Today's Top Stories:

  • Citizen Lab blows open Webloc. The surveillance tool tracks 500 million mobile devices using ad data scraped from everyday apps. No warrant needed. Customers include ICE, the US military, and Hungarian intelligence.
  • Hungary used Webloc to spy on citizens before today's elections. Orbán's intelligence agencies renewed Webloc licenses in March, weeks before April 12 parliamentary elections. It violates GDPR. Nobody's enforcing it.
  • FISA 702 sunsets in 8 days. The SAVE Act circus is eating floor time. Trump won't sign any bill without it. Democrats won't vote for it. The math still doesn't work.
  • ICE hit 100,000 facial recognition scans. Mobile Fortify isn't just for immigration enforcement anymore. ICE agents used it to identify people at anti-ICE protests. American citizens.
  • Alabama becomes the 21st state with a privacy law. Unanimous vote. 104-0 in the House, 34-0 in the Senate. The lowest consumer threshold of any state: 25,000 people.
  • Perplexity AI sent your "incognito" chats to Meta and Google. A 135-page class action lawsuit lays out how the AI search engine embedded ad trackers that piped user conversations (including financial and legal queries) to advertising platforms.

Your Phone Ads Are a Government Spy Tool. Citizen Lab Has the Receipts.

On April 9, the Citizen Lab at the University of Toronto published research that should make you look at every app on your phone differently. The report details Webloc, a geolocation surveillance system that tracks up to 500 million mobile devices globally by harvesting data from consumer apps and digital advertising networks [1].

Here's how it works. The apps you use every day (weather, games, news readers) collect your location and device identifiers for advertising purposes. That data flows through ad exchanges. A company called Penlink (formerly Cobwebs Technologies) buys this data in bulk and packages it into a surveillance product that lets government agencies track anyone, anywhere, with no warrant required.

What Webloc customers can do:

  • Draw a geofence around any location and see every device that enters it
  • Track individual devices across locations and over time, up to three years into the past
  • Build movement profiles linking device IDs to personal characteristics harvested from ad data
  • Monitor entire populations at scale. Half a billion devices.

Who's buying: ICE, the US military, Texas Department of Public Safety, DHS, NYC district attorneys, and police departments in Los Angeles, Dallas, Baltimore, Tucson, and Durham [2]. In March 2026, 72 members of Congress called for an investigation into "warrantless purchases of Americans' location data" by ICE and other federal agencies.

The advertising industry built a global tracking infrastructure for the purpose of selling you shoes. Governments realized they could use it to track protesters, immigrants, journalists, and anyone else, without ever going near a judge.

Related: How Webloc Works | Congress vs. Penlink | Citizen Lab's Webloc Report

Sources: [1] Citizen Lab - Uncovering Webloc, [2] The Hacker News

Hungary Renewed Its Webloc Spy Licenses Weeks Before Today's Elections

The Citizen Lab report connects directly to Hungary, where Viktor Orbán's government has been secretly using Webloc since at least 2022, making it the first confirmed EU country to deploy the tool [3].

In March 2026, Hungary's Special Service for National Security (NBSZ) quietly renewed six Webloc licenses through Cobwebs Technologies. That was weeks before today's April 12 parliamentary elections. The timing raises obvious questions about whether Webloc was used to track opposition figures, journalists, or protest organizers in the run-up to the vote [4].

This is a GDPR violation in broad daylight. Mass geolocation surveillance of EU citizens using commercially acquired ad data, with no legal basis, no oversight, and no notification. Hungary's data protection authority has taken no action. The EU hasn't enforced anything.

VSquare.org's investigation found that NBSZ distributed Webloc and other Cobwebs tools to partner agencies across Hungary's intelligence and law enforcement community. The entire surveillance apparatus is running on Israeli technology that Citizen Lab has now mapped in detail.

Sources: [3] VSquare.org, [4] UNITED24 Media

FISA 702: T-8 Days. The SAVE Act Is Making Everything Worse.

Section 702 expires April 20. Eight days. And the political situation just got more tangled.

President Trump has made it clear he won't sign any legislation until Congress passes the SAVE Act, a voter ID bill requiring proof of citizenship to register to vote. Rep. Anna Paulina Luna (R-FL) announced she'll try to attach the SAVE Act to FISA reauthorization [5]. Her argument: "Voter ID is national security."

The math for Speaker Johnson was already broken. The Congressional Progressive Caucus (98 Democrats) won't vote for reauthorization without major reforms. A dozen-plus GOP holdouts want the same. Now add the SAVE Act: no Democrat will vote for it. Rep. Jim Himes (D-CT) told reporters: "Oh, hell no" when asked if he'd support a FISA bill with the SAVE Act attached [6].

Meanwhile, the Wyden-Lee Government Surveillance Reform Act sits there with bipartisan sponsors, warrant requirements, and data broker loophole fixes. It has zero chance of getting a floor vote.

The administration wants a clean 18-month extension to October 2027. No reforms. Privacy advocates at EPIC and the Brennan Center are pushing "Reform or Sunset." The FISC judge renewed procedures last week, hedging against a lapse. Nobody in Congress has a viable path.

Eight days. April 19 is a Sunday.

Related: 9-Day Countdown | SAFE Act Analysis | SAVE Act + FISA Collision

Sources: [5] Axios, [6] The American Prospect

ICE Used Facial Recognition 100,000 Times, Including on American Protesters

The Department of Homeland Security has used the Mobile Fortify facial recognition app in the field more than 100,000 times since launch, according to a lawsuit brought by Illinois and Chicago [7]. That app lets ICE agents snap a photo of anyone they encounter and run it against 200 million images stored in government databases. NEC Corporation built the technology [8].

But the 100,000 number isn't even the worst part. NBC News documented that ICE agents are now using Mobile Fortify not just for immigration enforcement but to monitor anti-ICE protests and identify American citizens attending demonstrations [9]. CBP signed a $225,000 Clearview AI contract. ICE's $3.75 million Clearview deal is its largest facial recognition purchase ever.

Rep. Bennie Thompson, ranking member of the House Homeland Security Committee, flagged the core problem: ICE officials told congressional investigators that a Mobile Fortify match is a "definitive" determination of someone's status, and that agents "may ignore evidence of American citizenship" when the app says otherwise.

The American Immigration Council published a "Mission Creep" report documenting how DHS has crossed from immigration enforcement into tracking Americans. EPIC is running a coalition campaign demanding ICE end field facial recognition entirely.

Related: Mobile Fortify Deep Dive | ICE Surveillance Arsenal | Congress vs. Penlink/ICE

Sources: [7] NBC News, [8] Biometric Update, [9] Democracy Now

Perplexity AI's "Incognito" Mode Wasn't. A 135-Page Lawsuit Explains.

A class action filed March 31 in San Francisco federal court alleges that Perplexity AI embedded Meta Pixel, Google Ads, Google DoubleClick, and Meta's Conversions API trackers directly in its code [10]. These tools allegedly piped user conversations (prompts, responses, email addresses, IP addresses, device information) straight to Meta and Google for ad targeting.

The data flowed even when users activated "incognito mode," which the lawsuit calls a "sham." One plaintiff shared details about his family's finances, tax obligations, investment portfolio, and legal questions with Perplexity. All of it allegedly went to advertising platforms.

Potential penalties exceed $5,000 per individual violation. The class covers all US users from December 2022 to February 2026. With millions of users over three-plus years, the financial exposure is enormous [11].

An "AI search engine" that promised privacy was actually an advertising data pipeline. If you used Perplexity for anything sensitive (medical questions, legal advice, financial planning) assume that data is sitting in Meta and Google's ad systems.

Related: Our Full Coverage

Sources: [10] MediaPost, [11] Android Authority

Quick Hits

  • Alabama becomes the 21st state with a comprehensive privacy law. The Alabama Personal Data Protection Act passed unanimously: 104-0 in the House, 34-0 in the Senate on April 7. It has the lowest consumer processing threshold of any state: 25,000 people. Businesses with fewer than 500 employees are exempt unless they sell data. Takes effect May 1, 2027 [12].
  • Crunchyroll breach hits class action stage. After a hacker exfiltrated 8 million support ticket records (6.8 million unique emails) through a compromised Telus contractor's Okta account in March, a class action now alleges Crunchyroll failed to implement reasonable cybersecurity measures. The hacker demanded $5 million. Crunchyroll never responded [13]. Our Coverage
  • CISA Chrome patch deadline is April 15, three days from now. Federal agencies must patch Chrome CVE-2026-5281, the fourth actively exploited zero-day this year. The exploit enables renderer process escape via WebGPU. Full Analysis
  • Fargo facial recognition wrongful arrest case continues. Tennessee grandmother Angela Lipps spent five months in jail after Clearview AI wrongly matched her face to a North Dakota bank fraud suspect. NBC News counts at least 13 case dismissals nationwide tied to facial recognition errors. Nearly all victims were Black [14]. State-by-State Roundup
  • Maine's consumer privacy bill stalled on a procedural vote. Kentucky, meanwhile, amended its existing privacy law to classify automatic content recognition as sensitive data [15].

What to Watch

This week:

  • April 15 (Tuesday): CISA deadline for federal agencies to patch Chrome CVE-2026-5281
  • April 20 (Sunday): FISA Section 702 expires. Congress hasn't scheduled a vote.

Coming up:

  • May 4: EU CSAR trilogue negotiations resume: the permanent encrypted message scanning regulation is still alive
  • May 4: Meta's $375M New Mexico verdict enters Phase 2
  • July 1: Virginia Facial Recognition Law takes effect
  • August 2: EU AI Act full enforcement (unless the Omnibus delays it)

References

  1. Citizen Lab - Uncovering Webloc: An Analysis of Penlink's Ad-based Geolocation Surveillance Tech (April 9, 2026)
  2. The Hacker News - Citizen Lab: Law Enforcement Used Webloc to Track 500 Million Devices via Ad Data (April 11, 2026)
  3. VSquare.org - Orbán's Spying Kit Revealed: Israeli Surveillance Tool Combined with Hungarian Technology
  4. UNITED24 Media - Hungary Deploys Israeli Webloc Surveillance Tool, Violating EU Privacy Regulations
  5. Axios - Trump's SAVE Act Push Creates New FISA Problem for Mike Johnson
  6. The American Prospect - Warrantless Spying Reform Just Got a Whole Lot More Interesting
  7. NBC News - How ICE Agents Are Using Facial Recognition to Bring Surveillance to the Streets
  8. Biometric Update - ICE Facial Recognition App Mobile Fortify Powered by NEC
  9. Democracy Now - ICE Agents Film Protesters as Part of Massive Facial Recognition Push
  10. MediaPost - Perplexity, Meta, Google Hit With Privacy Suit (April 2, 2026)
  11. Android Authority - Perplexity 'Incognito' Chats Might Not Be So Private, Lawsuit Claims
  12. IAPP - Alabama Set to Add Variation to US State Privacy Patchwork
  13. ClassAction.org - Crunchyroll Data Breach Class Action
  14. NBC News - AI Watchdogs Say Facial Recognition Policing Errors Are on the Rise
  15. Troutman Pepper - Proposed State Privacy Law Update: April 6, 2026

Last updated: April 12, 2026