Today in Surveillance:
- FISA 702 vote this week, maybe. The House is supposed to vote on Johnson's three-year warrantless extension before the April 30 deadline. GOP rebels and Democrats are both balking. Two days left.
- Your ad data is a cop's best friend. The Citizen Lab's "Uncovering Webloc" report shows how a single tool lets ICE, DHS, the U.S. military, and dozens of police departments track hundreds of millions of phones, all without a warrant.
- LAPD deploys AI crime cameras in Studio City. A private company's surveillance unit watches 24/7, and an algorithm decides what counts as "suspicious." Welcome to automated policing.
- ADT confirms 5.5 million records stolen. ShinyHunters breached the home security giant through a vishing attack on an employee's Okta account. Names, addresses, phone numbers, and in some cases, partial Social Security numbers.
- MSG tracked a trans woman for two years. Wired's investigation revealed James Dolan's security team used facial recognition to build an 18-page dossier, tracking her bathroom breaks down to the second.
FISA 702: The House Votes This Week. The Warrant Is Still Missing.
Section 702 expires on Thursday. The House is supposed to vote on it this week. And after two failed attempts, Speaker Johnson is going bigger: a three-year extension with no warrant requirement for searching Americans' communications [1].
The bill (H.R. 8035) does include some reforms. FBI agents would need internal attorney approval before querying Americans' data, and a larger pool of lawmakers would get access to FISA Court proceedings. Johnson called it "the most significant reforms to Section 702 in its history" [2].
Privacy advocates call it a rebrand of the status quo. The bill doesn't require a judge to sign off before the FBI searches Americans' calls, emails, or texts collected under 702. The ODNI's own report found the FBI ran roughly 3.4 million warrantless searches of U.S. persons in 2021 alone. That's the system Johnson wants to keep running.
The opposition is bipartisan. GOP hard-liners want stronger accountability. Democrats want an actual warrant. Sens. Mike Lee (R-UT) and Dick Durbin (D-IL) have a competing proposal that would require warrants and block agencies from buying Americans' data from brokers, but leadership hasn't given it floor time [3].
The math is brutal. Johnson needs near-unanimous Republican support just to pass the procedural rule vote. After the last two collapses, that's far from guaranteed. If the House can't pass something by Wednesday, the Senate would need to act before the April 30 expiration, or Section 702 goes dark.
Related: Johnson's Third Attempt: Full Analysis | What Happens If 702 Expires | Bipartisan Reform Talks
Citizen Lab Exposes Webloc: The Ad-Tech Tool Governments Use to Track Your Phone
Every time you open an app or visit a website, your phone broadcasts information about you to thousands of advertisers in a millisecond auction. Your device ID, IP address, location, demographics, browsing history, all blasted out so someone can show you a shoe ad [4].
A new report from the Citizen Lab at the University of Toronto, published April 26, reveals that a surveillance tool called Webloc taps directly into that advertising infrastructure. Instead of bidding on ads, it collects the data, tracking hundreds of millions of phones worldwide without installing anything on them. No spyware needed. Your ad data does the job.
The list of U.S. government customers is long: ICE, DHS, the U.S. military, Texas Department of Public Safety, and police departments in Los Angeles, Dallas, Baltimore, Tucson, and Durham. District attorneys in New York use it too. Webloc is now owned by Penlink, which acquired it from the original developer, Cobwebs [5].
Ron Deibert, Citizen Lab's director, told NPR the core problem: the technology "is being used in ways that clearly circumvent legal protections that protect citizens" without judicial authorization or oversight. No warrant. No probable cause. Just an advertising cookie trail that leads straight to your front door.
This is the data broker loophole in action. While Congress debates whether the FBI needs a warrant to search your emails under FISA 702, dozens of agencies are already tracking your physical location through ad exchanges, and nobody asked a judge.
Related: Citizen Lab: Webloc Tracks 500 Million Devices | ICE and Webloc | The Data Broker Loophole Explained
LAPD Deploys AI Surveillance Cameras in Studio City
After a string of burglaries in the San Fernando Valley, the LAPD installed a mobile AI surveillance unit at the intersection of Ventura Boulevard and Ethel Avenue in Studio City. The unit, built by private security company ACS Security, watches the area 24 hours a day, seven days a week [6].
Here's how it works: the AI distinguishes between animals, people, and vehicles. When the algorithm flags something as "suspicious," it sends an alert to a private call center. Human operators can then dispatch law enforcement in real time.
ACS Security says the system has already provided footage, information, and license plates that led to arrests. The LAPD requested the deployment and the company says the unit will remain "for the foreseeable future" [7].
The problems should be obvious. A private company's AI decides what's suspicious in a public neighborhood. The criteria for "suspicious" aren't public. The data retention policies aren't clear. And the whole thing happened without any public hearing or city council vote, the LAPD just asked a private vendor to park a surveillance tower on a public street.
This is the quiet expansion of AI-powered policing: not through legislation, but through vendor relationships. No new law authorized this. No civil liberties review approved it. Just a contract between a police department and a company that sells "intelligent monitoring."
ADT Confirms 5.5 Million Records Stolen After ShinyHunters Vishing Attack
ADT, the home security company whose whole pitch is "we protect you," confirmed on April 24 that hackers stole customer data including names, phone numbers, addresses, and, for some customers, dates of birth and partial Social Security numbers [8].
The breach started on April 20 when the ShinyHunters group used a voice phishing (vishing) attack to compromise an employee's Okta single sign-on credentials. From there, they accessed ADT's Salesforce instance and exfiltrated the data. ShinyHunters posted the data on their leak site on April 27, claiming 10 million records. ADT says 5.5 million unique email addresses were affected [9].
The attack vector is worth noting: vishing. A phone call. Someone called an ADT employee, convinced them to hand over credentials, and that was enough to access millions of customer records. No zero-day exploit. No sophisticated malware. A phone call.
This is the same crew behind the Vercel breach, the Kemper Corporation hit, and dozens of other Okta-based intrusions this year. ShinyHunters have turned Okta SSO into their favorite entry point, using social engineering to bypass multi-factor authentication one employee at a time.
ADT says no payment data was compromised and customer security systems weren't affected. The company is offering identity protection services to those impacted. If you're an ADT customer: assume your address and phone number are in criminal hands and act accordingly.
Related: ADT Breach: Full Coverage | ShinyHunters' Okta Campaign
MSG Used Facial Recognition to Track a Trans Woman for Two Years
Wired published an investigation on April 20 revealing that James Dolan's security team at Madison Square Garden used the venue's facial recognition system to surveil a transgender woman over a two-year period. They built an 18-page dossier. They tracked her movements through the arena, including bathroom entries and exits, timed to the second [10].
According to former MSG security staff, the chief of security ordered the surveillance specifically because she was trans. She posed no security threat. No one alleged she'd broken any rules. The system that was supposed to catch criminals was used to stalk a fan who committed the offense of existing while transgender in James Dolan's arena.
MSG also used the facial recognition system to ban hundreds of people from the venue, including attorneys involved in legal disputes with Dolan, a practice we've covered before. But the targeted surveillance of a trans woman takes it further. This is discrimination automated by facial recognition, carried out by a billionaire's private security force in a public-facing venue.
Related: MSG Wired Investigation: Full Coverage | MSG's Facial Recognition System
Quick Hits
- UK Met Police facial recognition ruling stands. A week after the High Court ruled live facial recognition lawful, Thompson's legal team confirmed they'll appeal. But the ruling clears the path for the government to expand from 10 to 50 facial recognition vans across England and Wales [11]. Our Coverage
- South Dakota passes genetic privacy law. Senate Bill 49, effective July 1, requires direct-to-consumer genetic testing companies to get "express consent" before using DNA data and publish privacy policies. It's narrow, only covers consumer testing, but it's a start [12].
- Deepfake social engineering attacks accelerating. Security researchers report a sharp increase in AI-generated voice clones used to impersonate executives and IT staff in live phone calls. It's the same vishing tactic that hit ADT, but with AI-generated voices that sound exactly like your boss [13].
- Angela Lipps spent six months in jail over a facial recognition mistake. The Washington Post reported on April 14 that Lipps was arrested by armed federal agents at her Tennessee home after facial recognition misidentified her in connection with bank fraud in North Dakota. She's at least the 13th known wrongful arrest from the technology [14].
What to Watch
This week:
- April 28-30: FISA Section 702 final push. The House vote could come as early as Tuesday. If it passes, the Senate needs to act before Thursday's expiration.
- April 30: Section 702 expiration deadline. If Congress fails, the program doesn't immediately shut down, existing orders run through April 2027, but the government can't compel new collection.
Coming up:
- May 4: EU CSAR trilogue negotiations. The permanent chat-scanning law is still on the table. Voluntary scanning expired April 3, but Big Tech is still doing it anyway.
- May 4: Meta's New Mexico trial, Phase 2, the $375 million children's privacy verdict.
- May 1: World Password Day. A good reminder that "password123" is not, in fact, a password.
References
- Spectrum News - House Set to Vote This Week on FISA Section 702 (April 27, 2026)
- NPR - After 2 Failed Votes, Johnson Unveils New Plan to Extend U.S. Spy Powers (April 24, 2026)
- The Hill - House Republicans Head Into Hell Week With FISA and Reconciliation (April 28, 2026)
- NPR - A New Study Shows How Ad-Based Technology Is Used for Surveillance (April 26, 2026)
- Connecticut Public - Uncovering Webloc: Ad-Based Surveillance (April 26, 2026)
- KTLA - AI Crime Cameras Surveilling Valley Neighborhood After Spike in Break-Ins (April 2026)
- ABC7 - New Mobile Surveillance Unit Installed Along Ventura Boulevard in Studio City (April 2026)
- BleepingComputer - ADT Confirms Data Breach After ShinyHunters Leak Threat (April 2026)
- Help Net Security - Hackers Claim Millions of Records Stolen in ADT Breach (April 27, 2026)
- Inc. - At the World's Most Famous Arena, a Complex Surveillance System Tracks Fans (April 2026)
- News from Crystal Palace - MP Questions After Met Win Facial Recognition Judicial Review (April 26, 2026)
- Clark Hill - Right To Know, April 2026 Vol. 40
- NBC News - AI Is Making It Very Easy for the Government to Spy on You (April 2026)
- Washington Post - Woman Jailed for 6 Months After Facial Recognition Flagged Her (April 14, 2026)
Last updated: April 28, 2026