The United States Capitol building dome under overcast skies
Photo via Unsplash

Today in Surveillance:

  • FISA 702: Five days left. Speaker Johnson's latest plan extends the warrantless spying program through 2029. No warrant requirement. Barely any new oversight. The House Rules Committee meets Monday. Privacy reformers say it's not enough.
  • UK Biobank data on sale in China. Health records for 500,000 British volunteers showed up listed on Alibaba. Three Chinese research institutions have been banned. The data includes age, gender, lifestyle habits, and biological markers.
  • Google broke its promise to a student. EFF says Google gave ICE a student's IP addresses, account data, and location information, without notifying him first, breaking the company's own published policy.
  • Seiko USA hacked and extorted. Attackers defaced the watchmaker's website, claimed they stole the entire Shopify customer database, and gave a 72-hour ransom ultimatum.
  • Connecticut passes AI bill. The state Senate voted 32-4 for sweeping AI regulation including suicide detection requirements for chatbots and mandatory disclosures when AI makes hiring decisions.

FISA 702: Johnson's Third Try at Warrantless Surveillance

Five days. That's what's left before Section 702 of the Foreign Intelligence Surveillance Act expires on April 30.

Speaker Mike Johnson revealed his latest proposal on Thursday, and privacy reformers are calling it a reheat of the same plan that already failed twice [1]. The bill would extend the warrantless surveillance program through 2029, three years, without the warrant requirement that a bipartisan coalition has demanded for nearly two decades.

Here's what Johnson is offering instead of real reform:

  • Monthly FBI "explanations" submitted to an oversight official (not a judge)
  • Criminal penalties for "willful abuse" (good luck proving intent)
  • Annual FISA training for FBI agents
  • Supervisor approval for searches targeting Americans in general criminal investigations

Rep. Jamie Raskin, D-Md., called it a "straight reauthorization" dressed up with cosmetic additions. Rep. Scott Perry, R-Pa., a Freedom Caucus member who helped sink the previous votes, said bluntly: "We're not there yet."

The Trump administration is pushing hard for a clean extension. Officials argue warrant requirements would "overburden law enforcement and endanger national security", the same argument they've used for every surveillance expansion since 9/11.

The House Rules Committee convenes Monday. If the bill moves to the floor, it needs to pass both chambers by Wednesday night. That timeline is extremely tight, and another failure could mean 702 actually lapses, which has never happened.

For context: Section 702 allows intelligence agencies to intercept communications of roughly 350,000 foreign targets abroad. The catch is that many of those targets talk to Americans, and the FBI can search that data without a warrant. The government says it's essential. The data says the FBI has repeatedly abused it.

Related coverage: FISA 702 Vote Stalls | The 10-Day Extension | The SAFE Act Alternative

Half a Million UK Health Records Listed for Sale on Alibaba

Health data from roughly 500,000 UK Biobank volunteers appeared on three separate listings on Alibaba, the Chinese e-commerce platform [2].

The data includes age, gender, lifestyle habits, and biological measures collected from volunteers who signed up for the long-running health research project. Names, addresses, and phone numbers weren't included, but UK Biobank admitted it "could not guarantee it would be impossible to identify individuals" if the data were combined with other sources.

Three Chinese research institutions have been permanently banned from UK Biobank's platform. The current theory: these institutions downloaded the full dataset to local storage, and through methods still under investigation, someone listed it for sale.

The UK government's National Data Guardian issued a statement. The listings were pulled from Alibaba before a sale was confirmed. But the damage to trust in research data sharing, which depends entirely on the promise that anonymized data stays anonymous, is done [3].

UK lawmakers are now calling for an outright ban on sharing medical research data with Chinese institutions. Whether or not the data was actually "anonymized" enough to protect anyone is a question that genetic researchers have been raising for years. This breach just proved them right.

Google Promised to Warn Users Before Handing Data to Cops. It Didn't.

In April 2025, ICE sent Google an administrative subpoena demanding data about Amandla Thomas-Johnson, a Ph.D. student and former journalist with British and Trinidadian citizenship [4]. Google handed over his IP addresses, physical address, account identifiers, and session information.

Thomas-Johnson's crime? Briefly attending a pro-Palestinian protest at Cornell University in September 2024 while on a student visa.

Google's published policy says it will notify users before disclosing data to law enforcement. It didn't. Thomas-Johnson got no warning and no chance to challenge the subpoena. As he told the EFF: the data fragments create "a detailed surveillance profile" revealing where he slept, when he was active online, and his daily patterns, without the government ever reading a single message.

The EFF has filed complaints with California and New York attorneys general, alleging Google engaged in deceptive trade practices. Thomas-Johnson, who had already fled to Canada and then Switzerland, learned about the disclosure after the fact [5].

This is what "if you have nothing to hide" looks like in practice. A student attended a protest. A federal agency demanded his data. A trillion-dollar company broke its own rules to hand it over. And now he's in exile.

Related: Google ICE Subpoena: Previous Coverage

Seiko USA Hacked: Attackers Deface Website, Demand Ransom

Visitors to Seiko USA's Press Lounge section over the weekend got a surprise: a page titled "HACKED" where press releases should have been [6].

The attackers claim they breached Seiko's Shopify backend and stole the entire customer database, names, emails, phone numbers, shipping addresses, order history, and account details. They issued a 72-hour ransom ultimatum and provided a specific customer account ID as proof.

Seiko hasn't confirmed or denied anything. The company removed the defacement message but hasn't responded to press inquiries from BleepingComputer or other outlets. No threat actor has claimed the attack publicly, and security researchers haven't been able to verify the claims independently.

If the Shopify data theft is real, this is a textbook supply chain risk scenario. Seiko's e-commerce runs through Shopify, meaning the attacker may have exploited Shopify API access or admin credentials rather than Seiko's own infrastructure. We've seen this pattern repeatedly, Booking.com's breach worked the same way, through compromised partner accounts.

Connecticut Senate Passes Sweeping AI Regulation Bill

Connecticut's Senate voted 32-4 to pass SB-5, a broad AI regulation bill that takes on several surveillance-adjacent issues at once [7].

The standout provisions:

  • AI chatbot suicide detection: Operators must make "reasonable efforts" to detect suicidal ideation and self-harm indicators, then respond with appropriate resources.
  • Employment transparency: Employers must notify workers when AI is used in hiring and employment decisions. Discriminatory use of AI decision tools is explicitly prohibited.
  • Frontier model regulation: Developers of large-scale AI systems face new compliance requirements, including participation in a state "sandbox" testing program.

The bill heads to the Connecticut House, which killed a similar measure last session. If it passes, Connecticut would join a growing list of states writing AI rules while Congress remains stuck on its own AI legislation.

The employment provisions matter most for surveillance. Automated hiring tools are one of the fastest-growing forms of workplace surveillance, tracking keystrokes, monitoring "productivity," and making firing decisions based on algorithmic scores that employees can't see or challenge. Connecticut is trying to require at least a heads-up.

Also Watching

  • Wyden-Daines surveillance transparency bill: The bipartisan Government Surveillance Transparency Act would force law enforcement to notify targets about surveillance orders and create a process for unsealing applications. Connects directly to our previous coverage and the Arctic Frost nondisclosure story from this week.
  • EDUCAUSE Cybersecurity & Privacy Conference: Starts Monday in Anaheim. Watch for announcements on higher education surveillance and student data protection.
  • Conduent breach deadline: April 30 is the last day to sign up for credit monitoring if your data was exposed in the Conduent breach. Don't wait.
  • Privacy Guides breach roundup: Privacy Guides published their weekly data breach digest covering April 17-23, flagging Kemper Corporation, Russell Cellular, and several healthcare breaches we haven't covered yet [8].

The Five-Day Clock

The FISA 702 deadline dominates everything right now. If Johnson's bill fails again, and it might, given Perry and other Freedom Caucus members still aren't on board. Congress faces three options: another short-term extension, letting 702 lapse for the first time ever, or cutting a deal with reformers that includes an actual warrant requirement.

We'll be covering every twist through April 30. The stakes are simple: whether the FBI can continue searching Americans' communications without judicial approval, or whether two decades of bipartisan pressure finally forces a warrant requirement into law.

Sources

  1. NPR, "After 2 failed votes, Mike Johnson unveils new plan to extend key U.S. spy powers" (April 24, 2026)
  2. Washington Post, "Health data of 500,000 members of a UK project offered for sale online in China" (April 23, 2026)
  3. The Register, "500k Biobank volunteers’ data listed for sale on Alibaba" (April 23, 2026)
  4. EFF, "Google Broke Its Promise to Me. Now ICE Has My Data." (April 2026)
  5. TechCrunch, "Clarifai deletes 3 million photos that OkCupid provided to train facial recognition AI" (April 21, 2026)
  6. BleepingComputer, "Seiko USA website defaced as hacker claims customer data theft" (April 2026)
  7. CT Mirror, "Amended AI bill passed by CT Senate after extensive questioning" (April 21, 2026)
  8. Privacy Guides, "Data Breach Roundup (Apr 17-23, 2026)" (April 24, 2026)