that's the business model

Cybersecurity 4 min 80 sources

A study of six popular period-tracking apps found some quietly share intimate health data with ad and analytics firms — no break-in required. Plus fresh breaches at Suno, Ernst & Young and a hospital-software firm, a rare regulator's fine, and CISA racing to close holes already under attack.

Key takeaways

  • A study of six popular period-tracking apps found some quietly share intimate health data with ad and analytics firms — not a hack, but how free apps make money.
  • Fresh breaches hit AI music platform Suno (55M+ accounts), Ernst & Young, and a software firm serving 2,000+ US hospitals — in each, users carry a risk the company chose.
  • Spain fined 23andMe €2.4M for weak login security, a rare case of the cost landing on the company; CISA raced to patch flaws already under active attack.

When the leak isn’t a break-in

The Mozilla Foundation studied six popular period-tracking apps — Flo, Clue, Stardust, Spot On, Period Calendar and Euki [77]. Some lock your data down. Others handle it in ways you might not expect [77].

Stardust was the only app found sending detailed reproductive-health data — pregnancy status, birth control, moods, symptoms like cramps — to an outside data company not named in its privacy policy [77]. Several of the apps share information with Google, Meta and TikTok [77]. Stardust says it only routes data through that company as a “technical pipeline” and shares nothing that could identify you by name [77].

None of this is a hack. It is how many free apps make money: they collect what you do and pass it to advertising and analytics firms — outside companies that profile people to sell ads [77].

Why it matters: since the US Supreme Court overturned federal abortion protections in 2022, researchers warn this data could surface in criminal cases, and police have already pulled other tech-company data to help jail women [77]. Every extra company that holds your data is one more place it can leak or be handed over under a legal request [77].

There is good news too. Mozilla found some apps had cleaned up, and called one — Euki — “squeaky clean” [77]. If an app is free and holds something this private, it is worth checking what it shares.

The bank version of the same leak

Financial firms do a quieter version of the same thing. Researchers at Jscrambler found European and US banks transmitting customer data to advertising and analytics platforms through tracking pixels — often, it appears, without the banks realising [60]. A tracking pixel is a tiny invisible image that reports back who visited and what they did [60].

Across 14 cases the researchers documented, tracking fired without a valid consent choice at nine companies — sometimes before the cookie banner was touched, sometimes after the user had said no [60].

And when data leaks by force, the numbers are large. A breach at AI music platform Suno exposed more than 55 million user accounts, mostly email addresses, plus some names, physical addresses and partial card details [16]. Ernst & Young, one of the big-four accounting firms, disclosed a breach affecting personal and financial information [46]. Craneware, whose software runs in more than 2,000 US hospitals, said hackers stole data on employees, customers and business partners [56].

In each case the company made the security choices. The people whose data spilled — Suno’s users, hospital staff, accounting clients — had no say, and carry the risk.

When someone finally sends the bill

Occasionally the cost lands back on the company that made the choices. Spain’s data-protection regulator fined the genetics firm 23andMe €2.4 million (about $2.7 million) over its 2023 breach, which exposed data on 6.9 million people worldwide [45].

The regulator’s decision is pointed. It blames the firm’s lack of mandatory two-step login — a second check beyond the password — for letting attackers reuse stolen passwords to walk in [45]. That method, called credential stuffing, works because people reuse passwords across sites, so one leaked login opens many doors [45]. 23andMe’s own financial report had warned at length about cyber threats, while its systems still did not require that basic protection [45].

The cost isn’t always a fine. Nichirei, a Japanese frozen-food giant, had operations disrupted by a cyberattack, cutting supply to thousands of clients including major chains like KFC [8][18]. When a supplier’s systems seize up, the shortage travels down to everyone who depended on it.

The holes already being used

Meanwhile CISA, the US cyber-defence agency, spent the week ordering urgent patches [1]. Several flaws are being actively exploited — meaning attackers are already using them in the wild, before most organisations have fixed them — in Fortinet security appliances, Microsoft SharePoint, ServiceNow and Oracle software [1][10][6][7].

One of the Fortinet flaws lets an attacker with no login run commands on the device through a specially crafted web request [1]. A flaw is only a risk once someone uses it; these already are. The patches are out. The window to apply them before an attacker does is the whole game.

02 · Lesson · why it matters

The one who decides how safe you are isn't the one who pays

When the person choosing how well your data is protected isn't the person harmed if it leaks, protection loses every time it costs them money.

Two different people

Look at what these stories share. An app decides how carefully to guard your health data. A bank decides whether its website leaks to advertisers. A genetics firm decides whether to require a second login step. In every case, one person makes the choice — and a different person feels it if the choice is wrong.

You are the second person. Your pregnancy status, your card details, your DNA sit in systems whose owners don’t share your downside. When the app maker or the bank or the firm decides how much to protect that data, they are spending your risk, not their own.

That single gap — the decider and the payer are not the same person — explains more security failures than any clever attack does.

Why “free” points one way

Start with the period trackers. A free app has to make money somehow, and the usual way is to collect what you do and pass it to firms that profile people to sell ads. So the app’s incentive runs one direction: collect more, share more, guard less. Every scrap of data shared is a little more revenue; every wall built to protect it is a cost with no matching payoff.

This is not villainy. It is arithmetic. When sharing pays and protecting costs, and the harm from a leak lands on someone else, a rational company drifts toward sharing. Point the same arithmetic at a bank adding a marketing tracker, and you get customer data quietly firing off to ad platforms — often, the researchers found, without the bank even noticing. Nobody chose to harm you. Nobody had a reason to stop.

The gap has a name

Economists call this an externality — a cost of your decision that falls on somebody else, so you don’t weigh it. Security is the textbook case. The person who sets the defence doesn’t pay for the breach, so they under-build the defence. Not sometimes. Systematically.

23andMe is the gap in one sentence. The company warned about cyber threats at length in its own financial filings — it clearly understood the risk. And its systems still didn’t require a second login step, the cheap, standard protection that would have blunted the very attack that hit it. Understanding the risk didn’t fix it, because the risk wasn’t the company’s to carry. The exposure fell on 6.9 million people. The boardroom felt almost none of it.

Who is actually inside this

That is the part worth sitting with. The frightening numbers in the news — 55 million accounts at one music app, employee records across 2,000 hospitals — are not the company’s loss. They are yours, and people like you. The breach is counted in the company’s press release and paid for in your inbox, your bank calls, your years of watching for fraud.

The harm lands on whoever had the least say. You didn’t pick the app’s data-sharing partners. You didn’t design the bank’s website. You can choose the squeaky-clean tracker over the leaky one — and that is worth doing — but you cannot opt out of being the party who absorbs decisions made in rooms you’ll never enter.

The arrangement is a choice, not a law

Here is the part that hides in plain sight: who pays when data leaks is itself something people decided. For years the arrangement put almost none of the cost on the company that collected the data. That wasn’t nature. It was a set of rules, and rules can be rewritten.

That is what a fine is. When Spain’s regulator moved €2.4 million onto 23andMe, it wasn’t punishment for its own sake — it was an attempt to close the gap, to make the decider feel a slice of the harm so that guarding your data finally competes with the money saved by not guarding it. Breach-disclosure laws and privacy rules do the same thing: they drag some of the cost back toward the person who made the choice. The arrangement can serve the collector and still be renegotiated. Every fine is that negotiation, out loud.

What seeing this leaves you with

Knowing the shape doesn’t make you safe. It makes you steadier when the next breach headline arrives with your name somewhere inside it — because you’ll understand it wasn’t bad luck or a genius hacker. It was a gap that was always there, between the person who decided and the person who pays.

You are inside a system where safety is cheap for you to want and expensive for someone else to provide. Until those two are the same person — pushed together by a fine, a law, a market that finally rewards it — the gap holds, and it holds against you. That’s not a reason to despair. It’s a reason to hold the reassurances loosely, to notice who profits from the setting you’re being asked to trust, and to remember that the arrangement pointing the cost at you was written, which means it can be written differently.

03 · Lab · your turn

You Set the Security Budget

Rehearse how a decider who won't pay for a breach under-protects — until a fine moves the cost back onto them.

04 · Hope · carry this

The setup that let companies decide your safety and hand you the bill was written by people, not by nature — and every fine like Spain's is a quiet sign that people are starting to rewrite it.

Across the beats