What we found
Marriott Bonvoy: FHackers from Chinese intelligence had free access to every Starwood guest record for four years straight.
Chinese state-sponsored hackers lived inside the Starwood reservation system from July 2014 to September 2018 — four years undetected. 383 million guest records exposed including 5 million unencrypted passport numbers, credit card details, and stay histories. The ICO found Marriott failed to monitor privileged accounts, segment networks, or patch known vulnerabilities.
Fly Delta App: FDelta installed facial recognition across the entire Atlanta airport — the busiest in the world.
Delta deployed facial recognition across the entire Atlanta domestic terminal (the world busiest airport) in 2023, with plans for all US hubs. Delta CEO Ed Bastian stated the airline invested in making biometrics the "default" experience. Passengers reported that opting out requires verbally refusing to a gate agent in front of other passengers, creating social pressure. There are no separate non-biometric lanes. The EFF documented that Delta facial recognition data feeds into CBP systems regardless of domestic vs international travel.
Hilton Honors: FHilton knew hackers were stealing credit card numbers in February 2015.
The New York and Vermont Attorneys General fined Hilton $700,000 in October 2017 after discovering the company waited over nine months to notify customers about two separate data breaches in 2015. Data-stealing malware operated from November 2014 to April 2015 (first breach) and April to July 2015 (second breach), exposing 363,952 credit card numbers. Hilton did not notify the public until November 24, 2015. The investigation also found Hilton was not PCI DSS compliant.
SingaporeAir App: FPassengers found cameras embedded in every seatback screen on Singapore Airlines flights in 2019.
In 2019, passengers discovered cameras embedded in Singapore Airlines in-flight entertainment screens across economy and premium economy cabins. Singapore Airlines initially confirmed the cameras existed in seat-back screens (manufactured by Panasonic Avionics) but claimed they were "disabled" and had "no plans to enable" them. Security researchers noted the cameras were capable of monitoring passenger behavior, attention, and emotional state. No hardware removal was announced — the cameras remain physically present.
Waze: DWaze shows you as a cartoon avatar on the map.
University of California Santa Barbara researchers demonstrated they could track individual Waze users and determine their real identities through the app's social features. By monitoring the position of Waze avatars on the map over time, researchers reconstructed users' commute patterns, identified their home locations (where the avatar appeared each night), and mapped their daily routines. The research showed that Waze's social layer -- designed to show nearby drivers as cartoon avatars -- created a surveillance surface that could be exploited by anyone with patience. Even when users set their status to "invisible," the app continued collecting and transmitting location data to Waze/Google servers. The invisible mode hid you from other users but not from the company.
Emirates App: DAt Dubai Airport, cameras scan your face as you walk through tunnels — no consent screen, no opt-out button.
Dubai International Airport uses biometric tunnels that scan passengers faces as they walk through corridors — capturing biometric data passively without requiring explicit opt-in. Emirates implemented facial recognition across boarding gates, immigration, and lounges. With no UAE biometric-specific legislation and the government owning both the airline and the airport, there is no independent authority passengers can appeal to if their biometric data is misused.
Google Maps: DYou leave a Google Maps review for your favorite restaurant.
Government agencies and law enforcement have used Google Maps reviews and business data to identify and track individuals. ICE (Immigration and Customs Enforcement) has used Google data including Maps to locate and track immigrants. Business owners have been doxxed through Google Maps listings -- their home addresses exposed through business registrations tied to Maps. The review system has also been weaponized for harassment: coordinated fake review campaigns targeting businesses, review bombing during political disputes, and competitive sabotage. Harvard Business School researchers (Luca & Zervas) documented that the fake review economy around platforms like Google Maps is a billion-dollar industry. Your review of a local restaurant reveals your location, your habits, and your identity to anyone who wants to look.
Trivago: DTrivago told you it finds the cheapest hotel.
The Australian Federal Court found Trivago deliberately ranked hotels by who paid Trivago the most, not by cheapest price. The algorithm put the highest-paying advertiser in the top position while the display made consumers believe they were seeing the best deal. Fined AUD $44.7 million. Affected millions of Australians from 2016-2019.