Today's Top Stories:
- FISA 702 was supposed to die today. Congress passed a 10-day extension at 2 a.m. on April 17 after both a 5-year and 18-month renewal failed. New deadline: April 30. Twenty House Republicans killed the long-term deal.
- A one-person watchdog board says 702 is fine. The PCLOB released its Section 702 review, authored by its sole remaining member after the Trump administration gutted the board. CDT and Brennan Center call it a rubber stamp.
- Chime got breached, class action filed. Team 313 hit the fintech on April 1. Twenty thousand users locked out. Two customers sued in Northern District of California within 48 hours.
- Virginia banned geolocation data sales. Governor Spanberger signed SB 338 on April 13. Data brokers can no longer sell your precise location. Six more states are next.
- Anthropic built an AI that finds zero-days everywhere. Claude Mythos Preview found high-severity vulnerabilities in every major operating system and browser. Anthropic won't release it publicly. Instead, 50 companies get access through "Project Glasswing."
FISA 702: Today Was the Deadline. Congress Ran Out the Clock.
April 20, 2026 was circled on the calendar for months. Section 702 of the Foreign Intelligence Surveillance Act, the law that lets the NSA collect communications of foreigners abroad and sweep up Americans' data in the process, was set to expire today [1].
It didn't. At 2 a.m. on April 17, Congress passed a 10-day extension after a chaotic overnight session where everything else failed. Speaker Johnson tried a 5-year renewal. Blocked by a dozen Republicans who wanted privacy reforms. Trump demanded a clean 18-month extension. Twenty House Republicans killed that too [2].
The new deadline is April 30. Congress returns next week to try again. Here's the scorecard:
- Democrats: Nearly all 98 Congressional Progressive Caucus members oppose renewal without "dramatic reforms"
- Republicans: Split between national security hawks who want a clean extension and privacy-minded members who want a warrant requirement
- The Reform Bill: The Government Surveillance Reform Act (Wyden-Lee-Davidson-Lofgren) would require warrants for querying Americans' data. It has bipartisan support but leadership won't bring it to a vote
- Ron Wyden told NPR he's "never seen this level of support on both sides" for real reform [3]
The documented abuses haven't changed. The FBI ran warrantless searches on a U.S. senator, journalists, 6,800 Social Security numbers, and 19,000 donors to a single congressional campaign. But intelligence officials insist the program stopped a terrorist attack at a 2024 Taylor Swift concert in Austria, a talking point that gets trotted out every time the vote gets close.
Eleven days. Same math problem. Different deadline.
Related: House Vote Fails | 10-Day Extension | Black Caucus Backs Extension | The Warrant Fight
PCLOB's One-Person Board Endorses Section 702. Critics Aren't Buying It.
The Privacy and Civil Liberties Oversight Board, the independent agency created specifically to check intelligence surveillance programs, released its Section 702 review on April 2. The verdict: the program "remains one of the country's most valuable tools" and recent reforms are working [4].
There's a catch. The PCLOB was designed to have five presidentially appointed, Senate-confirmed members. Right now it has one. The Trump administration's mass firings and refusal to fill vacancies left a single board member to evaluate the most controversial surveillance program in the country.
The Center for Democracy and Technology called the report's rosy conclusions into question, noting that a one-person board cannot meaningfully provide independent oversight. The Brennan Center published a point-by-point response highlighting what the report left out, including the FBI's track record of searching Americans' data without warrants [5].
The timing isn't subtle. Releasing a "the program is fine" report 18 days before a congressional vote on reauthorization, from a gutted oversight board, is the kind of thing that makes reform advocates reach for stronger language than "concerned."
Related: PCLOB Independence Crisis
Chime Breached, 20,000 Users Locked Out, Class Action Filed in 48 Hours
On April 1, a cybercriminal group calling itself Team 313 hit Chime Financial's servers. At its peak, 20,000 users couldn't access their money [6].
Within 48 hours, two Chime customers. Cindy Castaneda and Lauren Goodloe, filed a class action lawsuit in the U.S. District Court for the Northern District of California. The suit alleges Chime failed to protect customer data and banking access, violated the California Consumer Privacy Act, and breached its implied contract with users [7].
Chime isn't a traditional bank. It's a fintech that holds roughly $1.5 billion in customer deposits. When its systems went down, customers couldn't pay rent, buy groceries, or access their own money. For people who rely on Chime as their primary banking relationship, often lower-income customers without backup accounts, even a few hours of downtime creates real harm.
The lawsuit is in its earliest stages. No judge assignment, no discovery schedule. But the speed of the filing tells you something about how fast the class-action bar moves when a fintech loses control of customer data.
Virginia Just Made It Illegal to Sell Your Location Data
On April 13, Virginia Governor Abigail Spanberger signed SB 338 into law, amending the Virginia Consumer Data Protection Act to ban the sale of precise geolocation data. The law takes effect July 1 [8].
The details matter. "Precise" means within a 1,750-foot radius, a buffer large enough to keep data brokers from pinpointing where you live, work, worship, and shop. Virginia joins Maryland and Oregon as the third state with this type of ban.
Six more states are working on similar legislation: California, Connecticut, Massachusetts, Vermont, New Jersey, and Minnesota. Consumer Reports called the Virginia bill a "landmark," and EPIC praised it as a model for federal action [9].
This matters because location data is the backbone of the commercial surveillance economy. Data brokers like X-Mode (now Outlogic), Babel Street, and Near Intelligence have sold location data harvested from weather apps, prayer apps, and dating apps to government agencies including ICE, CBP, and the IRS, all without warrants. Virginia just cut off one pipeline.
Related: Virginia SB 338 Analysis
Quick Hits
- Anthropic won't release an AI that finds zero-days everywhere. Claude Mythos Preview discovered high-severity vulnerabilities in every major operating system and web browser, including a 17-year-old remote code execution flaw in FreeBSD. Instead of releasing it publicly, Anthropic formed "Project Glasswing" with 50 companies. Apple, Microsoft, Google, AWS, CrowdStrike, and committed $100 million in credits to fix critical software. Anthropic says the risk of misuse is too high for public release [10]. The surveillance angle: if one AI lab built this, others will too. And they might not be as careful.
- Oklahoma woman jailed 6 months on faulty facial recognition. The Washington Post reported on April 14 that Kimberlee Williams was arrested and jailed for months in Maryland for bank fraud, in a state she'd never visited. Police ran a surveillance image through facial recognition, got a false match, and never checked her alibi. She's the 14th known wrongful arrest from the technology. The ACLU is demanding policy changes [11]. Our Coverage
- Seattle limits World Cup camera surveillance. Mayor Katie Wilson directed the Seattle Police Department not to use the city's 62 CCTV cameras to monitor soccer fans during the 2026 FIFA World Cup unless there's a "credible threat." This follows the city council's 6-3 vote to deactivate the cameras and a separate ordinance limiting ALPR and CCTV data collection tied to immigration enforcement [12]. Our Coverage
- DOGE Privacy Act lawsuits hit 12 and counting. Federal judges have issued restraining orders blocking DOGE from accessing data at the Social Security Administration, Treasury Department, and OPM after finding likely Privacy Act violations. DOGE team members reportedly circumvented IT rules to share private records on outside servers [13].
- Navia Benefit Solutions breach: 2.7 million affected. The healthcare benefits administrator disclosed that hackers accessed names, SSNs, dates of birth, and health plan details between December 22, 2025 and January 15, 2026. Notification letters went out March 18. Class action investigations are underway [14]. Our Coverage
What to Watch
This week:
- April 21-25: Congress returns from weekend. FISA 702 negotiations resume with 5 business days before the April 30 deadline. Watch for a new reform proposal or another extension attempt.
- April 22: COPPA revised regulations compliance deadline.
Coming up:
- April 30: FISA Section 702 new expiration deadline. Eleven days.
- May 4: EU CSAR trilogue negotiations resume, the permanent chat scanning regulation.
- May 4: Meta New Mexico $375M verdict Phase 2 trial.
- July 1: Virginia geolocation data ban and facial recognition law take effect.
References
- NPR: Why Congress Is Fighting Over a Central Tool of American Surveillance
- NBC News: Senate Extends Surveillance Powers Until April 30
- NPR: Congress Extends Controversial Surveillance Powers for 10 Days
- PCLOB: Report on Section 702 Surveillance (2026)
- CDT: Key Takeaways From PCLOB Report
- ClassAction.org. Chime Data Breach Lawsuit
- ClaimDepot: Chime Financial Lawsuit Details
- EPIC: Virginia Governor Signs Bill Banning Sale of Precise Location Data
- Consumer Reports: Virginia Governor Signs Landmark Location Privacy Bill
- Anthropic: Project Glasswing: Securing Critical Software for the AI Era
- Washington Post: Woman Jailed for 6 Months After Facial Recognition Flagged Her
- KIRO 7, Mayor Katie Wilson Limits CCTV Use for 2026 World Cup
- NPR: Trump Administration Admits Even More Ways DOGE Accessed Sensitive Data
- HIPAA Journal: Navia Benefit Solutions Discloses Data Breach Affecting 2.7 Million