:

GM PAYS $12.75M OVER ILLEGAL DATA SALES

AI DESK1 MIN READ
SAT, MAY 9, 2026

■ AI-SUMMARIZED FROM 2 SOURCES ▸ TIMELINE

General Motors agreed to a $12.75 million settlement with California to resolve allegations that it illegally sold OnStar subscribers' location and driving data to third-party brokers.

The settlement concludes an investigation into GM's practice of monetizing personal vehicle data without proper consumer consent. OnStar, GM's connected vehicle service, collected location and driving information from millions of subscribers. California authorities found that GM sold this data to insurance companies, financial institutions, and other brokers—activities not adequately disclosed to customers. The automaker's terms of service allowed data sharing for "business purposes," but regulators determined this language was insufficient for such sales. The $12.75 million penalty reflects growing regulatory scrutiny of automakers' data practices. Regulators across multiple states have examined how car manufacturers handle vehicle and driver information as connected cars become more prevalent. GM did not admit wrongdoing in the settlement. The agreement includes restrictions on future data sales and requires enhanced transparency for OnStar subscribers about how their information is used and shared. The case underscores ongoing tensions between automakers' revenue opportunities and consumer privacy expectations in the connected vehicle era.

■ SOURCES

TechCrunchTechmeme

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.

MAY 29Industry Desk

Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.

MAY 29Security Desk

Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.

MAY 29Industry Desk

Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.

MAY 29Security Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.