August 2026 Privacy Pulse: Data Breaches, Data Brokers & Personal Privacy
Privacy Pulse: August 2026
August was another reminder that the same personal details brokers publish every day — names, home addresses, phone numbers, family connections — are the raw material behind the month's biggest breaches, executive swatting campaigns, and identity-theft schemes. This month we cover two stories that show how open personal data becomes an operational risk, share a service update on the Priwall by mePrism companion app, and walk through the practical steps you can take right now to shrink your exposure.
Apollo and the return of social-engineering breaches
Private-equity giant Apollo Global Management confirmed on August 21 that intruders used a social-engineering attack to compromise "certain cloud platforms" between July 6 and July 10, exposing names, dates of birth, contact information, home addresses, and Social Security numbers for an undisclosed number of individuals (TechCrunch, Ground News).
Apollo is not an isolated case. August also brought the ShinyHunters extortion of 1.6 million RingCentral accounts, ongoing fallout from the CSC / CL0P leak, and a CNBC review showing that breach notices in the first half of 2026 have already surged, driven largely by the 275-million-victim Instructure Canvas incident (Privacy Guides, CNBC).
The common thread is not a novel exploit — it is reconnaissance. Attackers routinely start with data-broker profiles and people-search results to identify who to impersonate, which employee to call, and which personal detail to use as proof of identity. The less of that raw material a person has floating in the open, the fewer footholds a social-engineering crew has to build from.
ClarityCheck and the OSINT supply chain
On August 19, researcher Jeremiah Fowler disclosed an unauthenticated 450 GB cloud database belonging to reverse-lookup service ClarityCheck, containing 9,042,977 image files — profile photos, screenshots, and scanned pictures in folders labeled "faces" and "profiles" (WIRED via Security Boulevard, TechRadar).
ClarityCheck markets itself as "private and secure," yet its own database of uploaded faces sat on the open internet. That is the story of the people-search and OSINT industry in miniature: services that promise to help users check on others accumulate massive stores of personal information, and those stores routinely become the next breach.
And when they leak, the exposed data does not stay in one place. As one threat-tracking blog noted this month, "once a victim organization's data hits a leak site, the personal details inside (names, emails, phones, addresses) get scraped into the same broker-and-dump ecosystem every doxxer searches" (GalaxyWarden). The same ecosystem is now fueling the recent surge in executive swatting attacks, which researchers at BlackCloak have traced back to data-broker records, property records, and corporate leadership pages (CSO Online, SC World).
What it means for your data
Whether an attacker is targeting a Fortune 500 CFO or a homeowner two doors down, the workflow starts in the same place: a Google search, a people-search site, and a handful of broker profiles that assemble a name, address, phone number, relatives, and employer in seconds. Every removal you complete on those sites narrows that starting position.
Priwall by mePrism helps remove your personal information from U.S. data-broker and people-search sites, reducing the exposure that makes people easier to find, profile, and target. Priwall does more than submit a one-time request — it continuously rescans for reappearance and resubmits removal requests so your privacy work keeps moving after the first removal. With authorized-agent filings and proof-of-removal evidence, Priwall turns a difficult, fragmented data-broker process into an ongoing, documented privacy service.
Priwall by mePrism update: the companion app moves to the web
On October 1, 2026, we are retiring the Priwall by mePrism companion apps on iOS and Android and consolidating on our mobile-optimized web experience at app.meprism.com. Bringing everything onto one platform lets improvements reach every user faster and simplifies the path between you and an effective data removal.
Nothing changes about your account. Sign in at app.meprism.com with your existing email and password, and you will find the same removal history, active removals, exposure history, and reports. The web app works great on any mobile browser — no download required.
If you subscribed through the Apple App Store or Google Play, your subscription will run through the end of your current paid period but will not auto-renew through Apple or Google after October 1st. To keep your service going, resubscribe directly at app.meprism.com. Everything else — your account, history, and active removals — stays intact; only the payment route changes.
Steps to take now
You do not need to wait for the next breach headline to shrink your exposure. Three actions matter most this month.
Sign in to the web app
If you have used the Priwall mobile app, take a minute to sign in at app.meprism.com with your existing credentials before October 1 and confirm your removals and reports look right.
Freeze your credit
The FTC says a credit freeze is free and makes it harder for anyone to open a new credit account in your name, and it should be placed with all three bureaus (FTC, USA.gov). Use the official links:
Check whether you have been in a recent breach
Given how many notifications are being issued this year, it is worth a quick check against a trusted breach index such as Mozilla Monitor or Have I Been Pwned. If your email appears in a recent breach, change that password, enable multi-factor authentication on the affected account, and rotate the same password anywhere else you reused it.
Looking ahead
The pattern from August is impossible to miss: the personal information brokers make available on the open web is the same information that fuels social-engineering breaches, executive swatting, and identity theft. Federal privacy debate will continue, but the practical defense is the same one we have been building toward all year — remove your data from the places attackers look first, keep it out, and make privacy protection an ongoing service rather than a one-time task. Priwall will keep doing that work with you, and starting October 1, we will do it from a single, faster, mobile-friendly web experience.
Ready to try Priwall by mePrism?
If you're a company protecting at-risk employees, or an individual concerned about your digital footprint, start your privacy removal today at mePrism.com
Because your data shouldn’t be a roadmap for violence.
Explore more from Our Team
Browse more posts written by our team to help you stay in control.
Be Part of the Conversation