Period Trackers Leak Sensitive Data | Analysis by Brian Moineau

TL;DR

  • Mozilla’s tests found one period tracker, Stardust, routing reproductive health events (pregnancy status, birth control, symptoms) to RudderStack while also pinging Meta and AppsFlyer, contradicting the app’s “Your data is private. Period.” slogan [1][2].
  • The exposure isn’t just what you type; it’s where those events travel: every third‑party SDK or data “pipe” multiplies legal risk after Dobbs v. Jackson Women’s Health Organization (2022), while HIPAA’s April 26, 2024 update shields clinical PHI but not most consumer apps [3][7].
  • Enforcement signals are clear—FTC actions involving Flo (2021), GoodRx ($1.5M in 2023), and BetterHelp ($7.8M in 2023) preview how “privacy promises vs. practice” cases will hit femtech and its vendors next [4][5][6].

What the source said

In July 2026, BBC Future reported on Mozilla Foundation’s hands‑on testing of six period trackers—Flo, Clue, Stardust, Spot On, Period Calendar, and Euki—showing stark differences in how they transmit private data from the United States and Europe [1]. Mozilla and BBC found Stardust was the only app that sent labeled reproductive health events to RudderStack, a routing service not named in Stardust’s policy, while also sharing identifiers with Meta and AppsFlyer; Stardust says RudderStack can’t identify users and is contractually barred from repurposing data [1][2]. Spot On’s in‑app links to Planned Parenthood’s site exposed visits (e.g., for HIV testing or gender‑affirming care) to AB Tasty, while Period Calendar sent device IDs to Google and InMobi without an opt‑out; Mozilla called Euki “squeaky clean” by comparison [1].

Why it matters

Two groups have the most at stake in 2024–2026. First: users whose menstrual logs can imply pregnancy, fertility struggles, or miscarriage in states that criminalize aspects of reproductive care after the 2022 Dobbs ruling; HIPAA’s April 26, 2024 reproductive‑privacy rule protects clinical PHI but does not reach most consumer trackers, creating a gap prosecutors can exploit with subpoenas or geofence warrants [3][7]. Second: the femtech stack—app publishers, attribution firms, analytics routers, and ad platforms—because one mislabeled or misrouted event can turn “we protect your privacy” into Exhibit A for the FTC or a state AG, echoing Flo (2021), GoodRx (2023), and BetterHelp (2023) outcomes [4][5][6].

Original analysis

Consensus view: “Fix period tracker privacy with end‑to‑end encryption and you’re safe.” Contrarian read: encryption helps, but the weak link is metadata exhaust and server‑side event routing that Apple’s App Tracking Transparency dialog doesn’t meaningfully police, so sensitive streams can leave at app open to partners like RudderStack, AppsFlyer, or Meta, even before a user toggles a setting [2]. In discovery, the map of who received which payloads on which dates typically matters more than whether fields were encrypted in transit [4][5][6].

Historical analogue: Flo’s 2021 settlement and GoodRx’s 2023 penalty. In Flo, the FTC alleged the app labeled events like “Pregnancy” and sent them with identifiers to Facebook, Google, Flurry, Fabric, and AppsFlyer, contrary to public promises, leading to an order requiring affirmative express consent and external assessments [6]. GoodRx paid $1.5 million and was banned from sharing health information for advertising after claiming to be “HIPAA secure” while not being a covered entity; DOJ and FTC highlighted the mismatch between claims and data flows [5]. BetterHelp paid $7.8 million and faced a ban on sharing sensitive health data for ads, reinforcing that regulators don’t need a breach to act—just a broken promise with corroborating packet logs [4].

Back‑of‑envelope calculation (example math using 13 cycles/year and 2M MAUs):

  • Assumptions: a typical user logs 8 items per cycle (bleeding, PMS, two symptoms, mood, sex, contraception, note). At 13 cycles/year, that’s ~104 health events per user/year (author’s calc).
  • If an app routes those to 3 partners (analytics, attribution, data router), that’s ~312 transmissions per user/year (author’s calc).
  • With 2 million monthly actives sustaining this cadence, that’s roughly 624 million transmissions/year—a compounding discovery, breach, and subpoena surface if IDs or device metadata allow linkage later (author’s calc).

Period tracker privacy: a 2×2 that predicts risk based on Mozilla/BBC’s 2026 findings [1]

  • Axes: “Visibility of data flows” (transparent logs, partner lists, on‑device options such as iOS 17’s App Privacy Report) vs. “Third‑party dependence” (count and criticality of external SDKs/pipes on iOS 17 and Android 14).
Quadrant What defines it Example placement (from reporting/tests)
High visibility + Low dependence Clear partner registry, minimal SDKs, local storage by default Euki (“squeaky clean” per Mozilla/BBC) [1]
High visibility + High dependence Lots of SDKs but a detailed map and user controls Few period apps today; a target state
Low visibility + Low dependence Few partners but opaque disclosures Gap apps not audited this round
Low visibility + High dependence Multiple partners, event routing, limited controls Stardust (RudderStack for health data; AppsFlyer/Meta identifiers) [1][2]; Period Calendar (Google, InMobi, no user opt‑out per report) [1]; Spot On’s linked web features leaking to AB Tasty [1]

Named‑stakeholder breakdown (4 groups, 2024–2026):

  • App publishers (Stardust, Period Calendar, Spot On): if your privacy page and packet captures diverge, you are replaying Flo/GoodRx’s storyline in a harsher legal climate spanning Washington to Texas [1][5][6].
  • Data routers/SDKs (RudderStack, AppsFlyer, Meta): you are “processors,” and Washington’s My Health My Data Act (RCW 19.373, 2023) regulates processors via contracts, logs, and retention duties that will surface in discovery [7].
  • Regulators (FTC, state AGs, HHS OCR): toolkits and precedent—Flo (2021), BetterHelp (2023), GoodRx (2023)—align with HIPAA’s 2024 rule that clarifies covered‑entity limits and spotlights the consumer‑app gap [3][4][5][6].
  • Users: the safest default is local‑only logging or apps proven to avoid third‑party transmission of health events (Mozilla highlighted Euki in 2026 testing) [1][2].

What others are missing

The overlooked angle is vendor‑chain accountability one layer downstream of the app: event‑routing platforms that shuttle payloads between mobile clients and data warehouses in Seattle‑to‑San Francisco stacks. Washington’s My Health My Data Act (RCW 19.373) binds publishers and processors alike and compels a homepage‑linked health data policy, opt‑in consent, and deletion rights with concrete effective dates (large entities by March 31, 2024; small businesses by June 30, 2024) [7]. HIPAA’s April 26, 2024 reproductive‑privacy rule tightens disclosures inside clinics yet explicitly doesn’t cover fertility/period apps that aren’t regulated entities, so compliance pivots on state law and SDK contracts instead of hospital playbooks [3][7].

What to watch next

  1. By Q4 2026, at least one state attorney general will file a My Health My Data Act action against a consumer reproductive‑health app or a processor for undisclosed sharing of cycle or pregnancy events, citing packet logs and partner contracts as evidence.
  2. By Q2 2027, a top‑5 mobile analytics or attribution vendor (by market share in North America) will ship a “reproductive‑health safe mode” that rejects cycle‑ or pregnancy‑labeled events and enforces 30‑day deletion SLAs, and at least one major tracker will announce adoption in a press release.
  3. By Q1 2027, Apple or Google will update platform policy to restrict server‑side routing of sensitive health events to non‑clinical processors without explicit, in‑context consent and an in‑app partner list, with enforcement via app rejections.

My take

If you ship a period tracker in 2026, you can’t outsource privacy to your SDKs or routers. The rule of thumb is simple: if your network logs show pregnancy or symptom events leaving the device, you’re building a plaintiff’s timeline for the FTC or a state AG. Build a data diode now: keep health events on‑device, publish a partner bill of materials, and ban reproductive‑health labels in analytics streams. HIPAA’s 2024 fix protects clinic charts, not your app; FTC precedent punishes broken promises; Washington’s MHMD creates direct exposure for processors—choose the “squeaky clean” quadrant or budget for discovery [1][3][5][6][7].

Sources

  1. The privacy problems hidden in your period tracker — BBC (https://www.bbc.com/future/article/20260715-how-period-trackers-share-womens-private-details) — Core report from July 2026 based on Mozilla’s testing; details on Stardust–RudderStack, Spot On’s AB Tasty issue, Period Calendar’s tracking, and Euki’s “squeaky clean” status.

  2. Privacy Review: Stardust Period Tracker — Mozilla Foundation (https://www.mozillafoundation.org/en/nothing-personal/stardust-privacy-review/) — Confirms health‑event transmission to RudderStack and identifiers to AppsFlyer/Meta; explains why Apple’s ATT doesn’t constrain these pipes.

  3. The HIPAA Privacy Rule (incl. Apr 26, 2024 Final Rule to Support Reproductive Health Care Privacy) — HHS.gov (https://www.hhs.gov/hipaa/for-professionals/privacy/index.html) — Establishes scope and the 2024 reproductive‑privacy update; clarifies covered entities/business associates vs. consumer apps.

  4. FTC Gives Final Approval to Order Banning BetterHelp from Sharing Sensitive Health Data for Advertising, Requiring It to Pay $7.8 Million — Federal Trade Commission (https://www.ftc.gov/news-events/news/press-releases/2023/07/ftc-gives-final-approval-order-banning-betterhelp-sharing-sensitive-health-data-advertising) — Shows FTC bans on ad uses of sensitive health data and monetary relief.

  5. Digital Healthcare Platform Ordered to Pay Civil Penalties… (GoodRx) — U.S. Department of Justice (https://www.justice.gov/archives/opa/pr/digital-healthcare-platform-ordered-pay-civil-penalties-and-take-corrective-action) — Details $1.5M penalty and advertising bans for sharing health data despite privacy claims.

  6. FTC Finalizes Order with Flo Health, a Fertility‑Tracking App that Shared Sensitive Health Data — Federal Trade Commission (https://search.ftc.gov/news-events/news/press-releases/2021/06/ftc-finalizes-order-flo-health-fertility-tracking-app-shared-sensitive-health-data-facebook-google) — Lays out how labeled pregnancy/period events went to analytics firms and the remedial order (consent, audits).

  7. Protecting Washingtonians’ Personal Health Data and Privacy (My Health My Data Act FAQ) — Washington State Attorney General (https://www.atg.wa.gov/protecting-washingtonians-personal-health-data-and-privacy) — Clarifies RCW 19.373 scope, effective dates (Mar 31 and Jun 30, 2024), policy‑link requirement, and that processors are in scope.




Related update: We recently published an article that expands on this topic: read the latest post.

Discord Breach: 70,000 Users IDs | Analysis by Brian Moineau

Discord Cybersecurity Breach: What You Need to Know

In a world where our digital lives are increasingly intertwined with our personal identities, a recent cybersecurity breach involving Discord has sent shockwaves through the online community. With over 70,000 users potentially affected, the incident serves as a stark reminder of the vulnerabilities that come with using third-party services. Let’s delve into what happened and why it matters.

What Happened?

Discord, the popular communication platform primarily used by gamers and online communities, confirmed that a cyber attack on one of its third-party vendors compromised the personal information of over 70,000 users. Among the most concerning losses were images of government-issued IDs, including driving licenses and passports. This breach not only raises alarm bells about individual privacy but also highlights the risks associated with third-party integrations that many services rely on.

The Bigger Picture: Cybersecurity in the Digital Age

As technology continues to evolve, so do the tactics employed by cybercriminals. This incident is not an isolated case; it fits into a broader trend where data breaches are becoming alarmingly common. In recent years, we’ve witnessed numerous high-profile hacks affecting various sectors, from social media platforms to financial institutions. These incidents underline the importance of robust cybersecurity measures and the need for users to remain vigilant about their online security.

Recent data shows that more than 4,000 data breaches occurred in 2021 alone, impacting millions of users worldwide. As we become more reliant on digital platforms, the necessity for stringent security protocols is paramount. Companies must not only protect their systems but also ensure that their partners uphold the same standards.

Key Takeaways

Magnitude of the Breach: Over 70,000 Discord users may have had their government ID images compromised due to a third-party vendor attack.

Vulnerability of Third-Party Services: This incident underscores the risks associated with relying on third-party services for essential functions.

Need for Vigilance: Users should regularly monitor their accounts and personal information for any suspicious activity following such breaches.

Importance of Cybersecurity Measures: Organizations must prioritize cybersecurity to protect user data and build trust with their communities.

Rising Trend of Cyber Attacks: The frequency of data breaches is increasing, emphasizing the need for better security practices both for companies and individuals.

Reflecting on the Future of Online Safety

As we navigate through this digital landscape, incidents like the Discord breach serve as important wake-up calls. They remind us that our personal information is a valuable asset that must be safeguarded continuously. While companies like Discord must enhance their security measures, we too have a role to play by staying informed and proactive about our online safety.

As we move forward, let’s hope that this breach spurs meaningful discussions about cybersecurity protocols and leads to stronger defenses against future attacks.

Sources

– “Discord Confirms Over 70,000 Users Affected By Customer Service Hack That Has Compromised Images of Government-Issued ID like Driving Licences And Passports – IGN” [IGN](https://www.ign.com/articles/discord-customer-service-hack-70000-users-ids-compromised)

By staying informed and taking action, we can help create a safer online community for everyone.




Related update: We recently published an article that expands on this topic: read the latest post.


Related update: We recently published an article that expands on this topic: read the latest post.

Amazon Warns 220 Million Customers Of Prime Account Attacks – Forbes | Analysis by Brian Moineau

Amazon Warns 220 Million Customers Of Prime Account Attacks – Forbes | Analysis by Brian Moineau

Stay Calm and Carry On Shopping: Navigating the Amazon Prime Account Attacks

In a world where clicking “Add to Cart” is as routine as brewing your morning coffee, the recent warning from Amazon about potential Prime account attacks might feel like a plot twist right out of a suspense novel. With 220 million Amazon Prime subscribers potentially at risk, it’s time to don our digital armor and navigate these turbulent cyber seas with a steady hand.

The Lowdown on the Alert

Amazon has sounded the alarm on suspicious activities targeting Prime accounts, and while it’s easy to panic, it’s important to approach this with a level head. These cyber attackers are essentially phishing for your personal information — think passwords, credit card numbers, and other sensitive data. The key here is vigilance. Amazon, much like a watchful digital guardian, has urged users to be cautious of any unexpected emails or messages asking for account details. It’s a classic case of “trust but verify.”

Cybersecurity: The New Frontier

This isn’t just an Amazon issue. Cybersecurity threats have become increasingly common as our lives move more online. Remember the infamous Facebook data breach of 2019 when 540 million records were exposed? Or the 2020 Twitter hack that targeted high-profile accounts, including those of Elon Musk and Barack Obama? These incidents remind us that even the most robust platforms can be vulnerable.

Staying Safe in the Digital Marketplace

So, how can you protect yourself? Start by using strong, unique passwords and enabling two-factor authentication wherever possible. Be skeptical of unsolicited communications, and double-check URLs before entering your details. It’s the digital equivalent of looking both ways before crossing the street.

A Broader Perspective

This situation also highlights a broader truth about our digital age: convenience and risk often go hand in hand. As we increasingly rely on online services for everything from shopping to socializing, the importance of cybersecurity grows. It’s not just about protecting our accounts; it’s about safeguarding our digital identities.

Connections to the Wider World

The Amazon Prime account threat is a reminder of how interconnected our digital experiences are. As the world becomes more digitized, similar issues have arisen in other sectors. For example, during the COVID-19 pandemic, there was a surge in cyberattacks on healthcare systems, which were already under immense pressure. The lesson here is universal: as we embrace digital solutions, we must also embrace digital vigilance.

Final Thoughts

In conclusion, while the news of potential Amazon Prime account attacks might be unsettling, it’s an opportunity to reinforce our digital defenses. By staying informed and cautious, we can continue to enjoy the convenience of online shopping without falling prey to cyber threats. So, keep your passwords strong, your skepticism high, and your shopping carts full. After all, with a bit of caution, there’s no need to let cyber scoundrels spoil our digital adventures.

Read more about AI in Business

Read more about Latest Sports Trends

Read more about Technology Innovations


Related update: We recently published an article that expands on this topic: read the latest post.

Retired artist loses $2M in crypto to Coinbase impersonator – Cointelegraph | Analysis by Brian Moineau

Retired artist loses $2M in crypto to Coinbase impersonator - Cointelegraph | Analysis by Brian Moineau

The Cautionary Tale of Ed Suman: Art, Scams, and the Digital Frontier


In an age where technology is the brush and the world is the canvas, artists like Ed Suman have found new avenues to express their creativity and manage their finances. However, the digital realm, much like the art world, has its shadows. Recently, Ed Suman, a retired artist, fell victim to a scam that resulted in the loss of over $2 million in Bitcoin and Ether. This unfortunate event unfolded as scammers, masquerading as Coinbase support agents, exploited a recent data breach to dupe unsuspecting victims.

Ed Suman's story is not just a tale of financial loss but also a reminder of how the digital age, while offering vast opportunities, requires a new level of vigilance. As an artist, Suman spent his life creating works that speak to the human experience, yet in this digital landscape, he encountered a harsh lesson in human deception.

The Rise of Crypto Scams: A Digital Epidemic


The scam that targeted Suman is symptomatic of a larger epidemic that has plagued the crypto world. With the rise of cryptocurrencies like Bitcoin and Ether, there's been an equally significant rise in scams designed to exploit the uninitiated. According to a report by the Federal Trade Commission, consumers reported losing over $80 million to cryptocurrency scams in the six months leading up to April 2021, a tenfold increase from the previous year.

These scams often involve impersonating legitimate companies or individuals, a tactic that has proven devastatingly effective. In Suman's case, the scammers capitalized on a breach in Coinbase, one of the world's largest cryptocurrency exchanges, underscoring the importance of robust cybersecurity measures and user awareness.

Lessons from the Art World


If there's one thing the art world teaches us, it is the value of authenticity and discernment. Just as a seasoned art collector learns to distinguish a masterpiece from a forgery, so must we learn to navigate the digital landscape with a discerning eye. This means verifying sources, using two-factor authentication, and being cautious of unsolicited communications—especially those concerning financial assets.

Ed Suman's experience echoes the broader challenges faced by many as they navigate the digital economy. Whether it's an artist managing their portfolio or an investor diversifying their assets, the need for digital literacy and security is paramount.

The Broader Context: Digital Trust and Security


This incident comes at a time when digital trust is paramount. With data breaches becoming increasingly common, companies and individuals alike must prioritize cybersecurity. The World Economic Forum has highlighted cybersecurity as one of the greatest challenges of our time, emphasizing the need for a concerted effort to protect digital assets and personal information.

Interestingly, the art world itself is experiencing a digital transformation. Non-fungible tokens (NFTs) have emerged as a new frontier, enabling artists to monetize digital art. However, this too comes with challenges, as the NFT space has also been targeted by scammers.

Final Thoughts: A Call for Vigilance and Innovation


Ed Suman's story is a stark reminder of the vulnerabilities we face in an interconnected world. While technology offers unprecedented opportunities for creativity and financial growth, it also demands a new level of vigilance. As we step further into this digital frontier, it is crucial that we arm ourselves with knowledge and tools to protect our assets and our identities.

In the end, much like a painter refining their technique, we must continuously adapt and learn. By fostering a culture of awareness and innovation, we can turn the digital landscape into a canvas of opportunity rather than a minefield of scams. As we journey through this digital age, let us remember that while technology shapes our world, it is our responsibility to shape how we interact with it.

Read more about AI in Business

Read more about Latest Sports Trends

Read more about Technology Innovations

Harrods latest retailer to be hit by cyber attack after M&S and Co-op – BBC | Analysis by Brian Moineau

Harrods latest retailer to be hit by cyber attack after M&S and Co-op - BBC | Analysis by Brian Moineau

Title: Navigating the Digital Age: Harrods Under Cyber Siege

In the ever-evolving digital landscape, cyber attacks have become as inevitable as the passage of time. Once again, the retail world finds itself in the crosshairs of cybercriminals, with Harrods being the latest high-profile target. Following in the footsteps of M&S and Co-op, the iconic luxury department store has restricted internet access in its stores due to an attempted cyber attack, as reported by the BBC.

This isn't just a Harrods issue; it's a digital age dilemma that has been knocking at the doors of corporations globally. Companies today are grappling with the dual challenge of providing seamless digital experiences for their customers while safeguarding sensitive data from nefarious actors. The fact that a renowned establishment like Harrods, a beacon of luxury shopping, isn't immune to such threats underscores the ubiquity and persistence of cyber threats.

The Ripple Effect of Cyber Attacks


The implications of these cyber threats extend beyond just immediate financial losses. They erode consumer trust, damage brand reputation, and introduce operational disruptions. The retail sector, which is increasingly dependent on digital infrastructure for everything from supply chain management to customer engagement, is particularly vulnerable.

Consider the 2013 Target data breach, which compromised the credit card information of over 40 million customers. The retailer faced not only financial penalties but also a significant drop in profits and a tarnished brand image. Harrods, a stalwart of British retail since 1849, must now navigate these treacherous waters with caution and resilience.

Drawing Parallels: A Global Concern


The Harrods incident resonates with a broader global narrative. Just recently, MGM Resorts faced a similar predicament when a cyber attack led to operational disruptions across its properties, including the disabling of digital room keys and slot machines. This incident was a stark reminder that no industry is immune. From healthcare to entertainment, cyber threats are an omnipresent risk.

Moreover, the geopolitical landscape is not without its share of digital tension. With state-sponsored cyber activities on the rise, nations are scrambling to bolster their cyber defenses. The recent efforts by the European Union to establish a cyber unit to combat threats collectively highlight the scale of this digital arms race.

A Call for Robust Cybersecurity Measures


In light of these events, it becomes imperative for businesses, regardless of their size or industry, to invest in robust cybersecurity infrastructure. This includes regular security audits, employee training programs on phishing and other threats, and a strong incident response strategy.

For Harrods, this could be an opportunity to set a precedent in cybersecurity excellence. By turning this challenge into a showcase of their commitment to customer safety, they can reinforce trust and loyalty among their clientele.

Final Thoughts


As we continue to embrace the conveniences of the digital age, it's crucial to remember that with great connectivity comes great responsibility. The cyber attack on Harrods serves as a timely reminder of the vulnerabilities that accompany digital transformation. While the road ahead may be fraught with challenges, it also presents an opportunity for businesses to innovate and strengthen their defenses.

In the end, the key to navigating the digital age lies in being proactive rather than reactive. As cyber threats continue to evolve, so must our strategies to combat them. After all, in the words of the great strategist Sun Tzu, "In the midst of chaos, there is also opportunity." Let's hope Harrods and others facing similar challenges find theirs.

Read more about AI in Business

Read more about Latest Sports Trends

Read more about Technology Innovations

DeepSeek hit with large-scale cyberattack, says it’s limiting registrations – CNBC

In a shocking turn of events, DeepSeek, the popular online search engine, has been hit with a large-scale cyberattack. The company announced on Monday that it would be temporarily limiting user registrations due to the malicious attacks on its services. This news has sent shockwaves through the tech industry and raised concerns about the security of online platforms.

DeepSeek, known for its advanced search capabilities and user-friendly interface, has been a favorite among internet users for years. However, this cyberattack has exposed vulnerabilities in the company's systems and raised questions about the safety of personal data on the platform.

Cyberattacks are becoming increasingly common in today's digital world, with hackers constantly evolving their tactics to breach security measures. DeepSeek's decision to limit user registrations shows the severity of the attack and the company's commitment to protecting its users' information.

In response to the cyberattack, DeepSeek has assured users that it is working diligently to strengthen its security measures and prevent future breaches. The company has also advised users to be cautious when sharing personal information online and to regularly update their passwords to protect against potential hacks.

This incident serves as a reminder of the importance of cybersecurity in today's interconnected world. As more and more of our daily activities move online, it is crucial for companies to prioritize the protection of user data and invest in robust security measures.

In conclusion, the cyberattack on DeepSeek serves as a wake-up call for both companies and users to prioritize cybersecurity and take proactive steps to safeguard personal information. While the online world offers countless opportunities and conveniences, it also poses risks that must be addressed to ensure a safe and secure digital experience for all.