Close-up of a traffic surveillance camera mounted on a metal pole against an overcast sky
Photo via Unsplash

Today's Top Stories:

  • San Jose hit with federal class action over 474 license plate cameras. Three residents and the Institute for Justice filed April 15. The city keeps data for 365 days, passes searches along to ICE, and has let officers stalk ex-partners. The suit wants a 24-hour deletion rule and a Fourth Amendment ruling.
  • FISA 702 expires in four days. Still no House vote. Trump wants a clean 18-month extension. Speaker Johnson can't find the votes. The foreign targeting pool hit nearly 350,000 in 2025.
  • Monroe County becomes the latest jurisdiction to force sheriff's surveillance disclosure. Any purchase over $100,000 now requires quarterly public reporting.
  • ShinyHunters leaked Rockstar Games data after ransom deadline passed. 7.54GB of internal analytics, no player accounts. The attackers got in through Anodot, a third-party analytics vendor tied to Snowflake.
  • New York Senate passed the Facial Recognition Technology Study Act. S3699 creates a state task force to propose regulations. Governor Hochul still needs to sign.
  • Canada's NDP called for a federal ban on "surveillance pricing." Charging different people different prices based on their personal data.

San Jose's 474 License Plate Cameras Just Got Sued in Federal Court

On April 15, three San Jose residents (Tony Tan, Scott West, and Colin Wolfson) filed a federal class action lawsuit against the city over its automated license plate reader network [1]. The Institute for Justice is leading the case. The target is 474 cameras that photograph every vehicle that passes them and hold the data for 365 days.

Most cities that use ALPRs delete data within 30 days. San Jose keeps it for more than a year, then runs queries on behalf of anyone with access, including federal immigration agents. The complaint documents officers using the system to surveil protesters and run searches on ex-partners. None of that required a warrant. None of it required probable cause.

What the suit wants:

  • A ruling that mass ALPR surveillance violates the Fourth Amendment
  • A 24-hour deletion rule unless police obtain a specific warrant
  • An end to sharing ALPR queries with federal agencies without judicial oversight

This is the Institute for Justice's second swing at San Jose. A state-level lawsuit filed by EFF and the ACLU of Northern California in November 2025 is still working through California courts [2]. The federal filing opens a separate track aimed directly at the Supreme Court. IJ has said the goal is a binding federal ruling that applies nationwide.

That matters because San Jose's system is not an outlier. Flock Safety, Motorola Vigilant, and Axon have put ALPR cameras in thousands of American cities. Most operate under the same data retention rules San Jose uses. A federal ruling against San Jose would force every one of them to change.

Related: Colorado ALPR Warrant Bill | California Hidden ALPR Trailers

Sources: [1] Institute for Justice, [2] San José Spotlight

FISA 702: Four Days Left. Speaker Johnson Still Has No Plan.

Section 702 of the Foreign Intelligence Surveillance Act expires Monday, April 20. That is four days from today. The House has not scheduled a vote [3].

On April 15, Republican leadership punted again. Trump wants a clean 18-month extension with no reforms. Speaker Mike Johnson doesn't have the votes. The Congressional Progressive Caucus has locked in 98 Democrats against reauthorization without warrant requirements. A dozen-plus Republicans on the other flank are demanding the same [4].

The latest statistics from the Office of the Director of National Intelligence show why the stakes keep escalating: the number of foreign targets under Section 702 hit nearly 350,000 in 2025, up from 292,000 in 2024 [5]. Every one of those targets can pull in Americans who communicate with them: journalists, diaspora communities, humanitarian workers, business contacts. That pool is what the FBI has queried tens of thousands of times without a warrant.

Sen. Ron Wyden: "Journalists, foreign aid workers, people with family overseas, all could have their communications swept up in this surveillance merely because they talked to someone outside of this country."

EPIC and the Brennan Center are pushing a "Reform or Sunset" campaign. The Wyden-Lee Government Surveillance Reform Act would add warrant requirements and close the data broker loophole. It has bipartisan sponsors and zero chance of getting a floor vote before Monday.

Related: 19-Day Countdown | The Section 702 Debate | Wyden-Lee Analysis

Sources: [3] Common Dreams, [4] KSAT, [5] NPR

Monroe County Forces the Sheriff to Disclose Surveillance Purchases

The Monroe County Legislature passed a local ordinance on April 15 that forces the Sheriff's Office to file quarterly public reports disclosing any surveillance technology purchase over $100,000 [6]. The trigger is low enough to capture most real-world buys: Clearview contracts, Flock ALPR expansions, stingray upgrades, social-media monitoring tools.

Monroe County is home to Rochester. The move follows similar ordinances in San Francisco, Oakland, Cambridge, Seattle, New Orleans, and about two dozen other cities that have pushed community control of police surveillance (CCOPS) laws onto the books. The county-level version matters because most ALPR networks and aerial surveillance contracts sit at the sheriff's office, not the city PD.

What the ordinance does not do: require advance approval or community input before a purchase. Sheriffs can still buy anything they want. They just have to say so in the quarterly report. That's a weaker version than the strongest CCOPS laws, but it's something. Most surveillance contracts nationwide are signed with no public disclosure at all.

Full coverage: Monroe County Just Forced Its Sheriff to Show Receipts on Surveillance Spending

Sources: [6] Spectrum Local News

ShinyHunters Followed Through. Rockstar's Internal Data Is Out.

The April 14 extortion deadline passed without Rockstar paying. ShinyHunters leaked the files on April 15. The dump is 7.54 GB across 25 files: internal analytics reports, booking figures, regional performance tracking, virtual currency redemption data for GTA Online and Red Dead Online [7].

No player accounts. No unreleased GTA VI content. Rockstar's earlier statement about "limited non-material company information" was accurate. The breach itself is more interesting than what got leaked.

ShinyHunters compromised Anodot, an AI-powered cloud cost monitoring platform Rockstar used to manage its infrastructure [8]. From Anodot, they stole authentication tokens that gave them access to Rockstar's Snowflake environment. This is the same supply-chain pattern ShinyHunters has been running for months: hit a vendor, harvest OAuth tokens, pivot into customer cloud instances. Snowflake customers have been the primary target cohort.

If you're a CISO at a company that uses SaaS analytics tools plugged into Snowflake or similar warehouses, today is a good day to audit the OAuth grants and token lifetimes your vendors are holding.

Related: ShinyHunters SSO Campaign | Hims & Hers Breach

Sources: [7] HackRead, [8] Help Net Security

New York Senate Passed the Facial Recognition Technology Study Act

State Sen. James Sanders Jr. announced on April 15 that S3699 (the Facial Recognition Technology Study Act) cleared the New York Senate [9]. The bill creates a task force to study facial recognition use across New York State and recommend regulatory frameworks.

This is a weaker move than the outright moratoriums advocates pushed for. It doesn't stop police use. It doesn't stop retail deployment. It sets up a committee. But the composition of the task force matters: the bill requires seats for civil liberties groups, technology experts, law enforcement, and affected communities. That structure has worked elsewhere to build a legislative record that supports later restrictions.

The timing is notable. New York joins a growing list of states looking at facial recognition guardrails as the wrongful-arrest cases mount. Connecticut banned retail deployment in March. Virginia's new law takes effect July 1. The federal ICE Out of My Face Act is stalled in committee.

Governor Hochul has 10 days to sign once the bill hits her desk.

Sources: [9] NY State Senate

Quick Hits

  • Washington Post profiled Kimberlee Williams. A Black Maryland woman who spent six months in jail after a facial recognition mismatch. The piece landed April 14 and is driving a fresh round of coverage. Our Coverage | Washington Post
  • Meta facial recognition smart glasses got another 75-group coalition letter. LGBTQ+ groups, domestic violence organizations, and labor unions are asking Meta to kill the "Name Tag" feature on Ray-Ban and Oakley smart glasses. Meta has not responded substantively to a senate letter that demanded answers by April 6. Our Coverage | ACLU Coalition
  • Booking.com breach grows. Customers are receiving phishing messages referencing real reservation details. The company has confirmed unauthorized access to reservation data, contact info, and property-provider communications. Our Coverage
  • Canada's NDP asked the federal government to ban "surveillance pricing." The practice of using personal data and browsing history to charge different prices for the same item. Canada's privacy commissioner flagged the issue in February. No federal bill yet, but the party is pushing it into the 2026 platform [10].
  • pcTattletale founder avoided jail. Bryan Fleming, the first convicted commercial spyware maker in more than a decade, was sentenced April 10 to time served and a $5,000 fine. The Federal Trade Commission had banned him from selling surveillance software for life [11].
  • ICE's surveillance budget keeps climbing. Politico reviewed federal records showing more than $300 million in Trump-era ICE contracts for social media monitoring, facial recognition, license plate readers, and location tracking. Palantir's ImmigrationOS alone carries a $30 million price tag. Clearview AI's DHS contract can hit $9.2 million over two years. Our Arsenal Guide
  • A $238 million MQ-4C Triton surveillance drone crashed in the Persian Gulf April 9. The Navy confirmed April 14 after initial silence. Sensitive surveillance hardware is believed to be on the sea floor [12].

What to Watch

This week:

  • April 17–19: Last window for the House to schedule a FISA 702 vote before the Monday expiration.
  • April 20 (Monday): Section 702 of FISA expires if no reauthorization passes. FISC has renewed surveillance procedures to hedge against a lapse, but the legal authority ends.

Coming up:

  • April 28: San Jose's response to the IJ class action is due.
  • May 4: EU CSAR (child safety regulation) trilogue negotiations resume. The "Chat Control" scanning mandate is still alive.
  • July 1: Virginia's facial recognition law takes effect.
  • August 2: EU AI Act full enforcement (barring an Omnibus delay).

References

  1. Institute for Justice - Three San Jose Residents File Federal Class Action Lawsuit Over City's Mass Surveillance of Drivers (April 15, 2026)
  2. San José Spotlight - Another Lawsuit Targets San Jose's License Plate Cameras
  3. Common Dreams - 'This Fight Is Nowhere Near Over,' Privacy Advocates Warn After GOP Again Punts FISA Vote
  4. KSAT - Trump Urges Extending Foreign Surveillance Program (April 15, 2026)
  5. NPR - Why Congress is Fighting Over a Central Tool of American Surveillance
  6. Spectrum Local News - Monroe County to Require Disclosure of Sheriff's Surveillance Technology Purchases
  7. HackRead - ShinyHunters Leak Rockstar Games Data, No Player Records Impacted
  8. Help Net Security - Rockstar Games Receives "Pay or Leak" Warning After Cyberattack
  9. NY State Senate - Passage of Facial Recognition Technology Study Act
  10. VOCM - NDP Calls for Ban on Surveillance Pricing (April 15, 2026)
  11. TechCrunch - Convicted Spyware Maker Bryan Fleming Avoids Jail at Sentencing
  12. Pravda UK - MQ-4C Triton Surveillance Drone Lost in Persian Gulf