Today's Top Stories:
- FISA 702 vote stalled. Three days until expiration. The House delayed its Wednesday vote after GOP holdouts refused to back a clean extension. Trump dragged them to the White House. It didn't work. The Rules Committee blocked a warrant amendment. No new vote is scheduled.
- 75 organizations told Meta to kill facial recognition on Ray-Ban glasses. The ACLU-led coalition warned the "Name Tag" feature would endanger abuse survivors, immigrants, and LGBTQ+ people. Meta hasn't answered the Senate's April 6 deadline questions either.
- McGraw-Hill confirmed a 13.5 million account breach. ShinyHunters exploited a Salesforce misconfiguration. The education giant says it wasn't "sensitive" data. The leaked files contain names, emails, physical addresses, and phone numbers.
- Virginia banned the sale of precise geolocation data. Governor Spanberger signed SB-338 on April 13. Takes effect July 1. Third state after Oregon and Maryland.
- Adobe breach claims: 13 million support tickets allegedly exposed. A threat actor called "Mr. Raccoon" says they went through an Indian BPO firm. Unverified, but security researchers are taking it seriously.
- Chime fintech breach spawns class action. The April 1 attack knocked 20,000 users offline and exposed personal data. Two lawsuits already filed.
FISA 702: Three Days Left. The House Still Can't Find the Votes.
Section 702 of the Foreign Intelligence Surveillance Act expires Sunday, April 20. The House was supposed to vote Wednesday. That didn't happen [1].
Here's how it fell apart: the Rules Committee approved a closed rule Tuesday night that blocked any floor amendment adding a warrant requirement for searching Americans' communications. That was the one thing GOP holdouts wanted. When they didn't get it, they told leadership they wouldn't vote for the bill. Speaker Johnson delayed [2].
Trump intervened directly, hosting Republican holdouts at the White House Tuesday night. Politico reported that the meeting didn't flip enough votes [3]. The irony is thick. Trump called to "KILL FISA" in a 2024 social media post. Now his administration is the loudest voice demanding a clean extension.
The math problem hasn't changed since yesterday's briefing. The Congressional Progressive Caucus has 98 Democrats locked against reauthorization without warrant reform. A dozen-plus Republicans on the libertarian flank agree with them. Johnson's majority is razor-thin. He can't lose more than a handful.
What happens if the deadline passes? Legally, Section 702 sunsets. The FISA Court has renewed surveillance procedures as a hedge, but the statutory authority ends. Intelligence agencies say existing surveillance orders remain valid through April 2027 under a one-year certification cycle. But new targets can't be added without reauthorization [4].
Three days. No vote scheduled. The Intercept reported Wednesday that Democratic leaders aren't even bothering to rally their caucus against it, they're sitting back and watching Republicans fight among themselves [5].
Related: House Vote Preview | The Section 702 Debate | Wyden-Lee Analysis
Sources: [1] CBS News, [2] Nextgov, [3] Military.com, [4] NPR, [5] The Intercept
75 Organizations Told Meta to Kill the Face-Scanning Glasses
The ACLU, the ACLU of Massachusetts, and the New York Civil Liberties Union led a coalition of 75 organizations in a letter to Mark Zuckerberg demanding that Meta abandon its facial recognition feature for Ray-Ban and Oakley smart glasses [6]. The coalition includes domestic violence organizations, LGBTQ+ advocacy groups, labor unions, and immigrant rights organizations.
The feature in question is called "Name Tag." Internal documents obtained by TechCrunch in February revealed that Meta engineers are building a system that would let wearers identify strangers in real time. One version identifies people you're already connected with on Meta platforms. The scarier version would recognize anyone with a public Facebook or Instagram account [7].
Think about what that means at a protest. At a domestic violence shelter. At an immigration hearing. At a drag show. Anyone wearing the glasses could point them at you and pull your name, your profile, your connections.
The coalition's letter laid it out: "Glasses equipped with facial recognition technology would allow anyone wearing them to identify by name any strangers in their vicinity." LGBTQ Nation reported that queer advocacy groups are specifically warning that the technology could be weaponized by stalkers and abusive partners [8].
Meta's response was corporate vapor: the company "does not currently offer facial recognition on its smart glasses" and would "take a very thoughtful approach before rolling anything out." Three senators gave Meta until April 6 to answer specific questions about the feature. Meta blew the deadline. No substantive response has arrived.
Related: 64-Group Coalition (March) | Senate Deadline Coverage
McGraw-Hill Lost 13.5 Million Records to a Salesforce Misconfiguration
Education publisher McGraw-Hill confirmed on April 16 that hackers accessed its data through a misconfigured Salesforce environment. The company downplayed the breach. The numbers say otherwise [9].
ShinyHunters, the same crew that just leaked Rockstar Games data: announced McGraw-Hill as a victim on its dark-web portal and gave the company until April 14 to pay up. McGraw-Hill didn't pay. ShinyHunters dumped over 100 GB of data containing 13.5 million unique email addresses, along with names, physical addresses, and phone numbers [10].
McGraw-Hill's statement called this "a broader issue involving a misconfiguration within Salesforce's environment impacting multiple organizations." Translation: the problem isn't ours, it's Salesforce's. The company insists its internal databases, courseware, and customer systems weren't touched [11].
ShinyHunters claims it holds 45 million Salesforce records. McGraw-Hill says 13.5 million. Either number is bad. If your kid uses McGraw-Hill textbooks or online courseware, assume the family email and home address are in that dump.
Sources: [9] Bleeping Computer, [10] The Register, [11] The Record
Virginia Just Banned the Sale of Your Location Data
Governor Abigail Spanberger signed SB-338 on April 13, making Virginia the third state to ban the sale of precise geolocation data. The law takes effect July 1 [12].
SB-338 amends Virginia's Consumer Data Protection Act. Previously, the law let companies sell your location data as long as they got your consent (buried in a 40-page terms of service nobody reads). The new version flatly prohibits selling it. No opt-in. No consent form. Just no [13].
The bill passed unanimously at every stage of the legislative process. That's rare for privacy legislation. It happened because location data has become politically radioactive. Data brokers sold location data that tracked people visiting abortion clinics after Dobbs. ICE bought location data from commercial brokers to track immigrants. The bipartisan consensus: this particular category of data is too dangerous to sell.
Virginia joins Oregon and Maryland. California, Connecticut, Massachusetts, and Vermont are considering similar bans during the 2026 session [14].
Sources: [12] EPIC, [13] Broadband Breakfast, [14] Consumer Reports
Quick Hits
- Adobe breach allegations are growing. A threat actor called "Mr. Raccoon" claims to have stolen 13 million customer support tickets, 15,000 employee records, and HackerOne bug bounty submissions by compromising an Indian BPO firm contracted by Adobe. The attacker reportedly used a RAT deployed via spear-phishing. vx-underground says the claims look legitimate but the breach appears limited to the helpdesk system. Adobe hasn't confirmed or denied it. Bleeping Computer | Cybersecurity News
- Chime's April 1 breach spawned two class action lawsuits. Team 313 hit the fintech platform, knocked 20,000 users offline, and allegedly stole PII. One plaintiff couldn't access his bank account to pay rent. The suit accuses Chime of falling short of FTC guidelines and NIST Cybersecurity Framework standards. ClassAction.org
- Kentucky added "automatic content recognition" to its privacy law. HB 692 passed the legislature and heads to the governor. ACR is the technology smart TVs use to watch what you watch, identifying content frame-by-frame and sending it back to advertisers. Kentucky now classifies it as sensitive data requiring explicit consent. Troutman Privacy
- ICE's Graphite spyware is still making news. Acting Director Todd Lyons confirmed to Congress that ICE is using the Paragon-built zero-click spyware to intercept encrypted messages. Rep. Summer Lee said ICE refused to answer who can be targeted or what legal authority they're using. WhatsApp previously disclosed that Graphite was used against 90 journalists in 2025. Our Coverage
- Congressional Black Caucus indicated support for FISA 702 reauthorization. The American Prospect reported the CBC is likely to back the clean extension, despite the program having been used to surveil BLM activists. The move could give Johnson enough votes if the bill comes back to the floor. American Prospect
What to Watch
This week:
- April 17–19: The House has two working days to schedule and pass a FISA 702 vote before Sunday's expiration. No vote is currently scheduled.
- April 20 (Sunday): Section 702 authority expires. If it lapses, existing surveillance orders stay valid through April 2027 under current FISC certifications, but no new targets can be added.
Coming up:
- April 28: San Jose's response to the Institute for Justice class action is due.
- July 1: Virginia's geolocation data sale ban takes effect. Virginia's facial recognition law also kicks in.
- August 2: EU AI Act reaches full enforcement.
References
- CBS News - Controversial Surveillance Program Faces Uncertain Future Ahead of House Vote
- Nextgov - House Readies Vote to Renew FISA 702 Without a Warrant Amendment
- Military.com - Trump Summons GOP FISA Holdouts as Spy Law Vote Stalls (April 16, 2026)
- NPR - Why Congress Is Fighting Over a Central Tool of American Surveillance
- The Intercept - Dem Leaders Aren't Even Bothering to Rally Caucus Against Trump Domestic Spying Powers
- ACLU - 75 Organizations Sound Alarm on Meta's Facial Recognition Plans
- PetaPixel - Meta Urged to Abandon Facial Recognition Plans for Ray-Ban Glasses
- LGBTQ Nation - LGBTQ+ Groups Warn Meta's Facial Recognition Smartglasses Could Harm Queers and Abuse Victims
- Bleeping Computer - McGraw-Hill Confirms Data Breach Following Extortion Threat
- The Register - McGraw Hill Linked to 13.5M-Record Data Leak (April 16, 2026)
- The Record - McGraw-Hill Data Leak Tied to Salesforce Misconfiguration
- EPIC - Virginia Governor Signs Bill Banning Sale of Precise Location Data
- Broadband Breakfast - Virginia Bans Sale of Precise Geolocation Data
- Consumer Reports - Virginia Governor Signs Landmark Location Privacy Bill Into Law