LIVE · cybersecurity feed
Live wire
ai

Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal

More than 100 members of Congress have urged Google and Spirit Airlines to halt a proposed $10 million deal that would transfer Spirit's internal data to Google for the purpose of training artificial intelligence models. The lawmakers expressed significant concerns that even with de-identification safeguards, the data could still expose sensitive employee information.

ZeroDay News ·

Source: The Record

Photo: Corsario CL (CC BY-SA 4.0) via Wikimedia Commons

More than 100 members of Congress have urged Google and Spirit Airlines to halt a proposed $10 million deal that would transfer Spirit's internal data to Google for the purpose of training artificial intelligence models. The lawmakers expressed significant concerns that even with de-identification safeguards, the data could still expose sensitive employee information.

The proposed data transfer, which is part of a $10 million payment from Google to the defunct airline, reportedly includes a vast array of internal records. According to a press release from Rep. Steven Horsford (D-NV), the dataset encompasses approximately 100 million emails, 500 million Microsoft Teams messages, employment contracts, employee and timecard records, and payroll and tax information.

While Google has stated its intention to de-identify the data and has indicated that a third party would scrub the information before transfer, 114 federal lawmakers, led by Rep. Horsford and Sen. Elizabeth Warren (D-MA), contend that conventional de-identification methods may not adequately protect privacy in the context of modern AI. Their letter to the CEOs of both companies highlighted that simply removing direct identifiers like names or email addresses does not guarantee anonymity.

The lawmakers' concerns are particularly acute given the recent job losses at Spirit Airlines. Nearly 1,000 individuals in Las Vegas, a city partially within Rep. Horsford's district, lost their jobs after Spirit announced its shutdown plans in May.

Should Google and Spirit Airlines proceed with the agreement, the congressional letter recommends several additional protective measures. These include establishing a data de-identification process that incorporates feedback from former employees, minimizing the amount of employee information transferred, imposing strict limits on how the data can be utilized, and conducting an independent review of employee confidentiality.

Google has not yet responded to requests for comment regarding the congressional letter. Spirit Airlines, being defunct, could not be reached for comment.

ai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

'AgentCorruption' Puts AWS Environments At Risk With Single Prompt

A recently disclosed vulnerability, dubbed 'AgentCorruption,' reportedly allowed attackers to compromise AWS environments through a single prompt directed at an AI chatbot. The flaw, now patched, was identified within AWS Bedrock AgentCore and could have enabled an attacker to gain control over an organization's entire fleet of AI agents.

ransomware

Ransomware attack disrupts Japan's IDCF Cloud used by govt clients

IDC Frontier, a prominent Japanese cloud and digital infrastructure provider, has confirmed that its IDCF Cloud service was targeted in a ransomware attack. The incident, which began on October 7 at 3:40 AM local time, led to an outage at a data center cluster serving Japan's eastern region.

security

DOJ, FBI seize Flax Typhoon-linked hacking tools Microscan, FishHub

The U.S. Justice Department and FBI have announced the seizure of two hacking tools, Microscan and FishHub, which are linked to the Chinese government-affiliated group Flax Typhoon and the China-based firm Integrity Technology Group. The seizures, authorized by a court in the Western District of Pennsylvania, aim to disrupt access to these tools by denying hackers their domain names.

ransomware

Ransomware recovery CEO indicted after allegedly paying hackers and pocketing millions

Zohar Pinhasi, the owner and operator of the ransomware recovery firm MonsterCloud, has been indicted on charges of wire fraud and wire fraud conspiracy. Authorities allege that Pinhasi defrauded hundreds of clients by claiming to decrypt their data using proprietary tools without paying ransoms, while in reality, he secretly paid cybercriminals and then charged his clients significantly…

security

Italy’s Foreign Ministry Under Cyberattack as Embassy Sites Come Under Review

Italy's Ministry of Foreign Affairs confirmed on October 8, 2026, that its website was under cyberattack. The ministry stated that its protection systems successfully mitigated the incident, preventing any disruption to its services.

malware

Midnight Mimosa Malware Found Preinstalled on Low-Cost Android Phones

Recent reports indicate that a new malware strain, dubbed "Midnight Mimosa," has been discovered preinstalled on certain low-cost Android smartphones. This finding suggests that some devices may be compromised with malicious software embedded directly into their firmware before they even reach consumers, posing a significant supply chain security risk.