background image blur
background image
  • Blog
    >
  • News
    >
  • Internet Freedom in August 2026: The Month in Review

Internet Freedom in August 2026: The Month in Review

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 31 August, 2026
A man and woman using a laptop in their living room

Our Research Found 180,724 Smart Homes Open to Anyone

The Mysterium VPN Research Team scanned the internet and found 180,724 smart home MQTT brokers — the nervous systems of smart homes, through which every sensor reports and every device takes orders — accepting connections from anyone with no authentication. 138,607 sit on consumer home and mobile networks. 86% had at least one device actively connected. 

The median broker had been exposed for 67 days; the top 10% for more than 500. One South Korean internet provider, SK Broadband, accounts for 66.7% of all exposed brokers globally — pointing to a systemic deployment issue, not individual error. An open broker doesn't just leak data outward. It accepts commands inward.

Read the full article here.

The Web We Lost: 2006’s Top 50 Sites, 20 Years On

We measured the 50 most-visited websites of June 2006 against what they look like in August 2026. The median homepage is 38× heavier. One site grew 494-fold. In 2006, 22 of the 50 contacted zero tracking companies; today only 9 do, average 13. 

Yahoo told 1 company about your visit in 2006. Today: 136 companies, 326 cookies. Every wall you hit in 2026 — consent banners, paywalls, bot checks — was built in the last twenty years. None existed in the 2006 captures. And 1 in 5 of the biggest sites of 2006 no longer exists as itself.

Read the full article here.

KOSA Is Back Before the Senate — the Problems Haven’t Gone Away

The Kids Online Safety Act returned to the Senate Commerce Committee alongside four companion bills. KOSA's "duty of care" provision only works if platforms know which users are minors, creating structural pressure toward age verification for everyone. 

The EFF's position is unchanged: KOSA doesn't protect privacy. It creates new privacy problems, new incentives for platforms to preemptively remove lawful speech, and new databases of sensitive identity data vulnerable to breach. It may also cut teenagers off from the online communities — addiction support, mental health forums, peer groups — that the bill claims to protect them in.

Read the full article here.

The SCREEN Act Would Require Age Verification on Almost Every Website Online

Also heading to Senate markup: the SCREEN Act, introduced by Senator Mike Lee, which would require every website containing even one piece of content deemed "harmful to minors" to verify users' ages. Unlike existing laws that target sites where adult content makes up at least a third of material, SCREEN removes that threshold entirely — sweeping in most user-generated content platforms and mainstream services like Netflix.

It also directly attacks VPN use by requiring age verification based on IP addresses. The bill is backed by Heritage Action, a sister organization to the Heritage Foundation that authored Project 2025, whose stated goal is to redefine pornography as outside First Amendment protection.

Read the full article here.

Chat Control Passed the EU Parliament — but Encryption Protections Came With It

The ePrivacy derogation allowing Big Tech to mass scan private messages passed for the third time in four months, after EPP president Roberta Metsola used a procedural maneuver that counted absent MEPs as votes in favor. Despite the structural disadvantage, MEPs passed two amendments protecting end-to-end encrypted communications against client-side scanning — and both the European Commission and Council accepted them. The new derogation runs from August 3, 2026 to April 2028. 

The signal to Chat Control 2.0 negotiators is now on the record: no majority exists for mass surveillance. Only a proportionate approach can close the deal.

Read the full article here.

Apple Is Challenging the UK’s Second Secret Demand for an iCloud Backdoor

Apple filed a complaint last month at the UK's Investigatory Powers Tribunal after the government issued a second "technical capability notice" — a secret legal order demanding access to encrypted iCloud data belonging to British users. Apple is challenging not just this specific order but the UK's broader power to issue TCNs under the Investigatory Powers Act. 

Privacy International and Liberty have parallel complaints. UK users have been without iCloud's Advanced Data Protection since January 2025, when Apple removed it following the first order. There is no such thing as a backdoor only governments can use.

Read the full article here.

Russia Is Running What May Be Its Biggest VPN Blocking Campaign in History

More than 20 VPN services have been hit simultaneously, with restrictions targeting IP addresses and entire subnets belonging to major hosting providers. Leonid Volkov of the Anti-Corruption Foundation called it "the biggest attack in history." The mechanism: Russian apps track user IPs, giving Roskomnadzor the data to map and block VPN infrastructure at scale. 

The campaign coincides with plans by Russia's Digital Development Ministry to introduce continuous monitoring of corporate VPN exemption lists. When legitimate VPNs are blocked, users don't stop wanting to reach the open internet. They turn to whatever works — which is usually less safe.

Read the full article here.

Zambia Votes August 13. Digital Rights Groups Are Urging Authorities to Keep the Internet On

Access Now and the #KeepItOn coalition — 370 organizations from 106 countries — published an open letter urging Zambian authorities to guarantee uninterrupted internet access during elections on August 13. Zambia shut down social media during its 2021 election and experienced similar disruptions in 2020 and 2016. 

In June, Zambia's Ministry of Technology and Science committed publicly not to do so this time. The coalition is calling on President Hichilema to personally affirm and enforce that commitment. An election-day shutdown doesn't just silence social media — it silences accountability for everything that happens while connectivity is cut.

Read the full article here.

Brazil’s Supreme Court Received Its First Challenge to Biometric Age Verification

Partido Missão filed a constitutional challenge (ADI 7999) with the Supreme Federal Court against the biometric verification requirement in ECA Digital — Brazil's child online safety law that explicitly accepts facial recognition, fingerprints, iris scans, and voice verification as compliance methods. The challenge argues the law collects disproportionately sensitive biological data for its stated goal. 

The filing arrived as the law entered broader enforcement, creating legal uncertainty for hundreds of platforms in compliance planning. ANPD guidelines due this month may determine whether zero-knowledge cryptographic proofs — which can verify age without collecting biometric data — satisfy the law's reliability standard.

Read the full article here.

Decentralized Tech Defeated State Censorship in India

When Indian authorities blocked the Cockroach Janta Party's domain and social media handles, volunteers mirrored the site across dozens of alternative domains faster than regulators could issue takedowns. When authorities cut mobile internet at protest sites, supporters switched to BitChat — an off-grid Bluetooth mesh messaging protocol requiring no cell towers, no internet connection, and no central server. 

When GitHub was ordered to remove BitChat's source code, the code had already been cloned and distributed. The Cockroach Effect is a demonstration of what decentralized architecture does to the censorship model: it removes the choke points state orders depend on.

Read the full article here.

When the State Won’t Recognize You, the Internet Locks You Out Too

For the tens of millions of stateless people worldwide, every new digital verification requirement — banking apps, employment platforms, government services, age verification systems — is another wall. The Apatride Network facilitated a gathering in Malta in March 2026 bringing together stateless communities to document these experiences collectively. Their conclusion: states may control legal status, but they don't control identity or belonging. 

The digital world increasingly acts as though they do — and as verification requirements expand, the people hit hardest are those who have no documentation to provide even if they wanted to.

Read the full article here.

Indigenous Languages Are Disappearing Online, Too

Today is International Day of the World's Indigenous Peoples. Of the roughly 7,000 languages spoken worldwide, the internet actively supports only a fraction — and most of the endangered ones are Indigenous. A language without digital infrastructure has no search visibility, no content moderation, no AI assistance, and no realistic path into the spaces where public life increasingly takes place. The Māori language in New Zealand shows what intentional digital investment looks like over decades of sustained effort. 

For the vast majority of the world's approximately 3,000 endangered languages, no equivalent investment exists or is planned. Digital inclusion isn't an added feature for language survival. According to UNESCO's International Decade of Indigenous Languages framework, it's a requirement.

Read the full article here.

DHS Ran a Mass Spying Campaign Against Anti-ICE Protesters

Newly disclosed court records reveal that "Operation Puppet Master," launched by DHS in January 2026, sent undercover agents to community meetings, infiltrated Signal chats, and used administrative subpoenas — requiring no judicial authorization — to obtain financial records from major unions including SEIU and the Communications Workers of America. 

Organizations swept into the investigation include the AFL-CIO, the Sunrise Movement, the Democratic Socialists of America, and Minneapolis public school teachers' unions. None have been charged with any crime. The 94-page DOJ indictment filed against 15 protesters contains no allegations of injuries to specific ICE officers and no charges of serious violence.

Read the full article here.

Six Journalists Were Killed in Mexico in 2026. The Government Isn’t Responding

Six journalists have been murdered in Mexico in 2026, five of them in just over two months — one of the deadliest spikes the Committee to Protect Journalists has documented in over a decade. President Claudia Sheinbaum has not commented on the killings as a whole. State governors have largely denied the problem or stayed silent. CPJ is calling on Mexico's Federal Attorney General to federalize all cases, citing state prosecutors' poor track record. 

Approximately 80% of requests to join the federal journalist protection mechanism are currently being rejected — a significant rise in rejections at precisely the moment violence is spiking.

Read the full article here.

Platformicide: How Meta Has Been Suppressing Palestinian Voices

A report by Palestinian NGO 7amleh and Utrecht University analyzed 3,520 verified cases of digital rights violations against Palestinians on Meta platforms between 2021 and 2025. Only 32.5% had an identifiable policy violation attached. Where a reason was given, 57.2% cited Meta's Dangerous Organizations and Individuals policy — a provision designed for terrorist organizations, applied in 71.1% of journalist cases. 

7amleh submitted 2,828 appeals on behalf of affected users over five years and received no response for nearly half. The report's term for the pattern: platformicide — "the structural and intentional erasure of Palestinian digital presence."

Read the full article here.

Audio Recordings Prove the 2024 Internet Shutdown Was Ordered

Bangladesh prosecutors have presented court evidence showing that the July 2024 internet shutdown during the student uprising was a political decision ordered through a direct chain of command. A recording captures Awami League General Secretary Quader telling then-ICT Minister Palak to "slow down the internet." 

Palak replied he would seek permission from "Netri" — a reference to then-Prime Minister Sheikh Hasina. The prosecution's framing: Quader ordered it, Hasina approved it, Palak executed it. A BTRC document confirms 3G and 4G were shut down at 59 universities following a verbal instruction from Palak.

Read the full article here.

Moscow Police Beat a Teenager Based on an 85–90% AI Facial Recognition Match

In May 2026, Moscow police attacked a 15-year-old from behind, knocked him to the ground, and beat him — after a facial recognition system flagged him as an 85–90% match with a drug suspect. He was taken to a police station, questioned, and released. Doctors diagnosed him with a concussion, hematomas, and bruises. 

His parents appealed to Russia's Investigative Committee. Four months later, they have received only form letters. The official account says he "actively resisted." The AI was wrong.

Read the full article here.

Live Facial Recognition Now Running on the London Underground

British Transport Police expanded live facial recognition trials to London Underground stations, starting at Victoria and rotating across multiple stations until November. Their own deployment logs show that since February, the system has scanned approximately 530,000 faces across UK railway stations, producing zero matches, zero arrests, and one false identification. 

The technology that produced no arrests is now being expanded. Alternative routes are available for those who don't want to be scanned — presumably including the people the cameras are trying to catch.

Read the full article here.

The FTC Wants to Regulate AI for Ideological Bias

The FTC proposed treating "ideological bias" in AI systems as an unfair and deceptive practice under Section 5 of the FTC Act. More than 300 public comments criticized the proposal. The document mentions Anthropic — which has clashed with the Trump administration — more than half a dozen times as an example of ideological bias. Elon Musk, who has publicly admitted to intervening in Grok's outputs, isn’t mentioned. 

Legal experts say the FTC is conflating ideological content with factual deception, and that the proposal creates a mechanism any administration can use to pressure AI systems toward its political preferences.

Read the full article here.

Germany Filed a Criminal Complaint Against Meta’s Smart Glasses

Berlin non-profit HateAid filed a criminal complaint against Meta, Ray-Ban, Oakley, and several retailers, arguing that selling Meta's smart glasses in Germany constitutes a criminal offense because the devices allow covert filming. Privacy concerns have grown after reports of people being filmed without consent and intimate footage being captured without users knowing it could be reviewed by Meta contractors. 

Meta says an LED indicator light constitutes adequate disclosure. HateAid says an LED light most passersby don't recognize doesn't constitute genuine notice.

Read the full article here.

Flock Safety Planned to Turn 350,000 Rideshare Cars Into Surveillance Cameras

Documents reveal that Flock Safety planned to partner with dashcam company Nexar to turn Uber, Lyft, and delivery vehicles into mobile license plate readers for its surveillance network. The partnership never materialized, but Flock pitched it to the Georgia Office of the Attorney General as an existing capability. It's not known whether drivers would have been informed their cameras were feeding data to Flock. 

Fixed cameras at intersections already constitute ambient surveillance. 350,000 mobile units embedded in civilian vehicles would be a qualitative shift in the density and reach of that surveillance layer.

Read the full article here.

Youth Safety Laws Are Limiting Youth Rights

Young people are rights-holders under the UN Convention on the Rights of the Child, including the right to privacy, free expression, and access to information. Current online safety legislation frequently curtails those rights without acknowledging the tradeoff. Age verification systems collect biometric data from the teenagers they claim to protect. Blanket social media bans cut off access to LGBTQ+ communities, mental health resources, and reproductive health information. 

Even the European Data Protection Board has formally flagged the privacy implications of age assurance methods. Protecting young people and protecting their rights are not the same project.

Read the full article here.

Child Safety Laws Keep Expanding. The Surveillance Does Too

Age verification requirements started with pornographic websites and have moved to social media, messaging apps, forums, app stores, and now proposals at the operating system level. The EU's age verification system, feature-ready in April 2026, is built on the same technical specifications as the EU Digital Identity Wallet and explicitly designed to be interoperable with it. 

More than half of all US states have now passed age verification laws. Congress is weighing nineteen separate federal proposals. Each stage of expansion normalizes the framework and lowers the threshold for the next application. The question isn't whether child protection is a legitimate goal. It's whether surveillance infrastructure built in its name is the same thing as child protection.

Read the full article here.

France Strikes Down the Social Media Ban

France's Constitutional Council blocked the law that would have banned social media for under-15s on August 14, ruling it "constitutes an infringement that is neither appropriate, necessary, nor proportionate" to freedom of expression. The court found the legislation failed to distinguish between different platforms or actual risks, and that enforcing it would demand identity checks from every adult in France — a disproportionate privacy burden. 

The ruling also pauses the government's planned evaluation of VPN restrictions. Macron has tasked the Prime Minister with drafting a legally robust replacement. The fight isn't over, but the first attempt didn't survive constitutional scrutiny.

Read the full article here.

Australia’s Social Media Ban Built on AI Hallucinations

A Guardian Australia investigation found at least six citation errors in the $3.48 million report commissioned to test age assurance technologies for Australia's under-16 ban — including DOIs linking to papers that don't exist. ACCS, the UK firm that produced it, initially denied using AI, then conceded ChatGPT had been used to rewrite paragraphs after the Guardian identified ChatGPT metadata in the document. 

One cited study had a lead author who confirmed the paper wasn't publicly available until three months after ACCS claimed to have accessed it. The governments citing Australia as a model may want to examine the research it was built on.

Read the full article here.

A Whistleblower Exposes Meta on Teen Harm

The biggest trial Meta has ever faced opened in California on August 18, brought by 29 US states. Whistleblower Arturo Béjar, a former safety executive who worked directly with Zuckerberg, testified that Meta's published prevalence of teens exposed to graphic or violent content was 0.01–0.02% — while internal user surveys the company didn’t publish showed the real figure was 100 to 400 times higher. 

He described safety and security as "an afterthought" during Meta's "move fast and break things" era, and said research detecting significant harms was not acted upon. The trial is expected to last five to seven weeks.

Read the full article here.

Meta Is Removing India Protest Content

Following meetings between Meta's leadership and India's Union government, Instagram posts by the Cockroach Janta Party, opposition politicians, and ordinary protesters have been disappearing — including a clip with over ten million views. The removals are happening under Section 79(3)(b) of India's IT Act, which carries no criminal liability and does not legally require platforms to automatically comply. 

Critics say Meta is "removing content it is legally not even required to remove." The government has found a liability-free path to content suppression that bypasses the judicial safeguards that were supposed to make Section 69A workable.

Read the full article here.

The DRC Has Had No Internet for Over a Month

Mobile telecommunications and internet have been cut in Fizi Territory, South Kivu, since July 3 — over 45 days — as fighting intensifies between government forces and M23-allied rebels. Government soldiers confiscated Starlink equipment from four radio stations on July 8 and told journalists it would be returned "when the war ended." Local journalists have fled to Uganda and Burundi. Radio stations have suspended their news bulletins. 

The people still in the conflict zone cannot call family, access aid information, or be heard by the outside world. CPJ is calling for restoration of services. Its calls to DRC authorities went unanswered.

Read the full article here.

Communication Blackouts Are Humanitarian Threats

On World Humanitarian Day, we published an editorial on what internet shutdowns actually cost in conflict zones — beyond the digital rights framing. In 2025, there were 125 conflict-related shutdowns across 14 countries, the highest ever recorded, accounting for 40% of all documented shutdowns. During the DRC's January 2025 Goma blackout, a UN humanitarian official confirmed the response was "severely hindered." 

In Myanmar, earthquake rescue efforts were hampered by ongoing shutdowns. In Chad, Starlink access was cut to refugee camps. In December 2025, the ICC formally recognized that internet shutdowns can directly facilitate or contribute to international crimes.

Read the full article here.

Zero-Knowledge Proofs Won’t Fix Age Verification

The EFF published an analysis showing that zero-knowledge proofs — increasingly touted as the privacy-safe solution to age verification — are gameable, hackable, and introduce new centralization risks. A security researcher bypassed the EU's ZKP-based age verification "mini-wallet" using a Chrome extension that fed the same "over-18" token indefinitely without triggering fresh verification. More structurally: ZKP systems require a single credential issuer who can track every verification and revoke your internet access entirely. 

Over 400 security researchers signed an open letter warning these systems create a dangerous single point of failure. The age verification paradox doesn't disappear because the cryptography gets more sophisticated.

Read the full article here.

Oz Hair & Beauty Suffers Data Leak

On August 18, a group published a database claimed to be from Oz Hair & Beauty, an Australian beauty retailer. Most coverage repeated what the leaker said was inside. Our research team went and looked at the file. We found 2,187,157 genuine customer records — verified through Shopify's sequential account numbering system, which is unfakeable. The newest signups are from July 2026. More importantly: the leaker's description and the Have I Been Pwned listing both omit 24,204 records containing dates of birth embedded in a free-text notes field. 

A date of birth combined with a full name, phone number, and purchase history is a different class of exposure than an email address. If you shopped at Oz Hair & Beauty, check haveibeenpwned.com.

Read the full article here.

The Internet Forgets — and It’s Not Random

On the International Day for the Remembrance of the Slave Trade, we published an editorial on digital memory loss. The Internet Archive's research documents a genuine crisis: large portions of web content from a decade ago are already gone, and the losses fall unevenly. Community content, activist documentation, and archives from grassroots organizations have the worst survival rates. For communities whose histories were erased in physical archives, digital loss continues rather than corrects that pattern. 

UNESCO's Recommendation on Documentary Heritage frames digital preservation as a cultural rights obligation. Forgetting is not neutral — and neither is the silence about who bears the cost of digital forgetting.

Read the full article here.

Meta Settled for up to $18 Billion — After Five Days

Five days of trial. A former researcher testifying that his team knew default safety features would help teens but was told not to worry about adoption rates "because the team exists partially to protect the company against the upcoming lawsuits." Then a settlement. 

Meta will pay up to $18 billion and implement default time limits, night mode, school-hour mutes, hidden likes, and algorithmic feed alternatives. These are design decisions. Internal research showed they'd help. Meta chose engagement. $18 billion later, they're required.

Read the full article here.

Flock’s CEO Told Police a 404 Media Story Was False. Records Say Otherwise

A recording caught CEO Garrett Langley calling 404 Media's abortion tracking story "entirely false" in a private meeting with Ohio officials. Court records show Texas authorities discussed charging the woman with a crime on the same day they performed the Flock search. In the same call: "Let me handle The New York Times, you handle your local media. 

They want to hear from you — you know your reporters, they'll pick up a sob story." This follows a pattern: Flock lied to a city council about heat maps. A former employee says he was told the company had no ICE access. It did.

Read the full article here.

Russia Launched a Public Registry of “Enemies of the People”

The Justice Ministry launched a database stripping legal rights from people convicted in absentia who live abroad: frozen bank accounts, no real estate transactions, no Gosuslugi access, no online banking, no consular services. It went live August 21. Currently one entry — a fictional placeholder. 

State Duma Speaker Volodin said it would be used for political persecution of dissenters. That was his description, not a critic's.

Read the full article here.

Brazil Fined TikTok $30 Million for Collecting Children’s Data

The fine targets TikTok's "logged-out feed" — a feature available in Brazil but not in the US or EU that lets users browse without an account and bypasses age checks. An estimated 8 million children are affected. ByteDance must erase the data and build a real youth-protection framework. 

This is what enforcement-first regulation looks like: targeting a deliberate product decision, not building surveillance infrastructure to contain the consequences of it.

Read the full article here.

Reform UK Wants to Scrap GDPR

Replace it with a New Zealand-style "light-touch" privacy law. No right to erasure. Weaker enforcement. Framed as cutting red tape. The EU only grants data adequacy to countries with "essentially equivalent" protection. New Zealand doesn't have it. 

The week in which Brazil's fine, France's court ruling, and Russia's registry all showed data protection doing real work is probably not the ideal moment to propose weakening the UK's version.

Read the full article here.

We Documented 88 Identity Verification Breaches Since 2011

At least 2.15 billion records affected on a confirmed basis. In 41 of the 88 incidents, what leaked included the actual documents — ID scans, selfies, biometric templates. Data that can never be rotated. 42% of incidents date from 2024 to August 2026 — the period mandatory verification spread fastest. 

Every major verification vendor has appeared in the timeline. AU10TIX, IDMerit, Sumsub, Persona, inVOID. The wall you're forced to hand your ID to is exactly as breachable as everything else on the internet.

Read the full article here.

Why Governments Keep Reaching for the Kill Switch

313 shutdowns across 52 countries in 2025 — the highest ever recorded. Not a single day without at least one disruption somewhere. Conflict was the leading trigger, but six countries shut the internet down during school exams. 

The first shutdown requires political friction. The fifth is administrative. Myanmar: 95. India: 65. The same infrastructure built for a "necessary" shutdown gets reused for smaller provocations with less justification each time. That's normalization.

Read the full article here.

The Bodies Quietly Shaping the Future Internet

ICANN, the IETF, the Council of Europe, UNESCO — they're writing the rules that determine what the internet can and can't do years before any parliament votes. When the IETF standardized Encrypted Client Hello, Russia blocked it and severed hundreds of thousands of websites. 

When the Council of Europe opened its AI treaty, it defined what binding international AI obligations look like. These processes are technically open and practically inaccessible. The fight needs to show up earlier.

Read the full article here.

Public Schools, Private Platforms, and Your Student’s Data

Google Workspace and Microsoft Teams are enterprise products adapted for classrooms. They're free because schools generate usage data and create vendor lock-in. Students can't opt out when the platform is how they submit homework. 35 countries are already building publicly governed digital learning platforms. 

The question isn't whether technology should be in schools — it's whether the infrastructure delivering public education answers to the public.

Read the full article here.

Four Former Flock Employees Arrested for Misusing the Surveillance Network

Three former Savannah officers and one civilian charged with using Flock's system for non-law-enforcement purposes. An audit caught it after the fact. Flock's fastest-growing product is now 60 mph drones reading license plates from 2,000 feet. 

The surveillance network is expanding. Accountability is reactive — it catches misuse when someone looks.

Read the full article here.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"