
Sign up to save your podcasts
Or


Send us Fan Mail
Cameron & Gabe dig into 2026's wave of AI-blamed layoffs — the stats companies cite, the receipts they never bring, and what it actually means for the next generation of workers. Headlines vs. reality, Problem Lounge style. Explicit language.
Stat Disclaimer
The AI-attributed layoff figures cited in this episode (~38–40K May 2026 cuts, 100K+ total 2026 cuts, the 80% no-ROI-correlation figure) are drawn from public layoff-tracking reports and have not been independently verified against primary company disclosures.
Some figures cited in this episode are drawn from secondary reporting and layoff trackers and have not been independently verified. If you're citing these numbers, please check primary sources.
Support the show
Send us Fan Mail
Jacob Coxon spent three years doing pretraining research at OpenAI and then Anthropic. This week he resigned and posted a seven-part thread claiming neither company is acting responsibly with how fast they're racing toward self-improving AI. It hit 100 million views in a day.
This episode covers what he actually said, how Anthropic's own alignment science lead responded (and the important nuance buried in that response), the questions worth asking about Coxon's timing and incentives, a fair skeptic's rebuttal, and the AI safety legislation already moving in Congress as a result.
One thing on the title: it's a real quote, but it's Hubinger's general belief statement, not his assessment of present-day risk — he separately said present-model risk is low. Your own episode makes that distinction carefully. Worth a one-line callout in your pinned comment or community post after it's live, so the title doesn't end up being the thing people push back on in the comments before they've actually watched.
Support the show
Send us Fan Mail
Flock Safety's automated license plate readers are in over 5,000 communities and used by more than 40,000 cameras nationwide — sold to cities as a tool to catch car thieves and find missing people. But a Washington Post investigation found at least 50 officers accused of misusing the system, most of them to track romantic partners.
This episode covers:
flock safety, flock cameras, license plate reader, ALPR, police surveillance, data privacy, police stalking, automated license plate reader, mass surveillance, privacy please podcast, cybersecurity, ICE surveillance, police misconduct, LOVEINT
Support the show
Send us Fan Mail
Jonathan Sander is back on Privacy Please — and he's brought two blog posts worth arguing about.
Sander (42 Notions, now in an operational role at Myota) joins Cam and Gabe to dig into why ransomware resilience should work like New York City's storm surge infrastructure — building something that pays off before disaster strikes, not just a wall you wait behind. Then the conversation turns to AI agents: why Sander tried and failed to build a clean taxonomy for them, the six dimensions he landed on instead (authority, execution location, trigger, persistence, delegation, tool reach), and why the "hybrid agent" — switching between acting on your behalf and acting with power you never had — might be the hardest identity problem in security right now.
Also covered: why "back to basics" (secrets, resilience, identity) is Sander's answer for teams panicking about AI, and a real story about an AI agent that deleted a Postgres database and just... apologized.
Articles referenced:
Chapters:
Support the show
Send us Fan Mail
Full Show Notes
This week on Privacy Please, Cam breaks down four stories that all come back to one theme: choice.
GigaWiper — Microsoft researchers uncovered a new backdoor malware built from pieces of older malware families, giving attackers the ability to decide after they're already inside a network how they want to cause damage — from low-level disk wipes to fake ransomware with encryption keys that are never even saved. Multiple security firms are independently tracking it, with no group attribution yet.
Connecticut's new AI disclosure law — As of July 1st, companies covered by Connecticut's privacy law must clearly disclose whether their data is used to train large language models like ChatGPT, Gemini, DeepSeek, or Grok. Cam digs into why "disclosure" doesn't always mean "clarity," and what to actually look for in a privacy policy update.
California's Delete Act (DROP) — A correction and a deep dive: DROP has been live since January 1st, not launching in August as previously stated. What actually changes on August 1st is enforcement — the date data brokers become legally required to act on deletion requests. Cam walks through exactly how to submit one at privacy.ca.gov.
The Phantom Hacker gold bar scam — A 78-year-old Phoenix woman nearly lost $600,000 in gold bars to a scammer posing as a federal official — until she turned the tables and called the FBI herself. Cam covers the arrest, the courier-for-hire business model behind it, and the billion-dollar scale of phantom hacker scams since 2024.
Tips for this episode:
Sources referenced:
Chapter Timestamps
00:00 – Cold Open 01:30 – GigaWiper: Choose-Your-Own-Destruction Malware 04:00 – Connecticut's LLM Data Disclosure Law 06:15 – California's Delete Act & DROP Platform 08:30 – The Phantom Hacker Gold Bar Scam 11:30 – Recap & Close
Support the show
Send us Fan Mail
Last year, every major outlet ran the same story: 16 billion passwords exposed. Apple. Google. Facebook. The largest breach in history.
It was overblown. Security experts tore it apart within 48 hours.
But here's the thing: the real story underneath that headline is actually scarier. And nobody covered it.
It's called infostealer malware. It's been quietly running on millions of devices — stealing passwords, bypassing MFA, and feeding an underground credential economy that's behind nearly every major breach of the last two years. Ticketmaster. AT&T. Coinbase. All of it traces back here.
In this episode, I dig back into that story and break down:
SHOW NOTES
Episode: Your Password Is Already For Sale
Last year, the 16 billion password story dominated headlines. The headline was overblown — but the real threat underneath it, infostealer malware, is what nobody talked about. It's an industrial-scale credential theft economy running quietly in the background, and it's the engine behind almost every major data breach of the last two years. We dug back into it because it's only gotten worse.
Resources mentioned:
Key sources:
Connect:
🌐 theproblemlounge.com
📺 YouTube: The Problem Lounge Network
Support the show
Send us Fan Mail
Gabe and I dig into Shiny Hunters and why the scariest cyberattacks now look like ordinary logins instead of dramatic break-ins. We map how credential theft, social engineering, and SaaS data exports turn basic security hygiene into the difference between a close call and a headline.
• Shiny Hunters’ scale, loose structure, and why takedowns rarely stick
• Why ransomware and extortion keep growing as a business model
• How the tactics evolve from Microsoft 365 and developer creds to SaaS platforms like Salesforce
• Credential stuffing, vishing, and smishing as “low-friction” intrusion paths
• The Snowflake-style failure mode of missing MFA and weak password practices
• Password reuse and how consumer breaches can cascade into enterprise access
• Data retention and why old records increase privacy risk
• Vendor risk and the shared responsibility model for identity and data
• Practical steps that improve security without relying on perfect users
If you guys have not been to our website, theproblemlounge.com, check it out. Got some new blogs up there. Sign up for the newsletter. Support us, follow us. Let’s get this out to more people.
Support the show
Send us Fan Mail
SHOW NOTES
The Pornhub breach is being reported as a data story. It's actually a story about shame as a weapon.
In December 2025, a hacker group called ShinyHunters claimed to have stolen 200 million records from Pornhub Premium users — including email addresses, locations, and intimate watch and search history. They sent extortion demands. The data was verified as real.
In this episode of Privacy Please, Cameron Ivey breaks down:
✅ What was actually stolen — and why it's worse than most breaches ✅ The three-way blame game between Pornhub, Mixpanel, and a mysterious 2023 employee access ✅ Why ShinyHunters is one of the most dangerous and active hacker groups operating right now ✅ The bigger question nobody's asking: why does this data still exist? ✅ Five things you can do right now to protect yourself
🔗 RESOURCES MENTIONED:
📰 SOURCE REPORTING:
🎙️ Privacy Please is part of the Problem Lounge Network 🌐 theproblemlounge.com 📺 YouTube: The Problem Lounge Network
If this one hit different — share it.
Support the show
Send us Fan Mail
In this episode of Privacy Please, Cameron Ivey investigates Palantir Technologies — a data analytics company founded in 2003 with CIA backing that has quietly become embedded across nearly every major arm of the U.S. federal government.
This week's investigation covers:
The USDA Deal On April 22nd, the Department of Agriculture signed a $300 million blanket purchase agreement with Palantir to build "One Farmer, One File" — a unified digital profile for every American farmer. The deal was awarded without competitive bidding.
The IRS Bombshell The same week, The Intercept revealed — based on documents obtained by watchdog group American Oversight — that Palantir has been running financial crime surveillance operations inside the IRS since 2018. The IRS has paid Palantir over $130 million for access to a platform that cross-references bank records, tax filings, transaction histories, and more across millions of Americans.
The Immigration Enforcement Machine Palantir's ICE contracts — now over $145 million — power the agency's case management, deportation targeting, and real-time location tracking of immigrants. A tool called ELITE creates individual dossiers on deportation targets by pulling data from the Department of Health and Human Services.
The Pushback That's Working New York City's public hospital network canceled its Palantir contract after community organizing and City Council pressure. In the UK, 229,000 people have signed petitions to remove Palantir from the National Health Service. Public pressure is moving the needle.
Five Things You Can Do Right Now Cameron closes with specific, actionable steps every listener can take — from requesting your IRS transcript to freezing your credit to contacting your representative about sole-source contracting.
Privacy Please is part of the Problem Lounge Network. New episodes weekly. theproblemlounge.com
Chapter Markers
Support the show
Send us Fan Mail
A normal data breach steals names and passwords. This one may have stolen the recipe for building the world’s most powerful AI models, and it happened through software most people will never notice until it breaks. We follow the Mercor breach from the first warning signs to the moment poisoned Python packages hit PyPI and spread in minutes across systems that were set to auto-update.
We walk through what Mercor actually does in the AI economy, especially RLHF (Reinforcement Learning from Human Feedback), and why that behind-the-scenes work shapes how tools from OpenAI, Anthropic, Meta, and Google behave. Then we unpack Lite LLM, the open source “plumbing” that connects apps to multiple AI services, and how a supply chain attack can bypass the company you’re targeting by compromising the dependencies everyone trusts.
From there, the focus shifts to the fallout: contractors whose Social Security numbers and identity documents may be exposed, companies scrambling to assess backdoors and credential theft, and the bigger fear that proprietary AI training data sets and labeling strategies are being auctioned on the dark web. We also dig into the compliance controversy around SOC2 and ISO 27001 style certifications and what happens when security audits become performance instead of protection.
If you care about cybersecurity, data privacy, AI governance, and open source risk, listen through to the end for concrete steps you can take right now. Subscribe, share this with a friend who uses AI tools, and leave a review with your take on who should be held accountable.
Support the show
From the publisher's feed
Welcome to "Privacy Please," a podcast for anyone who wants to know more about data privacy and security. Join your hosts Cam and Gabe as they talk to experts, academics, authors, and activists to…
In today's connected world, our personal information is constantly being collected, analyzed, and sometimes exploited. We believe everyone has a right to understand how their data is being used and what they can do to protect their privacy.
Please subscribe and help us reach more people!
This podcast is part of The Problem Lounge network — conversations about the problems shaping our world, from digital privacy to everyday life.

67 Listeners

111,779 Listeners