- What: Apple's Hide My Email service has security flaws.
- Impact: Users may have their email addresses exposed.
Matt Burgess Lily Hay Newman Security Jul 4, 2026 6:30 AM Security Roundup: Apple’s Hide My Email Service Fails to Hide Your Email Plus: Alleged Scattered Spider hacking member extradited, dozens of license plate reader errors, and Indian officials are concerned about WhatsApp’s username rollout. Photograph: Nayuki/Getty Images Save this story Save this story A politician on the European Parliament’s PEGA Committee—created to investigate spyware abuses, including of the notorious Pegasus malware— was targeted with Pegasus himself , according to new research findings released this week. Meanwhile, top Google security staff warned this week that the pro-competition rule proposals in the EU could make Google Search and Android systems vulnerable to hacking and other abuse. A WIRED investigation revealed this week that Meta contractors posed as kids and teens to see how chatbots like Gemini and ChatGPT responded to prompts about high-risk subjects, including suicide, sex and drugs. And a researcher realized that he could use Anthropic’s Claude Opus 4.7 to break into the website of Front Gate and issue tickets to almost any United States music festival , including Lollapalooza and Bonnaroo. But wait, there’s more! Each week, we round up the security and privacy news we didn’t cover in depth ourselves. Click the headlines to read the full stories. And stay safe out there. Apple’s Hide My Email Service Fails to Hide Your Email Back in 2021, Apple launched its Hide My Email tool , which as the name suggests, allows people to sign-up for online services using an email address that isn’t linked directly to them. The privacy feature generates “unique, random email addresses” that will forward incoming messages to a user’s personal email address—reducing the amount of information you need to hand over to companies. Reporting from 404 Media this week revealed that a vulnerability in the system has made it possible, for at least a year, for people’s real email addresses to be uncovered when they are using Apple’s privacy service. “Apple Hide My Email is leaking email addresses that are supposed to be hidden,” security researcher Tyler Murphy, who discovered the flaw in June 2025, told the publication. “In our limited tests with volunteers, 100% of Hide My Email addresses were exploitable,” he said. The exact details of the vulnerability and how it works have not been revealed as the problem hasn’t been fixed. In tests conducted by 404 Media and Murphy, it was possible for a newly created Hide My Email address, which uses the @icloud.com domain, to be linked back to the real email address of its creator. Murphy said he originally reported the problem to Apple last summer and was told it had been “addressed” by March this year. However, when the researcher continued testing the issue, it remained exploitable, with Apple telling Murphy a couple of months ago that it was still investigating the issue. Apple did not respond to requests for comment from the publication. Alleged Scattered Spider Member Extradited To Face US Charges A nineteen-year-old has been arrested and extradited to the United States to face charges over their alleged involvement in the notorious Scattered Spider hacking group, the Department of Justice (DoJ) announced this week . Peter Stokes, an Estonian-US dual citizen, was arrested in Finland in April and has been charged with computer intrusion, conspiracy and fraud, linked to the criminal gang. It is alleged that Stokes, along with other members of the loose hacking collective, hacked into an unnamed “luxury jewelry retailer” and demanded a $8 million cryptocurrency ransom in May 2025. The company did not pay but still spent $2 million on the incident, according to a DoJ press release . In recent years, the Scattered Spider group, which is largely believed to be composed of young, English-speaking teenagers , has caused havoc around the world by hacking into and disrupting dozens of businesses. The arrest of Stokes follows two British Scattered Spider members, Thalha Jubair and Owen Flowers, recently pleading guilt y to hacking Transport for London in 2024 and causing millions in damages. India Threatens WhatsApp Over Introduction of Usernames Following a move by encrypted messaging app Signal last year, WhatsApp has announced it will soon roll out usernames to billions of people . The option means it is possible for people to connect and message each other without having to share phone numbers, increasing privacy protections. However, officials in India, one of WhatsApp’s biggest markets, who have previously tried to unfurl encryption protections on the Meta-owned app, have opposed the introduction of usernames. A letter from the Indian government, seen by Reuters , asked WhatsApp to pause the rollout of usernames in the country. The letter claimed the move could increase fraud and cybercrime, citing concerns around allowing online anonymity. The letter was followed by separate messages to Signal and Telegram about their use of usernames. License Plate Reader Errors Are Getting Innocent People Stopped By Cops Thousands of automatic license plate reader cameras , known as ALPRs, have appeared across the United States over the last few years. The cameras, which can be deployed by cops, cities, and businesses, photograph passing cars and record details about their movements. As well as license plate numbers, the systems can log the time and location of the photos, make and model of a vehicle, as well as bumper stickers . Billions of images and details of car movements have been captured in vast ALPR databases. However, an increasing body of evidence shows that when the camera systems make mistakes, innocent people can be detained by law enforcement officials and accused of crimes. A review of court records and media reports, which are likely the tip of the iceberg, by the nonprofit the Institute for Justice this week found at least 24 cases of misidentification over the last eight years. These reportedly include a couple with a baby in their car being detained at gunpoint; a camera misreading an “O” as a “0”, leading to grandparents being detained; and someone being pulled over after their license plate was not removed from a wanted list. The findings add to a growing list of errors from the AI-enabled cameras . Comments Back to top You Might Also Like In your inbox: Inside WIRED’s newsroom with Katie Drummond Trump mocked Zuckerberg and Bezos by showing off fawning texts Big Story: I found Jesus at a drone show Apple is making your older iPhone run faster and stay alive longer WIRED event: PepsiCo’s once-in-a-generation transformation Matt Burgess is a senior writer at WIRED focused on information security, privacy, and data regulation in Europe. He graduated from the University of Sheffield with a degree in journalism and now lives in London. Send tips to [email protected] . ... Read More Senior writer Lily Hay Newman is a senior writer at WIRED focused on information security, digital privacy, and hacking. She previously worked as a technology reporter at Slate, and was the staff writer for Future Tense, a publication and partnership between Slate, the New America Foundation, and Arizona State University. Her work ... Read More Senior Writer Topics security apple cybersecurity Europe Read More Hackers Claim to Leak Stolen Madison Square Garden Data Plus: Gay bars in San Francisco using face scanners, France quits Palantir, Apple plans to change its private email, and more. Matt Burgess The FCC Wants to Kill Burner Phones Plus: AI bug hunting fuels Microsoft’s biggest-ever Patch Tuesday, ShinyHunters ransomware gang exploits an Oracle zero-day, and more. Andy Greenberg Dialog Claims It Was Hacked. A Misconfigured Website Left Its Members Exposed The private events group, cofounded by Peter Thiel, says a “criminal” hacker is behind a breach that exposed members’ personal details. WIRED found no evidence a break-in was needed to access the files. Dell Cameron Truckloads of Tesla Batteries Keep Getting Stolen Before They Even Leave the Factory Nine major suspected cargo thefts happened at Tesla’s Nevada battery factory in January alone, according to sheriff’s records obtained by WIRED. Paresh Dave Crypto-Funded Chinese Peptide Labs Are Booming Plus: Hackers use Meta’s AI bots to hack Instagram accounts, Anthropic helps NSA hackers, a decades-long GPS satellite mystery may have been solved, and more. Andy Greenberg Top Google Security Staff Warn Search Data Could Be Hacked if EU Rules Change Europe’s pro-competition proposals could see Google Search and Android systems opened up. The company claims there are serious privacy flaws. Matt Burgess Federal Workers Can’t Get the White House’s App Off Their Phones “I deleted it as a test and it came immediately back,” says one government employee. Vittoria Elliott LastPass Users Had Their Data Stolen—Again Plus: Former national security advisor John Bolton pleads guilty in classified-materials case, Microsoft helps take down major infostealer infrastructure, and more. Lily Hay Newman A Crypto Scam Targeted a Gay OnlyFans Star. Then His X Feed Was Flooded With ‘MAGA Propaganda’ In recent months hackers have attempted to extort money from porn stars with big followings, in some cases filling their feeds with pro-MAGA and crypto content. Jason Parham The Pentagon Is Looking Into the Dialog Data Exposure for Unmasking National Security Officials Exposed records from the private group included the personal information of a senior White House intelligence official and an active-duty special operations officer. Dell Cameron World Cup Scams Are Getting Harder to Spot From fake tickets to cloned websites, AI is magnifying World Cup scams. Can fans distinguish between what’s real and what’s not? Jumana Naim Wrongful Arrest Exposes Failures in One of the Oldest Police Face-Recognition Tools in the US The ACLU is suing two Florida police departments over the arrest of a Fort