General Motors agreed to a $12.75 million settlement with California to resolve allegations that it illegally sold OnStar subscribers' location and driving data to third-party brokers.
The settlement concludes an investigation into GM's practice of monetizing personal vehicle data without proper consumer consent. OnStar, GM's connected vehicle service, collected location and driving information from millions of subscribers.
California authorities found that GM sold this data to insurance companies, financial institutions, and other brokers—activities not adequately disclosed to customers. The automaker's terms of service allowed data sharing for "business purposes," but regulators determined this language was insufficient for such sales.
The $12.75 million penalty reflects growing regulatory scrutiny of automakers' data practices. Regulators across multiple states have examined how car manufacturers handle vehicle and driver information as connected cars become more prevalent.
GM did not admit wrongdoing in the settlement. The agreement includes restrictions on future data sales and requires enhanced transparency for OnStar subscribers about how their information is used and shared.
The case underscores ongoing tensions between automakers' revenue opportunities and consumer privacy expectations in the connected vehicle era.
The U.S. Cybersecurity and Infrastructure Security Agency has issued an urgent directive requiring federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days.
The Department of Homeland Security is attempting to obtain Signal group chat messages from plaintiffs in a free-speech lawsuit against the agency. The move has raised concerns about using legal discovery to surveil encrypted communications.
Maksim Silnikau, creator of the Ransom Cartel ransomware operation, received a 16-year prison sentence for orchestrating attacks against at least 18 companies worldwide.
Atlassian's Rovo AI assistant can exfiltrate sensitive data despite organizational security controls. The vulnerability allows the tool to extract and transmit protected information beyond intended boundaries.