The United States Capitol building dome against a clear sky
Photo via Unsplash

Today in Surveillance:

  • COPPA deadline day. Starting today, apps collecting kids' biometric data need separate parental consent. The FTC says enforcement is a priority. We'll see.
  • FISA 702: 8 days. Congress is back from recess with no deal. The warrant requirement amendment is still the central fight. April 30 or the program lapses.
  • MSG tracked a trans woman for two years. Wired's investigation reveals James Dolan's security team compiled an 18-page dossier, tracked her bathroom breaks down to the second, and tried to keep her off camera. Her crime: being trans at a Knicks game.
  • Anthropic's MCP has a design flaw exposing 200,000 AI servers. OX Security found remote code execution vulnerabilities across the AI supply chain. Anthropic called it "expected behavior."
  • Scattered Spider hacker pleads guilty. Tyler Buchanan, 24, admitted to hacking Twilio, LastPass, DoorDash, and stealing $8 million in crypto via SIM-swap attacks.
  • Carnival cruise breach: 8.7 million records. ShinyHunters strikes again. The group set an April 21 pay-or-leak deadline. Carnival won't say if customer data was compromised.

MSG Built a Private Surveillance State. A Trans Woman Was One of Its Targets.

A Wired investigation published April 20 exposes the full scope of Madison Square Garden's facial recognition operation, and it's worse than the lawyer ban stories suggested [1].

Over two years, James Dolan's security team used cameras, facial recognition, and open-source intelligence tools to track a trans woman identified as "Nina Richard" (name changed for her safety). An 18-page dossier obtained by Wired shows security logged her every movement: which entrance she used, where she sat, when she entered and exited the bathroom, down to the second [2].

Why? According to former employees, MSG's chief security officer John Eversole wanted to keep her away from the players and off TV broadcasts. She posed zero security threat. She was a regular ticket-buying fan who happened to be trans [3].

The same system banned hundreds of others, lawyers suing Dolan, a graphic designer who sold anti-Dolan T-shirts, critics of any kind. MSG's surveillance network spans Madison Square Garden, Radio City Music Hall, and the Sphere in Las Vegas. MSG Entertainment calls the Wired story "false, misleading and unverified allegations" and says it's weighing legal options [4].

This is what happens when private companies deploy military-grade surveillance with zero oversight. No warrant needed. No probable cause. Just a billionaire with cameras and a grudge.

Related: MSG's Facial Recognition System | NYC Facial Recognition Ban Bills

COPPA Deadline Day: Your Kid's Face Is Now Legally Protected (In Theory)

Today, April 22, is the compliance deadline for the FTC's COPPA rule amendments. Every app, game, and website that collects data from kids under 13 now has new obligations [5].

The biggest changes:

  • Biometric data is now "personal information." Fingerprints, facial templates, voiceprints, gait patterns, all covered. Companies need verifiable parental consent before collecting any of it.
  • Separate consent for third-party sharing. Companies can't bundle data-sharing consent into general terms anymore. If they want to share a child's data with advertisers, they need a separate "yes" from parents.
  • Data retention limits. No more hoarding kids' data indefinitely. Companies must maintain written retention policies and delete data when it's no longer needed.
  • "Mixed audience" sites defined. The FTC finally defined what counts as a mixed-audience website, closing a loophole companies used to avoid COPPA entirely.

FTC Commissioner Mark Meador says "keeping children safe as they navigate a digital world" is a priority. Whether the current FTC actually enforces these rules against major platforms is the question that matters. The legal obligation exists starting today. The political will remains unproven [6].

Related: COPPA 2026: What the New Rules Change | COPPA 2.0 Passes Senate | Full COPPA Compliance Guide

FISA 702: Eight Days, No Deal

Congress returned from Easter recess this week with the April 30 Section 702 deadline looming and nothing resembling a plan [7].

The same dynamics that killed both the five-year and 18-month renewals are still in play. Twenty House Republicans refuse to vote for any extension without a warrant requirement for FBI searches of Americans' communications. The intelligence community is lobbying against it. The bipartisan Problem Solvers Caucus and the Wyden-Lee Government Surveillance Reform Act remain the best vehicles for reform, but leadership hasn't committed to bringing either to a vote [8].

Meanwhile, the program continues sweeping up communications from 350,000+ targets, "incidentally" capturing Americans' calls, texts, and emails along the way. The FBI's track record with this data includes warrantless searches on a sitting senator, journalists, 6,800 Social Security numbers, and 19,000 donors to a congressional campaign [9].

Eight days. Three options: reform with a warrant requirement, clean extension without reform, or the program lapses. The intelligence community wants option two. Privacy advocates are fighting for option one. Option three terrifies everyone in the national security establishment.

Related: The 2AM Vote | Bipartisan Reform Talks | Wyden-Lee Bill Analysis

Anthropic's AI Protocol Has a Remote Code Execution Flaw. They Called It "Expected Behavior."

OX Security published research on April 15 describing a design-level vulnerability in Anthropic's Model Context Protocol (MCP) that enables remote code execution on any system running a vulnerable implementation [10].

The numbers are staggering: 14 CVEs assigned, more than 200,000 AI servers affected, 150 million+ downloads across vulnerable packages. The flaw hits flagship AI products including LiteLLM, LangFlow, Windsurf, Cursor, Flowise, DocsGPT, and GPT Researcher [11].

The root cause: Anthropic's official MCP SDKs across Python, TypeScript, Java, and Rust take user-configurable values and pass them straight to shell invocations with zero sanitization. The trust model assumes configs are written by end users and are therefore safe. In practice, any attacker who can modify a config file gets arbitrary command execution [12].

Anthropic's response to the disclosure? Two words: "expected behavior." They confirmed the design is intentional and declined to modify the protocol, saying sanitization is the developer's responsibility. Coming two days after the Vercel breach showed what happens when AI tools become attack vectors, the timing is brutal [13].

Related: Full MCP Vulnerability Analysis | Vercel Breach via AI Tool

Scattered Spider Hacker Pleads Guilty to $8 Million Crypto Theft

Tyler Buchanan, 24, a Scottish national described as a ringleader of the Scattered Spider hacking group, pleaded guilty in a California federal court to conspiracy to commit wire fraud and aggravated identity theft. He faces up to 22 years in prison [14].

Buchanan admitted to launching tens of thousands of SMS phishing attacks in 2022 that breached Twilio, LastPass, DoorDash, Mailchimp, and other major tech companies. The group used those breaches to steal at least $8 million in cryptocurrency from individual investors [15].

He was arrested at Palma Airport in Spain in June 2024 trying to board a flight to Italy, and has been in U.S. custody since April 2025. He's the second Scattered Spider-linked defendant to plead guilty. Sentencing is set for August 21, 2026 [16].

Scattered Spider, also tracked as 0ktapus, remains one of the most prolific cybercrime groups operating today. Their playbook: SIM-swapping, vishing, and phishing kits that bypass multi-factor authentication. Multiple members remain at large.

Related: Full Coverage: Buchanan Guilty Plea

Quick Hits

  • Carnival cruise breach: 8.7 million records. ShinyHunters listed Carnival Corporation on its pay-or-leak portal on April 18, claiming theft of 8.7 million PII records. Carnival confirmed detecting a phishing incident affecting a single user account but won't say whether customer data was compromised. The April 21 leak deadline passed yesterday [17]. Our Coverage
  • DOGE appeals court: discovery reopens. The Fourth Circuit vacated the injunction limiting DOGE's SSA data access on April 10. But the district court immediately reopened discovery on April 14, meaning plaintiffs can now investigate the full scope of DOGE's data access, including that DOGE employee who signed an agreement to share SSA data with a political group trying to overturn elections [18]. DOGE's Privacy Lawsuits
  • Booking.com breach fallout continues. Users are reporting targeted phishing using their real reservation details after the April 13 breach. Booking.com forced PIN resets but still hasn't disclosed how many customers were affected. Over 4,000 confirmed, with credit card data exposed for 300 [19]. Our Coverage
  • NBC: facial recognition policing errors "on the rise." AI watchdogs told NBC News that wrongful arrests from facial recognition are increasing, not decreasing. At least 13 case dismissals nationwide. The latest: Angela Lipps, arrested at her Tennessee home by armed federal agents based on a facial recognition match to bank fraud suspects in North Dakota [20].

What to Watch

This week:

  • April 22 (Today): COPPA rule amendments compliance deadline. Watch for FTC enforcement signals or lack thereof.
  • April 28-30: EDUCAUSE Cybersecurity & Privacy Conference, Anaheim.
  • April 30: FISA Section 702 expires. Eight days.
  • April 30: Conduent breach credit monitoring signup deadline.

Coming up:

  • May 4: EU CSAR trilogue negotiations resume. The permanent replacement for expired chat control scanning.
  • May 4: Meta's $375M New Mexico verdict Phase 2.
  • July 1: Virginia facial recognition ban takes effect.
  • August 21: Tyler Buchanan sentencing.

References

  1. Democracy Now - Wired: Facial Recognition Used to Monitor MSG Fans
  2. Futurism - MSG Used Facial Recognition to Stalk Trans Woman for Two Years
  3. The Advocate - MSG Tracked Trans Woman's Movements Down to the Second
  4. Complex - MSG Owner Uses Surveillance to Spy on People
  5. Toy Association - Updated COPPA Rule Requirements Take Effect April 22
  6. Davis Polk - FTC Prioritizes COPPA Enforcement
  7. CNBC - Three Things to Know About FISA Section 702
  8. NPR - Congress Extends Surveillance Powers for 10 Days
  9. 5 Calls - Reform FISA Section 702
  10. OX Security - Critical Vulnerability at the Core of MCP
  11. The Hacker News - Anthropic MCP Design Vulnerability Enables RCE
  12. OX Security - MCP Supply Chain Advisory
  13. DevOps Daily - The MCP Design Flaw That Exposes 150M Downloads
  14. Krebs on Security - Scattered Spider Member 'Tylerb' Pleads Guilty
  15. The Record - British Hacker Tied to Scattered Spider Pleads Guilty
  16. The Register - Scattered Spider-linked Scot Pleads Guilty
  17. Cyber Insider - Carnival Corporation Probes Data Breach
  18. Nextgov - Appeals Court Removes DOGE SSA Limits
  19. BleepingComputer - Booking.com Breach Forces PIN Resets
  20. NBC News - AI Watchdogs Say Facial Recognition Policing Errors Rising

Last updated: April 22, 2026