Privacy Pulse July 2026 - Day One Is Almost Here. The Rest of the Threat Model Isn't Waiting.
By Tom Daly, Founder & CEO, Priwall by mePrism
July was the month the theory turned into a schedule. On August 1, 2026, California's Delete Request and Opt-out Platform (DROP) flips on and, in a single API call, more than 322,000 registered Californians will be able to demand that every registered data broker delete their personal information (Mercury News). That's the headline. But July also delivered a stack of quieter proof points that the open-source data problem is getting worse, not better — and that neither individuals nor enterprises can afford to wait for the next law to save them.
Priwall by mePrism exists for exactly this window: shrink the open-source footprint of your customers, your employees, and yourself before an attacker, a regulator, or an AI agent gets there first.
What Happened in July
Breaches are outrunning last year — and insiders are the story
The Identity Theft Resource Center's H1 2026 report landed this week. In the first six months of the year, ITRC counted at least 1,803 data compromises and more than 471 million victim notices — already surpassing all of 2025. The most striking data point: malicious insider incidents jumped from 3 in all of 2025 to 21 in H1 2026, a sevenfold increase (HIPAA Journal). Mega-breaches at Instructure's Canvas platform (275M notices), Under Armour (72.7M), and SoundCloud (29.8M) drove the volume. The lesson for CISOs: the perimeter is already gone, and now the trusted-insider layer is fraying too.
Healthcare kept bleeding
Just in the first two weeks of July, a New Jersey law firm disclosed a breach exposing PHI for ~12,800 patients across multiple hospital systems (GalaxyWarden); AdaptHealth confirmed patient data was exfiltrated via a social-engineering attack — not a firewall bypass (TechTarget); and UnitedHealthcare notified 34,574 individuals of a new incident (Claim Depot). The through-line: attackers didn't kick down the door. They called the help desk with details they bought or scraped from the open web.
Vishing is now the primary initial-access vector
A widely-shared July analysis of "The Com" — the loose social-engineering supergroup that includes Scattered Spider and adjacent crews — spelled out what defenders have been seeing all year: help desks, not firewalls, are the perimeter. The attackers map password-reset workflows via LinkedIn and open-source data, then impersonate an employee to get MFA re-provisioned to their device (The Com analysis). The recommended countermeasure is FIDO2/WebAuthn phishing-resistant MFA — but that only works if the attacker can't first pass identity verification with the personal data that's freely available about the employee.
SIM-swap and port-out fraud are back at scale
The FBI has now tracked over 1,000 SIM-swap attacks with roughly $50M in losses, and the average victim loses more than $26,000 (reporting summary). Polish and U.S. authorities arrested a four-person ring tied to at least $5M in crypto theft, and a separate $15M SIM-swap fraud hit multiple crypto exchanges. Every one of these attacks starts with brokered personal data — name, DOB, address, last-four of SSN — that lets the attacker convince a carrier rep they're you.
Regulators are moving, but slowly
As of July, 24 states now have comprehensive consumer privacy laws on the books (Lewis Rice), with Oklahoma and Louisiana effective January 2027, Alabama in May 2027, and Vermont in 2028. The FTC opened a public-comment period through July 31 on a proposed policy statement targeting AI companies that manipulate their systems' outputs contrary to consumer expectations (Simmons & Simmons). And the Bank of England opened a review of whether current frameworks can even govern agentic AI acting without direct human instruction. Translation: the regulators know AI agents are going to weaponize open-source personal data at scale, and they don't yet have the tools to stop it.
What This Means for the Enterprise
If July taught CISOs anything, it's that the attack surface everyone still calls "external" is actually internal to the human. Your employees' home addresses, phone numbers, family members, and personal email accounts sit in data-broker databases and people-search sites, indexed and enriched, ready to be handed to a help-desk impersonator or a SIM-swap crew. That's not a marketing problem. That's an initial-access vector.
Open-source data removal — the operational discipline of continuously shrinking that footprint — is now a security control, not a compliance box. Three ways to frame it for your leadership team:
Reduce initial-access surface. Every phone number, home address, and personal email removed from a broker is one less input for a vishing script or a SIM-swap application.
Reduce regulatory exposure. As states pile on and DROP goes live, the question "what did you do to minimize open-source exposure of employee and customer data?" gets asked by more regulators, more auditors, and more enterprise procurement teams.
Reduce AI-era blast radius. Agentic AI dramatically compresses the cost of personalized attacks. The defense isn't just better MFA — it's denying the model the personal data it needs to build a convincing pretext.
Priwall by mePrism does this at enterprise scale: continuously identifies and removes personal data across 700+ U.S. brokers, monitors for reappearance, and gives you auditable evidence for your SOC 2, your board, and your regulators. If you want to see what's already exposed on your executive team, we'll run a bake-off against whatever you use today — that's how Priwall vs. DeleteMe conversations usually start.
The Consumer Checklist (share this with your team)
Removal is the ceiling. These four controls are the floor. If you haven't done all four, do them this weekend.
1. Freeze your credit at all three bureaus
Free, takes an hour total, and it stops most new-account fraud cold.
Equifax:equifax.com/personal/credit-report-services/credit-freeze or 888-298-0045
Experian:experian.com/freeze/center.html or 888-397-3742
TransUnion:transunion.com/credit-freeze or 800-916-8800
Per USAGov, freezes apply within one business day online or by phone and lift within one hour.
2. Lock your phone number with your carrier
This is the July upgrade to the checklist. Add a port-out PIN / number transfer lock with your mobile carrier today. It stops SIM-swap attacks even when the attacker has your PII. Every major U.S. carrier offers this for free — call them, ask for "port-out PIN" or "number lock," and set it. Five minutes, zero cost.
3. Turn on phishing-resistant MFA everywhere you can
SMS codes are not enough anymore. Attackers intercept them via SIM swap; help desks re-provision them via vishing. Move to an authenticator app or, ideally, a hardware security key (FIDO2/WebAuthn) on:
Your primary email
Your password manager
Your bank and brokerage accounts
Any account with your Social Security number or payment information
4. Use a password manager with unique 15+ character passwords
One reused password across sites is how brokered data turns into a total account takeover. Pick a reputable manager, generate long random passwords for every account, and protect the manager itself with MFA — preferably a hardware key.
Bonus: Register with the FTC Do Not Call Registry
Free. Cuts down legitimate telemarketing so the scam calls stand out. Register at donotcall.gov or by calling 1-888-382-1222 from the number you want to protect. If you register online, click the confirmation link within 72 hours.
For Californians: Sign up for DROP before August 1
The California Privacy Protection Agency's DROP portal opens August 1. Signing up lets you send one delete request that every registered California data broker must honor. It's the single highest-leverage privacy action a Californian can take this year — and if you want continuous removal across the 700+ brokers not covered by the DROP scope, that's exactly the gap Priwall fills.
The Bottom Line
July made three things clear. Breaches are outpacing last year, and insiders are a growing share of them. Attackers are moving up the stack from firewalls to help desks, and they're powered by data that's freely available. Regulators are moving in the right direction but they will not be there in time.
The playbook for the next 90 days is the same for CISOs and individuals: assume your data is already exposed, remove what you can, harden what you can't, and don't wait for Day One.
For CISOs — run a Priwall exposure scan on your executive team and see what's out there before an attacker does. For everyone else — freeze your credit, lock your number, and turn on real MFA this weekend.
August is going to be a big month. Let's be ready.
— Tom
Priwall by mePrism is enterprise open-source data removal. We continuously identify and remove personal data across 700+ U.S. data brokers, monitor for reappearance, and provide SOC 2 Type 2-audited evidence of reduction. SSO/SCIM, API-first, 60-day pilots at ~$300/protected user/year. Learn more at meprism.com or reach out at support@meprism.com.
Ready to try Priwall by mePrism?
If you're a company protecting at-risk employees, or an individual concerned about your digital footprint, start your privacy removal today at mePrism.com
Because your data shouldn’t be a roadmap for violence.
Explore more from Our Team
Browse more posts written by our team to help you stay in control.
Be Part of the Conversation