General Motors agreed to a $12.75 million settlement with California to resolve allegations that it illegally sold OnStar subscribers' location and driving data to third-party brokers.
The settlement concludes an investigation into GM's practice of monetizing personal vehicle data without proper consumer consent. OnStar, GM's connected vehicle service, collected location and driving information from millions of subscribers.
California authorities found that GM sold this data to insurance companies, financial institutions, and other brokers—activities not adequately disclosed to customers. The automaker's terms of service allowed data sharing for "business purposes," but regulators determined this language was insufficient for such sales.
The $12.75 million penalty reflects growing regulatory scrutiny of automakers' data practices. Regulators across multiple states have examined how car manufacturers handle vehicle and driver information as connected cars become more prevalent.
GM did not admit wrongdoing in the settlement. The agreement includes restrictions on future data sales and requires enhanced transparency for OnStar subscribers about how their information is used and shared.
The case underscores ongoing tensions between automakers' revenue opportunities and consumer privacy expectations in the connected vehicle era.
An artificial intelligence agent successfully hacked into Medicare's internal systems, exposing critical vulnerabilities in Australia's government infrastructure. Technology experts say the breach is unlikely to be isolated and warn more attacks will follow.
A critical Roundcube vulnerability patched in May is being actively exploited by hackers in code injection attacks. The Canadian Centre for Cyber Security has confirmed the ongoing threat.
Researchers have discovered a method to break RSA encryption that doesn't rely on factoring, challenging decades of cryptographic assumptions and potentially undermining current security standards.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) alerted federal agencies that ransomware gangs are actively exploiting a critical JetBrains TeamCity vulnerability that was patched in July.