TL;DR: Six months into 2026, five surveillance threats have moved from theory to default. FISA Section 702 is expiring in five days (June 12) with the Senate still stuck. DOGE has had nine months of unrestricted access to federal data, including Social Security and Treasury systems, and is now the subject of a 19-state lawsuit. ShinyHunters have stolen 1.8 billion records across more than 40 confirmed breaches. Meta's facial recognition code is shipping in millions of Ray-Ban smart glasses. And age verification has gone from niche to mandatory across platforms most teenagers use daily. This is the state of play at the halfway mark, and none of it is getting better on its own.
Why a Mid-Year Check Matters
Privacy stories tend to land in isolation. One week it's a facial-recognition rollout. The next it's a data breach. The week after that, a new Senate bill. Step back, and the pattern is harder to see.
We're six months in. January 1, 2026 looks very different from June 7, 2026. FISA 702 was supposed to be reauthorized cleanly. DOGE was a 2025 story. ShinyHunters was a Salesforce campaign, not an industrial-scale data-laundering operation. And "Name Tag" was a rumored Meta feature that an EFF researcher had to manually enable in debug mode to confirm existed.
Halfway through the year, all five of those have moved past "rumor" to "default." Here are the threats defining 2026, and what the back half is likely to bring.
1. Warrantless Surveillance Is on Life Support, and That's the Best-Case Scenario
FISA Section 702 is the law that lets the NSA vacuum up foreigners' communications transiting through U.S. infrastructure. The FBI gets to search that database for Americans' messages without a warrant. Every renewal since 2018 has extended the authority. Every year, the reform coalition has lost.
This year, the coalition might win by default. The statute expires June 12. The House passed a three-year extension in April and tacked on a Central Bank Digital Currency ban to win conservative votes. The Senate called the CBDC provision a poison pill. Majority Leader John Thune killed it on the floor.[1]
Congress passed a 45-day punt on April 30. That punt runs out June 12, five days from now. The Senate still has no bill. Trump installed Bill Pulte, a housing-finance official with no intelligence experience, as acting Director of National Intelligence on June 2. Senate Democrats are threatening to block any reauthorization that doesn't include a warrant requirement.[1]
The most likely outcome is another short extension. The most interesting outcome is actual expiration. Even then, FISA Court certifications likely keep collection running through early 2027. The deadline is real. The expiration is mostly theater.
Why this matters: 702 is the legal backbone of the post-9/11 domestic surveillance system. Every other threat on this list rides on data flows that 702 made possible. If it lapses, even briefly, the entire edifice gets a stress test it's never had.
Read more: FISA 702 Expires in 7 Days: Three Scenarios for June 12, The 45-Day Extension and What Killed Reform.
2. DOGE Has Your Data. There's No Plan to Give It Back.
Elon Musk's Department of Government Efficiency walked into federal agencies in January 2025 with a mandate to cut costs. By February 2025, DOGE operatives had read-access to Treasury payment systems, the Office of Personnel Management, and (per a whistleblower's sworn declaration) a copy of the entire Social Security database on a thumb drive.[2]
The whistleblower, whose disclosure was reported by The Washington Post on March 10, 2026, said the data set included 548 million records drawn from two restricted SSA databases: the Numident (a comprehensive record of every Social Security number ever issued) and the Master Death File. The whistleblower alleged the data was stored in a cloud environment with no audit trail and no access controls, accessible to anyone on the DOGE team.[2]
By mid-2026, the situation has metastasized. The 19-state lawsuit, originally filed in February 2025 in the Southern District of New York to block DOGE's Treasury access, has dragged through a year of reversals: a federal judge blocked the access, the appeals court reversed, and in January 2026 the U.S. Supreme Court ruled 6-3 that DOGE could access Social Security data. Separately, SSA's own Chief Data Officer Chuck Borges resigned in August 2025 after filing a whistleblower disclosure documenting that DOGE had copied sensitive data to unauthorized Cloudflare servers while court orders were still in effect. House Democrats have called the SSA exposure "the largest data breach in our nation's history." Two DOGE employees have been referred for Hatch Act violations over an alleged voter-roll matching scheme.[3]
And the original access has not been revoked. DOGE teams are still embedded at SSA, Treasury, HHS, and the Department of Education. The data they copied is still out there, somewhere, on infrastructure no one outside the DOGE circle can audit.
Why this matters: This isn't a breach you can freeze your credit against. This is the government itself losing control of the data it holds about you, and then arguing in court that the loss isn't its problem.
Read more: The Whistleblower: 548 Million Records on a Thumb Drive, The 19-State Lawsuit, What You Can Actually Do About It.
3. ShinyHunters Have Stolen 1.8 Billion Records. They're Not Done.
One group. Three playbooks. Forty-plus confirmed breaches. Approximately 1.8 billion records.[4]
ShinyHunters started as a RaidForums crew in 2019. They've evolved into what Google Threat Intelligence Group tracks as three coordinated clusters: UNC6661 and UNC6671 for the break-ins, UNC6240 for the extortion. Four alleged members were arrested in France in June 2025. The group kept operating.
The 2026 campaign has been industrial. Canvas/Instructure: 275 million students' records. Carnival: 6 million passengers' passport data. ADT: 5.5 million customers. Charter Communications: 4.9 million. Kemper and McGraw-Hill: 13 million each. Rockstar Games: 78.6 million, via a supply-chain compromise of analytics vendor Anodot. The European Commission: a confirmed ShinyHunters victim. The Salesforce Experience Cloud misconfiguration alone netted them approximately 1.5 billion records across a thousand-plus organizations.[4]
The technique that keeps working is voice phishing. An attacker calls an employee pretending to be IT. They direct the target to a lookalike SSO domain. A live operator proxies the session in real time, capturing the session token. Push notifications, SMS codes, authenticator apps: all useless. Hardware security keys work. Almost no one has them.
TechCrunch published a "Worst Hacks of 2026" roundup on June 3. ShinyHunters dominated it.
Why this matters: This is what data-broker-fueled identity theft looks like at scale. When 1.8 billion records are in criminal hands, every breach becomes a credential-stuffing attack against every other service you've ever used.
Read more: ShinyHunters 2026: The Full Breach Tracker, The 16 Billion Passwords Breach Explained.
4. Meta's Smart Glasses Already Have Facial Recognition. They Just Haven't Turned It On.
In early June 2026, the EFF's Threat Lab confirmed via static code analysis that Meta has deployed facial-recognition code to millions of Ray-Ban and Oakley smart glasses currently in circulation. The feature is called "Name Tag." It converts faces in the camera's field of view into 2,048-number faceprint arrays, then matches them against the wearer's Facebook friends list. An EFF researcher manually activated the feature in debug mode and watched the glasses detect a known face in real time.[5]
Internal documents obtained by Wired and reviewed by EFF show Meta planned to launch the feature "during a dynamic political environment" (language the ACLU and 75 opposition organizations characterized as an attempt to launch while civil-society attention was elsewhere).[5]
Texas Attorney General Ken Paxton opened a civil investigative demand in May. The Texas AG's office is examining whether Meta's deployment violates the state's capture-or-use prohibition, which bars commercial use of facial recognition data without consent. Meta settled a similar BIPA case in Illinois for $650 million in 2024.[6]
The pattern is consistent: ship the code, get the hardware in people's faces, hold the activation until legal exposure is mapped. By the time anyone regulates it, the install base is too large to roll back.
Why this matters: Smart glasses are the only surveillance device most people will voluntarily put on their own face. The same threat model that made us skeptical of Clearview AI's database is now running on consumer hardware, in your local coffee shop, with no warning label.
Read more: EFF: "Move Fast, Surveil Things" (June 4, 2026), Texas AG Investigation, 64 Organizations Urge Congress to Block Name Tag.
5. Age Verification Is the Surveillance Creep of 2026
Age-verification laws were supposed to keep kids off adult websites. In 2026, they've become a generic identity-verification requirement, and the identity brokers selling the service have a track record of catastrophic breaches.
Discord rolled out global age verification in March 2026. Users in the U.S. and U.K. now have to submit to a face scan or upload a government ID to access the platform.[7] Discord's new verification partner is k-ID, which promises "immediate deletion" of identity documents after age confirmation. The previous vendor, 5CA, was breached in October 2025 by attackers who maintained access for 58 hours and stole at least 70,000 ID images. Some analyses put the exposure at 2.1 million ID photos.[7]
Australia passed a social-media age-verification law in 2025. The implementation has been messy: VPN downloads surged in the days after the law took effect as younger users routed around the verification entirely. The U.K. followed with its own Online Safety Act enforcement, with similar workarounds. Louisiana, Utah, and Connecticut have all passed state-level age-verification laws with no consistency on which IDs are accepted, which biometric vendors are approved, or what data retention rules apply.[8]
The end result is a fragmented identity-verification layer that collects faceprints and government IDs from teenagers, stores them at vendors most users have never heard of, and provides no clear data-deletion path, even when the vendors promise one.
Why this matters: Every age-verification mandate normalizes the idea that proving your age (and therefore your identity) is the price of using the internet. The infrastructure being built today for "is this user over 18?" will be the same infrastructure a future administration uses for "is this user a citizen?" or "is this user a protester?"
Read more: Discord's Age Verification Rollout (March 2026), Australia's VPN Surge, The Long-Term Surveillance Risk.
What the Back Half of 2026 Is Likely to Bring
Five threats, but they don't move in parallel. The calendar is the calendar.
June 12: FISA 702 expiration. Senate returns Monday. Emergency session, short extension, or actual lapse are all on the table. Whatever happens, the surveillance authority will be the most litigated and least reformed it's been in a decade.
July 1: Virginia's facial-recognition rules flip. Local police can start using the technology, but only under the model-policy framework set by State Police (each agency has to either adopt the model or publish an equivalent policy). Connecticut's privacy law amendments are also expected to take effect around the same date (watch for AG implementation guidance).
August 2: EU AI Act GPAI rules take effect. The first real enforcement test of the most aggressive AI regulation in the world.
October 1: Maryland's surveillance-pricing ban (HB 895), the first state law in the U.S. to prohibit dynamic pricing based on personal data, takes effect.
And somewhere in the second half, the next ShinyHunters campaign will land. The next DOGE lawsuit will be filed. The next smart-glasses rollout will ship with the face-recognition code already on board. The next age-verification mandate will require a new biometric, from a new vendor, with no retention guarantee.
The five threats above are not a forecast. They're a snapshot. The state of surveillance at the end of 2026 will be defined by which of these five keeps moving, and which gets caught by a court, a regulator, or a public that finally gets angry enough to act.
Sources
- FISA Section 702 procedural history: Politico reporting on the CBDC-rider standoff and the April 30 45-day extension; Congress.gov roll-call records for H.R. 8413 (the 3-year extension killed on the Senate floor).
- The Washington Post, "Ex-DOGE engineer allegedly copied SSA databases to a personal thumb drive" (March 10, 2026); SSA Inspector General notification to Congress, March 6, 2026.
- The 19-state lawsuit filed in the Southern District of New York, February 2025, to block DOGE's Treasury access; Government Accountability Project / Whistleblowers Blog disclosure by SSA Chief Data Officer Chuck Borges, August 26, 2025; U.S. Supreme Court ruling on DOGE SSA data access, January 2026.
- Google Threat Intelligence Group reporting on ShinyHunters / UNC6240 / UNC6661 / UNC6671, 2025-2026; TechCrunch, "The Worst Hacks and Breaches of 2026 (So Far)" (June 3, 2026); our ShinyHunters 2026 full tracker.
- EFF Threat Lab, "Move Fast, Surveil Things" (June 4, 2026); Wired reporting on internal Meta documents, May 2026; ACLU coalition statement, May 2026.
- Texas Attorney General civil investigative demand, May 2026; BIPA settlement reporting on the $650 million Meta–Illinois agreement (2024).
- Discord age verification announcement and k-ID partnership disclosure, February–March 2026; 9to5Mac, "Discord will soon require face scans or ID for all users" (February 9, 2026); our Discord age-verification deep dive.
- Australia eSafety Commissioner compliance reporting, 2025–2026; U.K. Ofcom Online Safety Act enforcement updates; Future of Privacy Forum state-law tracker for Louisiana, Utah, and Connecticut age-verification statutes.