Today in Surveillance:
- FISA 702: 9 days. Congress returns this week with no deal on warrant requirements. The Problem Solvers Caucus is pushing bipartisan reform. 20 House Republicans killed both the 5-year and 18-month renewals. April 30 or bust.
- COPPA compliance deadline hits tomorrow. New rules expand "personal information" to include biometric data like fingerprints, facial templates, and voiceprints. If your kid uses an app, the company now needs separate parental consent before sharing that data with third parties.
- DOGE used Grok to spy on federal employees. A TechPolicy.Press 100-day assessment reveals DOGE deployed Elon Musk's chatbot to monitor government workers' communications for criticism of Musk or Trump.
- McGraw Hill breach: 13.5 million records. ShinyHunters exploited a Salesforce misconfiguration. Student email addresses, names, physical addresses dumped online.
- Vercel breach fallout expands. Hundreds of organizations may be affected by the Context.ai supply chain attack. ShinyHunters claiming $2M for stolen API keys and source code.
- White House AI framework wants to preempt state privacy laws. The March 20 policy document calls for federal override of state AI regulations. Translation: weaker protections.
FISA 702: Nine Days, No Deal, No Warrant Requirement
Congress returns to Washington this week with the April 30 FISA Section 702 deadline staring them down, and nothing close to an agreement [1].
Here's how we got here: On April 17, 20 House Republicans revolted against leadership and killed both a five-year clean extension and an 18-month renewal that Trump personally backed. The only thing that passed was a 10-day Band-Aid, pushing the deadline from April 20 to April 30. Trump signed it the next day [2].
The bipartisan Problem Solvers Caucus is now the best hope for reform. They're pushing a warrant requirement for FBI searches of Americans' communications, the same amendment that tied 212-212 in the House in 2024 [3]. One vote short. The intelligence community is lobbying hard against it, arguing warrants would cripple the program. Privacy advocates say the FBI has already proven it can't be trusted with warrantless access, citing years of compliance violations including improper searches related to January 6 and racial justice protests [4].
Nine days. The same program that sweeps up 350,000+ targets' communications, and "incidentally" captures Americans' calls, texts, and emails, is running on borrowed time.
Related: The 2AM Vote That Bought 10 Days | Bipartisan Reform Talks | The Full 702 Fight
COPPA's Biometric Protections Kick In Tomorrow
April 22 is the compliance deadline for the FTC's COPPA rule amendments, and they're more significant than most people realize [5].
The updated rules expand what counts as "personal information" to include biometric identifiers: fingerprints, retina patterns, voiceprints, gait patterns, and facial templates. Any app collecting this data from kids now needs to maintain a written information security program and a written data retention policy. They can't hold children's data indefinitely anymore [6].
The big change: companies need separate verifiable parental consent before disclosing a child's personal information to third parties for purposes that aren't "integral" to the service. That targets the advertising pipeline, the entire business model of "free" kids' apps that monetize children's behavioral data.
Whether the current FTC has the appetite to enforce these rules is another question. But starting tomorrow, the legal obligation exists.
Related: COPPA 2026: What the New Rules Actually Change | COPPA 2.0 Passes Senate
100 Days of DOGE: Grok, Signal, and Monitoring Government Workers
A TechPolicy.Press assessment of DOGE's first 100 days details how Musk's team weaponized AI against federal employees [7].
The highlights are grim:
- DOGE deployed Grok: the chatbot built by Musk's xAI, to monitor federal employee communications for critical sentiment toward Musk or Trump. Workers who expressed dissent got flagged.
- DOGE fed Department of Education data into AI systems to identify programs for elimination. Not analysis by humans. By AI.
- DOGE members communicated over Signal with auto-delete enabled, according to depositions. Those records are gone.
- DOGE is building a centralized immigration database by merging data from IRS, SSA, and HHS for enforcement and deportations.
Meanwhile, the Fourth Circuit vacated the injunction limiting DOGE's access to Social Security data on April 10, even after a DOGE employee was caught signing an agreement to share SSA data with a political advocacy group trying to overturn election results [8]. The court said plaintiffs couldn't prove "irreparable harm." Four days later, the district court reopened discovery, meaning DOGE's full data access is finally getting investigated [9].
DOGE has a July 4, 2026 deadline to accomplish its goals. In 100 days, it cut 200,000+ federal jobs, accessed the personal data of hundreds of millions of Americans, and deployed surveillance tools against the government's own workforce.
Related: DOGE's 12 Privacy Act Lawsuits | How to Protect Your Data From DOGE
McGraw Hill Breach: 13.5 Million Records, and ShinyHunters Got Bored Waiting
Education giant McGraw Hill confirmed a data breach after ShinyHunters dumped over 100GB of data when ransom negotiations broke down [10].
The breach exploited a Salesforce misconfiguration in a third-party environment. The leaked data contains 13.5 million unique email addresses, with names, physical addresses, and phone numbers scattered across multiple files. McGraw Hill says its "core internal systems" weren't compromised, cold comfort for the 13.5 million people whose data is now public [11].
This is the same ShinyHunters crew currently selling alleged Vercel customer data for $2 million. Same group behind the TransUnion breach, the European Commission breach, and at least a dozen other Salesforce-linked attacks this year. The pattern: find misconfigured Salesforce instances, exfiltrate everything, extort the company, dump the data when they don't pay.
Related: Full McGraw Hill Breach Coverage | ShinyHunters' Salesforce Campaign
Vercel Breach: The First AI Agent Supply Chain Attack Gets Worse
The Vercel breach keeps expanding. On April 20, Vercel confirmed that attackers accessed internal systems after compromising Context.ai, an agentic AI evaluation tool used by an employee [12].
The attack chain, as detailed by CyberScoop: Lumma Stealer malware (disguised as Roblox cheats) infected a Context.ai employee. That gave attackers compromised OAuth tokens, which they used to hijack a Vercel employee's Google Workspace account. From there, they accessed Vercel environments and environment variables [13].
Vercel warned the compromise "potentially affecting its hundreds of users across many organizations." The ShinyHunters-affiliated group claiming responsibility says they have customer API keys, source code, and database records. Though the original ShinyHunters group denies involvement [14].
This is the first confirmed major breach caused by an AI agent tool. Context.ai was designed to evaluate AI model performance. It became the entry point for a supply chain attack that could ripple across the tech industry.
Related: Vercel Breach: Full Analysis
n8n Phishing Campaign: 686% Spike in Trusted-Domain Attacks
Cisco Talos published research showing attackers have been abusing n8n, a workflow automation platform, to deliver malware and fingerprint victims since at least October 2025. The volume of phishing emails using n8n webhook URLs spiked 686% between January 2025 and March 2026 [15].
The attack works because n8n's webhook URLs live on *.app.n8n.cloud, a trusted domain that corporate email filters wave through. Attackers embed these URLs in emails disguised as shared documents. Click the link, solve a CAPTCHA, and you're downloading malware. Another variant uses invisible tracking pixels to fingerprint every person who opens the email, silently collecting email addresses and device data [16].
The end goal: deploying remote management tools like Datto and ITarian for persistent access. It's the automation-as-a-weapon playbook, same theme as the Vercel breach, same lesson. Tools built for productivity become vectors for surveillance and attack.
Quick Hits
- White House AI framework wants to preempt state privacy laws. The March 20 National Policy Framework calls for Congress to override state AI regulations while preserving "traditional police powers." Law firms are calling it the most significant AI governance moment of 2026. The framework also prioritizes child safety and age verification, which means more biometric data collection, not less [17].
- Booking.com phishing follow-on hits users. After the April 13 breach exposed reservation data, users are reporting targeted phishing using their real booking details. The company forced PIN resets but declined to say how many customers were affected [18]. Our Coverage
- NBC: Facial recognition "Wild West." AI watchdogs told NBC News that policing errors from facial recognition are rising. This follows the 14th known wrongful arrest (Kimberlee Williams, 6 months in jail) and the ACLU coalition of 75 organizations demanding Meta halt facial recognition on Ray-Ban glasses [19]. Meta's Silence on FR
- DOGE depositions reveal Signal use. Washington Post reporting shows DOGE members regularly communicated via Signal with auto-delete enabled. A "club-like atmosphere" where they pushed grant and contract cancellations "with little oversight" [20].
What to Watch
This week:
- April 22 (Tomorrow): COPPA rule amendments compliance deadline. Watch for FTC enforcement signals.
- April 28-30: EDUCAUSE Cybersecurity & Privacy Conference in Anaheim.
- April 30: FISA Section 702 expires. Again. Nine days.
- April 30: Conduent breach credit monitoring signup deadline.
Coming up:
- May 4: EU CSAR trilogue negotiations resume. The permanent replacement for expired Chat Control scanning. Parliament wants encryption exemptions. The Council wants to scan everything.
- May 4: Meta's $375M New Mexico verdict Phase 2.
- July 1: Virginia facial recognition ban takes effect.
- July 4: DOGE's deadline to accomplish its goals.
References
- CNBC - Three Things to Know About FISA Section 702
- US News - Trump Signs FISA Extension Until April 30
- House GOP Revolt Sparks Bipartisan FISA Talks
- NPR - Congress Extends Surveillance Powers for 10 Days
- Toy Association - Updated COPPA Rule Requirements
- White & Case - Unpacking the FTC's COPPA Amendments
- TechPolicy.Press - 100 Days of DOGE
- Nextgov - Appeals Court Removes DOGE SSA Limits
- Democracy Docket - DOGE's Secret Voter Data Deal
- BleepingComputer - McGraw Hill Confirms Breach
- The Register - McGraw Hill Linked to 13.5M-Record Leak
- TechCrunch - Vercel Confirms Security Incident
- CyberScoop - Vercel's Breach Started With Malware Disguised as Roblox Cheats
- BleepingComputer - Vercel Confirms Breach
- Cisco Talos - The n8n n8mare
- The Hacker News - n8n Webhooks Abused for Phishing
- Consumer Finance Monitor - White House AI Framework
- BleepingComputer - Booking.com Breach Forces PIN Resets
- NBC News - AI Watchdogs Say Facial Recognition Errors Rising
- Washington Post - DOGE Depositions Reveal Signal Use
Last updated: April 21, 2026