Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlation and limit the impact of breaches, spam, and identity theft. [...]

The internet's prevailing business model, often described as surveillance capitalism, relies on collecting extensive personal data from users. This system aggregates information from various online activities, including app usage, account creation, website visits, and form submissions, to build detailed profiles that are then monetized. Data brokers play a significant role in this process, purchasing, selling, and cross-referencing fragments of personal information to construct comprehensive user profiles, often without the individual's awareness or consent.
This data aggregation, which is inherent to the default internet, allows a single email address to link diverse aspects of a user's life, such as shopping habits, health searches, location history, and social connections. The resulting profiles are then used for purposes like targeted advertising, price discrimination, and can contribute to identity theft. The rise of artificial intelligence has further exacerbated this issue, enabling data brokers to correlate disparate actions and create even more valuable profiles from vast amounts of information.
In response to this pervasive data collection, a strategy known as compartmentalization has emerged as a countermeasure. This approach advocates for breaking the correlating identifiers that tie all online activities back to a single individual. Instead of using one set of credentials—such as a single email, phone number, or payment method—across all online interactions, users deliberately create separate, purpose-built digital identities, or "personas," for different contexts.
For example, a user might employ one persona for online shopping, another for dating applications, a third for travel, and yet another for newsletter subscriptions. Each persona operates as a self-contained identity, equipped with its own unique email address, phone number, payment method, browser, and communication handle. The crucial aspect of this method is that these personas are designed to be disconnected from each other and from the user's actual identity, making it difficult for data brokers or advertisers to link them.
Should one of these personas be compromised in a data breach, attract spam, or be sold to a marketing list, the damage is contained within that specific persona and cannot be easily traced back to the user's overarching identity. This differs from traditional security tools that focus on protecting a single identity with stronger passwords or encryption; compartmentalization assumes that any single identity is eventually susceptible to correlation and mitigates risk by ensuring that no single identity holds all of a user's valuable information.
Anonyome Labs has developed and patented several concepts related to online personas and compartmentalization, including methods for supporting telephonic synthetic identities (US9374689), email applications for synthetic identities (US9729519), identifying and warning of synthetic identity behavior that reduces user privacy (US10178106), providing persona masking in a computer network (US10320753), and administering proxy identities (US10356052).
The company's product, MySudo, is designed to implement this compartmentalization paradigm for typical users. It allows individuals to create up to nine distinct personas, or "Sudos." Each Sudo provides a unique phone number for calls and SMS, an email inbox for sending and receiving messages, a virtual payment card for online purchases, a communication handle for end-to-end encrypted messaging, voice, and video calls, and a separate browser for isolated browsing. MySudo is available as a mobile app for iOS and Android, and a desktop companion app for Windows and Mac, with additional features planned for the desktop version. Anonyome Labs also offers a privacy-focused VPN and has a password manager in development.

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.