Weekly brief, 2026 week 41

Seven stories from 13 September to 6 October, including a suspected customer data leak at MOS Burger in Taiwan and a member email exposure at Singapore's Bee Cheng Hiang, a breach of about 8.8 million people's records in Denmark's population register, Sequoia PGP in Ubuntu 26.10, a commentary questioning how large language models reason, a US court ruling on a licence plate reader search, US border surveillance towers, and China's deleted-content archive and a sensitive-terms list.

This issue collects seven stories from 13 September to 6 October that did not warrant a full article.

MOS Burger's suspected data leak and Bee Cheng Hiang's member email exposure

On 1 October, An-Shin Food Services, which runs MOS Burger in Taiwan, filed a material information announcement saying a small number of customers had reported a problem. According to the announcement, a third party appears to have improperly obtained data from a platform managed by an outsourced vendor and then contacted customers by email. The company says the platform is not its own MOS ordering app, that it has told the vendor to fix the problem and that it has added anti-fraud warnings on its website and app. The announcement does not say how many people or which data were affected.

Singapore's Personal Data Protection Commission (PDPC) published a voluntary undertaking, a commitment a company makes to the regulator to fix a problem, from the Singapore food company Bee Cheng Hiang. It concerns a marketing email sent on 25 April to 95,364 members in batches of 1,000, in which everyone in a batch could see the others' email addresses. The PDPC, relaying Bee Cheng Hiang's own findings, says the cause was a missing bracket in an email script an employee wrote with a generative AI tool, because the prompt did not ask for other recipients to be hidden, rather than a malfunction of the AI tool. As of the 5 October reports, neither the announcements nor the coverage of the Bee Cheng Hiang case mention members in Taiwan.

Data breach in Denmark's population register

On 5 October, the authority that runs Denmark's population register (CPR) announced that someone had misused a Danish company's legitimate search access to obtain names, addresses and CPR numbers, Denmark's personal identification numbers, of about 8.8 million registered people. According to the press release from the Ministry of Research, Education and Digitalisation, the register holds about 11 million people, and the leak covers living people, people who have moved abroad and the deceased. Names and addresses of people registered with name and address protection were not included. Denmark's data protection authority, citing the CPR's report, says a very large number of automated lookups were reportedly made to identify valid CPR numbers.

The ministry's press release reminds people not to give passwords or other confidential information over the phone or by email, even when the caller appears to know their name, address and CPR number. As of the 5 October press release, the police investigation was at an early stage and it was not possible to say who was behind it.

Sequoia PGP in Ubuntu 26.10

According to the Ubuntu 26.10 release notes, this release brings Sequoia PGP, an OpenPGP implementation written in Rust, into the main archive with official support. OpenPGP is the standard for encrypting and signing email and files. Sequoia's sq and sqv correspond to gpg and gpgv from GnuPG, the OpenPGP tool commonly used on Linux. As of 7 October, gpg and gpgv remain in the main archive, so the two sit side by side.

Ubuntu's Rust update on its forum on 1 October says Sequoia may become Ubuntu's default OpenPGP toolchain in the future. According to the official schedule as of 7 October, 26.10 is due to be released on 15 October.

A commentary on how large language models reason

In a commentary published by MIT Technology Review on 2 October, the author uses AlphaGo as an example and argues that the chain of thought produced by large language models is still the same next-token prediction run for longer, whereas AlphaGo had a separate search mechanism. The author lists three shortcomings: models keep no inspectable record of hypotheses and evidence, knowledge and reasoning are mixed together in the model's weights, and research has shown that models often write their reasoning after the fact. The article links two papers on the third point. Judging by their abstracts, they cover extracting encrypted reasoning from commercial model APIs and chains of thought that are hard to read, and neither addresses reasoning written after the fact.

We also found an Anthropic paper from May 2025, "Reasoning Models Don't Always Say What They Think", which tests whether a model's stated reasoning mentions hints it actually used. According to the paper, when models used a hint, their reasoning often mentioned it less than 20% of the time. The paper concludes that monitoring chains of thought is a promising way to notice problems during training and evaluation, but not enough to rule them out.

US court ruling on a licence plate reader search

On 1 October, the US District Court for the Northern District of Oklahoma granted a defendant's motion to suppress evidence in a criminal case. The opinion says that when an officer searched licence plate reader systems, including one from the US company Flock, all he knew was that the vehicle had a California plate, and the search returned more than 50 records of the defendant's movements across the country over a month. The court held that the search was a search under the Fourth Amendment, which prohibits unreasonable searches and seizures. The judge called such systems "a type of indiscriminate mass surveillance".

According to 404 Media, the ruling does not bind other courts. A Flock spokesperson told 404 Media that the company was not a party to the case and that it expects the ruling to be appealed and overturned.

According to 404 Media, three members of Congress announced the Ban Flock Act on 2 October, which would bar federal agencies from using licence plate readers. The same article says a Republican senator announced in late September that he would introduce the Stop Flock Abuse Act, which would require agencies to delete driver data after ten days, except for active investigations. As of 7 October we could not confirm bill numbers for either.

US border surveillance towers

A 21 September investigation by MIT Technology Review compared where human remains were found with tower locations and found more than 1,050 people who died within the advertised range of surveillance towers between 2015 and early 2026. According to the same article, the government estimated in 2023 that its plans for the towers would cost $6.2 billion over their lifespan, and there were 803 towers as of the article. US Customs and Border Protection (CBP) plans to spend $1 billion on 1,497 more towers by 2034.

CBP said the towers use AI to detect activity and alert agents, and that Border Patrol agents decide how to respond. A spokesperson for Anduril, which makes some of the autonomous towers, said an incident nearby does not mean a tower missed a detection, and that actual coverage depends on terrain.

MIT Technology Review reported on 23 September that a member of Congress announced plans to introduce the Reimagining Safety Act to end the border tower programme. The proposal is broader, replacing the Department of Homeland Security with a new department, and the towers are one part of it. The text had not been released as of the report. The article judged that the proposal faces a steep uphill battle in Congress.

China's deleted-content archive and a sensitive-terms list

China Digital Times (CDT), a site that has long documented censorship on the Chinese internet, collects content deleted from Chinese platforms such as WeChat, Weibo and Douyin into its "404 Deleted Content Archive" and summarises it each month. CDT's summaries say it added 47 items in July and 35 in August, mostly from WeChat. As of the August summary published on 2 October, the archive held 2,662 items. CDT also notes that this is only a small fraction of what disappears from the Chinese internet each day.

On 19 September CDT also published a list of 5,241 sensitive terms, which it says comes from internal content-review documents leaked from ByteDance in the first half of 2020. The categories CDT lists include political figures and events, religious and human rights groups, and names of VPN and circumvention tools. As of 7 October, the article does not describe independent verification or a response from ByteDance.

Get new stories by RSS, newsletter or Bluesky