background image blur
background image
  • Blog
    >
  • News
    >
  • Internet Freedom in September 2026: The Month in Review

Internet Freedom in September 2026: The Month in Review

Image of author
By Tech Writer and VPN Researcher Gintarė Mažonaitė
clock icon
Last updated: 30 September, 2026
Woman in a wheelchair is being watched on the street by CCTV cameras

Utah's VPN-Targeting Age Verification Law Is Live

Utah's Senate Bill 73 took effect September 3rd as the first US law that explicitly targets VPN use in age verification, holding adult sites liable for verifying anyone physically in Utah regardless of IP address. Platforms are also now barred from telling users how to bypass the checks with a VPN.

The EFF calls the VPN detection requirement "technical whack-a-mole" and flagged the speech ban as a First Amendment problem, since no reliable way to detect VPN traffic at scale actually exists. At least 26 states are watching how this test case plays out in court.

Read the full article here.

EU Brings ChatGPT, Reddit, and Roblox Under Its Toughest Digital Rules

The European Commission designated ChatGPT as a Very Large Online Search Engine and Reddit and Roblox as Very Large Online Platforms under the Digital Services Act on August 31st, after all three confirmed reaching 45 million monthly EU users.

The three now have until January 2027 to assess and mitigate systemic risks to minors, mental wellbeing, and elections, joining 28 total designated services now facing this level of Commission scrutiny.

Read the full article here.

Your Messaging App Is Three Things at Once Now

Messaging apps have quietly become critical infrastructure, a political target, and a data source simultaneously. Platform blocks hit a record 94 documented cases across 40 countries in 2025, with Togo, Sudan, Nepal, and Russia all cutting access this year alone.

Even unblocked apps hand over user data at scale through legal requests, and what a platform can disclose depends entirely on what it stores, making encryption choices and retention policies matter more than most users realize.

Read the full article here.

"Pervert Glasses": Norway Moves to Regulate Camera Wearables

Norway's digital minister Karianne Tung is considering regulating or banning camera-enabled smart glasses from Meta and Snap, citing covert surveillance risks in public spaces, and may specifically target facial recognition of bystanders.

The move follows Germany's HateAid filing a criminal complaint against Meta, Ray-Ban, and Oakley in August, with an EU-level regulatory report on smart glasses also due. Meta's defense in both cases rests on an LED light most people don't recognize as a privacy notice.

Read the full article here.

What Happens When Governments Pressure Platforms to Change What the Map Says

President Trump signed an executive order renaming Lake Ontario to Lake America after trade talks with Canada collapsed, and Google complied for US-based users within days. Apple is now being pressured directly to follow.

MapQuest refused, said so publicly, and briefly became Canada's top free app download as a result. Google shows three different names depending on the viewer's location, a live demonstration that what a map says is a compliance decision, not a neutral fact.

Read the full article here.

UK Police Averaged 34 Speech Arrests a Day

Big Brother Watch counted at least 62,199 arrests for communications offenses across the UK between 2021 and 2025, an average of 34 a day. Only 18,520 of those arrests led to a charge, and just 12,292 ended in a conviction, so roughly four in five went nowhere. 

Cumbria Constabulary arrested 25.7 people per 10,000 residents while neighboring Northumbria managed 1.9, a gap of nearly 14 times under the same laws. Two parents were held for 11 hours over sarcastic WhatsApp messages about their daughter's school, and Hertfordshire Police later admitted the arrest was unlawful and paid £20,000 in damages.

Read the full story here.

UK Wants ID Checks Built Into Every Phone

Culture Secretary Lisa Nandy told MPs that legislation is coming after Apple and Google's voluntary commitments failed to meet the scale of the problem. The plan would force age checks at the operating system layer, so nudity, cameras, messaging, and apps unlock only once someone hands over an ID or a payment card. 

The government insists adults are not the target, but the Open Rights Group warned that every adult would still be pushed through a digital ID checkpoint, with private images potentially scanned by default. Big Brother Watch described the plan as a crossing of the Rubicon, and ministers have offered no detail on how any of it reaches end-to-end encrypted apps like WhatsApp and Signal.

Read the full story here.

California Signed 13 Child Safety Laws

Governor Gavin Newsom signed 13 youth online safety and privacy laws on September 10, 2026, the most significant state-level package since the Meta settlement. AB 1709 bars social media companies from serving personalized feeds, infinite scrolling, and autoplay to under-16s, while still letting them use the platforms with those features switched off. 

SB 1119, backed by OpenAI's Sam Altman, requires AI chatbots to verify ages, restricts advertising to minors, and limits the persistent memory features that advocates say were used to isolate and manipulate a California teenager. AB 2 creates liability of up to $1 million per child where a platform is found to have fostered anxiety, depression, or other harm, which makes the Meta settlement look modest at scale.

Read the full story here.

Musk's Voter Site Harvests and Sells Your Data

America PAC, Elon Musk's super PAC, has spent over $180,000 in a single week promoting votesafe.org to voters as a place to check their registration. Visiting it hands over a name, date of birth, full address, email, phone number, IP address, and device fingerprint, with data sent in real time to Facebook, Google, X, and The Trade Desk. 

On August 29th, 2026, the privacy policy quietly dropped the language limiting data use to America PAC's own activities and replaced it with permission to sell personal information, including psychological inferences, to business partners. The government's own resource, vote.gov, collects no personal information at all, which makes the gap between the two a business model rather than an accident.

Read the full story here.

LG TVs Keep Recording After You Turn Them Off

Researchers working with Gamers Nexus and Level1Techs found current LG OLED televisions, including the G5, capturing microphone audio while the screen sat dark in standby. Disconnected from Ethernet, the sets kept recording, stored the audio locally, and uploaded the backlog automatically once the connection returned. 

The same TVs scanned local networks for phones and smartwatches, collected Wi-Fi and location data, and ran automatic content recognition on everything crossing the screen, HDMI inputs included. LG has said publicly that it does not record or store ambient conversations, a claim the investigation's own plaintext logs directly contradict.

Read the full story here.

36,769 AI Endpoints, and Almost No Locks

Our census found 36,769 self-hosted AI endpoints reachable on the public internet and identifying themselves in a single scanning index. Only 741 of them, or 2.02%, return any HTTP authentication challenge, and Open WebUI alone accounts for 18,529 endpoints with exactly one sitting behind a gate. 

The agent builders are the sharpest risk, since 5,223 endpoints across Flowise, n8n, ComfyUI, and similar tools exist specifically to store API keys, database logins, and webhook secrets. Every figure is a floor rather than a ceiling, because independent scanners have put the exposed Ollama population near 175,000 hosts, and two major vector databases are not scanned by this source at all.

Read the full story here.

Exposed Databases Map Cheap Hosting, Not Borders

We examined 1,654 internet-facing databases, each holding at least one million records, spread across 81 countries. In Germany, 52.5% of them sit with a single low-cost hosting provider, and in France 48.9% sit with another, though neither provider lost any data itself. 

The United States is the control group at 36% across its top three providers, because managed platforms make public exposure a deliberate act instead of an omission. The country ranking published every year as a risk map is really measuring hosting markets, so the useful question is who configured the instance and under which defaults.

Read the full story here.

Literacy Now Means Knowing What to Trust Online

Literacy used to mean reading and writing, and it now quietly includes finding information, judging whether a source is credible, and recognizing manipulation. That expanded definition assumes reliable material exists in your language, which does not hold for most of the roughly 7,000 languages spoken worldwide. 

Search engines can only rank what has been published, and AI assistants trained mostly on English sound exactly as confident in languages where they are considerably less reliable. UNESCO's Global Roadmap for Multilingualism in the Digital Era treats that gap as a design failure, which places the responsibility on the infrastructure rather than on the person struggling to use it.

Read the full story here.

Cutting the Internet Is an Attack on Education

Attacks on education get counted when a school is shelled, or a teacher is abducted, but an order that cuts remote learning across a region rarely gets counted at all. Since 2020, remote and hybrid learning has become the standard fallback when schools cannot open, which makes continuity depend on a connection a government can switch off. 

In Afghanistan, where UNESCO reported in 2025 that 2.2 million girls remain banned from classrooms, the Taliban imposed four shutdowns that cut off more than 43 million people. Six countries also cut access during national exams last year, including Iraq, where six shutdown instances produced 36 nationwide disruptions between May and September.

Read the full story here.

Safety Filters Are Deleting the Support Too

For a lot of people, online communities are not a supplement to mental health support but the only support within reach. Automated moderation looks for patterns in language and cannot reliably tell someone describing their own experience apart from someone posting genuinely harmful material, so peer support threads vanish alongside the risk. 

Age verification adds a second layer, and Freedom House's Freedom on the Net 2025 report documented UK forums on LGBT+ issues, journalism, and public health caught by overbroad application. Safety systems are measured on what they block and almost never on who they cut off, which builds a permanent blind spot into every system designed this way.

Read the full story here.

EU Bans Under-13s From Social Media in New KIDS Act

At the State of the Union address in Strasbourg on September 16th, European Commission President Ursula von der Leyen announced the EU KIDS Act, proposing a full social media ban for children under 13. Ages 13 to 15 would access platforms only through "mini-accounts" — limited in features, subject to parental supervision, and capped at one hour per day. 

Platforms serving users aged 15 to 18 would face a safe-by-design obligation, though the Commission has not yet defined what that requires in practice. A full legislative text is expected in the coming days or weeks, and we will update our coverage as further detail emerges.

Read the full article here.

UK Parliament Calls for a Dedicated AI Oversight Law

A cross-party UK parliamentary committee published a 100-page report arguing that existing law cannot handle what AI is already doing to human rights, and called for a dedicated AI bill and a single independent oversight body on a statutory footing. The committee wants certain uses banned outright, including subliminal manipulation techniques and facial scanning without consent — the latter already embedded in age verification systems, retail security, and public space monitoring. 

The same week, Anthropic published a report disclosing that it had blocked attempts to use its models for cyberattacks, surveillance, and coordinated influence operations originating in Russia, Iran, Turkey, and elsewhere. A Cornell computer science professor noted that this puts AI companies in the position of making value judgments at societal scale with no democratic oversight attached — which is exactly the gap the committee's bill is meant to close.

Read the full article here.

New US Bill Would Force ISPs and VPNs to Block Piracy Sites

Rep. Darrell Issa's American Copyright Protection Act of 2026 would allow copyright holders to obtain court orders requiring ISPs, DNS providers, and VPN services with over 100,000 US users to block designated foreign piracy websites, with a default 14-day objection window that can be shortened for live sports and time-sensitive content. 

Critics, including the EFF, Public Knowledge, and the Re: Create coalition, argue the bill builds a broad censorship infrastructure — applying a blocking order to DNS resolvers means a single court can cut off global access to a website based on a single filing through an expedited process. 

Europe's experience with site-blocking is the bill's sharpest problem: Spain's system has disrupted payment processors and a national healthcare provider, and Italian researchers found hundreds of legitimate websites caught in Italy's Piracy Shield. Small businesses facing erroneous blocking orders have no remedy for lost business, and no meaningful resources to challenge orders before the damage is done.

Read the full article here.

Australia's Online Safety Bill Hides Censorship in Plain Sight

The Online Safety Amendment (Digital Duty of Care) Bill 2026 contains two measures, and the Australian government is publicly discussing only one of them. The first — a requirement for platforms to offer a chronological feed alternative — is largely redundant, since most platforms already offer this. 

The second is a vague duty of care enforced by the eSafety Commissioner, with fines exceeding $100 million available for platforms deemed to have moderated content insufficiently, with no precise definition of what that means. The bill is at exposure draft stage, published September 8th, and written feedback was open until September 22nd.

Read the full article here.

A $1.4B Federal Deal Could Kill California's Net Neutrality

The National Telecommunications and Information Administration announced on August 31 that it would award California $1.4 billion to expand broadband — with a condition requiring the state to stop enforcing any law restricting internet service providers for 14 years. That would suspend California's net neutrality law, its broadband affordability protections, and a ban on throttling emergency services — a provision that followed Verizon slowing firefighters' connections during a major wildfire in 2018. 

The deal would also nullify a requirement that the Verizon-Frontier merger offer a $20 monthly plan to low-income residents, in a state where the average urban broadband cost runs $51 per month. The EFF is urging Governor Newsom to reject the enforcement ban before accepting the funds.

Read the full article here.

Türkiye Is Building State Age Checks for Social Media

Türkiye is developing an age-verification system routed through e-Devlet, the government's own identity portal, to enforce a new law banning social media access for children under 15. The law, published in the Official Gazette on May 1st, takes effect November 1st; platforms must also offer a restricted version of their services to users aged 15 to 17 and implement parental controls. 

The government's stated design — confirming age without disclosing identity to the platforms — sounds privacy-preserving on paper, but puts the state in the position of gatekeeper for social media access, with a verification infrastructure that can be pointed at other categories of access without any architectural change. Türkiye had already blocked more than 1.26 million website addresses by the end of 2024.

Read the full article here.

Elections Have Become a Trigger for Internet Shutdowns

Election-related internet shutdowns have become predictable enough that civil society now publishes a watchlist of at-risk countries before the votes take place. Access Now and the #KeepItOn coalition documented 12 election-related shutdowns across 8 countries in 2025 — matching 2024's total and more than doubling 2023's figure, and more than 40 countries representing 1.6 billion people are holding elections in 2026. 

Tanzania imposed a five-day nationwide blackout during its October 2025 general elections; the African Union subsequently declared the vote undemocratic. The pattern — warning issued, shutdown imposed, condemnation delivered, result stands — keeps repeating because the calculation keeps coming out the same way.

Read the full article here.

Censorship by Paperwork: The Quiet Way Content Dies

Most government content control doesn’t happen through bans or blackouts — it happens through legal removal orders processed by platform compliance teams, generating no error page, no news story, and no measurable network event. A block announces itself; a removed post doesn’t, and the person who posted it often never learns a government was involved. 

The transparency reports documenting these requests exist because companies chose to publish them, not because any law requires it — making the entire public record voluntary and incomplete by design. The chilling effect follows not from the removal itself but from the uncertainty: if you do not know what triggered a takedown, the rational move is to write more carefully next time.

Read the full article here.

Transparency Reports Are More Useful Than You Think

Major platforms publish detailed records of government demands for content removal and user data, broken down by country, legal basis, and compliance rate — and almost nobody reads them. The compliance rate is the most revealing figure and the one most coverage skips: a government filing thousands of requests that a platform mostly declines tells a very different story from one where nearly all are acted on. 

The EU's DSA Transparency Database raised the bar by making disclosure mandatory and per-decision rather than voluntary and summarized. None of it captures informal pressure — the phone call, the ministerial meeting, the quiet warning — which is the category most likely to matter and least likely to appear anywhere.

Read the full article here.

We Clicked "Reject All" on 47 Sites. Tracking Kept Going on 12/13

Our research crawled 47 major news and media websites three times each — untouched, after clicking Reject All, and after clicking Accept All — and measured exactly what each site did in every case. On 12 of the 13 sites where a genuine Reject All was possible, tracking companies kept being contacted after the refusal; on 5 of them, more were contacted than if the banner had been ignored entirely. 

Accepting was still worse on all 13 sites by roughly a factor of ten, so the button is worth pressing — it just is not worth trusting. The sites that never asked permission at all were running a median of 98 tracking companies before the page finished loading.

Read the full article here.

Pakistan's Internet Shutdown in Kashmir Passes 100 Days

Mobile data and broadband services have been suspended in Pakistan-administered Kashmir since June 5th, when protests over electoral reform erupted — passing 100 days as of Al Jazeera's September 15 report, confirmed by independent internet monitor NetBlocks. Staggered elections were held across three rounds and a new government has since been formed, but the partial shutdown continues, leaving online banking, academic services, and everyday communication disrupted for the territory's entire population. 

A legal analysis published in Opinio Juris finds that Pakistan's shutdown process — running from army directives through the National Crisis Management Cell to telecom providers — is a rubber-stamp chain that rarely pushes back, with orders never released publicly and no meaningful legal mechanism for challenge. A shutdown that outlasts the election it was imposed to manage is no longer an emergency measure; it is a policy.

Read the full article here.

US States Are Putting Age Verification Into Your Operating System

California, Colorado, and Illinois have passed laws requiring operating systems — Windows, macOS, Android, ChromeOS — to collect users' ages during device setup and share an age bracket with every app on the device, with California's law taking effect January 1st, 2027. On paper, California's law accepts a self-declared age with no ID required; in practice, the EFF expects Apple, Google, and Microsoft to demand more — facial scans or government documents — to protect themselves from liability if a minor enters a false age. 

Because tech companies build one OS for all states, the EFF expects a single national system to roll out to every user of those operating systems, including people outside the US. A proposed federal Parents Decide Act would extend the requirement nationwide, and the open-source community is fighting a patchwork of exemptions — California and Colorado exempt Linux; Illinois does not.

Read the full article here.

Türkiye Blocked 400+ Journalist and Rights Group Accounts

Starting on September 12th with LGBTI+ organizations including Kaos GL and Velvele, Turkish blocking orders expanded within 48 hours to cover Evrensel newspaper, Amnesty International Türkiye, Academics for Peace, the Media and Law Studies Association, Lawyers for Justice, named journalists including İrfan Değirmenci and Şirin Payzın, and women's organizations.

The İstanbul Chief Public Prosecutor's Office confirmed a total of 419 accounts and one link restricted, all justified under the same label: sharing "obscene content" to protect families, children, and young people. Amnesty International Türkiye isn’t an obscene content provider, and neither are the journalists or academic freedom groups on the list — the legal label is functioning as a catch-all applied to whatever the prosecutor's office decides to sweep up next.

Read the full article here.

Discord Is Now Profiling Every User's Age

Discord rolled out age verification globally on September 22nd, automatically sorting every account into adult, teen, or unconfirmed age groups using a machine learning model trained on behavioral signals — server membership, account age, activity patterns — without reading messages or content. Discord says more than 90% of users will be placed automatically with no action required; the remaining 10% can verify through a credit card, app store age signals, Google Wallet, a video selfie, or an ID scan. 

The rollout follows a delayed February 2026 launch after user backlash, and a September 2025 data breach at a third-party vendor that exposed government ID photos and selfies from around 70,000 users. Discord has built the least bad version of this — the 90% figure is framed as a privacy win, but it means the platform has already inferred and acted on the probable age of almost its entire user base from behavioral data, without asking.

Read the full article here.

The US Called Australia's Algorithm Opt-Out Law "Censorship"

The US embassy in Canberra filed formal objections to Australia's draft Digital Duty of Care laws, warning that vague harm definitions enforced by the eSafety Commissioner risk "viewpoint-based censorship" and that mandated algorithm design requirements could affect users globally. Prime Minister Albanese, at the UN General Assembly, responded that the law is about giving individuals control over their feeds — not giving government control over content. 

Both arguments are partly right, which is the problem: the US is correct that a regulator with nine-figure fines and no precise content standard creates conditions for politically shaped enforcement, while Albanese is correct that engagement-optimized algorithms cause real harm. What neither side is fully engaging with is that the bill bundles a popular algorithm opt-out with a vague enforcement power, and the US submission is aimed at the second while Australia defends the first.

Read the full article here.

Ireland Fined Google €403M for Unlawful Location Data Processing

Ireland's Data Protection Commission fined Google €403 million after a six-year inquiry into how the company handled location data across three features between May 2018 and February 2020. The DPC found Google's processing was unlawful, unfair, and non-transparent — users had no clear picture of how their location was being used to target advertising or infer their interests, and Google retained it longer than necessary. 

Google has also been ordered to bring its practices into compliance within six months, indicating the DPC isn't satisfied that its post-2019 updates fully meet GDPR's requirements. The six-year gap between complaint and fine is its own problem: Ireland handles an outsized share of Europe's major tech enforcement cases and consistently takes years to resolve them.

Read the full article here.

Gates Foundation Builds a Coalition to Fix AI's Language Gap

The Gates Foundation announced that it's convening 60 organizations — including Anthropic, Google, and the OpenAI Foundation — to build more representative language data sets for AI tools, aiming to reach more than 3 billion people over five years. The Mozilla Data Collective's CEO described the core problem as the "original sin" of AI: models were trained on internet-scraped data, and the internet isn't representative — a pregnant woman in Malawi describing her water breaking could receive a mistranslation so literal it becomes medically meaningless. 

Google's Project Vaani is already collecting more than 150,000 hours of audio across every district in India just to cover dialects within a single language. This is, for once, movement in the right direction on a problem we've been documenting for some time.

Read the full article here.

A Rogue OpenAI Agent Hacked a Government Site — and Told No One for Months

According to the BBC, a rogue OpenAI agent accessed Australia's Medicare Statistics Reporting Service portal in June, entering public and non-public government files without authorization — the first known case of an AI agent breaching a government system of its own volition. OpenAI says it didn't discover the breach until August, and notified the relevant agency on September 10th via a general inbox email; it took five more days before the Prime Minister was informed. 

Albanese told OpenAI CEO Sam Altman directly that the disclosure took too long and that there would be legal consequences; Altman acknowledged "issues with protocols." The disclosure timeline is the second story: OpenAI's response to its model doing something it wasn't supposed to was to internally review it, wait, and send an email to a general inbox.

Read the full article here.

Ofcom Investigates Whether Pornhub's Age Checks Actually Work

According to the BBC, Ofcom has launched a formal investigation into Pornhub owner Aylo over whether its age verification process meets the Online Safety Act's "highly effective" standard — specifically whether Aylo conducted sufficient due diligence before deploying Apple's age check system for UK users. 

Pornhub's UK traffic dropped more than 75% when tougher OSA checks came into force in October 2025, the site restricted access entirely in January, and partially reopened in May — but the traffic that left didn't disappear; it went to VPNs and non-compliant sites Ofcom can't touch. Age verification creates a gate at the compliant site, generates data in the process, and leaves the non-compliant internet untouched. The checks may not be working. The data collection is.

Read the full article here.

Pakistan Is Planning Another Internet Shutdown — This Time for a Political March

According to Bloom Pakistan, Punjab's Home Department has asked the federal government to cut mobile and internet services in parts of Rawalpindi and Attock from September 27th, ahead of PTI's planned long march toward Islamabad — with internet jamming also requested at specific sites along the route. 

Punjab has simultaneously imposed Section 144 across the province banning gatherings of five or more people, and Pakistan-administered Kashmir has been under a partial internet shutdown for more than 100 days — imposed the day protests started in June and still running after the elections it was nominally meant to manage have concluded. The mechanism is identical: law enforcement request, Interior Ministry, telecom regulator, no public order, no legal challenge before it takes effect. What differs is the political target.

Read the full article here.

VPN Restrictions Are Following Age Verification Laws

September 25th was the second annual Defend VPNs Day of Action, organized by Fight for the Future. The pattern driving it is consistent across several jurisdictions: an age verification law passes, VPN adoption rises in that jurisdiction, and a follow-up proposal appears to close the "gap." Utah became the first US state to meaningfully restrict VPN use, placing enforcement on site operators rather than users — creating an incentive to over-block anyone connecting through a VPN, regardless of why. 

Brazil treats VPN use as an aggravating factor in criminal sentencing; Michigan has a proposed VPN ban; Wisconsin removed a VPN provision before passage. A restriction on a general-purpose privacy tool used by journalists, researchers, people in abusive households, and anyone with a legitimate reason to browse privately is a considerably wider intervention than the child safety problem it's responding to.

Read the full article here.

Cutting the Network Is Now a Weapon of War

Conflict has been the leading trigger of internet shutdowns for several years running, and the tactic is becoming more deliberate — with strikes on cables and power infrastructure, cyberattacks, seizure of satellite terminals, and in some cases the criminalization of owning satellite internet equipment. When people found ways to stay connected after terrestrial networks failed, those fallback routes were closed too. 

Peace processes depend on communication: a ceasefire has to be monitored, violations have to be reported, and civilians have to be able to find out whether a route is safe. Ceasefire agreements almost never mention telecommunications infrastructure. International legal bodies are beginning to recognize that deliberately cutting communications during conflict isn't a neutral act — but the frameworks for accountability are still catching up to the targeting.

Read the full article here.

Trump Renamed a Lake. Apple, Google, and the US Government Complied

President Trump signed an executive order on August 27th renaming Lake Ontario to "Lake America," directing the Interior Department to update the US geographic naming service within 30 days. Apple Maps and Google Maps implemented the change shortly after; this week the National Weather Service and AccuWeather followed. 

The renaming applies to US-facing services only — a user in Europe opening the same apps still sees Lake Ontario; a user in Ohio sees Lake America, because the lake is shared with Canada, which has not renamed it and has no intention of doing so. It is a small and unusually visible illustration of something that happens constantly online: what the internet shows you depends not only on where you are, but on which government's instructions the platforms serving you have decided to follow.

Read the full article here.

Russia Is Now Attacking VPN Infrastructure Directly

Human Rights Watch published a report on September 24th documenting Russia's escalation from blocking individual VPNs to bulk IP takedowns, coordinated DDoS attacks, phishing campaigns against VPN employees, app store removals, and payment system restrictions. The clearest case is the June 2026 attack on Amnezia VPN — authorities blocked its IP addresses in bulk, ran simultaneous DDoS attacks, and targeted staff with phishing emails; it took a month and a half to fully restore service. 

In April, the Ministry of Digital Development instructed more than twenty of Russia's largest internet companies to detect and deny access to services when VPN connections are identified, with at least thirty major apps found to be gathering and sharing that data — which was then used in infrastructure attacks against the VPNs themselves. Despite 469 VPNs being blocked, advertising bans, criminal penalties, and payment restrictions, approximately 57 million Russians — 40% of the population — still use them.

Read the full article here.

The EU KIDS Act Explained: What It Does and What It Means

Now that the Commission has published its full FAQ, the EU KIDS Act is clearer than the State of the Union announcement made it. It does two things: a three-tier age staircase — no accounts under 13, parent-supervised accounts for 13- to 14-year-olds with a one-hour daily limit, independent accounts from 15 — and a safe-by-design mandate banning infinite scrolling, streak mechanics, notifications designed to pull children back, and recommender systems optimized for engagement. 

Age verification uses "zero-knowledge proof" technology that tells the platform only whether a user is above or below the threshold. Large platforms must submit audited compliance plans before their services reach children, at their own expense. Fines reach 6% of global annual turnover. The implementation questions are real, but the design is more thoughtful than most national schemes.

Read the full article here.

A Federal Judge Blocked Utah's VPN Age Verification Law

U.S. District Judge David Barlow granted a preliminary injunction against Utah's SB 73 on September 24th, blocking rules that required platforms to identify and geolocate users even when using a VPN. His reasoning: "perfect geolocation" doesn't exist, the law's demands are technically impossible, and attempting to fulfill them creates free speech and privacy problems that age verification doesn't justify. 

The law also banned websites from explaining how VPNs work — a direct restriction on communicating lawful information about a lawful tool. The ruling is preliminary, and Utah may appeal, but it creates a federal court record that other states drafting similar VPN provisions will need to write against. Proton's response: "VPNs should not be used as a scapegoat."

Read the full article here.

Pennsylvania's Age Verification Bill Is a Privacy Disaster in Progress

Pennsylvania's Senate Judiciary Committee advanced SB 603 on September 28th — requiring state ID verification before accessing any website where at least one-third of content is adult material — without specifying how the collected data must be secured or protected. The bill uses private right of action enforcement, meaning any website arguably in scope faces lawsuit risk and has every incentive to over-gate content. 

Sen. Maria Collett voted against it while naming the specific problem: age verification for adult content creates a link between an identity document and a record of access — exactly what enables targeted blackmail. A third senator agreed with the privacy concerns, voted yes anyway, and said it wouldn't be the last word. The adults bearing the cost of that approach are the ones who use the internet legally.

Read the full article here.

Russia Struck Ukraine's Largest Mobile Provider. That's a War Crime

According to Reuters, Russia struck the Kyiv headquarters of Kyivstar — Ukraine's largest mobile network — with a jet drone on September 27th, the same day Russia's defense ministry claimed a strike on a Vodafone Ukraine data center. Over the preceding week, attacks on Ukrainian internet infrastructure caused outages for 100,000 households in the Kyiv region. 

Ukraine's foreign minister said missile alerts depend on the communications infrastructure being bombed — the systems that tell people to take shelter run on the same networks Russia is targeting. Kyivstar was hit with a major cyberattack in December 2023. This time Russia hit the building. We published a piece this week arguing that targeting communications infrastructure is a deliberate weapon of war, not collateral damage. The Kyivstar strike is what that looks like.

Read the full article here.

Malaysia Wants a Freedom of Information Law. It's Not Enough

September 28th was the International Day for Universal Access to Information. Malaysia's parliament is considering its first federal FOI bill, which the Center for Law and Democracy assessed at 47 out of 150 points — with no independent oversight body, no requirement for proactive disclosure, and no protection against existing secrecy laws overriding it. 

The Najib Razak pardon case is the live illustration: the Pardons Board minutes, the AG's submission, and the conditions governing his politically sensitive house arrest haven't been published. A law that performs transparency without delivering it changes the name of the problem, not the problem.

Read the full article here.

A Right to Information Assumes It Still Exists

Access to information laws give the right to request records. They say almost nothing about whether those records must be preserved and remain reachable. The Internet Archive's Vanishing Culture project documents how much web content published a decade ago is gone — through link rot, platform shutdowns, and institutional churn. 

The material most likely to vanish is local government pages, small publications, and the working documentation of bodies since restructured — exactly the material accountability questions tend to turn on. The closest thing the public has to a systematic web record is maintained by nonprofits and volunteers without a public mandate or stable funding. A right to request something that no longer exists isn't a meaningful right.

Read the full article here.

The One-Language Internet Is a Form of Censorship

September 30th is International Translation Day. Most of the world's languages are functionally absent from the internet, and the effect on speakers resembles censorship even though nobody issued a ban. AI tools perform well in languages with large training data sets and considerably worse elsewhere — while sounding equally confident in both, making the gap invisible to users who rely on them. 

The Gates Foundation's coalition of 60 organizations, covered here last week, represents a real shift: treating language coverage as infrastructure rather than a localization afterthought. But how that data gets collected matters as much as whether it exists — communities are asking who controls translations of their languages and whether consent was given.

Read the full article here.

The EFF Says the EU Kids Act Will Create a Privacy Minefield

The EFF published its detailed critique of the EU Kids Act on September 21st. The proposal reserves full unrestricted internet access for adults only, requires parents of 13- to 15-year-olds to verify their own identity on top of their child's age check, and covers virtually all mainstream platforms. 

The safety-by-design pillar extends to AI companions, chatbots, and app stores — and the EFF warns that deciding what's "safe" can easily slide into deciding what content people can access. The proposal also bypassed a full impact assessment, meaning the Commission hasn't formally examined whether less invasive alternatives could achieve the same goals. The EFF is calling on EU lawmakers to pull back the most harmful provisions before the legislative text is finalized.

Read the full article here.

London Scanned 500,000 Faces in Six Months. Made Zero Arrests

According to a freedom of information document obtained by Liberty Investigates and The Guardian, the British Transport Police's six-month live facial recognition trial at London railway stations scanned more than 500,000 faces, produced one alert — a false match — and led to zero arrests directly from any LFR alert. The trial cost more than £320,000 and consumed almost 100 hours of police officers' time. 

BTP's response is that officers made "associated arrests" for other offenses during the period, while noting those aren't counted in LFR performance data — which, on its own terms, recorded nothing. The trial is being extended for four more months and expanded to the London Underground. Parliament's joint committee on human rights has called the rollout a "particularly clear example of risk," and a Labor MP has called for suspension until a legal framework is in place.

Read the full article here.


Share on
Facebook share Twitter share Reddit share Linkedin share

Be part of the resistance, quietly.

Get Mysterium VPN Arrow icon
awareness campaign banner img
Image of author
Gintarė Mažonaitė
Tech Writer and VPN Researcher

Gintarė is a cybersecurity writer at Mysterium VPN, where she explores online privacy, VPN technology, and the latest digital threats in editorial pieces. With hands-on experience researching and writing about data protection and digital freedom, Gintarė makes complex security topics accessible and actionable.

Read our editorial policy here.

Read more by this author
© Copyright 2026 UAB "MN Intelligence"